Comment on NHTSA ADS Incident Reporting (SGO 2021-01)
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- Self-reported ADS incident data suffers from definitional discretion, root-cause attribution bias, and software version opacity — the reporting entity controls what is reported.
- Three proposed verification mechanisms: periodic third-party audits, cryptographic software version attestation (paralleling SBOM requirements), and safety case cross-referencing.
- Extends the four-element conformance pattern from the Zoox comment into the incident reporting context.
+ Jump to Section
1. Support for Extension with Modifications
Box Commons supports the proposed three-year extension of the SGO 2021-01 information collection. Incident reporting for ADS and ADAS-equipped vehicles is essential to building the evidence base that regulators, insurers, standards bodies, and the public require to evaluate the safety performance of autonomous systems in real-world operation.
2. The Self-Reporting Limitation
The current SGO framework relies entirely on self-reporting by manufacturers and operators. A framework in which the regulated entity is the sole source of its own safety data creates an inherent verification gap that grows as ADS deployment scales.
The verification gap takes several forms:
(a) Definitional discretion. The SGO defines reportable incidents using criteria that leave the reporting entity to determine whether a given event meets the threshold. Without independent verification, underreporting is difficult to detect.
(b) Root-cause attribution. The reporting entity determines whether the ADS was engaged and to what extent the system contributed — with the strongest interest in the outcome of that determination.
(c) Software version opacity. ADS vehicles receive over-the-air updates that can change operational behavior between incidents. The SGO does not independently verify whether the software version reported at incident time matches the version actually deployed.
3. Independent Verification as a Complement to Self-Reporting
We propose three complementary verification mechanisms:
(a) Third-party audit of reported data. NHTSA could require periodic audits of reported incident data by independent conformity assessment bodies operating under ISO/IEC 17020 or ISO/IEC 17065, verifying that classification processes align with SGO definitions.
(b) Software version attestation. Reporting entities could include a cryptographically signed attestation of the software version deployed at incident time, verifiable against a manufacturer-maintained version registry. This parallels SBOM attestation already required under Executive Order 14028.
(c) Cross-referencing with published safety cases. Incident data could be systematically cross-referenced against assumptions in published safety cases (per UL 4600 and NHTSA's AV STEP framework). An incident falling outside the claimed operational design domain is categorically different from one falling within it.
4. Burden Considerations
Third-party audit is a periodic activity (annual or semi-annual), not a per-incident requirement, and the cost is de minimis relative to ADS deployment costs. Software version attestation requires signing infrastructure that most ADS developers already maintain for OTA update authentication. Safety case cross-referencing requires only that the reporting entity maintain the safety case it has already developed — the analytical burden falls on NHTSA, not the reporter.
This comment extends the four-element conformance pattern proposed in our April 9, 2026 Zoox comment (Docket No. NHTSA-2025-0523) into the incident reporting context.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Filings
Comment on NHTSA Zoox FMVSS Exemption Petition
Does not oppose Zoox's petition but proposes a four-element conformance pattern (published criteria, independent assessment, machine-readable attestation, continuous reporting) that NHTSA could condition any temporary FMVSS exemption upon, mapping to existing conformity assessment architectures.
FAR CouncilComment on FAR Semiconductor Prohibition (Case 2023-008)
Analysis of federal acquisition regulation changes and implications for AI data provenance in government procurement. Proposes credentialing mechanisms that verify both hardware provenance and AI behavioral safety for federal contractors.