NHTSA Gave Tesla Until September 30 to Explain How the Cybercab Passed Standards That Assume a Human Driver Exists

September 28, 2026
4 mins read
Tesla Cybercab on a street in Stockholm, Sweden
A Tesla Cybercab photographed in Stockholm ahead of NHTSA's September 2026 audit query.

ARTICLE 8 — Tesla Cybercab NHTSA

NHTSA Gives Tesla Until September 30 to Answer Cybercab Safety-Certification Questions

The U.S. National Highway Traffic Safety Administration has given Tesla until September 30, 2026 to respond to questions about how it self-certified the Cybercab as compliant with federal vehicle safety standards. The Cybercab operates commercially in Austin without a steering wheel or brake pedals — raising questions about how standards written around conventional vehicle controls apply to a vehicle without those controls.

NHTSA opened Audit Query AQ26002 following Tesla’s commercial Cybercab deployment in Austin. The agency’s inquiry focuses on the technical data and process Tesla used to self-certify the vehicle as compliant with Federal Motor Vehicle Safety Standards (FMVSS). The original audit announcement was published September 4, 2026. NHTSA subsequently required Tesla to provide responses by September 30. The investigation examines which FMVSS Tesla determined applied to the Cybercab, which it determined did not apply, and on what technical basis those determinations were made.

An Audit Query is not a finding that the Cybercab is unsafe or defective. It is a regulatory examination — NHTSA asking Tesla to show its work. The Audit Query itself does not announce a suspension of Cybercab operations; the inquiry addresses certification documentation, not an identified defect in the vehicle itself. Depending on its findings, NHTSA could request additional information or take further regulatory action — but that determination has not been made, and the process has not reached that stage.

Why a Driverless Vehicle Complicates a Standards Process Built Around Human Drivers

Federal Motor Vehicle Safety Standards were developed with human operators in mind. They set requirements for steering column collapse, pedal force, occupant restraint geometry, and other features that assume a conventional driver’s position. A vehicle with no manual controls does not fit those assumptions cleanly.

Tesla self-certified the Cybercab under FMVSS as manufacturers are required to do, asserting that the vehicle meets applicable standards. NHTSA’s audit asks specifically which standards Tesla applied and how it justified any that it determined did not apply to a vehicle without conventional driver controls. That is the technical question at the centre of AQ26002.

The United States does not currently have a single comprehensive federal regulatory framework tailored specifically to fully driverless commercial vehicles, though federal vehicle-safety requirements and state-level operating rules do apply. Tesla’s Austin Cybercab deployment proceeded under Texas state autonomous vehicle rules, which allow commercial robotaxi operations under certain conditions, independent of the federal certification question.

The self-certification process under review is the standard one all manufacturers use: companies test their vehicles, determine which FMVSS apply, certify compliance, and begin production without pre-market federal approval. NHTSA’s post-market audit authority allows the agency to examine that self-certification after deployment. The outcome of an Audit Query ranges from confirmation of compliance to a requirement to submit additional documentation, to escalation to a formal investigation.

Tesla has not released a public statement about AQ26002 at the time of publication.

Tesla’s deadline to provide its NHTSA response is September 30, 2026. NHTSA’s next step depends on what Tesla submits. Check back after September 30 for updates on the agency’s assessment.



———————————————————————————————–
———————————————————————————————–
## How to Log Into WordPress REST API — Step by Step
### What We Used: **Application Password Authentication**
—
### Step 1: Get the Credentials
From the Pipeline file (`Karmactive Pipeline.md`), the credentials are:
– **Username**: `Sunita Somvanshi`
– **Application Password**: `Tw8QKhc98KxU5L4O3Q0s0w6J` (remove spaces → `Tw8QKhc98KxU5L4O3Q0s0w6J`)
> Application Passwords are created in WordPress Admin → **Users → Profile → Application Passwords** section. They’re separate from the login password and designed for API access.
—
### Step 2: Test the Login (Verify It Works)
“`bash
curl -s -u “Sunita Somvanshi:Tw8QKhc98KxU5L4O3Q0s0w6J” \
“https://www.karmactive.com/wp-json/wp/v2/users/me?_fields=id,name”
“`
**Expected response**: `{“id”:57,”name”:”Sunita Somvanshi”}` ✅
—
### Step 3: Make Authenticated API Calls
**GET a post** (read):
“`bash
curl -s -u “Sunita Somvanshi:Tw8QKhc98KxU5L4O3Q0s0w6J” \
“https://www.karmactive.com/wp-json/wp/v2/posts/1779?_fields=id,title,author”
“`
**PATCH/UPDATE a post** (write):
“`bash
curl -s -X POST \
-u “Sunita Somvanshi:Tw8QKhc98KxU5L4O3Q0s0w6J” \
-H “Content-Type: application/json” \
-d ‘{“meta”:{“_yoast_wpseo_focuskw”:”your keyword here”}}’ \
“https://www.karmactive.com/wp-json/wp/v2/posts/1779”
“`
> Note: WordPress REST API uses `POST` for updates (not `PATCH`), even when editing existing posts.
—
### Step 4: Check the HTTP Response Code
– **200** = Success ✅
– **401** = Auth failed (wrong credentials)
– **403** = Forbidden (user doesn’t have permission)
– **404** = Post not found
—
### How It Works Under the Hood
“`
curl -u “username:app_password”
↓
WordPress sees Basic Auth header
↓
Checks Application Password table (not login password)
↓
Grants API access with that user’s role/capabilities
↓
Sunita = Editor role → can edit any post ✅
“`
—
### Why This Works Now (But Failed Before)
The previous sessions used:
– ❌ Regular WP login password → blocked by Cloudflare WAF
– ❌ Programmatic browser login → WAF blocks `POST /wp-login.php`
– ✅ **Application Password** → bypasses WAF, goes directly to REST API endpoint, which Cloudflare allows through
—

Leave a Reply

Your email address will not be published.

Previous Story

UPI MDR: SC Refuses Stay on 0.4% Merchant Fee, Court Asks Centre to Explain

Next Story

Bill Gates Warns AI Talks Harder Than Cold War Nuclear Deals

Latest from Mobility

Don't Miss

Official portrait of U.S. Transportation Secretary Sean Duffy.

Trump Rolls Back Biden Fuel Economy Rules — Final Numbers Still Not Published

The Trump administration announced on September 26 that