How Do You Actually Test a Self-Driving Car Before Letting It Loose on the Road?

If you wanted to prove, through driving alone, that a self-driving car crashes less often than a human, you’d need to drive it roughly 275 million kilometres without a fatal accident just to be statistically confident it matches today’s already very good human safety record — a widely cited RAND Corporation estimate, and one that would take a fleet of a hundred test cars several decades of continuous driving to rack up. No manufacturer can do that before a launch date, which means “test it a lot” was never going to be how SAE Level 3-plus cars get validated. What replaced it is a mix of simulation, synthetic scenarios and statistical modelling that the EU has spent the better part of a decade building, one project passing its results directly to the next.

 

Why you can’t just drive your way to proof

The core problem is called the “safety validation gap”: current fatality rates for human drivers are low enough (roughly one per hundred million kilometres in Europe) that proving a statistically meaningful improvement requires an amount of real-world mileage that no test fleet, budget or timeline can realistically deliver. Waiting for enough real crashes and near-misses to accumulate naturally would also mean deliberately exposing the public to an unvalidated system in the meantime, which regulators won’t accept. So the industry inverted the approach: instead of driving until enough data accumulates by chance, it generates the dangerous, rare, statistically decisive scenarios on purpose — in simulation first, then on closed proving grounds, and only then on public roads for the residual cases simulation can’t fully capture.

 

Scenario-based testing: driving the 1-in-a-million case a million times

The core technique is called scenario-based testing: rather than accumulating generic kilometres, engineers identify specific, well-defined situations — a cyclist swerving out from behind a parked van, a sudden cut-in at motorway speed, a pedestrian obscured by fog — and run the automated driving system against thousands of parameterised variations of each one in simulation (different speeds, distances, lighting, weather) before ever testing a single one on real asphalt. This is only useful if the scenario library is realistic, standardised and shared across the industry rather than invented ad hoc by each manufacturer, which is precisely the gap the EU projects described below were funded to close.

 

The other missing ingredient: a realistic model of how humans actually drive

Simulated scenarios are only as good as what they’re compared against, and that baseline is a realistic model of ordinary human driving behaviour — how much a real driver brakes, swerves, hesitates or misjudges a gap under specific conditions — not an idealised, rule-following driver nobody actually resembles. Building and validating that human behavioural baseline, so that a self-driving system’s simulated performance can be benchmarked against something real rather than an assumption, has itself become a dedicated EU research strand running in parallel with the scenario-generation work.

 

The EU’s validation pipeline: four projects, one continuous framework, 2019-2028

What makes this area unusual is that it isn’t four unrelated grants on a similar theme — it’s a single Safety Assurance Framework (SAF) being built, tested and extended in sequence, project handing results directly to the next, across two framework programmes. It started under H2020 with HEADSTART (“Harmonised European Solutions for Testing Automated Road Transport”, 2019-2021, €6.0M EC contribution): the first EU project to define shared testing and validation procedures for automated driving functions by cross-linking simulation, proving-ground and real-world field tests against the needs of type-approval authorities, not just manufacturers. Horizon Europe then picked up where it left off with SUNRISE (“Safety assUraNce fRamework for connected, automated mobIlity SystEms”, coordinated by IDIADA in Spain, €13.09M EC contribution, 2022-2025, SIGNED), which built the actual harmonised Safety Assurance Framework that HEADSTART had only scoped out. Once the framework existed, SYNERGIES (“Real and synthetic scenarios generated for the development, training, virtual testing and validation of CCAM systems”, €18.64M EC contribution, 2024-2027, SIGNED) put it to work, explicitly built to implement SUNRISE’s framework by federating multiple pre-existing scenario databases (including the industry’s Safety Pool Scenario Database, ADScene and StreetWise) into one interoperable resource instead of leaving every manufacturer to build scenarios from scratch. The newest link, CERTAIN (“Resilient and Continuous Safety Assurance Methodology for CCAM and its HMI Components”, €14.0M EC contribution, 2025-2028, SIGNED, still running), is now extending that same framework from a one-off pre-launch check into a continuous assurance process that keeps monitoring a system’s safety case as software updates roll out after the car is already on sale — recognising that a self-driving system validated once at launch, then updated over-the-air for years afterward, needs a validation process that doesn’t stop at the factory gate.

 

The parallel track: modelling the human being compared against

Running alongside SUNRISE under the same 2022 call, two further projects tackled the human-baseline half of the problem directly: i4Driving (“Integrated 4D driver modelling under uncertainty”, €6.77M EC contribution, 2022-2026) is building a modular simulation library of human driving behaviour models to establish a credible safety baseline for virtual assessment, while BERTHA (“BEhavioural ReplicaTion of Human drivers for CCAM”, €7.98M EC contribution, 2023-2026) is developing a validated, scientifically grounded Driver Behavioural Model that OEMs and suppliers can share as common ground when testing how an automated system interacts with human-driven traffic around it — the missing benchmark that scenario-based testing on its own doesn’t provide.

 

What this buys the industry

None of this eliminates real-world testing — a system still has to prove itself on an actual road eventually, the same layered logic behind the redundant hardware that lets a car fail safely if something does go wrong on that road. What this pipeline changes is how much of the safety case can be built and stress-tested before a single public kilometre is driven, and it’s the reason regulators are increasingly willing to accept simulation-heavy evidence as part of a type-approval file rather than demanding physical mileage alone — the only realistic way the “275 million kilometres” problem gets solved before, rather than after, cars are already on sale.

 

Photo: © Car-Shooters