Removing a familiar control changes more than the interface. It changes what a person can do when something unexpected happens. That is an engineering question for a vehicle and an operating question for any business delegating consequential actions to software.

What happened

On 4 September 2026, the US National Highway Traffic Safety Administration opened an Audit Query into Tesla’s self-certification of its Cybercab against federal motor vehicle safety standards, following commercial deployment in Austin. The announcement concerned an investigation; it did not establish a final finding of non-compliance. NHTSA’s notice describes the inquiry.

The broader management lesson is an analogy, not an equivalence between a car and an office assistant. When a system changes how people intervene, its owners need to demonstrate how responsibility and control still work.

Why it matters

In an AI workflow, the missing steering wheel may be less visible. It can be an approval step that disappears because a demonstration looked reliable, or a background process that continues after its sponsor assumes it has stopped.

Consider an assistant authorised to prepare changes to customer appointments. Drafting a proposed change, updating a calendar and sending a message are separate actions with different consequences. A manager should know which of them can occur automatically and where intervention remains possible.

A useful review would follow one task from request to completion. Identify the moment before an external commitment, the person who can interrupt it and the evidence that interruption has succeeded. If a process fails midway, establish who owns the incomplete work and how customers will receive an accurate explanation.

This is more practical than asking whether a system has a human in the loop. A person can technically be present while lacking the information, time or authority required to make a difference.

The bigger shift

My reading is that autonomy moves some managerial work from individual approval to the design of operating boundaries. That can be valuable, but the boundaries must be real.

For a low-impact internal task, checking a sample afterwards may be reasonable. For an action that creates an external obligation, the organisation may need verification before execution. Some situations will require the system to pause when the evidence is incomplete.

The appropriate design depends on the consequence, reversibility and speed of the action. A generic approval button does not resolve those differences.

Testing should include a realistic interruption. Change the customer’s instruction halfway through a trial. Remove access to a required system. Introduce an ambiguous request. Observe whether the workflow pauses cleanly, leaves an understandable record and makes unfinished work visible. These are proposed business tests, not proof that any particular model or vehicle is safe.

The ownership questions belong in AI governance before a team expands its deployment.

My take

I am interested in autonomy that removes unnecessary effort while leaving accountability clear. A business should be able to explain what happens when the autonomous process meets a situation outside its mandate.

Before authorising another step, ask its owner to demonstrate three things: how the process is stopped, how a partial action is detected and who resolves the consequences.

If those answers exist only in a presentation, the operating design is unfinished. The next milestone should be a supervised rehearsal that makes the controls observable, with the people who will actually use them taking part.