Pacific Design/ artificial intelligence

Robotics & Embodied AI · entry 05/06

Self-driving

Driverless taxis are real in a growing list of cities, consumer cars supervise their drivers, and the two get called the same name — the architectures, the ODD, and the line that actually matters.

Three products, one name

"Self-driving" covers three different things. Driver assistance (L2): the car steers and brakes, a human supervises every second and owns every outcome. Conditional automation (L3): the car drives itself in a narrow band — certain highways, speeds, weather — and hands back to a human on request, the only level where responsibility changes hands mid-drive, which is why it is the live regulatory fight. And bounded full autonomy (L4): no one in the seat, a remote operations center behind the edge cases, the vehicle owning the drive within a defined territory and set of conditions — its operational design domain. Robotaxis running driverless in a lengthening list of cities are L4; highway consumer cars are overwhelmingly the first kind, with a thin L3 vanguard. The level number is not a capability score; it marks who is responsible at any instant — which is why the marketing that blurs it draws regulators, and why an "L2 that feels like L4" is the industry's most dangerous product category.

The architecture argument

The classical stack is sense-plan-act at its most elaborate: HD maps as prior memory, lidar-camera-radar fusion for perception, a prediction module guessing what every actor does next, a planner threading it all. The insurgent bet is end-to-end: sensors in, trajectory out, one network trained on fleet-scale human driving in place of hand-built interfaces between perception, prediction and planning — in its camera-first form promising cheaper sensors, no HD-map dependency, and the data flywheel as the moat. The argument is narrowing from both sides: modular stacks absorb learned components everywhere, end-to-end systems sprout safety rails and structure, and both lean increasingly on simulation to manufacture the miles that matter. What's actually decisive is less philosophy than validation cost — whichever architecture can prove its safety case cheaply per city wins the map.

Miles don't prove safety

The hard part isn't driving; it's demonstrating rarity. Fatal crashes are so infrequent that raw miles can't statistically certify a fleet — the events that matter are exactly the long tail. So serious programs argue from a portfolio: scenario-mined simulation replaying every fleet near-miss with variations, closed-course adversarial testing, component-level guarantees, and public incident data compared against human baselines per mile type. Remote assistance is part of the honest economics — not joystick driving, but humans resolving "is this construction zone passable" at fleet scale — and its staffing ratio is a better health metric than any demo video.

Failure mode

Reading fluency as competence — from the driver's seat. An L2 system that handles ninety-nine boring minutes trains its human to stop supervising in exactly the minute it can't handle; automation complacency is the best-documented failure in the partnership, and no disclaimer screen has ever fixed it. The question that cuts through every launch, spec sheet and influencer video is the responsibility question: who accepts liability when it's wrong, here, tonight, in the rain? If the answer is "you do," it's a driver-assistance product — behave accordingly.