AI Lessons

The Crash Didn't Kill Cruise. The Cover-Up Did.

The Crash Didn't Kill Cruise. The Cover-Up Did.

General Motors spent more than ten billion dollars building a self-driving car company. Last month, it stopped funding it entirely. The unit, Cruise, is being folded into GM's ordinary driver-assist group, its robotaxi ambitions over.

Here's the part worth your attention: the thing that ended Cruise wasn't the accident everyone remembers. A self-driving car was involved in a horrible injury, yes. But the company might have survived that. What it didn't survive was the decision, made in the hours and days afterward, to not tell regulators the whole truth.

If you're deploying AI anywhere its mistakes can hurt someone or cost real money, this is the case study to internalize. Not because your business runs robotaxis, but because the failure that actually killed Cruise is one any company can make, and most haven't planned for it at all.

What happened on October 2, 2023

On a night in San Francisco, a woman was crossing the street when a human-driven car struck her and threw her into the next lane, directly into the path of a driverless Cruise robotaxi. The Cruise car couldn't have avoided that first impact. No system could have.

What happened next is where the technology failed. The robotaxi ran over the woman and then, not detecting that a person was trapped underneath it, tried to do the sensible-sounding thing a car pulls over to the side of the road. In doing so, it dragged her about 20 feet.

This is the kind of edge case that autonomous systems handle badly: a situation no one programmed for, where the "reasonable" default action was catastrophically wrong. It's a genuine, hard technical failure. And on its own, it might have been survivable for the company. Self-driving was understood to be experimental. A freak accident, honestly disclosed, is the kind of thing a regulator works through with you.

Cruise chose a different path.

The omission

The morning after the crash, Cruise held a video call with the National Highway Traffic Safety Administration, the federal regulator. Company representatives walked through what happened. They did not mention the dragging.

Later that day, Cruise filed its formal one-day incident report with NHTSA. That report also left out the dragging. The single most important fact about the incident, that the vehicle's own actions had pulled an injured person 20 feet down the road, was simply absent.

It gets worse. Cruise later provided NHTSA with video that showed the dragging. But even after handing over footage that made the omission obvious, the company did not go back and correct its report. That correction didn't come until 10 days after the crash. By then the pattern was clear enough that federal prosecutors would later describe it as filing a false record with intent to impede, obstruct, or influence a federal investigation.

What it cost

The consequences didn't come mainly from the crash. They came from the lack of candor about it.

California regulators suspended Cruise's driverless permits almost immediately. The company recalled its vehicles nationwide and grounded its fleet. It laid off about a quarter of its workforce. Its CEO and other leaders departed. The financial penalties stacked up from multiple directions: a $1.5 million NHTSA fine, a six-figure state penalty, and a settlement with the victim herself reported to be around $8 million.

Then came the criminal piece. Cruise entered a deferred-prosecution agreement with the U.S. Department of Justice and paid a $500,000 criminal fine, formally admitting it had submitted a false report to a federal regulator. A federal prosecutor put the principle bluntly: companies that want to share the road have to be fully truthful with the people who regulate them.

And in December 2024, GM ended it. More than $10 billion invested since 2016, and the plug was pulled, the robotaxi program dissolved.

The lesson has nothing to do with cars

It's tempting to file this under "self-driving is hard" and move on. That's the wrong takeaway, and it's the one that will get a business into trouble.

The real lesson is that Cruise faced two separate risks, and it managed only the obvious one. The first risk was the technical failure: the car did something terrible. The second risk was the response to the failure, and that's the one that actually destroyed the company. The instinct to minimize, to leave out the worst detail, to hope the fuller picture doesn't surface, is exactly the instinct that converts a survivable incident into an existential one.

Every company deploying consequential AI is exposed to that second risk, and almost none of them have a plan for it. They plan for the AI to work. They rarely plan for what they'll do, specifically, in the hours after it fails in a way that hurts a customer, exposes data, or produces a decision they have to answer for.

What to actually do about it

Decide your disclosure posture before you need it. The time to decide how honest you'll be about an AI failure is not in the panicked hours after one happens, when every incentive pushes toward minimizing. It's now, in writing, while it's abstract. Who gets notified, how fast, and with how much of the truth? A company that has pre-committed to full disclosure doesn't have to win that argument with itself under pressure.

Assume the full picture will surface. Cruise handed over the video that exposed its own omission. There is almost always a log, a recording, a timestamp, or a witness. Any incident response built on the hope that the damaging detail stays buried is building on sand. Plan as if everything comes out, because it usually does.

Separate the failure from the response in your own planning. When you map the risks of an AI deployment, write down two columns: what happens if it fails, and what we do in the first 48 hours after it fails. Most risk assessments only fill in the first column. The second is the one that determines whether a bad day becomes a bad year.

The real lesson

We help clients put AI into workflows that carry real weight, where a mistake isn't just an awkward chatbot reply but a decision with consequences. In every one of those, the deployment plan is only half the job. The other half is the incident plan: the honest, pre-agreed answer to "what do we do when this goes wrong."

Cruise had a world-class deployment and no honest incident plan. The crash was a tragedy. The cover-up was a choice. And it was the choice, not the crash, that ended the company.

Andrew Lay

Written by

Andrew Lay

Andrew Lay is the founder and CEO of Hiero, a Michigan-based development studio that helps businesses use AI, automation, and custom software to improve how they operate. A business strategist specializing in AI, Andrew brings more than 20 years of experience building apps, digital products, and operational systems. His work focuses on the part of AI adoption most companies skip: identifying the right business problem, determining whether AI is actually the right solution, defining a defensible return, and putting the controls and feedback loops in place to protect that return after launch. Andrew is the author of the forthcoming book, Lessons from Bad AI Implementations and How to Guarantee ROI With AI, a practical field guide built from 34 verified failure cases and the Hiero implementation method. He also hosts the Hiero Exclusive podcast and speaks on AI strategy, entrepreneurship, and operational growth.

All posts by Andrew