There once was a time when most cars on the road did not have air bags as a standard under federal law. It took until 1998, in fact, for every vehicle on the round to have an airbag as required by federal law — that’s over 100 years after the invention of the first automobile and roughly 30 years after airbags were first invented as a safety measure. Something like that is playing out again, except this time with robotaxis and cyber protections.
Louay Abdelkader, director of product management at QNX, identified it as a huge problem for the sector, “of course … keep in mind that in automotive safety, it took a while for it to adopt.” Abdelkader told Fortune lawmakers should make cybersecurity a primary consideration akin to airbags, noting that every connected vehicle introduces some degree of cyber risk.
Much of the debate over robotaxis has focused elsewhere, such as whether they are indeed smart enough to avoid collisions, how insurance companies should assign liability in an accident, or how police can deal with driverless cars that commit traffic violations.
Abdelkader told Fortune lawmakers should make cybersecurity a primary consideration, noting that every connected vehicle introduces some degree of cyber risk.
Robotaxis are proliferating across the country, however, with the robotaxi company Zoox most recently receiving regulatory approval from the National Highway Traffic Safety Administration for a commercial exemption, allowing the paid service broader access without manual controls. Tesla also has moved into the robotaxi space, with the advent of Cybercab in at least seven cities.
Meanwhile, Alphabet-owned Waymo has expanded from its beginnings in Arizona to 11 major U.S. cities—even pairing with rideshare company Uber in a few cities.
Unlike conventional vehicles, robotaxis depend on dozens of interconnected electronic control units, high-speed networking, cloud connectivity, GPS, cameras, lidar, radar and AI models that continuously interpret the world around them. Every one of those components expands what cybersecurity professionals call “attack surface,” or the number of possible entry points hackers can exploit.
While Hollywood often depicts hackers remotely hijacking an entire vehicle, experts say modern attacks are more likely to target the broader ecosystem surrounding autonomous cars.
Even if attackers cannot directly steer a vehicle, disrupted communications could degrade an autonomous system’s ability to safely navigate. In San Francisco, self-proclaimed “tech prankster” Riley Walz organized a group DDOS—a denial-of-service—attack on local Waymos.
The prank consisted of 50 individuals simultaneously ordering a Waymo on the same dead-end street, creating a pileup that made the company disable rides until the next morning.
The DDOS came despite rules from California, where Waymo operates service in San Francisco and Los Angeles, that require autonomous vehicle manufacturers to demonstrate they can safely monitor, update and maintain their fleets while complying with federal vehicle cybersecurity guidance.
Waymo and the California DMV did not respond to requests for comment.
The advent of generative AI has added to cybersecurity risks in robotaxis. Historically, hackers often needed significant time, technical expertise and resources to identify and exploit vulnerabilities. But AI has dramatically compressed that timeline, according to Abdelkader.
He said malicious actors can use AI to identify vulnerabilities, automate attacks and develop exploits far faster—and with more malicious intent—than Walz’s “prank.”
Abdelkader said cybersecurity for robotaxis is largely the responsibility of both manufacturers and lawmakers. He argued manufacturers must build security into autonomous vehicles from the beginning, not treating it as an add-on.
“When you’re developing a cybersecurity system, you start from the ground up. It’s like building a house,” he said. “If your foundation is not strong, it becomes very difficult for you to build a robust and secure house.”
Like California, some jurisdictions have already begun treating cybersecurity as part of autonomous vehicle regulation rather than an afterthought. Arizona has incorporated cybersecurity planning into broader autonomous vehicle deployment policies, while states including Michigan have established cybersecurity initiatives through partnerships with industry and research institutions.
Internationally, regulators have also moved further. The United Nations’ UN Regulation No. 155 now requires automakers in many markets to maintain certified cybersecurity management systems throughout a vehicle’s lifecycle, while ISO/SAE 21434 establishes engineering standards for cybersecurity across vehicle development.
But in New York City, where Mayor Zohran Mamdani has refused to renew the license for Waymo, cybersecurity has been missing from the debate over robotaxis. The young mayor has instead focused on labor protection, citing taxi drivers as the main point of concern with allowing robotaxis to roam Manhattan.
“If a company like Waymo finds itself in New York City, what they will also find is a City government that is committed to delivering for the workers who keep the city running,” he said at a press conference. “Those workers also include our taxi drivers who, for far too long, have been sold a dream of being able to work their way to the middle class.”
Mamdani’s office did not respond to a request for comment.
But Abdelkader argues that all lawmakers across the country should build on existing frameworks rather than waiting for a cyber incident to expose a weakness. He says policymakers often separate safety from cybersecurity too often, even though “they are tied at the hip.”
“The legislators and politicians have to work with them to make sure that moving forward, if there are improvements that need to be done, what type of support is required,” he told Fortune. “You need to be able to talk and share that feedback. That’s the only way for the industry to grow effectively and benefit society.”
breaks the traditional barrier between audience and newsroom. The show transforms
Fortune DailyFortune’s trusted reporting into actionable, conversational, and entertaining insights for an emerging class of business leaders.
Watch here.