NHTSA investigates Comma's hands-off driving tech after 3 deaths
Regulators catch up with hands-off driving, OpenAI arms Ukraine's cyber defenders, and a 2B open model punches two weight classes up.
A federal safety investigation is underway into Comma.ai's hands-off driver assistance system after five reported crashes — two of them fatal, killing three people — and as many as 11 injuries across four of the incidents. The National Highway Traffic Safety Administration's defects office opened the probe this week, saying the crashes involved Comma devices failing to detect or respond to slow or stopped vehicles in the same lane. The detail that should worry every open-source project: some of the crashes, including at least one of the fatal ones, appear to involve "forked" versions of Comma's openpilot software. In the February crash in Ascension Parish, Louisiana, a Toyota RAV4 running FrogPilot — a third-party fork — struck a stopped first responder vehicle, and state police say two rear-seat passengers died.
Comma's openpilot controls steering, adaptive cruise and automated lane centering on a range of consumer cars, promising an experience "similar to Tesla Autopilot" — with the standing warning that the driver must be ready to retake control instantly, backed by a camera-based system that watches for distraction. That warning is exactly what the probe will stress-test: whether a camera and a driver-responsibility disclaimer are enough for hands-off highway use, and whether an open-source codebase with unofficial forks can carry safety-critical liability at all. Founder George Hotz, who stepped back from day-to-day operations in 2022, has not commented.
OpenAI is giving the Ukrainian government free access to Daybreak, its program for putting frontier AI in the hands of cyber defenders. Announced on the sidelines of the UN General Assembly with Ukraine's Ministry of Digital Transformation, the deal lets Ukrainian teams hunt vulnerabilities and test fixes faster — national incident response team CERT-UA handled nearly 6,000 cyber incidents in 2025, most aimed at hospitals, energy and telecoms. OpenAI had already lent the same models to defenders in France, Germany and Poland, where ENISA's sweep of EU-institution software turned up flaws that are now fixed and Poland's cyber agency found six vulnerabilities in third-party router software. Ukraine is the most battle-tested recipient yet, and the deal is a quiet datapoint in the argument that cyber defense is the acceptable face of military AI. We covered how Cloudflare turns OpenAI's cyber model into an edge patch shop — this is the same playbook, pointed at a state under fire.
OpenBMB's MiniCPM5-2B is making the case that 2 billion parameters is enough — if you train the small model like a big one. The open-weight release from the Tsinghua-rooted team, out earlier this month under Apache 2.0 with 131K-token context and tool calling, averages 53.9 across its eval suite versus 51.1 for Qwen3.5-4B, and scores 46.4 on SWE-bench Verified — ahead of everything else in its comparison set. The standard caveat applies: the headline numbers are OpenBMB's own evals, though an early independent estimate lands in respectable territory for the size. Small, permissively licensed models like this are what actually runs on a laptop — the same efficiency story as Europe's top-scoring AI model is a compressed GLM-5.2.
What to watch: whether NHTSA's probe stays on Comma's official builds or widens to the fork ecosystem — the answer sets the liability template for every open driving stack that follows.
Should open-source driving software carry the same liability as a commercial stack when a fork is behind the wheel? Tell us in the comments.
Sources: TechCrunch · NHTSA · Louisiana State Police · OpenAI · Techmeme · OpenBMB MiniCPM5-2B (Hugging Face) · ModelScope · DigitalToday