Autonomous vehicles (AVs) are programmed to put safety above all else. When sensors encounter unexpected situations like a detour or blinding sun glare, the vehicle halts in response. While this fallback mechanism prevents collisions, stalled AVs become a different kind of hazard and cause operational downtime.

Technically speaking, this happens because statistical confidence drops below required safety thresholds. Frameworks like ISO 21448 Safety of the Intended Functionality (SOTIF) provide the guidelines for handling these scenarios, while regional regulations enforce strict limits on roadside standoffs.

Understanding SOTIF is one thing; operationalizing across a growing fleet is another. The rest of this piece breaks down how.

What is SOTIF?

While other regulations like ISO 26262 (Functional Safety) addresses internal system failures, such as a short-circuited camera, damaged wiring or a processor malfunction, SOTIF focuses on functional limitations. It governs scenarios where hardware and software operate as intended, but the AI misinterprets a complex environment. 

“Physical sensors and AI excel at calculating road-scenario probabilities,” says Siva Raghava, Sr. Director for Autonomous Mobility Center of Excellence, Safety & Client Services at TaskUs and SOTIF-trained professional. “While emerging vision-language-action (VLA) models are helping bridge this gap, handling sudden situational changes and unpredictable edge cases remains a complex challenge.”

To ensure an AV does not guess its way through these edge cases, SOTIF mandates structured risk mitigations. Crucially, it provides the engineering framework for operational design domain (ODD) fallback mechanisms and minimal risk maneuvers (MRMs), ensuring that when an AI encounters its limits, the vehicle safely yields or halts.  

The limits of automation in resolving AV edge cases

Adding more sensors, increasing onboard compute power and training models on millions of additional miles significantly improves AV intelligence. Siva says, “However, environmental conditions remain inherently unpredictable, so edge cases will always occur.” 

Achieving complete software automation to address 100% of the unforeseen is both physically and economically impractical. “Fixing rare problems with more computing power and data eventually stops working. It clutters the system and harms overall performance, which is why human expertise is critical,” Siva explains. 

Additionally, regulatory safety type approvals prohibit live, unsupervised neural network updates on active fleets. “To comply with SOTIF, operators should build a human-in-the-loop (HITL) triage layer to evaluate edge cases and move vehicles out of minimal risk states safely,” Siva adds. 

How AV remote operations really work

Remote operations for autonomous fleets are often mistaken as manual teledriving — a reactive approach where an operator steers from afar. However, this approach would create dangerous network latency risks.

In practice, a SOTIF triage layer acts as a proactive oversight system, allowing a single specialist to monitor dozens of AVs at once. When an edge case arises, the operator evaluates the context, resolves situational ambiguity (such as verifying detours or hand signals) and approves a safe trajectory. The onboard AI then executes the maneuver autonomously.

Operational metric Legacy teledriving Proactive SOTIF edge-case triage
Human role Direct manual control (steering, braking) Cognitive decision validator & supervisor
Network sensitivity High; vulnerable to network latency Low; sends high-level waypoint approvals
Fleet scalability 1 operator: 1 vehicle 1 operator: Dozens of AVs
Safety integration Direct override of onboard systems Onboard AI validates human path against collision avoidance

Because human performance limitations are a core concern in SOTIF, industry standards like the UK’s BSI PAS 1884 — which governs safety operators in AV testing — codify strict requirements for operator selection, competence and performance management

Siva points out that organizations deploying remote triage must enforce:

  • Strict skill vetting: Rigorous testing of spatial awareness, reasoning and real-time decision-making prior to onboarding.
  • Standardized training: Comprehensive curriculum covering tele-operation protocols, spatial data and regional traffic laws.
  • Continuous recertification: Regular performance evaluations to maintain high operational and safety standards.
  • Clear approval protocols: Defined rules for when operators can approve vehicle waypoints versus when automated fallbacks must trigger.

3 Key operational & SOTIF support metrics

To validate SOTIF safety cases while maintaining fleet efficiency, Siva recommends AV operators monitor three critical metric categories:

1. Triage accuracy & compliance

Event classification accuracy: How precisely remote teams differentiate genuine perception edge cases (e.g., severe road hazards) from false alarms caused by overly conservative sensor thresholds, avoiding unnecessary vehicle freezes.

Regulatory compliance rate: The adherence of operator-provided remote guidance to local traffic laws and ODD rules.

2. Response speed & recovery

Initial response time: The duration from when the vehicle triggers a SOTIF fallback stop until a remote operator initiates contextual evaluation or sends initial path vectors.

Total resolution time: The elapsed time from the initial safe stop until the vehicle verifies the operator’s input and safely resumes autonomous operation.

3. Managed fallbacks & MRMs

Minimal Risk State (MRS) Compliance: The percentage of stationary or degraded vehicles successfully guided to a designated safe location (e.g., shoulder, parking space or safe pull-off zone) without impeding traffic flow.

Escalation & dispatch accuracy: The precision with which triage teams categorize cases requiring physical roadside intervention versus those resolvable via remote guidance.

Fallback recovery duration: The overall time required to execute remote vehicle relocation or dispatch physical roadside assistance when remote guidance cannot resolve the scenario.

The path to true AV fleet scalability

Commercializing autonomous fleets demands more than powerful compute and advanced sensor suites. Under frameworks like SAE J3016 (Levels of Driving Automation), Level 4 systems must seamlessly manage the dynamic driving task (DDT) fallback whenever environmental conditions exceed system limits.

Integrating a SOTIF-compliant triage layer turns this regulatory requirement into an operational advantage. As Siva notes, Fleet operators satisfy regulators and the public while clearing road congestion and maximizing vehicle uptime.”

This human-in-the-loop framework creates a virtuous cycle. Every remote edge-case resolution captures valuable corner-case data to continuously retrain onboard perception models. “As the vehicle stack learns to autonomously navigate increasingly complex scenarios, human specialists can shift their focus to rarer longtail events and expand their oversight ratio even further,” says Siva. 

By bridging the gap between mathematical probability and real-world ambiguity, operationalized SOTIF transforms isolated AV deployments into scalable, resilient transportation networks.