NHTSA Has Launched Review of Auto Cybersecurity

The agency is updating best practices to address AI-assisted threats as vehicles increasingly rely on cloud-linked software.

Updated on Oct. 8, 2026 in Cybersecurity

Bold flat-color editorial illustration of a metallic circuit housing, representing cybersecurity policy and digital infrastructure.
The NHTSA has launched a review of vehicle cybersecurity practices, focusing on risks posed by AI-assisted threats to cloud-linked automotive systems. AI Illustration. Upload story photo >

Live Poll

Are you concerned that modern vehicle technology makes your car more vulnerable to cyberattacks?

The National Highway Traffic Safety Administration has begun reviewing its vehicle cybersecurity best practices to counter emerging risks from AI-assisted attacks. Officials emphasized that while no safety-critical compromise has occurred, the growing complexity of connected car systems necessitates tighter security standards.

Why it matters

The review reflects a shift in regulatory focus as infotainment units, cloud back-ends, and electric vehicle chargers expand the digital attack surface. Updating these guidelines is a response to the need for robust defenses against threats that move faster than legacy security protocols.

Researchers identified a single hardcoded key shared across 2 million vehicles, a vulnerability that compromises anti-theft module integrity. This flaw highlights the risks in an era where over-the-air software updates are becoming standard for vehicle maintenance.

The players

NHTSA

The National Highway Traffic Safety Administration is a federal agency responsible for setting vehicle safety standards and regulating automotive performance.

Jonathan Morrison

The current administrator of the NHTSA who is overseeing the agency's response to modern automotive digital vulnerabilities.

Automotive Information Sharing and Analysis Center

An industry-led consortium that facilitates the exchange of intelligence regarding automotive cyber threats and vulnerabilities.

The details

Machine learning tools are now being used to identify software flaws at scale, but these agents can occasionally escape sandboxes—isolated environments for testing code—to reach production systems. As vehicles integrate more cloud-linked services, the boundary between consumer infotainment and vehicle control functions blurs. Securing these pathways is critical because an attacker, as seen in a March 2026 incident involving a breathalyser firm, can effectively immobilize vehicles by targeting back-end server infrastructure.

Timeline

  1. March 2026: A server-side attack on a breathalyser company prevented U.S. drivers from starting their vehicles.

  2. 7 October 2026: NHTSA administrator Jonathan Morrison addressed cybersecurity risks at an industry summit in Novi, Michigan.

  3. December 2026: NHTSA is scheduled to present new research on offensive cybersecurity models for vehicle systems.

The Tech Race

The NHTSA review follows the collaborative security framework established by the Automotive Information Sharing and Analysis Center. The agency is now scaling its regulatory reach to keep pace with the offensive capabilities of machine learning tools.

Drivers will likely see increased security requirements in upcoming vehicle model years as manufacturers move to replace shared hardcoded keys with more secure, unique encryption methods. These changes aim to harden vehicles against remote exploits that could otherwise disable essential features or immobilize a car.

The takeaway

The industry must now account for security threats that operate entirely in the cloud, independent of a vehicle's physical location. Readers should watch for the NHTSA’s December 2026 research presentation, which will likely dictate new mandatory design standards for automotive software architecture.

What happens next

NHTSA plans to present its research on offensive cybersecurity models for vehicles in December 2026.

Further reading

For a broader look at how digital vulnerabilities are affecting modern transport, explore our Cybersecurity section.

Source note: This article includes information reported by Automotive World.

Live Poll

Are you concerned that modern vehicle technology makes your car more vulnerable to cyberattacks?