Driverless cars: Who bears the risk?
- By Dr Martyn Taylor
- Aug 9
- 16 min read

A legal perspective on autonomous vehicles, insurance and liability
Liability is migrating up the value chain: When software drives a car, responsibility begins to shift from the individual driver to the organisations that design, operate, update and supervise the system. The driverless car is, in effect, an emerging test of how corporations govern software-controlled risk in the physical world.
Who bears the loss today, and who may bear it tomorrow: In Australia, personal injury from motor accidents is generally addressed through compulsory motor accident injury insurance schemes, but the more difficult question is who ultimately bears the loss. As automated systems spread, more disputes are likely to concern recovery, contribution and indemnity claims between insurers, manufacturers, operators and technology providers rather than driver negligence.
Different regulatory models: The United States enabled commercial robotaxi deployment through state regulation and that left liability largely to the courts. The United Kingdom channels compensation through insurers first, leaving questions of fault to later recovery. Australia proposes a national framework imposing in-service safety duties on a designated corporation, the Automated Driving System Entity (ADSE).
The near-term Australian risk is not robotaxis: Australian Consumer Law scrutiny can arise well before any fully driverless vehicle is available for ordinary use on a public road. Marketing claims may be scrutinised in relation to privately owned Level 2 automation (driver assistance under continuous human supervision) and the prospective introduction of Level 3.
Driverless cars in 2026
When a human driver causes a crash, the law asks whether the driver was negligent. When software performs the driving task, it asks a different question: which organisation should bear responsibility? For more than a century, liability has assumed a human driver. As that assumption becomes unsustainable, responsibility will move from the conduct of an individual driver toward the design, operation and supervision of the systems controlling the vehicle. Responsibility may extend beyond manufacturers to insurers, fleet operators, technology providers, and infrastructure owners responsible for safety-critical systems.
Automation has developed progressively, from driver-assistance features such as adaptive cruise control and lane keeping to systems capable of performing the driving task. The Society of Automotive Engineers (SAE) framework classifies automation from Level 0 (no automation) to Level 5 (full automation in all conditions). The first legally important transition is from Level 2, where the human continuously supervises the system and remains responsible for driving, to Level 3, where the system performs the driving task within defined conditions but may require a fallback-ready user to resume control when prompted.
At Level 4, the system performs both the driving task and the fallback within its operational design domain (that is, the specific conditions under which it is designed to operate, such as certain road types, speed limits, weather conditions, or geographic areas) without relying on a human driver.
Many driver-assistance systems available to consumers today, including adaptive cruise control combined with lane-keeping, operate at Level 2.

As of 7 August 2026, Waymo has commercially deployed Level 4 services within defined operational domains in a number of US cities. Waymo grew out of Google’s autonomous driving project and became one of the first operators to carry fare-paying passengers at scale with no safety driver in the vehicle. By early 2026 it was reported to be providing around half a million paid trips a week, with ambitions to expand further. Waymo’s operational footprint remains dynamic as service areas, highway operations and weather-related restrictions evolve.
Because a single corporate group develops the software, operates the fleet, maintains the vehicles, controls updates and supervises safety, the Waymo model resembles an airline or rail operator rather than private car ownership: the accountable party is identifiable, insurance can potentially be procured centrally, and litigation turns on whether the system was reasonably designed and supervised, rather than on the conduct of an individual. That is why centrally managed robotaxi fleets may be legally easier to scale than privately owned autonomous vehicles, which fragment responsibility across owners, designers and manufacturers, software providers, insurers and remote service providers.
Who is liable for driverless cars?
Traditional motor accident litigation is organised around the conduct of a human driver, with manufacturers liable mainly for product defects. Automated vehicles complicate that. Alternative questions may arise, including whether the system was defective, a sensor failed, mapping was inaccurate, the interface misled the user, or the operator managed the system unreasonably.
The focus of liability evidence may shift from reconstructing speed and reaction times to examining software architecture, update history and data integrity. The evidence that decides these questions usually sits with the party being sued.
Three features of autonomous vehicles make the problem of determining liability more difficult:
First, transitions of control are a recognised safety risk, because a user who has not been actively performing the driving task may have reduced situation awareness or readiness when asked to resume control. The United Kingdom, for example, has reallocated primary responsibility away from the user while authorised self-driving functions are engaged, subject to qualifications including transition demands and misuse.
Second, unlike conventional accidents, a defective software update may affect an entire fleet at once, creating aggregation and accumulation exposures materially different from conventional single-vehicle accidents. These continuously updated, networked vehicles also make the software version in control at the time of an incident a disputed issue, turn cybersecurity into a road-safety issue, and blur the line between accident, product defect and malicious interference.
Third, the reliance of automated vehicles on road markings, signage, digital mapping and other external inputs raises questions of causation, contribution and responsibility where an incident results partly from degraded infrastructure, inaccurate mapping or conflicting information.
Further complications also arise. Automated driving systems combine conventional engineering with machine-learning components whose behaviour is probabilistic: unlike traditional software that follows fixed rules, machine-learning systems make predictions based on patterns in training data, and their
behaviour across the full range of real-world conditions may therefore be difficult to anticipate. The same external situation may not always produce an identical system response, and behaviour can emerge in ways no engineer specifically designed or foresaw. That tests the orthodox rule that a defendant answers for the type of harm that was reasonably foreseeable, even if the precise manner was not.
Where a system behaves in a way nobody anticipated, courts will have to decide whether the result is an unforeseen manner of a foreseeable type of harm (for which liability would typically attach) or a different type of harm altogether (which could break the chain of liability). The answer will shape how far up the chain responsibility runs.
United States: State-led deployment and court-based liability
The United States was among the earliest jurisdictions to permit large-scale deployment of autonomous vehicles, yet it still lacks a comprehensive federal framework allocating responsibility for autonomous driving. Federal regulators set vehicle standards and investigate incidents, but fault, liability and compensation remain largely matters for state law and the courts.
Congress has repeatedly considered federal autonomous-vehicle legislation. Most recently, the House Committee on Transportation and Infrastructure approved H.R. 8870, the BUILD America 250 Act, on 22 May 2026; among other things, it would establish a federal framework for autonomous commercial motor vehicles. As of 7 August 2026 it had not passed the full House or the Senate. Until the BUILD Act passes, there is no comprehensive federal regime governing passenger vehicles or allocating civil liability, and the legislative framework in the United States remains predominantly state-based.
In that absence, the enabling work has occurred at state level: legislatures have redefined the driver, permitted operation without a person in the driving seat and created mechanisms for enforcing road rules against corporations. The resulting fragmentation allows states to experiment, but creates compliance complexity, and operators must navigate a patchwork of licensing, reporting and enforcement requirements. Liability is then largely resolved through existing product liability, negligence and insurance frameworks rather than a dedicated national compensation regime.
California illustrates the approach: driverless testing and deployment require authorisation from the Department of Motor Vehicles, while carrying passengers as a regulated commercial service also requires approval from the Public Utilities Commission. The model focuses on permitting, oversight and enforcement, leaving courts to determine responsibility after incidents occur. From 1 July 2026, California law enforcement officers may issue a formal notice of autonomous-vehicle non-compliance where a driverless vehicle allegedly contravenes applicable traffic rules, creating an enforcement mechanism for conduct that cannot be attributed to an individual driver.
United Kingdom: channelling claims through insurers
The United Kingdom has taken a different path, adapting its existing motor-insurance framework rather than building a new system. Under the Automated and Electric Vehicles Act 2018 (AEVA), a person injured by an automated vehicle while it is driving itself may claim directly against the vehicle's insurer; existing insurance rules are preserved when the self-driving function is disengaged and a human is in control.
The significance goes beyond continued compensation. An injured person need not work out whether a developer, manufacturer, operator or owner was responsible before being compensated: the legislation preserves the claimant's direct route to the insurer and moves the harder questions of fault into later recovery proceedings. Contributory negligence may reduce recovery, and liability may be excluded where an accident was wholly due to the injured person negligently allowing the vehicle to drive itself when it was inappropriate to do so. The Act also permits specified policy exclusions, as between insurer and insured, for prohibited software alterations or failures to install safety-critical updates.
The Automated Vehicles Act 2024 adds a fuller authorisation regime. A self-driving vehicle may be deployed only if authorised, and every authorised vehicle must have a designated Authorised Self-Driving Entity (ASDE), typically the manufacturer or software developer, responsible for how the vehicle drives and for ongoing compliance. Under the fully implemented regime, where a vehicle operates with no human available to take control, a licensed 'No User in Charge' (NUiC) operator will carry specified responsibilities for overseeing the vehicle's operation.
The 2024 Act is being implemented in stages, with full implementation intended for the second half of 2027. The early permitting scheme operates ahead of full commencement and does not yet bring the complete authorisation, ASDE and NUiC framework into operation. Part 5 was brought substantially into force on 15 May 2026, establishing the permitting framework for early automated passenger services, including taxi, private-hire and bus-like services operating without a human driver.
Permit applicants are subject to risk-based assessment and operating conditions addressing matters including safety, security and cyber-resilience. Several operators, including Waymo, Wayve and Uber, have announced plans for London trials and prospective autonomous passenger services, subject to permitting and regulatory approval. This approach spares injured parties from having to identify the responsible party within a complicated chain of developers and operators: insurers compensate first, and ultimate responsibility is settled later through recovery.
Australia: building a single national rulebook
In November 2025, Australia’s Transport Ministers agreed to allow the conditional deployment of automated vehicles from 2027 in selected locations in Australia, with full national readiness to follow. This timeline will depend on each Australian state and territory updating its legislation and building the necessary capabilities to support safe and lawful operation.
Until those changes are made, automated vehicles cannot lawfully be deployed for ordinary commercial use on Australian public roads outside existing trial or exemption arrangements. Existing road rules remain substantially organised around a human driver, and the existing first-supply framework under the Road Vehicle Standards Act 2018 (Cth) does not itself provide the complete in-service regulatory architecture required for automated driving.
However, Australia is attempting something different from both the United States and the United Kingdom. Rather than relying mainly on courts, insurers or existing doctrines to allocate responsibility after an incident, Australia will seek to identify in advance the corporate entity responsible under the regulatory framework for the in-service safety of an automated driving system.
Nationally coordinated reform led by the National Transport Commission (NTC) is built around a proposed Commonwealth Automated Vehicle Safety Law (AVSL) and a new national in-service safety regulator. The central feature of the AVSL is proposed to be the imposition of statutory responsibility for the in-service safety of the automated driving system on a corporation, the Automated Driving System Entity (ADSE), rather than the human occupant.
The ADSE will be subject to a general safety duty to ensure the safe operation of its ADS so far as is reasonably practicable, and will also be deemed responsible for driving the vehicle when the ADS is engaged. The ADSE may be, for example, the manufacturer or software developer, but could be any corporation that applies for the role under the framework. Accordingly, this answers in advance a question many jurisdictions have left to litigation: who is responsible when software is driving?
The AVSL would principally address in-service safety (that is, the ongoing safe operation of an automated vehicle after it has been supplied to the Australian market). The collection and use of connected-vehicle data would engage existing privacy, consumer and competition laws. For insurers, the existence of an ADSE would not eliminate uncertainty, but it would identify the corporation subject to the general safety duty and may provide a clearer focal point for investigation and any available recovery claims. Whether the ADSE becomes liable to an injured person or an insurer will depend on the enacted legislation, the applicable cause of action and the operation of the relevant state or territory accident compensation scheme.
As of 7 August 2026, the broad policy architecture is well developed but the legislative and implementation framework remains incomplete: the AVSL has not been enacted, and the detailed safety duties, regulatory powers and enforcement mechanisms remain under development. Criminal liability is a particular challenge, since many driving offences assume a human capable of intention, recklessness or negligence, requiring governments to determine which obligations should attach to the ADSE or another responsible entity, which should remain with a human user, and which require reform because they cannot sensibly apply where an automated system performs the driving task.
Australia - Compensation, responsibility and ultimate loss
Compensation and ultimate loss are two different things. There are three separate questions: first, who compensates the injured person initially (typically through Australia’s compulsory motor accident injury insurance (MAII) scheme; second, who is legally responsible for having caused the incident, and third, which participant or insurer ultimately retains the economic loss after all recovery and contribution claims have been resolved.
Instead of common law claims, compensation for personal injury from motor accidents in Australia is generally addressed through MAII, which comprise compulsory third party (CTP) schemes (whose structure, scope and operation differ materially between jurisdictions, variously incorporating fault-based, no-fault and hybrid models) and the National Injury Insurance Scheme.
CTP insurance is paid as part of annual vehicle registration. It protects the insured driver from liability arising from death or injury to a third party caused by a motor vehicle accident, and compensates the third party. In some jurisdictions it is paid to a statutory body and in others, a private insurer. The National Injury Insurance Scheme provides no-fault cover for persons who suffer catastrophic injuries in motor vehicle accidents, and who have not received a common law compensation payment. It is funded via a levy, premium or charge paid at the time of vehicle registration, either as part of CTP laws in some jurisdictions, and under special purpose laws in others.
The more difficult question is who ultimately bears the loss. Where an automated driving system rather than a human driver is alleged to have caused the harm, the entity that compensates the injured person (typically the insurer) may pursue recovery, contribution or indemnity claims against others in the chain. This may be done by subrogation (that is, the insurer steps into the rights of the person it has compensated to recover from the party at fault), though the existence and extent of those rights vary between jurisdictions and may be constrained by the design of a no-fault scheme. Potential targets for recovery will include manufacturers, importers, software developers and operators. Under the Australian Consumer Law (ACL), an importer may in specified circumstances be treated as the manufacturer.
Any recovery claim by an insurer will depend on the available evidence and the applicable cause of action, including the ACL safety-defect regime and negligence. The relevant motor-accident injury scheme will remain the principal compensation pathway, subject to its statutory scope and eligibility requirements, while liability for the ultimate loss may move, through recovery and only as far as the framework permits, towards the party responsible for a defective ADS.
Recovery will rarely be automatic: the difficult task may not be identifying a defendant but assembling the technical evidence, potentially including source code or model documentation, version histories, update logs and operational data. Cross-border structures and overseas witnesses will add to the legal costs, so that proving a defect against a global manufacturer may not be worth pursuing.
The proposal to identify an ADSE does however change the picture. The ADSE is intended to carry the statutory responsibility for the in-service safety of the automated driving system, providing a designated corporate entity against which the regulator can direct supervision and enforcement. That may also assist insurers by clarifying who controlled the driving system and held the relevant information, but it would not itself give an insurer a direct civil claim against the ADSE; a claimant would still need to establish an available cause of action, such as negligence or a breach of the ACL, against the ADSE, manufacturer or another participant.
The proposed scheme will simplify the pathway for injury claims. Motor-accident injury schemes are intended to be amended to compensate injured persons involved in ADS-caused crashes, consistent with the ministers' August 2019 decision that no person should be better or worse off if injured by an ADS-engaged vehicle than by a human-controlled vehicle. This means that an injured person would not be required to seek damages under the ACL for an unsafe or defective ADS, but could simply claim under the MAII scheme.
The National Transport Commission’s 2019 consultation paper indicated that more work was required to consider the adequacy of insurers’ rights of recovery against liable parties, and determine whether new mechanisms are required (such as a legislated right of recovery against the ADSE).

The most difficult disputes may arise between insurers rather than between claimants and defendants. A serious incident could engage motor vehicle, product liability, technology, cyber and directors' and officers' insurance programs simultaneously, making allocation, contribution and priority of cover almost as important as the underlying dispute (that is, which policy responds first and how losses are shared between insurers). As responsibility moves from driver conduct toward system performance, a greater share of serious losses may fall on those insurance programs alongside traditional motor cover.
Autonomous systems might in time reduce both crash frequency and injury severity while producing a smaller number of technically complex recovery disputes. What matters, in the end, is which party is best placed to prevent the harm, manage the risk and insure against it.
Australia - What happens if no one was negligent?
The hardest liability questions may arise where everyone appears to have done the right thing and harm nevertheless occurs: the manufacturer designed and validated the system appropriately, the operator deployed it responsibly, the vehicle or system had received the required regulatory authorisations and the occupant did nothing wrong, yet harm occurs through a combination of circumstances nobody anticipated.
Conventional negligence may provide no straightforward answer, particularly if reasonable care was taken by every identifiable participant. Other regimes may still respond without proof of negligence, including statutory product liability under the ACL, MAII arrangements and contractual warranties.
The remaining question is whether those regimes reach the particular loss and the defendant, especially for property damage and economic loss, and whether a mechanism exists to spread residual loss across those who benefit from the technology, whether or not any one participant was negligent.
The proposed Australian framework addresses part of the problem. For personal injury, and depending on the applicable jurisdictional scheme and its eligibility requirements, motor-accident injury insurance will provide an initial compensation pathway before every question of ultimate responsibility is resolved. In practical terms, this means an injured person may receive compensation relatively quickly though the MAII scheme without first having to prove the ADS was at fault, making autonomous vehicles easier to accommodate than many other forms of software-driven harm.
The ADSE framework would identify the corporation subject to the in-service safety regime, although whether economic responsibility attaches to the ADSE without proof of fault will depend on the final statutory and insurance arrangements.
The more difficult questions concern property damage, business interruption and pure economic loss, which fall largely outside CTP insurance and may require courts to apportion responsibility among multiple participants. Possible policy responses include mandatory insurance for higher-autonomy operations, sector-specific statutory liability and, potentially, no-fault pools funded by those who benefit most. In the meantime, through underwriting requirements, exclusions and audits, insurers may become one of the most significant sources of practical discipline, shaping how autonomous systems are designed and deployed long before courts rule on liability.
Australia - Practical implications
Organisations need not wait for fully autonomous vehicles to prepare; many of these issues already arise through driver-assistance systems, software updates and connected-vehicle technology. The following points are indicative and directed to Australian organisations; depending on the deployment, work health and safety, heavy vehicle, privacy, critical infrastructure and consumer law obligations may also apply:
Operators and fleet owners in logistics, resources and similar sectors should map their exposure across the testing, supply and in-service phases, monitor the locations and conditions in which deployment may be permitted from 2027, and identify which entity carries responsibility for the automated driving function at each stage; for heavy vehicles, chain of responsibility obligations may arise under the Heavy Vehicle National Law.
Manufacturers, importers and technology providers should assess whether they may seek, or be required, to assume the ADSE role, and separately evaluate their exposure under first-supply regulation, the ACL, negligence, contract and insurer recovery, without assuming an overseas model transfers directly. Under the proposed framework, a corporation must be certified as an ADSE by the in-service regulator before a first-supply approval can be issued for a vehicle with an ADS. The ADSE certification requirements contemplate that the corporation must have an Australian corporate presence capable of bearing civil and criminal liability.. Those requirements contemplate that the corporation must have an Australian corporate presence capable of bearing civil and criminal liability, although the final statutory implementation remains to be enacted.
Insurers should recognise that autonomous systems may redistribute rather than remove risk, and look beyond claim frequency and severity to concentration, accumulation and recovery risk. A single incident may engage motor, product liability, cyber, technology errors and omissions and directors' and officers' cover at once, so aggregation wording, cyber exclusions, software triggers and accumulation across common platforms deserve close attention.
Businesses involved in data and incident response should secure contractual rights to access, use, preserve, retrieve and disclose relevant vehicle and system data, including after an incident or termination, since important evidence may sit with the operator, manufacturer or technology provider, and should establish evidence-preservation protocols before the first serious event; where the deploying organisation is subject to the Privacy Act 1988 (Cth) and the relevant data is personal information, the Australian Privacy Principles may apply.
Boards and marketing teams should treat deployment of a safety-critical autonomous system as a board-level risk decision rather than a technology procurement, with oversight of software assurance, cyber resilience, operational safety, incident escalation and responsibility allocation among suppliers and operators; after a serious incident that oversight may be examined under directors' general duties, work health and safety laws and, where the entity or a relevant asset falls within its scope, the Security of Critical Infrastructure Act 2018 (Cth). Marketing claims about automated capability should be reviewed against the ACL, since overstating capability or understating the need for human supervision is a present risk.
Organisations that understand where responsibility sits, and how it can move between operators, manufacturers, software developers and insurers, will be better placed to manage both the risks and the opportunities of increasingly autonomous systems.
Transport is the test case for wider AI deployment
Autonomous vehicles are emerging as one of the first mass-market applications of AI to exercise operational control over safety-critical physical assets in open public environments at mass-market scale. Transport is therefore likely to become an early test case for wider AI deployment. Similar liability questions will arise wherever software is permitted to exercise operational discretion, including industrial automation, robotics, medical devices, logistics and critical infrastructure.
Accountability does not disappear when the human driver does. Rather, it moves toward the organisations that design, deploy, operate and insure the system. Driverless cars may therefore provide one of the first sustained tests of how courts, regulators and insurers allocate responsibility as consequential decisions pass from people to software.
Authored by Dr Martyn Taylor, Marcus Evans, Lucy Bruce Jones, Ray Giblett and Dietrich Marquardt
of Norton Rose Fulbright
Click to connect

Martyn’s practice covers transactional, contentious and advisory. He is a corporate and commercial lawyer and a well-known telecommunications, internet, media and technology (TMT), infrastructure/utilities, energy, competition and regulatory specialist.
Martyn has been endorsed as a 'top 10' TMT legal advisors in Asia. He is recommended by the key legal directories, including Best Lawyers.
Recent awards include:
Australian Law Firm Partner of the Year - Competition, Trade & Regulation, 2023
Australian Law Firm Partner of the Year - Commercial, 2016, 2017, 2019, 2021
Australian Law Firm Partner of the Year - TMT, 2016, 2017, 2018, 2020, 2022
Best Utilities Project (Global) – World Bank Partnerships Awards, 2022 (Ethiopian telecoms rollout)
M&A Deal of the Year – Australasian Law Awards, 2016, 2021 (Vodafone/TPG merger)
Best M&A Deal - Finance Asia, 2020 (Vodafone/TPG merger)
Asia-Pacific Telecoms Deal of the Year - IJ Global, 2015, 2020 (Kacific satellite launch)
Global Merger of the Year - Global Competition Review, 2015, 2020 (GSK/Pfizer JV)
Energy & Resources Deal of the Year - Australasian Law Awards, 2016 (Transgrid privatisation)
Telecommunications Infrastructure Deal of the Year - Asia-Pacific, 2016 (Myanmar telecoms rollout)
Martyn was also a finalist for 'Australian Deal Maker of the Year' in 2015, 2016 and 2019.


