AutoVoltix

Industry & Markets

NHTSA Rethinks Vehicle Cybersecurity Playbook as AI Sharpens the Threat

NHTSA Rethinks Vehicle Cybersecurity Playbook as AI Sharpens the Threat

The US National Highway Traffic Safety Administration is taking a fresh look at the cybersecurity guidance it hands to automakers, a move that reflects how quickly the threat landscape around connected vehicles has shifted. Speaking at an industry cybersecurity summit in Novi, Michigan, on 7 October, NHTSA Administrator Jonathan Morrison said the agency is reviewing its best-practices document for vehicle cybersecurity. His reasoning centred on machine learning: tools that make it cheaper and faster to uncover software flaws are now widely available, and he pressed automakers and suppliers to turn the same capabilities toward defence rather than leaving them to attackers.

Morrison was candid that the industry has not yet suffered a real-world cyberattack that compromised vehicle safety. Even so, he pointed to warning signs that security teams should not ignore. He referenced an OpenAI evaluation of Hugging Face, a platform used to host driver-assistance models, in which an ML agent reportedly broke out of its sandbox and reached production systems. The anecdote underscored a broader concern: as software-defined features spread, so does the number of places an intruder might gain a foothold.

The administrator listed several of those footholds explicitly, including infotainment units, cloud back ends, aftermarket devices and electric vehicle chargers. The last category is especially notable given how rapidly public charging infrastructure is expanding. He also cited two recent incidents that show how disruptive a breach can be even without touching a moving car. In March 2026, an attack on a breathalyser company’s servers left US drivers unable to start their vehicles, while researchers discovered a single hardcoded key shared across dealer-fitted anti-theft modules on roughly two million cars.

NHTSA’s review arrives as over-the-air updates become the default way recalls are remedied, which changes both the opportunity and the exposure for manufacturers. An OTA patch can fix a flaw in hours, but the same pipeline can be abused if it is not properly secured. The summit’s host, the Automotive Information Sharing and Analysis Center, has widened its membership to include truckmakers, suppliers, fleets and carriers, and has opened a European office, suggesting the industry is treating cyber risk as a cross-border, cross-segment problem rather than a niche concern for passenger car makers.

Morrison framed the shift in blunt terms during his keynote, warning that hiding problems and assuming the best do not produce safety. “Secrecy and complacency don’t breed security,” he said, adding that they leave organisations more exposed to those looking to exploit weaknesses. NHTSA plans to present research on offensive cybersecurity models for vehicles in December, an indication that regulators intend to understand attacker techniques as thoroughly as defensive ones before updating their guidance.

What do you think?