FOUNDING OFFER · 3 MONTHS
FOR $45 $17.76
CEO TIMES
JOIN NOW
CEO Times
Sign Up
Markets & FinanceBusiness & CorporatePoliticsThe WorldOpinion
NOW
U.S. National Debt Crosses $40 Trillion as Boomer-Era Policies Drive 81% of Future Spending GrowthBillionaire Igor Tulchinsky Donates £5M to British Museum's Bayeux Tapestry Show — the Biggest European Exhibition of 2026Oil Hits $99.85 a Barrel — Up More Than $33 in a YearMystery Nonprofit Drops $2M Bitcoin Ad Blitz in the Wall Street Journal — and Nobody Will Say Who's PayingHunter Biden Launches $LAPTOP Meme Coin — 1 Billion Tokens, 30% Kept by FoundersAdaptability Over Forecasting: Top Executives Declare Certainty a Dead StrategyGavekal's Gave: Chinese Bonds Offer Safe Haven as U.S. Debt Hits $40 TrillionCanada Reroutes $10B in Oil East as U.S. Tariffs Hit 50%Macau Bets $16 Billion to Reinvent Itself as a Business City by 2030Peru's Inflation-Targeting Model Cannot Fix Venezuela — Here's WhyU.S. National Debt Crosses $40 Trillion as Boomer-Era Policies Drive 81% of Future Spending GrowthBillionaire Igor Tulchinsky Donates £5M to British Museum's Bayeux Tapestry Show — the Biggest European Exhibition of 2026Oil Hits $99.85 a Barrel — Up More Than $33 in a YearMystery Nonprofit Drops $2M Bitcoin Ad Blitz in the Wall Street Journal — and Nobody Will Say Who's PayingHunter Biden Launches $LAPTOP Meme Coin — 1 Billion Tokens, 30% Kept by FoundersAdaptability Over Forecasting: Top Executives Declare Certainty a Dead StrategyGavekal's Gave: Chinese Bonds Offer Safe Haven as U.S. Debt Hits $40 TrillionCanada Reroutes $10B in Oil East as U.S. Tariffs Hit 50%Macau Bets $16 Billion to Reinvent Itself as a Business City by 2030Peru's Inflation-Targeting Model Cannot Fix Venezuela — Here's Why
CEO Times
Sections
The outlet
Business & Corporate

50 Waymos Jammed One Street by a Prankster — and the Robotaxi Industry Has No Airbag for That

A coordinated denial-of-service stunt in San Francisco exposed a regulatory blind spot that AI-powered bad actors could exploit far more dangerously than any college prank.
Imagen ilustrativa
Friday, August 14, 2026

The Prank That Became a Warning

A self-proclaimed 'tech prankster' named Riley Walz organized 50 individuals to simultaneously order a Waymo on the same dead-end street in San Francisco. The coordinated denial-of-service attack created a vehicle pileup that forced the company to disable rides until the following morning. No one was hurt. The next time, experts warn, the outcome may not be so benign.

The incident has reignited a debate that the autonomous vehicle industry has largely avoided: cybersecurity is not yet a primary regulatory requirement for robotaxis, and the attack surface these vehicles present is enormous.

An Attack Surface the Size of a Fleet

Unlike conventional vehicles, robotaxis depend on dozens of interconnected electronic control units, high-speed networking, cloud connectivity, GPS, cameras, lidar, radar and AI models that continuously interpret the world around them. Every one of those components expands what cybersecurity professionals call the 'attack surface' — the number of possible entry points a hacker can exploit.

Louay Abdelkader, director of product management at QNX, called it a significant problem for the sector. 'Of course … keep in mind that in automotive safety, it took a while for it to adopt,' Abdelkader told Fortune. He argued that lawmakers should make cybersecurity a primary consideration akin to airbags, noting that every connected vehicle introduces some degree of cyber risk.

The airbag analogy is precise. Federal law did not require airbags in every vehicle until 1998 — more than 100 years after the first automobile and roughly 30 years after airbags were first invented as a safety measure. The industry is now running the same slow clock on a threat that moves at the speed of software.

AI Compresses the Timeline for Attackers

The advent of generative AI has sharpened the risk considerably. Historically, hackers needed significant time, technical expertise and resources to identify and exploit vulnerabilities. Abdelkader told Fortune that AI has dramatically compressed that timeline. Malicious actors can now use AI to identify vulnerabilities, automate attacks and develop exploits far faster — and with far more destructive intent — than Walz's prank.

Even without directly steering a vehicle, disrupted communications could degrade an autonomous system's ability to safely navigate, experts note.

A Patchwork of Rules, No Federal Floor

California requires autonomous vehicle manufacturers to demonstrate they can safely monitor, update and maintain their fleets while complying with federal vehicle cybersecurity guidance. Arizona has incorporated cybersecurity planning into broader autonomous vehicle deployment policies. Michigan has established cybersecurity initiatives through partnerships with industry and research institutions.

Internationally, the United Nations' UN Regulation No. 155 now requires automakers in many markets to maintain certified cybersecurity management systems throughout a vehicle's lifecycle, while ISO/SAE 21434 establishes engineering standards for cybersecurity across vehicle development.

Waymo and the California DMV did not respond to requests for comment.

Meanwhile, the robotaxi sector keeps expanding. Zoox recently received a commercial exemption from the National Highway Traffic Safety Administration allowing paid service broader access without manual controls. Tesla has moved into the space with Cybercab in at least seven cities. Waymo now operates in 11 major U.S. cities.

The Market Deserves a Foundation, Not an Afterthought

Abdelkader put the responsibility squarely on both manufacturers and lawmakers. 'When you're developing a cybersecurity system, you start from the ground up. It's like building a house,' he said. 'If your foundation is not strong, it becomes very difficult for you to build a robust and secure house.'

That is the right frame. Free enterprise built the robotaxi industry at remarkable speed, and the market will ultimately price in risk — but only if regulators establish a clear, uniform floor before a bad actor with an AI toolkit does the pricing for them. A college prank exposed the gap. Washington should not wait for something worse to close it.

More from Business & Corporate