The Certification That Cannot Exist: Tesla FSD, the AI Act, and Europe's Verifiability Gap

CredLion
Bitcoin

Hook

Europe's vehicle approval system is a library of forms. Each form describes a fixed object. A brake caliper. A lighting array. A lane-keeping assist that, under UNECE Regulation No. 157, is capped at 130 km/h and must hand control back to a human. Every form presumes a frozen artifact that a regulator can inspect once and certify forever.

Tesla does not sell a frozen artifact. It sells a subscription to a model that is retrained, recompiled, and redeployed over the air every few weeks. There is no form for that. That absence — not any single accident statistic, not any one marketing claim — is the load-bearing fact in the current collision between Tesla and European regulators. The company is reported to be pushing EU authorities toward approval of Full Self-Driving while its safety claims draw scrutiny. The framing is thin. The underlying problem is not.

I have spent most of my career on the other side of this exact wall: verifying systems that were designed never to be verified. The lesson transfers cleanly. The bug is always in the assumption — and Europe's assumption is that a certifiable object holds still.

Context: How Europe Actually Approves a Car

To understand why FSD's European approval is stuck, you have to understand that the European Union does not regulate "autonomous driving" as a single category. It regulates through type approval, and type approval is a manufacturing-era instrument. A vehicle, or a specific function within it, is certified against a named standard. The certification binds the object as built. It assumes a production line, a fixed bill of materials, and a state that does not change after the signature.

UNECE R157 — the Automated Lane Keeping System regulation — is the closest existing channel for hands-off driving. It permits operation only below 130 km/h, only on motorways, only with a human able to resume control on request. Mercedes' Drive Pilot cleared that bar, becoming the first system to hold a genuine Level 3 approval in a major market. Note what it is: a narrow, bounded, verifiable claim. It does not say "the car drives." It says "under these conditions, in these lanes, below this speed, the car performs this specific function."

The United States does not work this way, and the difference matters. American regulation relies heavily on self-certification — manufacturers attest to compliance with Federal Motor Vehicle Safety Standards, and the government reacts after the fact through recalls and investigations. That is why FSD can ship in North America as an evolving, supervised product while European regulators require pre-market, function-by-function demonstration. Europe asks permission. America asks forgiveness. Tesla was built for the second system.

FSD fits no existing European channel. In North America it is, legally and operationally, a Level 2 system: the driver remains responsible and must monitor at all times. But the name — Full Self-Driving — asserts a capability the system does not hold. Under the EU's Unfair Commercial Practices Directive, a name that implies Level 5 autonomy while delivering Level 2 supervision is not a branding quirk. It is a potential misrepresentation, and regulators treat it as one. The gap between the label and the function is itself a regulated object.

Layer on the AI Act. It classifies AI systems used in the safety components of vehicles as high-risk. High-risk classification is not a label; it is a compliance program. Risk management systems. Technical documentation. Automatic logging. Human oversight. Accuracy, robustness, and cybersecurity requirements. Post-market monitoring. For a conventional rule-based control system, this is arduous but tractable — you document what you wrote. For a data-driven, end-to-end neural network, the documentation obligation collides with the architecture itself.

And beneath all of it sits the General Data Protection Regulation and the bloc's data-sovereignty posture. FSD's improvement depends on aggregating driving data. Europe's rules restrict how that data crosses borders. The data flywheel has a legal seam running through it.

None of these are marketing problems. Each is a structural incompatibility between a living system and a static approval regime. Composability without audit is just delayed debt — and Tesla has been compounding that debt in public.

Core: The Architecture That Cannot Be Read

Here is the technical core of the impasse, and it is a problem my field has been wrestling with for a decade under a different name.

Traditional autonomous stacks were modular. Perception produced objects. Prediction estimated their trajectories. Planning chose a path. Control executed it. Each stage had an interface. You could probe an interface. You could feed a perception module a synthetic frame and check its output. You could unit-test the planner against recorded scenarios. The system was a pipeline of inspectable parts, and — critically — you could write a document that described what each part did.

FSD V12 and its successors collapsed the pipeline. The architecture is, in Tesla's own description, roughly "photons in, controls out": a single neural network mapping sensor input to driving commands, with the intermediate reasoning buried in latent space. This is a genuine engineering achievement. It removes the information loss that accumulates when you force the world through hand-designed interfaces. It generalizes more gracefully. It behaves more like a human.

It is also, from a regulator's standpoint, opaque by construction. There are no interfaces to probe. There is no module to point at and say "this is where the lane-keeping happens." The behavior emerges from billions of weights shaped by data. You cannot read the model the way you read source code. You cannot diff two versions and explain what changed, because the change is distributed across the whole network. The old modular stack was a building with labeled rooms. The end-to-end model is a single room with no doors and no map.

A type approval is a snapshot. An OTA model is a stream. You cannot certify a stream by photographing it once. This is the heart of the matter. Every time Tesla ships a weight update, the certified object — assuming one could be certified — is replaced by a different object. The regulator's signature attaches to something that no longer exists. In software terms, Europe wants a release candidate; Tesla ships a rolling build.

Now, I have audited systems built specifically to survive this problem, and the answer is not "try harder." The answer is determinism and verifiability. In 2026 I stress-tested an autonomous AI-agent framework that used zk-SNARKs to verify identity and action without revealing the underlying data. The design principle there was not transparency — it was provability. The agent did not have to expose its weights. It had to produce a proof that a specific computation had occurred correctly over a committed input. That is the primitive European regulators actually need, and it is the primitive Tesla's architecture currently cannot supply.

The Certification That Cannot Exist: Tesla FSD, the AI Act, and Europe's Verifiability Gap

I also found the failure mode that framework was most exposed to, and it maps directly onto FSD. We poisoned the oracle feed — the input that told the agent what state the world was in — and watched ambiguous state transitions turn into unauthorized actions. The model behaved correctly given corrupt inputs. The bug was upstream, in the assumption that the inputs were honest. FSD has the same exposure. Its safety case rests on inputs it cannot fully verify: sensor data, map data, and — crucially — its own performance metrics.

This reframes the entire debate. Europe is not asking Tesla to reveal its source code. It is asking Tesla to make a claim that a third party can check without trusting Tesla. FSD's safety case, as currently constructed, is an oracle claim: it says, in effect, "trust our internal metrics." But trust is a variable, not a constant — and in a regulated industry, an unverified oracle is a single point of failure. When your safety argument reduces to "believe us," you have not built a safety argument. You have built a testimony.

The data localization problem compounds the verifiability problem. Suppose Europe demanded an independent audit of FSD's safety performance. The evidence would live in Tesla's fleet data — disengagement counts, intervention logs, shadow-mode comparisons, near-miss reconstructions. Much of that data originates in Europe but is aggregated in the United States for training. Under GDPR and the bloc's sovereignty posture, the regulator may not be able to obtain the raw material of the audit it wants to run. So the audit cannot be conducted even if both parties agreed it should be. The verification gap is not only architectural. It is jurisdictional. You cannot prove a property about data you are not allowed to hold.

I have watched this movie in another protocol. In 2020 I spent four hundred hours simulating flash-loan attacks against early Aave, tracing value flows across six lending pools until a reentrancy edge case surfaced in the interest-rate logic. The finding was not that any single pool was broken. It was that composability had turned six individually reasonable components into one system with a shared failure mode nobody had documented. FSD is composable in the same way. It depends on sensors, maps, connectivity, cloud training, and a regulatory regime — and each dependency is an input it must trust. The safety case that treats FSD as a self-contained box is the same error as treating each DeFi pool as self-contained. The debt comes due at the seams, not in the parts.

Then there is liability, and this is where the whole structure starts to creak. Under a Level 2 classification, the human is responsible. That is legally clean and commercially awkward. Tesla markets a capability it disclaims at the moment of accountability. If the driver is liable when FSD fails, then FSD is an advanced driver-assist system, and the name is a liability. If Tesla is liable, then Tesla is asserting a Level 3-or-higher claim that triggers an approval regime it has not cleared. The company is caught between two legal identities and needs the marketing of one with the liability of the other. No regulator in the world signs off on that.

I have seen this pattern before, in a different asset class. In 2022 I spent six weeks pulling apart the TerraUSD mechanism and concluded that the incentive structure was mathematically unsustainable regardless of market conditions. The parallel is not the collapse — it is the argument. Terra's defenders said the community's will would hold the peg. The peg was a function of arbitrage incentives, not sentiment. Here, FSD's defenders argue the technology is safer than the metrics show. But safety, like a peg, is a property that must be demonstrated to the counterparty, not asserted by the issuer. Logic does not care about your narrative.

The name deserves one more pass, because it is doing more damage than any single technical shortfall. "Full Self-Driving" is not a description; it is a claim about a capability class. In Europe, a claim about a capability class is a regulated statement. A system that is Level 2 in fact and Level 5 in name creates a gap that regulators must close — either by forcing a rename, by restricting activation, or by refusing approval until the name matches the function. Zero knowledge of a system's behavior is a liability, not a virtue — and here the phrase cuts two ways. The public has zero knowledge of what FSD actually decides. The regulator has zero knowledge of how it decides it. And the technology that could resolve both — a zero-knowledge proof of correct execution over committed inputs — is precisely what is absent from the certification file.

What would a verifiable FSD actually look like? I have proposed this pattern before in the on-chain identity space, and it translates. You do not certify the weights. You certify a wrapper. The wrapper does three things. It commits to a specific model version by hash, so the certified object has a name. It constrains the operational design domain in code — speed, geography, weather, road class — so the certified claim is bounded and checkable. And it logs every decision with a tamper-evident record, so that after any incident a third party can reconstruct exactly which model, over which inputs, produced which output. None of that requires Tesla to open-source FSD. All of it requires Tesla to make FSD provable rather than merely asserted.

That is a heavier engineering lift than a public relations campaign. It is also the only bridge across the verifiability gap, because it converts a testimony into a proof. And it explains why the current fight looks the way it does: Tesla is pushing regulators, not because the technology is ready for the current regime, but because the current regime has no category for what Tesla built.

Contrarian: Europe Is Not Afraid of AI. It Needs a Defendant.

The prevailing narrative says Europe is slow, bureaucratic, and hostile to innovation — that Brussels is strangling a safer technology out of caution. That narrative is comfortable and wrong in its emphasis.

Europe is not blocking FSD because it fears artificial intelligence. It is blocking FSD because its entire legal system requires a defendant. Type approval is, at bottom, a liability-assignment machine. It exists to answer one question: when this thing fails, who is responsible? For that machine to work, the thing must be a fixed object that someone built and someone can be held to. A model that rewrites itself over the air every few weeks has no stable author for its behavior on any given day. You cannot sue a gradient.

The deeper blind spot is that everyone is debating whether FSD is safe enough when the binding constraint is whether it is auditable at all. These are different questions, and only one of them has a form. A system can be statistically safer than a human driver and still be uncertifiable, because certification is not a measure of outcomes — it is a demonstration of process. Europe certifies processes. Tesla ships outcomes. The two sides are not having the same conversation, and no amount of safety data will bridge a gap that is procedural rather than empirical.

There is also a quieter force at work, and it is not about safety. Europe's automotive incumbents — Volkswagen, Mercedes, BMW — are behind on Level 3 and beyond. Mercedes cleared R157 first, but at 60 km/h in a narrow band, and it did so partly because the approval regime was written around what was demonstrable at the time. A Tesla approval would hand a foreign competitor a time window over the domestic industry that European regulators have little incentive to open. Industrial policy and safety regulation are not separable here, whatever the official framing. Interdependence amplifies both yield and risk — and the European supply chain's dependence on a slow approval cycle is itself a variable nobody puts in the model.

The Certification That Cannot Exist: Tesla FSD, the AI Act, and Europe's Verifiability Gap

And the laser-lidar camp has every reason to let FSD stay blocked. If a pure-vision, end-to-end system clears the world's strictest regulator, the argument that lidar is a safety necessity — and with it a slice of the sensor supply chain — weakens. The approval fight is not only Tesla versus Brussels. It is a proxy war over which technical route gets to write the next standard. Whoever's route becomes the certified template owns the reference architecture for a decade.

The Certification That Cannot Exist: Tesla FSD, the AI Act, and Europe's Verifiability Gap

Meanwhile the actual competitive clock is running elsewhere. Waymo operates genuine Level 4 robotaxis in limited geographies, with a multi-sensor stack and a safety record it can point to. Chinese players — Baidu's Apollo, XPeng, Huawei — are scaling domestically at a pace no European regulator is built to accommodate. Europe is, by design, the slowest major market to adopt autonomous driving. That is not a bug in the European model; from Brussels' perspective it is the feature. But it means the standard Europe eventually writes will be written late, and possibly written around a technology that has already been overtaken.

The uncomfortable conclusion is that the FSD fight is not really about FSD. It is a rehearsal for a much larger question: how does any AI system enter any high-consequence physical domain under a regime built for deterministic machines? The same wall stands in front of medical AI, financial execution, grid control, and legal decisioning. FSD just happens to be the most visible thing currently walking into it.

Takeaway

The template Europe sets for FSD will not stay confined to cars. It will become the template for every AI system that wants to enter a regulated physical industry. The question regulators are fumbling toward is not "is this model good?" but "can this model's behavior be proven to a third party without trusting its author?" That is a verifiability question, and it is the same question blockchains have been answering badly and slowly for years.

Watch for one tell. If Tesla quietly ships a compliance-degraded, region-limited FSD variant for Europe — a bounded operational design domain, a renamed supervised mode, a deterministic fallback layer, a tamper-evident log — that is not a retreat. It is the company admitting the real constraint. The bug is always in the assumption. Europe's assumption is that the certified object holds still. Tesla's assumption is that being faster than the rulebook is the same as being right. Only one of them can be revised without an act of legislature. Which one do you think moves first?

Market Prices

BTC Bitcoin
$83,650.1 -3.06%
ETH Ethereum
$2,574 -5.22%
SOL Solana
$117.18 -2.54%
BNB BNB Chain
$766.5 -2.22%
XRP XRP Ledger
$1.44 -4.56%
DOGE Dogecoin
$0.0890 -6.88%
ADA Cardano
$0.2540 -8.73%
AVAX Avalanche
$10.99 -4.29%
DOT Polkadot
$1.11 -9.93%
LINK Chainlink
$13.4 -4.65%

Fear & Greed

71

Greed

Market Sentiment

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$83,650.1
1
Ethereum
ETH
$2,574
1
Solana
SOL
$117.18
1
BNB Chain
BNB
$766.5
1
XRP Ledger
XRP
$1.44
1
Dogecoin
DOGE
$0.0890
1
Cardano
ADA
$0.2540
1
Avalanche
AVAX
$10.99
1
Polkadot
DOT
$1.11
1
Chainlink
LINK
$13.4

🐋 Whale Tracker

🔴
0xdb75...7b4c
6h ago
Out
1,446 ETH
🔵
0xa853...6db5
12h ago
Stake
49,869 SOL
🔵
0xef4d...b09a
5m ago
Stake
683,568 DOGE

💡 Smart Money

0xcb97...2eca
Arbitrage Bot
+$2.8M
93%
0x13f0...3ed8
Institutional Custody
+$1.5M
70%
0x83d6...27ee
Experienced On-chain Trader
+$4.4M
73%