The Tesla Cybercab began offering rides in Austin this month without a steering wheel, pedals, or a final Federal Motor Vehicle Safety Standard that covers its design. Tesla self-certified the vehicle under existing FMVSS rules, a process that allows manufacturers to declare their own compliance while the National Highway Traffic Safety Administration runs a separate administrative clock. NHTSA opened a safety audit within forty-eight hours of the launch, but the audit does not stop the rides. The gap between DOT's statutory amendment process, which moves at the speed of Congress and the Federal Register, and NHTSA's enforcement query, which moves at the speed of an engineering analysis, is not a bug in the system. It is the system. Tesla treats this friction as a product feature: deploy first, argue compliance later, and let the regulatory lag become market share.

Across the Atlantic, the European Union's AI Act has entered force with Articles 9 and 40 already enforceable, requiring "adequate" risk management and conformity assessment for high-risk AI systems including autonomous vehicles. But adequate to whom? The European standards body CEN-CENELEC, through its Joint Technical Committee 21, has published only a quality framework (EN 18286:2026). The risk-management standards that would give member states a shared baseline remain eighteen to thirty-six months away. The result is an interpretive gap: Germany, France, and the Netherlands must each decide what "adequate" means without harmonized guidance. The EU gap rewards a different kind of actor than the US gap. Where the American temporal gap favors deployers with high risk tolerance and a launch-first legal strategy, the European interpretive gap favors incumbents with compliance departments large enough to shape national interpretations before competitors can enter the market.

These gaps do not stay empty. Adjacent institutions colonize them. In the United States, state prosecutors are using criminal discovery to obtain data that NHTSA cannot reach through its civil subpoena power. At the United Nations, the Digital Governance working group is voting on federated AI auditability frameworks in precisely the space where EU standards remain unfinished. The colonization is predictable: when a regulator leaves a vacuum, other actors with different mandates, timelines, and thresholds of proof will fill it.

The usual framing is that gaps are failures to close. But for technologies that move faster than statute or standard can follow, the gap may outlast the technology it was meant to govern. FMVSS was designed for mechanical failure modes; the AI Act's drafters wrote for a conception of AI that is already two deployment cycles behind the current frontier. If the gap becomes the environment in which deployment decisions are actually made, then we are not regulating in spite of the gap. We are regulating through it, and the shape of the gap determines the shape of the market more powerfully than the text of the rule ever could.

What remains to be seen is whether any institution can make the gap itself visible enough to become a subject of politics, rather than merely a terrain for tactical advantage.

Sources
CEN-CENELEC Artificial Intelligence
EU AI Act (Regulation (EU) 2024/1689), Articles 9 and 40
NHTSA Opens Engineering Analysis into Tesla Full Self-Driving (Supervised)
Tesla Cybercab is already under NHTSA investigation after launch
US opens probe into Tesla self-certification of Cybercab robotaxis
US Regulator Examines How Tesla Certified Its Driverless Cybercab