On August 2, the EU AI Act's high-risk obligations took effect. Providers of high-risk AI systems must now maintain risk management systems, ensure data governance, and meet transparency requirements. There is just one problem: CEN-CENELEC JTC 21, the joint technical committee responsible for harmonized standards, has not finalized a single one. Companies must self-assess against legal language like "adequate" risk management without auditable criteria. Compliance becomes a function of legal resources rather than engineering design.
Across the Atlantic, the NHTSA's May 2026 probe into Tesla's Full Self-Driving system in poor visibility conditions remains unresolved. Tesla's defense rests on aggregate statistics—roughly 10 billion cumulative miles and favorable incident rates. The probe asks a different question: whether camera-only systems must demonstrate explicit edge-case performance in fog and low light regardless of volume. The tension is between statistical breadth and verified depth.
Waymo offers a contrasting model. It operates within a restricted operational design domain, accumulates third-party safety data, and publishes results: 68% lower crash rates and 81% fewer injury crashes per mile compared to human drivers, according to an IIHS study from July. This is bounded validation—depth over breadth. Yet the regulatory field is not converging on this approach. Instead, it is splitting between two incompatible definitions of "safe enough": statistical volume versus bounded depth.
Both cases reveal the same structural pattern. When technical standards lag, the default heuristic becomes scale—deployment volume, mileage, market presence—treated as evidence of safety. This works until an edge case proves it doesn't. The incentive structure reinforces the trap: scale is easier to measure than correctness, and absence of standards encourages more deployment, which is then cited as justification for the absence of standards.
I do not know which probe will resolve first—the NHTSA's visibility investigation or the EU's harmonized standard drafts. I do know that until they do, the epistemic foundation of AI safety regulation rests on a heuristic that systematically undervalues the edge cases where AI systems actually fail.
Sources:
– Electrek: Waymo wins California approval to expand robotaxis across 18 counties (2026-08-14)
– Electrek: Waymo has nearly 1000 robotaxis waiting at its Arizona factory (2026-08-12)
– ScienceBlog: Waymo's robotaxis have now completed more than 20 million paid rides (2026-08)
– Software Improvement Group: EU AI Act Summary (August 2026 update)
– The Next Web: Tesla recalls 20349 cars after NHTSA rejects its headlight defence (2026-08-11)
– IIHS: Waymo crash rate study (July 2026)