A Waymo Robotaxi Saw Floodwater and Drove Into It Anyway
What happened
On April 20, 2026, an unoccupied Waymo robotaxi entered a flooded roadway near Salado Creek in San Antonio and was swept into a nearby waterway. No passengers were aboard and no injuries were reported. What made the incident more than a weather mishap was the sequence that produced it: the vehicle had already detected the floodwater as potentially untraversable before it moved into it.
Waymo disclosed the relevant detail to regulators. The automated driving system perceived floodwater it classified as potentially untraversable and then proceeded anyway, at reduced speed. That is not a failure of perception. The system saw the hazard. The failure was in what came next, when the vehicle treated reduced speed as an adequate response to a condition it had already identified as potentially impassable. The floodwater was not a surprise the sensors missed; it was a risk the system acknowledged and discounted, and the car went in anyway.
The response from Waymo came in stages. The company restricted operations in the affected area after the event and reported the incident to regulators. A recall followed, covering 3,791 fifth- and sixth-generation automated driving systems. The recall addressed the behavior at the center of the San Antonio event: a system that could detect a potentially untraversable hazard but lacked a reliable mechanism to stop rather than slow down in response to that classification.
Recalls of this kind are routine in the automotive industry, but autonomous vehicle incidents introduce a problem that mechanical recalls do not. When a human driver misjudges floodwater, the decision is ephemeral. There is no log, no threshold value, no record of the reasoning to audit after the fact. When an automated system makes the same error, there is, or there should be. The question is whether what the system logged at the moment of decision is specific enough to reconstruct why the threshold was set where it was and what input tipped the balance toward proceeding.
That reconstruction is what any rigorous post-incident review requires and what the current documentation landscape frequently cannot supply. Without a complete, timestamped record of what the system perceived, what confidence level it assigned to the floodwater classification, and what rule triggered the decision to proceed at reduced speed, the recall addresses a code path but not a verified cause. A provable record of what a system did, at what confidence level, against what environmental input, is the baseline for knowing whether the fix actually closes the gap. This incident shows that baseline is not yet standard.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.