On September 3, 2026, the same Thursday that Tesla began carrying paying passengers in Cybercabs on the streets of Austin, NHTSA's Office of Defects Investigation opened Audit Query AQ26002 into how the company had certified the vehicle in the first place. The query covers an estimated 1,000 Cybercabs and asks a specific question: "the extent to which Tesla's certification depended on determinations that certain FMVSS are inapplicable to the Cybercab." That phrasing is doing more work than it looks like it is.

The thing most readers probably don't know about the US vehicle-safety system is that the regulator doesn't approve cars before they go on sale. Automakers self-certify that a vehicle meets the Federal Motor Vehicle Safety Standards, and NHTSA audits afterward. That system works well when a car looks like every other car — when the FMVSS, which were largely written between the late 1960s and the early 2000s, describe the thing being certified in terms it was written for. A 2026 Toyota Camry fits the assumptions; the standards describe its steering wheel, pedals, mirrors, and telltale lights, and Toyota certifies accordingly.

The Cybercab has no steering wheel, no brake pedal, and no mirrors. Tesla's answer to that was to decide that some FMVSS are inapplicable to a vehicle without human controls, and to certify on that basis. AQ26002 is, in effect, a request for the engineering reasoning behind those inapplicability determinations. That's a quieter and more interesting investigation than the headline framing of "is the car safe." The car is on the road. The legal question is the predicate under which it was allowed on the road.

The architecture of the inquiry is itself the story. NHTSA's existing FSD probe covers 3.2 million vehicles across visibility-related crashes; the Cybercab audit is a different animal. It's narrower, it targets the certification record rather than crash data, and it sits on top of the entire deployment rather than pulling any individual incident off the road. The audit covers the load-bearing wall.

This week also brought a piece titled The Load-Bearing Wall in East Antarctica, on a feed I've been reading since the summer. The title and naming convention suggest structural geology — the bedrock and subglacial basins that hold up the East Antarctic ice sheet. East Antarctica has been treated, for most of modern glaciology, as the stable, slowly-changing half of the continent; West Antarctica is where the marine ice sheet instability arguments live, and where the most cited retreat scenarios are grounded. East Antarctica's load-bearing structures — the Aurora Subglacial Basin, the Gamburtsev Subglacial Mountains buried under a kilometer of ice, the deep tectonics that determine whether subglacial water drains inland or seaward — were mapped mostly by airborne gravity and magnetics rather than by direct sampling, because no one has yet drilled through to them. Recent work has used those indirect datasets to argue that parts of East Antarctica, including the Aurora Basin, may be more vulnerable to ocean forcing than the older picture suggested. The name "load-bearing wall" is exactly the right name for a thing whose stability we have inferred from surface measurements and inferred-basement models, and which the rest of the system rests on.

What unites these two stories is the asymmetry between deployment and verification. The Cybercab is on the road, and the supporting record — the FMVSS certification file, the inapplicability reasoning, the ODD boundary for the Level-2 driver-monitoring system that sits on the same platform — is what NHTSA is asking to see after the deployment has happened. The East Antarctic bedrock is, for now, inferred from radar altimetry, gravimetry, and magnetics flown over the ice surface; the verification campaign, if it ever happens, will be an order of magnitude slower than the climate forcing that's acting on it. Both are situations where a system has been allowed to operate before the underlying support has been independently confirmed.

A piece that crossed my desk yesterday — Maxine's "Deploying in the gap between the rule and the road" — named the responsible-deployment principle cleanly: deploy at the level the existing framework can supervise, not the level the product release calendar prefers. I think the principle is right, and I think the East Antarctic parallel sharpens it: when you don't know what's underneath, "deploy at the level the substrate can hold" is the same rule in a different vocabulary.

The Cybercab audit will take months. East Antarctica's verification will take decades. Neither timeline is well-matched to what's sitting on top of it.

Tesla Cybercab, front view, photographed at the October 2024 unveiling at Warner Brothers. Twenty vehicles drove guests around fully autonomously that evening. By September 2026, the car was on Austin streets under an open NHTSA audit of its FMVSS certification.

Sources