Vehicle Sensing: Detection Is Not Authority
Vehicle Sensing: Detection Is Not Authority
Foundation article for the mandate-skeptic series - Vehicle Sensing Mandates
Generally, vehicle sensing system may detect a condition, classify a state, or estimate risk.
However, detection alone does not justify intervention, reporting, restriction, immobilization, or control.
That distinction matters as vehicles become more software-defined, sensor-dependent, and capable of changing operating states through electronic logic. A sensing signal may begin as information, but it can become something much more powerful when connected to propulsion enablement, vehicle-state management, telematics, gateways, or driver-access logic.
At that point, the question is no longer only whether the system can detect something.
The question becomes:
What is the system allowed to do with that detection?
That is the authority boundary.
A signal may support awareness. It may support a warning. It may support a diagnostic state. But once the signal becomes a command that can report, restrict, prevent, limit, or disable operation, the burden shifts.
The burden is no longer only sensing performance.
The burden becomes proof, false-positive control, owner rights, override logic, cybersecurity protection, and release responsibility.
Detection is evidence.
Hence, it is not authority.
The Signal-Output Problem
The most difficult point is not sensing activity.
The difficult point is proving what the signal means.
A system may detect eye closure, steering variation, head movement, facial orientation, delayed response, lane position, driver behavior, cabin condition, or some other signal. Yet the signal does not automatically prove drowsiness, distraction, impairment, or incapacity.
This is especially important for human-state sensing.
Human behavior is variable. A driver may look tired but remain capable. Another driver may appear alert while impaired. Lighting, face shape, glasses, medical conditions, fatigue, medication, emotional state, camera angle, sensor obstruction, and individual behavior can all affect classification.
Therefore, the system must do more than detect a pattern.
It must prove what that pattern means.
That is the hard problem. The issue is not merely whether a sensor produces output. The issue is whether the output can be interpreted with enough certainty to justify action.
The uploaded drowsiness note captures the difficulty directly: the most difficult point is achieving complete accuracy for the signal output.
That problem cannot be avoided by calling the feature “safety.”
False Positives and False Negatives
Both error directions matter.
A false negative misses a real risk. The system fails to detect a dangerous condition and may allow continued operation when intervention or warning should have occurred.
A false positive creates a different problem. The system claims risk where the real condition may not justify action.
If the system only issues a warning, the consequence may be limited. The driver may ignore it, reset it, or treat it as a nuisance.
However, when the system can restrict mobility, the false-positive problem changes.
A false positive is not a minor inconvenience when it controls mobility.
If the system prevents start, limits propulsion, disables a function, reports the driver, restricts operation, or triggers another authority path, the error becomes more than a sensing mistake.
It becomes an authority failure.
This is why accuracy cannot be discussed only as a statistical performance metric. The consequence of error matters.
A 95 percent classification rate may sound strong in a laboratory or report. However, if the remaining error can wrongly prevent a person from driving to work, leaving an unsafe location, responding to a family emergency, or accessing medical care, then the system’s authority must face a much higher burden.
The question is not only:
How often is the system right?
The stronger question is:
What happens when the system is wrong?
Warning Versus Control
A warning system is one thing.
A control system is another.
A vehicle may warn the driver, request attention, display a message, sound an alert, or recommend a break. These actions may be appropriate when the system detects possible risk but does not have enough authority to command the driver’s mobility.
However, when the same signal becomes connected to actuation, the ethical and engineering boundary changes.
A system that informs the driver preserves human authority.
A system that prevents, limits, or disables operation challenges that authority.
That does not mean control should never exist in safety-critical systems. Vehicles already contain many legitimate control functions. Brakes, stability control, airbags, immobilizers, and driver-assistance systems all involve authority under defined conditions.
But those systems require requirements, validation, failure-mode analysis, cybersecurity controls, diagnostics, release authority, and known operating boundaries.
The same discipline must apply to sensing-based authority.
Detection may support awareness.
It does not automatically create authority.
Calibration, Environment, and Human Variation
Signal meaning can change across conditions.
A driver-facing camera may perform differently in bright sun, darkness, glare, reflection, partial obstruction, or sensor contamination. A behavior model may respond differently to medical conditions, disability, fatigue, facial features, cultural behavior, stress, medication effects, age, or normal personal variation.
In addition, vehicle state matters.
The meaning of a signal may depend on whether the vehicle is parked, starting, moving slowly, operating at highway speed, navigating traffic, stopped at a light, or responding to an emergency.
Calibration also matters. A sensing system may depend on camera position, software version, sensor cleanliness, algorithm threshold, interior configuration, lighting model, or training-data assumptions.
For that reason, the system cannot treat every signal as universal truth.
It must understand the conditions under which the signal remains valid, the conditions under which confidence is degraded, and the conditions under which the signal should not support authority.
Signal confidence is not the same as moral, legal, or engineering authority.
A system may be confident and still wrong.
The Authority Handoff
The most important moment occurs when a signal becomes a command.
That is the authority handoff.
Before that point, the signal may inform, warn, classify, estimate, or support diagnostics. After that point, the signal may affect what the vehicle is allowed to do.
This handoff must be explicit.
Generally, who decides when warning becomes limitation?
Then, who decides when detection becomes reporting?
Followed by. who decides when classification becomes immobilization?
Finally, who decides when estimated risk becomes operating restriction?
These questions cannot remain hidden inside software logic, cloud policy, calibration strategy, or vague safety language.
The system must prove not only what it detected, but what it is allowed to do with that detection.
That proof must include the signal basis, operating conditions, confidence boundary, false-positive protections, override logic, recovery path, cybersecurity controls, and accountable release authority.
Otherwise, the vehicle may treat uncertain sensing output as legitimate command authority.
That is the line I object to.
Why This Matters Now
This discussion matters because advanced impaired-driving prevention technology is no longer only a theoretical topic. NHTSA has issued rulemaking material and a Report to Congress on advanced impaired-driving prevention technology, and the official discussion concerns passive technology intended to detect impaired driving and prevent or limit vehicle operation.
That does not mean every vehicle already contains a literal government “kill switch.”
That claim is too loose.
The real issue is more precise and more important:
Future sensing logic may become connected to vehicle operating authority.
Once that happens, the engineering question is not only whether detection is possible. The question is whether the authority created from that detection is justified, bounded, secure, reversible, auditable, and accountable.
Modern vehicles are cyber-physical systems, and NHTSA’s cybersecurity guidance recognizes that cybersecurity vulnerabilities can affect safety.
Therefore, sensing authority cannot be evaluated only as a driver-monitoring feature. It must also be evaluated as a control interface inside a software-defined vehicle.
Conclusion - Vehicle Sensing
In conclusion, I do not object to vehicle safety technology.
I object to treating uncertain sensing outputs as legitimate authority over mobility.
The harder the classification problem, the more dangerous it becomes to convert the signal into a control command.
Drowsiness, impairment, distraction, and driver readiness are difficult human-state classifications. They depend on signals, assumptions, thresholds, and context. They may support warnings or awareness, but they do not automatically justify restriction, reporting, immobilization, or control.
Detection is evidence.
It is not permission to command.
Before a vehicle sensing system can control mobility, the system must prove what it detected, what the signal means, what uncertainty remains, what errors are possible, what the vehicle is allowed to do, and who is accountable when the system is wrong.
That is the authority boundary.
Finally, a safety signal cannot become authority simply because it exists.
References
External References
- NHTSA — Report to Congress: Advanced Impaired Driving Prevention Technology, 2026.
https://www.nhtsa.gov/sites/nhtsa.gov/files/2026-03/Report-to-Congress-Advanced-Impaired-Driving-Prevention-Technology.pdf - Federal Register — Advanced Impaired Driving Prevention Technology, NHTSA ANPRM, 2024.
https://www.federalregister.gov/documents/2024/01/05/2023-27665/advanced-impaired-driving-prevention-technology - NHTSA — Cybersecurity Best Practices for the Safety of Modern Vehicles, 2022.
https://www.nhtsa.gov/sites/nhtsa.gov/files/2022-09/cybersecurity-best-practices-safety-modern-vehicles-2022-tag.pdf
Related Reading
- Vehicle Sensing Mandates Need Engineering Boundaries. https://georgedallen.com/vehicle-sensing-mandates-need-engineering-boundaries/
- Verification Boundaries: Why Capability Is Not Enough.
https://georgedallen.com/verification-boundaries-why-capability-is-not-enough/ - Runtime State Awareness: Why Systems Must Know Their State.
https://georgedallen.com/runtime-state-awareness-why-systems-know-their-state/
Copyright Notice
© 2026 George D. Allen.
All rights reserved. No portion of this publication may be reproduced, distributed, or transmitted in any form or by any means without prior written permission from the author.
For editorial use or citation requests, please contact the author directly.
About George D. Allen Consulting:
George D. Allen Consulting is a pioneering force in driving engineering excellence and innovation within the automotive industry. Led by George D. Allen, a seasoned engineering specialist with an illustrious background in occupant safety and systems development, the company is committed to revolutionizing engineering practices for businesses on the cusp of automotive technology. With a proven track record, tailored solutions, and an unwavering commitment to staying ahead of industry trends, George D. Allen Consulting partners with organizations to create a safer, smarter, and more innovative future. For more information, visit www.GeorgeDAllen.com.
Contact:
Website: www.GeorgeDAllen.com
Email: inquiry@GeorgeDAllen.com
Phone: 248-509-4188
Unlock your engineering potential today. Connect with us for a consultation.

