Skip to content
AFTER CERTAINTY
Skip to chapter text

No Time to ThinkPart III — Responsible Speed

Chapter 11 — The Missing Steering Wheel

About 11 mins
TextMedium

The Missing Steering Wheel

There is empty space where a steering wheel would normally be.

In a conventional car, the wheel is both control and promise. It says that a human body still stands between intention and motion—that someone present can interrupt the vehicle's path. Remove the wheel, and the cabin gains room. It also loses an old grammar of intervention. The absence is not only industrial design. It is an institutional question made physical: when something goes wrong, whose hand reaches for what?

In July 2026, the National Highway Traffic Safety Administration granted Zoox a temporary exemption permitting commercial deployment of purpose-built robotaxis without traditional human controls such as steering wheels, subject to the exemption's limits and applicable state and local approvals.1 Zoox had already offered free rides; the exemption opened a federal pathway toward charging customers once those additional permissions were in place. Safety standards written for human-driven vehicles do not map neatly onto vehicles without human drivers.

The regulatory mismatch is not incidental. Federal Motor Vehicle Safety Standards were built around a core assumption: a licensed human operator occupies the vehicle and can, at any moment, override its behavior. Steering system standards assume a wheel connected to a column connected to hands. Brake standards assume a pedal reachable by a foot. Many occupant-protection standards assume specific seating configurations designed around a person positioned to operate controls. When the human driver is removed from the active control loop, those standards either do not apply or apply awkwardly—designed for a vehicle architecture that no longer exists. Regulators have been working to address this since at least the mid-2010s. The Zoox exemption reflects genuine progress in that project: an acknowledgment that the old regulatory architecture cannot simply be layered onto the new design, and that new frameworks must be built from the actual control architecture of vehicles that have no driver to override.

Removing an old control can be rational when the system no longer uses it. Extra hardware can confuse, add failure modes, or create a false impression that a human recovery path exists when it does not. A steering wheel in a vehicle that passengers are not trained or authorized to drive can become theater—an object that looks like safety while offering no real authority. Designers are right to ask whether the inherited interface still matches the actual control architecture. Rules written for hands on a wheel cannot simply be pasted onto software that has no hand to give.

But the physical absence reveals a deeper question: when an automated system encounters something it cannot handle, where does intervention live?


What replaces the immediate human capacity to steer or stop?

The answer that autonomous-vehicle (AV) developers have converged on involves several overlapping mechanisms, each of which relocates the constraint differently. Remote monitoring and intervention: a human operator watching a fleet of vehicles from a central facility, able to send instructions to individual vehicles if they request guidance or enter an uncertain state. The operational design domain (ODD): a defined envelope of conditions—geographic boundaries, weather ranges, traffic environments, speed limits—inside which the system has been validated to operate and outside which it should not. Forced pullover: the ability of the vehicle to slow and stop safely when it encounters a condition its software cannot handle. Software limits: the parameters defining what the system will attempt and what it will refuse regardless of passenger instruction.

Each mechanism answers a different failure mode. The operational design domain answers the question of what conditions the system was tested for. Remote monitoring answers what happens when the system encounters something outside that domain. Forced pullover answers what happens when remote contact is unavailable or insufficient. Software limits answer what the system will decline to do regardless of how it is instructed.

What none of these mechanisms answers, in themselves, is whether the relocated intervention capacity is sufficient—whether it can act quickly enough, with enough context, and with enough authority to substitute for the person who used to be sitting at the wheel.


Remote monitoring illustrates the problem concretely. A human operator watching a fleet of vehicles from a remote facility is not providing the same form of oversight as a driver in a vehicle. The driver has continuous attention on one vehicle's environment and immediate physical access to the controls, without the network latency and interface mediation a remote operator must work through. The remote operator has attention distributed across many vehicles simultaneously, a latency between observation and response that depends on network quality, and authority mediated through software protocols that add steps between decision and action.

When a vehicle in the field encounters an unexpected road condition—a partial lane closure without advance signage, a pedestrian behavior outside the model's training distribution, a detour that reroutes through a previously unmapped street—the remote operator's ability to resolve the situation depends on the quality of the camera feeds, the data link latency, the interface design that allows the operator to understand what the vehicle is experiencing quickly enough, and the vehicle's own ability to hold its position safely while the operator assesses. These are solvable engineering problems at small scale. At the scale of ordinary urban infrastructure, a different question emerges: what is the ratio of operators to vehicles, and does that ratio provide genuine oversight capacity for the actual volume of edge cases the fleet encounters?

If one operator monitors a hundred vehicles, their ability to give any single vehicle focused attention when it needs it is constrained by what is happening with the other ninety-nine at the same moment. A busy afternoon in a dense urban area is not the same demand profile as a light weekend morning in a geofenced test zone. The constraint has been relocated from the driver's seat to the control room. Whether the control room is staffed for the peak volume of exceptions that the fleet actually generates is not a question the technology answers. It is a question about organizational design—and about whether the operational pressure to reduce cost per vehicle trip will be applied to remote-operator staffing ratios before the edge-case distribution at scale is fully understood.


The operational design domain is the formal answer to the question of what the system was tested for. A vehicle operating within its ODD is operating inside conditions the developer has evaluated against the system's capabilities. Outside the ODD, the system should not operate, or should stop operating and wait for a situation to resolve. The ODD is in this sense structurally similar to an aviation checklist's scope: a defined boundary inside which a systematic approach has been validated, outside which a different response is required.

That analogy also reveals the ODD's limits. A checklist's scope is visible in the procedure itself—the crew can see when they are doing something the checklist does not address and know they are in a different mode. An AV's ODD boundary is embedded in software, not always visible to passengers, and not always cleanly separable from the ambiguous conditions of real roads. The defined weather exclusion might specify adverse weather without specifying the precipitation intensity at which that exclusion applies. The defined speed limit range might exclude high-speed roads without specifying how the vehicle should behave when traffic speeds exceed the range. These boundary conditions are real engineering and regulatory challenges. They matter not because they make autonomy impossible but because they define the residual cases that must be handled by some other mechanism—remote operator, forced pullover, the passenger calling for assistance, or the vehicle holding position until a condition resolves itself.

Every deployment that operates successfully within its ODD does not prove that the ODD boundary is correctly set for ordinary infrastructure. It proves that the conditions encountered in that deployment fell within the tested range. Even a system that has operated successfully over two years of limited free rides has demonstrated performance only in the conditions those rides encountered. It has not demonstrated performance in the full range of conditions that a permanent priced service would encounter across all weather, all traffic patterns, all times of day and night, including the rare events that occur once every several thousand trips and are consequential when they do.


The transition from pilot deployment to ordinary infrastructure is the moment when the evidence calculus changes most sharply. A pilot can remain experimental because participants know it is experimental. They treat the service with the attention of people who know they are involved in something being demonstrated. Operators and developers watch closely. Problems are data.

Ordinary infrastructure does not carry that framing. Once a service is priced, scheduled, and integrated into how people travel regularly, both the public and the organization begin to treat it as background. The service becomes part of the transportation environment rather than an observation of it. Failures are no longer data points in a test; they are disruptions to infrastructure. The accountability that was concentrated during free rides—every incident scrutinized, every engineer paying attention—becomes distributed. Commercial pressure to expand coverage, increase utilization, and reduce cost per trip applies to operations that were previously run as demonstrations.

This transition has a long precedent in other domains. Early commercial aviation was watched carefully by its designers, regulators, and the public, precisely because it was understood to be new. The systems that became ordinary infrastructure over subsequent decades were not watched in the same way, because they were no longer new. The industry had, by then, built the institutional apparatus that substituted for careful watching: the checklists, the sterile cockpit rule, the anonymous reporting system, the independent accident investigation. The question for autonomous vehicles is whether the equivalent institutional apparatus is being built in parallel with deployment—or whether deployment is being used as the test, and the apparatus will be designed from what the test reveals.


Responsibility, in the absence of a driver, distributes across designers, operators, regulators, and the public in ways that have limited precedent. A driver in a human-operated vehicle can be held responsible for the vehicle's behavior under most conditions—they chose to drive, they were present, they retained physical capacity to intervene. A passenger in a robotaxi who has no controls and cannot intervene is not responsible in the same sense. The software developer, the deployment operator, the regulator that approved the design, and the municipality that permitted the service all hold parts of what was previously unified in one licensed human.

Distributed responsibility is not the same as no responsibility. But it can become, in practice, a situation where no single party has full visibility into what the system is doing across its full range of conditions, and no single party has the authority to stop it before an edge case becomes a consequence. Designers are responsible for what they built and tested. Operators are responsible for deployment within approved conditions. Regulators are responsible for defining those conditions. Each actor's authority and information is partial. The integration of those partial responsibilities into something that functions like a unified stop authority—that can act quickly, with sufficient context, before consequences arrive—is the institutional design problem that the missing steering wheel poses.


This chapter is not an argument against robotaxis. Autonomy can reduce certain categories of human error, expand transportation access for people who cannot drive, reduce exposure to fatigue-related crashes and other occupational driving risks, and provide service in conditions where human-driven alternatives are scarce. The diagnostic point matches the rest of the book. An old bottleneck—the human driver—can be redesigned away. The scarce work then moves into validation, monitoring, edge-case handling, regulatory interpretation, maintenance of the autonomy stack, the design of remote oversight that functions at fleet scale, and the institutional architecture for stop authority that no longer lives in any passenger's hands.

If those forms of work are treated as temporary launch costs rather than permanent operational capacity, the empty space where the wheel was becomes a metaphor for a missing institutional control as well as a missing physical one. The cabin looks freer. The system is freer only if interruption still has somewhere to live—someone who can act on what the system cannot handle, with enough time and enough authority to act before what cannot be handled becomes consequence.

Deployment compounds the problem in a predictable way. A pilot can still feel experimental, can still carry the careful attention of a team that knows it is building evidence. Ordinary infrastructure does not feel that way. Once a service becomes background—priced, scheduled, and depended upon—the public and the organization both stop watching as carefully. That is often the defining feature of successful technology: it becomes invisible. It is also when insufficient stop authority becomes hardest to notice, because nobody is watching for it anymore. Until an edge case arrives that the old wheel would have made interruptible by someone present, and the new architecture has to prove that interruption still lives somewhere real, with enough attention and authority to act before consequence arrives.

By this point in the book the sequence should be recognizable. Make a step faster, cheaper, or unnecessary. Watch the constraint move. Ask whether the new location of judgment is staffed, visible, and interruptible. The missing steering wheel is that sequence rendered in metal and air.

The vehicle has more room because the wheel is gone. The empty space asks who can interrupt it now.

Footnotes

  1. National Highway Traffic Safety Administration, "Zoox—Grant of Temporary Exemption From Portions of Various Requirements of the Federal Motor Vehicle Safety Standards for an Automated Driving System-Equipped Vehicle," 91 Fed. Reg. 48494 (July 31, 2026), https://www.federalregister.gov/documents/2026/07/31/2026-15485/zoox-grant-of-temporary-exemption-from-portions-of-various-requirements-of-the-federal-motor-vehicle. Temporary Exemption No. 2026-01, effective July 31, 2026 through July 31, 2028; up to 2,500 exempted vehicles per 12-month period for commercial deployment; vehicle lacks manually operated driving controls. Secondary report: Josh Funk and Ty ONeil, Associated Press, July 30, 2026, https://apnews.com/article/1bdb3bb8ecc80a23721504315cfa50ce.