The Robotaxi Didn't Crash Itself. Every Time, a Human Grabbed the Wheel.
Three low-speed robotaxi crashes, each with a human steering from an office. What they reveal about “keep a human in the loop” — the safety answer nobody is measuring.
Follow the sequence, because the sequence is the whole story.
A car drives itself across Houston. Nobody in the driver's seat. It handles the merges, the unprotected lefts, the delivery van double-parked in the bike lane — the small negotiations that make city driving hard for a machine and thoughtless for us. Then it turns down a road that ends where the map said it continued, and stops. Hazards on, defeated by geography, politely and completely stuck.
So it does what it was designed to do: it asks for a person. Somewhere in an office, a remote assistance operator picks up the video feed, takes control over a data link, and starts easing it out of the dead end. And at two miles an hour — walking speed, the speed of someone carrying a full mug of coffee across a kitchen — the human drives the robot into a tree stump.
I laughed out loud. Ten seconds later I stopped, because this small, slow, faintly ridiculous collision demolishes a sentence I have used for years. Here is the confession: I have said "as long as there's a human in the loop" more times than I can count — about hiring software, about medical triage, about AI agents holding a credit card. It is the most comfortable phrase in the AI-safety vocabulary, because it sounds like a solution: whatever the machine gets wrong, a person will catch.
The stump is what happens when you check that assumption. Not because the operator was careless, and not because robotaxis are secretly murderous — they are not, and I will show you the numbers. It is because the human fallback is not a magic layer sitting outside the system. It is a component with its own failure modes, and almost nobody is measuring it.
What actually happened, at two miles an hour
On July 20, Electrek reported a hidden tree stump in Houston — a May 2026 incident in which the system got stuck and, "as the remote assistance operator continued to recover the vehicle, they made contact with a hidden tree stump." Two miles an hour. Minor damage. Nobody hurt.
What made it notable was one field on the form. The Driver/Operator Type reads "Remote (Commercial / Test)" — the first time Tesla has used that code in any of its 22 unique autonomous-driving incident reports as of the July 2026 release. The paperwork finally says it out loud: the machine wasn't driving. A person was.
It was not the first. Two months earlier, TechCrunch surfaced a metal fence and a construction barricade from earlier filings: in July 2025 a teleoperator drove "up the curb and made contact with a metal fence" at eight miles an hour; in January 2026 another vehicle hit "a temporary barricade for a construction site at approximately 9MPH." Same shape every time — the machine gets stuck, a human takes over remotely, and the human is the one who hits something.
Let me be plain, because this argument dies the moment it gets inflated. Nobody was injured in any of these. Two, eight and nine miles an hour — a scraped fender, a bent fence, a stump. If a human driver did all three it would not make the local paper, and I am not telling you robotaxis are killing people. The force is in the pattern, and in who was holding the wheel.
Tesla does not hide this. Tesla calls it a redundancy system: "domestically located remote operators in both Austin and the Bay Area." But redundancy is an engineering word — a spare that fails independently of what it backs up. Which raises the only question that matters: what is the failure rate of that spare?
The regulator's language elsewhere is a clue. In the federal defect investigation into Full Self-Driving — the supervised consumer feature, not the robotaxi service — NHTSA notes that inputs commanded by FSD induced behaviour "that violated traffic safety laws," while "the driver remains fully responsible at all times." The machine acts. The human owns it.
The number nobody will give you
Now let me argue with my own headline, because you deserve the precise version.
It is true, and Electrek says so, that every remote intervention appearing in a Tesla crash report ended in a collision. It is also nearly a tautology: a crash report is the document that exists because there was a crash. We see only the takeovers that went wrong. So, unambiguously — I am not telling you that every time a remote operator takes the wheel, they crash. Operators are almost certainly rescuing stuck cars all day without incident. I am telling you we cannot know: Tesla does not publish how often they intervene. No denominator, no rate — just a few numerators that surface by accident, when something gets bent.
Sit with the strangeness. Every other safety-relevant component in a car has a failure rate you can look up — brakes, airbags, battery packs, tyres. The human fallback layer, on which the whole "keep a person in the loop" argument rests, has a numerator we glimpse when it dents something and a denominator nobody will hand over. You cannot manage what you refuse to count — and the refusal to count is not a footnote to this story. It is the story.
So the machines are the problem? Not really.
Here an honest argument hands the microphone to the other side.
Days before I sat down to write this, the Insurance Institute for Highway Safety published a study finding Waymo's driverless vehicles involved in 68% fewer crashes than human drivers per mile travelled across San Francisco, Phoenix, Los Angeles and Austin. Not six percent. Sixty-eight. Nor is it a lone result: Timothy B. Lee read every crash report one by one and found the mundane truth beneath the aggregate — most Waymo crashes involve "a Waymo vehicle scrupulously following the rules while a human driver flouts them: speeding, running red lights, careening out of their lanes." It is usually the human who hits the robot.
The caveats are real: Waymo only, 2021–2024; IIHS is insurance-industry funded, and insurers like fewer claims; Austin came in about 4% higher on a small sample. Even fully discounted, the direction is not in doubt. At the task of driving a car down a street the machine is already better than we are — and I would rather share a road with a patient robot than with the man doing fifty through a school zone while texting.
So does that settle it? No — and notice why. Every one of those numbers describes the autonomous system. My three crashes happened in the moments that system had switched off and handed over. Two different systems, two failure modes, graded as one.
Note, too, that the researchers with the best news about robotaxis are the ones warning you about the instruments: the same study says "the present data collection system isn't good enough to allow continuous monitoring of a large-scale expansion." Believe both halves.
The same three words, two entirely different machines
Here is where it gets genuinely interesting — and where the public conversation is quietly confused.
"Human in the loop" describes at least two architectures that share nothing but the phrase. Mario Herger calls them two different things wearing the same word. In teleoperation, operators sit at "a driving console that allows them to take control of a vehicle remotely and steer it out of a situation." In teleassistance, nobody has a steering wheel at all; the operations centre sends the car instructions.
One hands a distant stranger the wheel. The other lets the car ask a question.
Waymo's design is the second kind, and says so. Waymo's fleet response team answers the car's questions — is that cone actually a cone — but it cannot drive. In Waymo's own words, "the Waymo Driver does not rely solely on the inputs it receives from the fleet response agent and it is in control of the vehicle at all times." The car can decline the advice. That is the difference between a design where human error reaches traffic directly and one where it structurally cannot.
The engineering objection to the first design is old news. Remote driving depends on cellular connections that drop or lag, and Carnegie Mellon's Philip Koopman put it plainly: "Eventually you will lose connection at exactly the worst time." Former Waymo chief executive John Krafcik called remote driving "very risky."
But the advisory design buys that safety with a different currency, and San Francisco just got the bill. On the Fourth of July, in the gridlock around the Presidio, at least a dozen of them stalled at once, batteries drained by hours of idling; some got out when the jam cleared, others ran out of charge and had to be towed.
There is the trade-off, in two anecdotes. Teleoperation buys recovery and pays with a new source of human error. Teleassistance refuses that error and pays in immobility — nobody is permitted to move the car, so you call a tow truck. Neither is free. What is unacceptable is that both are sold under the same three words, and what the public hears is: someone is watching.
The regulator has started looking at the humans
Something shifted this month — and it is worth being accurate about how much. On July 8, NHTSA administrator Jonathan Morrison told the whole industry so in writing: "an AV that cannot safely interact with first responders is a danger to the general public." What prompted it was a clear pattern the agency says it has documented: driverless vehicles that "drove into active emergency scenes, blocked the paths of ambulances and firefighters, or failed to recognize and respond to basic safety conditions like flashing lights, flares, smoke, fire, and traffic cones." The official term is "functional insufficiency" — bureaucratic for the car cannot read the room.
Now the pedantic part, because much of the coverage has not been. What NHTSA committed to is that it "will schedule meetings with driverless automated driving system developers by month's end to hear your solutions." A summons to a conversation — not a rule, a recall or an enforcement action, whatever the more excitable headlines implied. By the time you read this that deadline is upon us or just behind us; either way, keep the applause holstered. And this is not a Tesla or a Waymo problem: there is already a third operator under investigation in Dallas — Avride, Uber's partner in Texas — over sixteen crashes since December.
The most interesting rulemaking, meanwhile, is not federal at all. California's new autonomous vehicle rules, adopted in April, are the first in the country to write standards for remote operations personnel into the permit itself — alongside first-responder interaction plans, access to manual override systems, and two-way communication links with a 30-second response time. Somebody in Sacramento specified the human fallback the way you would specify a brake line — which is, functionally, what it is.
Now put ten thousand of these on the road
Three low-speed bumps across three years is not frightening. It is a preview — and previews are useful because they are cheap.
So let me get imaginative, in a way I think is entirely plausible. Scale the fleet a hundredfold and the fallback must scale too — except software scales by copying itself, while humans scale by hiring, training and stretching. One operator supervising four cars becomes one supervising twelve, with a queue.
Picture an August evening in 2029. A stadium empties early because of weather; a substation trips and takes out a corridor of traffic lights; the cell network saturates with sixty thousand people uploading video. Within twenty minutes, two hundred confused vehicles sit in a six-block radius, each politely stopped, each pinging the operations centre for a human.
Now picture that operations centre: someone in hour seven of a shift, fourteen cars in the queue, each a small emergency with a horn blaring behind it, each a live steering wheel at the end of a congested network. Not a villain, not incompetent — a professional asked to do a hard thing quickly and repeatedly, with partial vision and lagging video. Which describes nearly every industrial accident inquiry ever written.
And when one of those takeovers clips a bollard, or a parked motorcycle, or something worse than a stump, the statement writes itself: "The vehicle was under human control at the time of the incident."
Technically true. And entirely beside the point — because the human was handed the wheel at the exact moment the machine gave up, in a situation the machine created, with seconds to decide.
What the smart people are saying — from several directions at once
That press release has a name, coined before robotaxis were commercial. Madeleine Clare Elish called it the moral crumple zone: the way "responsibility for an action may be misattributed to a human actor who had limited control over the behavior of an automated or autonomous system." A car's crumple zone protects the human inside; the moral one "protects the integrity of the technological system, at the expense of the nearest human operator." The person in the loop is not only a safety mechanism. They are also somewhere to put the blame.
Past the diagnosis, serious people disagree about the remedy — and you should see the whole spread. The free-market R Street Institute makes the free-market case for moving faster: a patchwork of state rules is inhibiting deployment of a technology already outperforming human drivers, and endangering safety on the roads. If the machines genuinely crash less, every year of hesitation is measured in people.
The safety camp answers that the promise is real but the guardrails are not: Advocates for Highway and Auto Safety says AVs "may have the potential to meaningfully reduce crash deaths and injuries" once subject to minimum performance requirements and robust oversight — and today's deployments are not. Consumer Reports warned Congress, meanwhile, that the federal bill on the table would let manufacturers self-certify their safety claims and keep the data out of public hands.
Notice what those three share while they argue. R Street wants one clear rulebook instead of fifty. Advocates wants minimum performance requirements. Consumer Reports wants the homework marked by someone other than the student. Strip the ideology and all three describe the same absence: nobody can see the numbers. A missing instrument panel — the one thing this story keeps pointing at.
What does this mean for you?
Here is the practical version — most of which has nothing to do with cars.
Ask which kind of loop it is. Whenever anyone — a robotaxi company, your bank, your own employer — says "a human is in the loop," ask the question that separates the architectures: can that person act, or only advise — and can the system overrule them? Identical phrase, opposite property.
Ask for the denominator. "We have humans standing by" is a staffing fact, not a safety fact. How often does the fallback trigger, and what share of those handovers go badly? If the answer is a shrug, you have learned something important — not that the system is unsafe, but that nobody knows.
Report the small stuff, if you live where these operate. The blocked driveway, the car frozen at a green light, the one that nosed toward a fire scene. It feels petty; it is not. A complaint is how an incident becomes a record instead of an anecdote.
Notice where you are the fallback. The approve/reject button. The AI-drafted email you sign. The output you rubber-stamp because forty more are queued behind it. We have been here before: when software acts on your behalf, the bill still lands with the human standing closest to it. If you are the loop, insist — in writing — on what makes a loop real: time, context, and the authority to say no.
Don't overcorrect into panic. The machines really are better than us at driving. The answer is not to ban them; it is to refuse to accept the silhouette of a human being as a substitute for evidence.
The lesson, as I see it
We reached for "keep a human in the loop" because it is comforting — and because it is usually better than the alternative. But comfort is what stopped us looking, and the tree stump is what was hiding behind it.
A human in the loop is not a safety feature. It is a component, with a response time, a failure rate, a fatigue curve and, in the teleoperated version, a link that will drop at the worst moment, exactly as Koopman promised. Components get specified, tested and published. Talismans get invoked — and we have spent five years invoking.
Aviation did not get safe by hoping pilots would be perfect. It got safe by instrumenting everything. We are still refusing to instrument the one moment where these crashes live: the handoff, the half-second where a machine says I don't know and a person a hundred miles away says I've got it.
My vote? Keep the human — and publish the handoff. Every takeover, timestamped and counted: how often, how long, what happened next. Do that and "human in the loop" stops being a slogan and becomes a number. Numbers can be argued with, and improved. Slogans just sit there sounding reassuring until something bends.
Which is why I think of that Houston stump as a gift. It showed us the weakest joint in the system while the stakes were a scraped bumper and a bruised ego. Most industries never get a warning that cheap. Take it, before the next one arrives at a speed that makes nobody laugh.
"There's a human in the loop" is a question, not an answer — and the follow-up is "holding what?" If that reframe was worth your coffee, send it to whoever in your life uses the phrase like it settles the matter, and come find the rest of these.




