BIP America

collapse
Home / Daily News Analysis / Toyota's FSD-like system arrives in 2028, but the driver stays liable

Toyota's FSD-like system arrives in 2028, but the driver stays liable

Sep 02, 2026  Twila Rosenbaum  5 views
Toyota's FSD-like system arrives in 2028, but the driver stays liable

Toyota has confirmed that it will bring a system designed to compete with Tesla's Full Self-Driving to production vehicles in the 2028 model year. The technology will not be sold as an autonomous driving system. Instead, Toyota plans to describe it as "Level 2++", a commercial label intended to convey advanced driver assistance while making it clear that a human is still ultimately in control.

"Level 2++" is not an SAE International classification. It belongs more to marketing than to formal standards. In practice, it signals something richer than current Level 2 systems but short of Level 3 conditional autonomy. The important distinction for Toyota is liability: with Level 2++, the manufacturer will not be treated as the driver, and the person behind the wheel remains accountable for the car's behaviour at all times.

What Toyota's system is expected to do

Although Tesla markets its Full Self-Driving package as a step toward autonomy, it too remains a driver assistance system rather than a fully autonomous product. Toyota wants to rival that level of capability, but its engineering approach will be different. Other systems often rely on a single neural network that converts sensor input directly into driving commands. Toyota has said it will add a guardrail layer over that neural network, creating a second oversight mechanism that humans have calibrated in advance.

That guardrail is not an autonomous fallback system. It is designed to check the neural network's output against boundaries set by engineers before the vehicle reaches customers. If the network proposes a manoeuvre that appears unusual, dangerous, or outside the predefined rules, the guardrail layer can block it or force the system to request a different course. The goal is to reduce the kind of unpredictable behaviour sometimes seen in end-to-end machine-learning models.

Akihiro Sarada, who leads Toyota's software development centre, explained the strategy in stark terms: "We'll develop Level 4 technology from a technical standpoint, but offer it commercially as Level 2++." That means Toyota may be able to demonstrate an ability to handle more complex driving situations during development, but it will not ask customers or regulators to treat those capabilities as proof that the vehicle can drive itself.

This approach has consequences for safety, but also for legal exposure. The guardrail layer is not just a filter against unusual neural-network suggestions. It is also a mechanism for explainability. When a request is rejected, the system can provide an answer that refers to the human-defined parameters that caused the rejection. When an action is accepted, there is a record that it fell within the boundaries set by engineers. In an era when courts are beginning to ask hard questions about software decisions, explainability is no longer a purely technical nicety.

Europe has already opened the door

Europe is one of the first major markets to create a regulatory category for systems that sit between conventional driver assistance and higher levels of automation. UN Regulation No. 171 on driver control assistance systems entered into force on 30 September 2024. This regulation was written for systems that can help the driver with steering, braking, or acceleration but do not remove the driver from the loop.

The regulation is explicit about who is driving. The driver retains responsibility, must permanently monitor the road, and must be able to intervene at any moment. Carmakers are also required to make this clear in advertising and in dealership materials. The intention is to prevent manufacturers from using names such as "Autopilot" or "Full Self-Driving" to create an impression that the car can operate without a responsible human.

For Toyota, that regulatory environment is favourable. The company can market a technically sophisticated system without needing to enter the higher-liability Level 3 or Level 4 categories. The label "Level 2++" signals that the driver remains in charge, which aligns with the legal framework that Europe has built for this generation of assistance technology.

The Dutch approval of Tesla's FSD Supervised

The Netherlands has already shown how this type of approval works in practice. The Dutch vehicle authority, the RDW, approved Tesla's FSD Supervised after 18 months of testing and after analysing 1.6 million kilometres of European road data. That approval did not mean the software became autonomous. The regulator stated plainly that the software is not self-driving and that the driver remains responsible and must maintain control at all times.

This was not a small procedural detail. It was a formal determination that Tesla's advanced driver assistance system belongs in the same legal category as other driver assistance technologies, despite its name and despite the impression that some promotional materials may create. The approval gave Tesla permission to introduce the system on European roads, but it also placed an obligation on Tesla to ensure that drivers understand they are still driving.

Toyota appears to be watching this model closely. Rather than seeking an autonomous classification and then defending it, Toyota will sell its future system as a Level 2++ product that promises to be technically advanced but legally restrained. The driver is still the operator. The automaker is still responsible for the safety of the underlying software, but it is not asking the law to treat the vehicle as the driver.

Product liability law is catching up with software

The traffic law side may be clear, but the product liability side is changing. From 9 December, the European Union's updated Product Liability Directive will treat stand-alone software as a product across the bloc. That applies regardless of whether the software is embedded in a physical vehicle or delivered over the air. If defective software causes harm, the producer can be held liable in the same way as a manufacturer of a defective physical component.

This is a major shift. Where a Level 2++ system causes a crash, the driver may still receive a traffic ticket or be blamed for failing to monitor the road. But a civil compensation claim can also target the automaker if the software itself was defective. The directive does not stop at the distinction between driver assistance and autonomy. It applies to the software as a product whenever it fails to provide the safety a person is entitled to expect.

The directive also eases the burden of proof in circumstances where technical complexity makes it extremely difficult for a claimant to demonstrate a defect. In such cases, a court may presume that a defect exists. Courts may also order defendants to disclose evidence that helps explain how the software behaved. This is where Toyota's guardrail layer could become more valuable than the label on the marketing brochure.

Explainability is not only a good engineering principle. It is increasingly a legal requirement. If Toyota's system can explain why a proposed action was allowed or blocked, and if those explanations are stored and made available in litigation, then the company is in a stronger position. The opposite approach, a pure end-to-end neural network that cannot explain its decisions, is far harder to defend in a regime that allows courts to draw inferences from a lack of transparency.

Why the label is not the deciding factor

Automakers have traditionally used SAE levels to communicate how much responsibility the driver has. But the new product liability rules are indifferent to that badge. Whether a system is described as Level 2, Level 2++, Level 3, or Level 4, the software still has to be safe. The directive looks at the actual product, the way it is presented, and the safety that the public can reasonably expect.

This means a carmaker cannot escape liability simply by putting a Level 2++ sticker on a system that is capable of far more. If the software makes a driving decision that injures someone, a court may decide that it was defective. The marketing label may influence what drivers expect, but it does not override the fundamental requirement that products sold in the EU must not cause unreasonable harm.

Toyota's commercial decision to offer technology as Level 2++ may protect it from certain claims that the car was driving itself. But it does not shield the company from product liability claims based on poor software decisions. In that sense, the company's emphasis on guardrails and explainability is strategically important. Safety and legal defensibility are converging in this generation of automotive software.

Mercedes has chosen the other path

Not every automaker is taking the same route. Mercedes-Benz has chosen to sell a system approved as Level 3. Drive Pilot allows the driver to take their eyes off the road under certain conditions, such as slow-moving motorway traffic. When the system is engaged, the car is doing the driving, and responsibility shifts away from the driver during that specific window.

This is a fundamentally different liability position. Mercedes has accepted that the vehicle itself must perform the entire dynamic driving task within its operating conditions. The driver is allowed to do certain non-driving activities, but must be able to respond when the system requests takeover. This creates a legal framework in which the manufacturer has a much larger share of the risk.

Toyota could have followed that path, but it has decided not to do so. It wants to develop Level 4 technology behind the scenes, while selling a Level 2++ experience. The company seems willing to let the software handle difficult driving situations, but it wants the driver to remain legally responsible for what the vehicle does on the road. That is a defensible commercial strategy, but it is not a way to avoid all liability. The new product liability rules ensure that software is judged not by its name, but by the safety it actually provides to the people who use it.

The coming years will show whether Toyota's guardrail approach can produce both the sophistication of Tesla's Full Self-Driving and the explainability that European regulators and courts increasingly expect. The 2028 launch will arrive after the new product liability framework is already in force, which means Toyota will not be able to claim that its label was unclear or that software should be treated differently from physical parts. It will have to demonstrate that its Level 2++ system can do exactly what the software was designed to do without crossing into territory where the driver no longer has meaningful control.


Source: TNW | Artificial-intelligence News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy