The Name Is the Defect: What Tesla's $240m Verdict Teaches About Autonomous-Feature Liability
Call a feature 'Full Self-Driving' and a jury will read the promise, not the disclaimer. Tesla just found out what that sentence costs, and every team shipping an 'autonomous' agent should read the bill.
Call a feature 'Full Self-Driving' and you have written the sentence a court will read back to you. In August 2025 a jury in the U.S. District Court for the Southern District of Florida found Tesla partly liable for a 2019 crash near Key Largo that killed Naibel Benavides Leon while the driver was using Autopilot. As the Associated Press and Reuters reported, the jury set compensatory damages at about $129m, put roughly a third of that, near $43m, on Tesla, then added $200m in punitive damages. Tesla has said it will appeal. The verdict form does not spell out why the jury reached for a punitive award, so what follows is analysis rather than a finding: the plaintiffs' theory and the sheer punitive-to-compensatory ratio point at the product's name, not only its performance on the day. Punitive damages are not compensation. They are a message, and the message worth reading is that autonomous-feature liability now attaches to what you called the thing.
Follow the mechanism. Autopilot and Full Self-Driving are driver-assistance systems that need a hands-on, attentive human, and the manual says exactly that. The name says the opposite. When a user over-relies on the system, the maker's instinct is to point at the manual, but the name is the louder representation: repeated in marketing, priced into the purchase, printed on the car itself. A caveat three menus deep does not undo a two-word brand promise. Marketing writes cheques the legal department is later asked to honour.
The trial's facts matter mostly because they show why this one reached a jury at all. The driver, George McGee, admitted he was distracted, yet Tesla still carried a share of the blame, because user fault does not erase a defect in the representation. But the plaintiffs were not customers who had clicked 'agree'. They were the family of a pedestrian, alongside her injured companion Dillon Angulo, so the arbitration clauses and confidential settlements that usually keep these disputes quiet did not apply, and the case reached open discovery. There the plaintiffs alleged Tesla had withheld or failed to preserve vehicle data from the seconds before the crash, telemetry the company first indicated it did not hold before it surfaced in the litigation. Missing data in a case about an 'autonomous' system reads to a jury as a company that could not, or would not, show its own machine's decisions.
What does the Tesla verdict mean for companies building AI agents?
Port the logic to software shipping this year, because the naming pattern has already jumped domains. Salesforce sells Agentforce on the promise of autonomous agents that act without a human in the loop, and Cognition markets Devin as an autonomous AI software engineer. Read honestly, most systems wearing that label are supervised assistants with a strong demo and a long tail of quiet failure. The distance between the noun on the tin and the behaviour in production is precisely the gap the Tesla jury put a number on. An 'autonomous agent' is a representation, and a representation is something a court can measure a customer's reliance against.
In one respect the exposure is sharper than a car's. A driver still has hands near the wheel and eyes that could have been on the road, however badly they used them. A business that buys an 'autonomous' agent is told, by the name, that it can take its hands off entirely. So when that agent empties an account, wires money to the wrong counterparty, deletes the records it was meant to reconcile or approves a contract nobody read, the buyer's defence writes itself: the product said it could run unsupervised, so we let it run unsupervised. Every instance of the over-reliance you advertised becomes evidence against you rather than user error. Aspirational naming turns your own marketing into the plaintiff's opening slide.
That makes naming an engineering decision with a price tag, not a style choice. If the shipped capability is supervised, the honest label is 'assistant', and the honest architecture keeps a person genuinely in the loop on anything you cannot take back, which is why practical AI with human control is a legal posture as much as a technical one. The same discipline runs through how you bound secure agentic systems: a capability you cannot constrain is a capability you will be asked to answer for, so the controls that hold up are reversibility and a hard ceiling on blast radius, not a promise that the model behaves. Treated properly, feature nomenclature is a technical strategy question for the board, settled before the launch copy is written rather than after the first bad run.
There is a second-order move worth making now. The word 'autonomous' in a product name, a sales deck or a master services agreement is a warranty you may be held to, so the cheapest insurance is to describe what the system does rather than what the roadmap hopes it will. Vendors quietly retitling 'autonomous agent' as 'agent-assisted workflow' are not being modest. They are pricing the name before a court does it for them.
Why are courts and regulators classifying by function, not label?
The naming trap has a regulatory twin: claim the lighter category and hope the rules follow the label. YouTube has argued it is a video-sharing platform rather than social media, which would place it outside a youth ban, even as a broadcaster airing the same clips wears full content rules. Australia's eSafety regime bars under-16s from social media from 10 December 2025, and after first leaning towards carving YouTube out, the government folded it back in on the eSafety Commissioner's advice, with penalties reported to reach A$49.5m per breach. The direction of travel is the point. Regulators are increasingly classifying a product by what it does, which is the same instinct the Florida jury applied to a name. Self-description is losing to function, in the statute book and the courtroom alike, and an 'autonomous agent' that is really a supervised assistant sits on exactly the wrong side of that line.
The through-line is short. A name is a claim, a claim is a representation, and a representation is something you can be made to pay for. Price the name before the marketing team ships it.
Questions people ask
Is calling a system 'Full Self-Driving' the same as false advertising?
Not automatically, but it narrows your defences. The risk is not only a regulatory false-advertising claim; it is that in a product-liability case the name becomes the representation a jury weighs against the user's actual reliance. A capability name that outruns the shipped capability turns ordinary over-reliance into evidence of a defect.
Does a driver or user admitting fault protect the company that built the system?
Less than firms assume. Fault is apportioned, not awarded all-or-nothing. A user's admitted carelessness can sit alongside a finding that the product, as named and marketed, encouraged that carelessness. Both can be true at once, and the manufacturer can still carry a substantial share plus punitive damages.
How does the Tesla verdict affect companies building AI agents?
Directly. The exposure attaches to the promise in the name, so an 'autonomous agent' marketed as running unsupervised is measured against that claim when it causes harm. The mitigations are design-level: genuine human oversight, hard constraints on what the agent can do, and naming that describes the shipped capability rather than the roadmap.
Related
- Epic v Google: The App Catalogue Remedy That Hands Rivals the Moat
- Memory Prices Turned. Renegotiate the Supply Contract Before the Next Refresh.
- How AI Makes Bad Bosses Worse: The Agreeability Machine in the Corner Office
- Digital Business
Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.