AI Vacuum

An illustration of an 'AI' driver being told off by a judge.

The Regulatory Vacuum Around AI in Transport


20th July 2026 - Alistair Gollop for ITS Now

Artificial intelligence has entered the transport world with a pace and confidence that feels almost breathless. It is reshaping how vehicles move, how networks operate and how decisions are made in real time. Yet while the technology accelerates, the law follows at a far more measured speed. The result is a widening gap between what AI can do and what regulators are prepared to govern. It is a gap filled with questions about liability, certification and the future of safety cases, and it is becoming one of the defining challenges for the sector.

Transport regulation has always been built on predictability. Systems were designed to behave in consistent ways and humans were assumed to be the ultimate decision makers. AI disrupts both assumptions. Machine learning models behave probabilistically rather than deterministically. They adapt, evolve and respond to conditions in ways that are not always transparent. Responsibility becomes distributed across developers, operators, data suppliers and infrastructure owners. The traditional legal frameworks begin to look increasingly out of step with the reality of modern mobility.

Across Europe, the most significant attempt to address this mismatch is the EU Artificial Intelligence Act. Adopted in 2024, it is the first comprehensive horizontal AI regulation in the world, and it casts a long shadow over transport. The Act introduces a risk-based structure that places automated driving systems, traffic management algorithms and AI used in critical infrastructure firmly within the category of high-risk. These systems must meet strict requirements before they can be placed on the market. They must demonstrate strong data governance, provide clear human oversight mechanisms, maintain detailed logs and ensure transparency throughout their lifecycle. They must also undergo conformity assessments and commit to post market monitoring so that regulators can understand how they behave once deployed.

For transport operators and manufacturers, this creates a new layer of compliance that sits alongside existing vehicle type approval and safety certification regimes. Automated driving systems must still meet UNECE regulations such as R157, but they now also need to satisfy AI specific obligations that relate to data quality, risk management and human oversight. The AI Act does not replace sector regulation. It overlays it, creating a more complex and demanding landscape for anyone developing or deploying AI in transport.

The European Commission has also moved to update product liability rules. The revised Product Liability Directive and the proposed AI Liability Directive aim to clarify how fault should be determined when AI systems behave unpredictably. They introduce presumptions of causality when AI systems fail to meet transparency or logging requirements. In practice, this shifts the burden of proof towards manufacturers and developers, who must demonstrate that their systems behaved as intended.

The UK has taken a different path. Rather than creating a single AI law, the government has opted for a principles-based approach that places responsibility on sector regulators. Safety, transparency, fairness, accountability and contestability form the core of this framework. Regulators such as the DVSA, CAA, ORR and the ICO are expected to interpret these principles within their own domains. This approach offers flexibility and avoids the risk of over regulation, but it also creates fragmentation. Without a unified statute, transport operators must navigate a patchwork of guidance and consultations that vary from one regulator to another.

The Centre for Connected and Autonomous Vehicles continues to shape policy around automated vehicles, but the legislation needed to enable commercial deployment remains in development. The Automated Vehicles Bill, currently progressing through Parliament, is a major step forward. It introduces a new safety assurance regime and clarifies criminal liability when an automated driving system is in control. It also creates the concept of an Authorised Self Driving Entity, which would assume responsibility for the behaviour of the automated system. This marks a significant shift away from the traditional assumption that the human driver is always liable. Yet even with this progress, the UK still lacks a comprehensive AI regulatory framework that spans the entire transport ecosystem.

Liability remains one of the most complex issues in the regulatory vacuum. When an autonomous bus makes a decision that leads to a collision, responsibility becomes a puzzle. The operator deployed the system. The manufacturer built the vehicle. The AI developer created the model. The data provider supplied the training data. The infrastructure owner maintained the road environment. Each plays a role, yet none is solely responsible. The EU’s approach attempts to create a chain of accountability through transparency and conformity assessments. The UK’s ASDE model places responsibility on the organisation that certifies the system. Both approaches are promising, but neither fully resolves the challenge of assigning fault in systems that learn and adapt over time.

Certification faces similar difficulties. Traditional safety cases rely on proving compliance with standards and demonstrating predictable behaviour. AI systems do not behave predictably. They may respond differently to edge cases, degrade over time or behave in novel ways when confronted with unfamiliar conditions. This undermines the foundations of conventional certification. New approaches are emerging, including continuous assurance models that rely on real time monitoring, scenario-based testing using vast libraries of synthetic and real-world situations, explainability requirements that allow regulators to interrogate AI decisions and the use of digital twins to test systems in virtual replicas of real environments. These methods represent a shift towards dynamic oversight rather than static approval, but they are still in their infancy.

The regulatory vacuum is not only a challenge. It is an opportunity. The transport sector has a chance to shape frameworks that are genuinely fit for an AI defined future. International standards for AI safety, shared testing environments, clear liability pathways and stronger regulatory capacity will all be essential. Ethics and human factors must be embedded into AI design and deployment. Above all, regulators and innovators must work together to ensure that the pace of oversight begins to match the pace of technological change.

AI is moving faster than transport law can keep up, but regulation is beginning to accelerate. The next few years will determine whether Europe and the UK can close the gap or whether the sector will continue to operate in a space where innovation outstrips governance. For now, the vacuum remains, but it is slowly being filled by the first outlines of a new regulatory landscape.



Click the buttons below to see more articles:

See all ArticlesIndustry InsightEventsITS Thought LeadershipITS Educational