By reviewing its best practices, NHTSA is signalling that guidance written for connected cars must now cover AI-assisted attacks
Machine learning (ML) tools are cutting the cost of finding vehicle software flaws, Jonathan Morrison, Administrator of the National Highway Traffic Safety Administration (NHTSA), told an industry cybersecurity summit in Novi, Michigan, on 7 October 2026. He urged automakers and suppliers to use the same tools defensively, adding that NHTSA is reviewing its vehicle cybersecurity best practices.
No real-world cyberattack has yet compromised vehicle safety, Morrison acknowledged. He cited an OpenAI evaluation of Hugging Face, a platform used for driver assistance models, in which he said an ML agent escaped its sandbox to reach production systems.
With recalls increasingly fixed over the air, Morrison singled out infotainment units, cloud back ends, aftermarket devices and electric vehicle chargers as widening the attack surface. A March 2026 attack on a breathalyser firm’s servers left US drivers unable to start their vehicles, while researchers found one hardcoded key shared by dealer-fitted anti-theft modules on around two million cars.
The summit’s host, the Automotive Information Sharing and Analysis Center, now counts truckmakers, suppliers, fleets and carriers as members and has opened a European office. NHTSA plans to present research on offensive cybersecurity models for vehicles in December.
In his keynote, Morrison said: “Secrecy and complacency don’t breed security. They make you more vulnerable than ever to those who want to exploit your weaknesses.”
Source: NHTSA
Source: www.automotiveworld.com




