The Consequence Library · How records are made and graded
An Uber Advanced Technologies Group test vehicle operating in autonomous mode struck and killed pedestrian Elaine Herzberg in Tempe, Arizona on 18 March 2018, the first pedestrian death caused by a developmental self-driving vehicle, after engineering decisions left a single unmonitored operator as the designed final defence.
What happened
NTSB investigation HWY18MH010, final report HAR-19/03 adopted 19 November 2019, established the following. The modified Volvo XC90's automated driving system detected Herzberg 5.6 seconds before impact but repeatedly reclassified her, as an unknown object, then a vehicle, then a bicycle, discarding tracking history at each reclassification, and did not compute a collision path until 1.2 seconds before impact. Volvo's factory forward-collision warning and automatic emergency braking were disabled while the ADS was engaged, and Uber's system was designed not to perform emergency braking beyond specification limits, relying instead on the operator. About five months earlier ATG had reduced the operator count from two to one, rarely reviewed inward-facing camera footage, and had no effective mechanism against automation complacency. The operator was streaming video on a personal phone and looked down for roughly five of the final six seconds. Arizona suspended Uber's testing authority on 26 March 2018. Prosecutors declined to charge Uber; the operator pleaded guilty to endangerment in 2023 and received three years' probation. Afterward Uber restored a second operator, added attention monitoring, removed action-suppression logic, re-enabled compatible Volvo AEB, and built a safety management system.
Where control failed
The NTSB identified the operator's distraction as the probable cause and identified deficiencies in Uber ATG's safety risk assessment, operator oversight and management of automation complacency as contributing factors. The vehicle also relied on a human safety operator after automatic emergency-braking functions had been limited or disabled during autonomous operation.
The authority question
The system relied on a single safety operator as its final human intervention path. The relevant control question is whether that role was supported by monitoring, system design and organisational controls sufficient to allow timely intervention.
What could be proven afterward
The public record is strong. The NTSB docket documents sensor data, the reclassification sequence, operator camera footage and the design decisions at forensic level. What remains outside the public record is the internal decision trail on disabling the AEB and consolidating operators: the evidence bearing most directly on organisational accountability is the evidence never produced.
Control state, before and after
Before the consequence
Factory automatic emergency braking disabled during autonomous operation. Emergency braking suppressed by design. One operator, unmonitored, as the final defence.
After the consequence
Second operator restored, attention monitoring added, action-suppression logic removed, compatible factory AEB re-enabled, safety management system built.
Sources
- Primary: NTSB, "Collision Between Vehicle Controlled by Developmental Automated Driving System and Pedestrian, Tempe, Arizona" (HWY18MH010 / HAR-19/03), adopted 19 Nov 2019 · https://www.ntsb.gov/investigations/Pages/HWY18MH010.aspx
Record history
Published 16 August 2026. Load-bearing facts re-verified against the cited sources on 16 August 2026. Corrections and material changes are appended here with their dates. To report an error in this record, write to hello@regulayer.com with the record slug and the source you believe is authoritative.
This record describes what sources establish about a consequence and the control state around it. It separates confirmed fact from source-stated cause and from architectural analysis, and it makes no claim that any control or product would have prevented the outcome. Gap codes identify a failure class, not a remedy.
