Autonomous Solutions

Shahrukh Kazmi
2026-08-31
Blog

Author

Author

Shahrukh Kazmi
Chief Product Officer, Volvo Autonomous Solutions

Redundancy in autonomous trucking is not about eliminating every possible failure. It is about making sure that a single fault in a critical system does not become a loss of control. For heavy-duty trucks operating at highway speeds, that distinction is fundamental.

Autonomous trucks are designed for a reality where components can fail, but where it does not lead to a loss of control.

In conventional vehicles, a human driver can often detect a problem and take corrective action. In a self-driving truck, that responsibility must be built into the vehicle itself. Critical functions such as steering, braking, power, communication, and computation cannot rely on only one system. If one system becomes unavailable, the truck must still be able to detect the fault, preserve control, and move toward a safe condition.

That is the purpose of redundancy. 

The purpose of redundancy in autonomous trucks is avoiding that a single system failure leads to a loss of control. Rather than simply duplicating components, effective redundancy requires independent backup systems that can safely take over when needed. Volvo applies redundancy where risk demands it, for example for braking and steering. The goal is to maintain safe operation and achieve a minimal-risk condition even when failures occur.

What does redundancy mean?

Redundancy means preserving a required function when one component or system becomes unavailable. This may involve a backup steering system or an additional computer. But effective redundancy is not simply a matter of duplication. The backup must also be sufficiently independent of the primary system. If both rely on the same power supply, communication network, or control unit, one fault could disable them at the same time.

This is where Volvo’s approach to autonomous trucking differs from a simpler “add another component” view of redundancy. The goal is not to duplicate every part of the vehicle, but to protect the functions that are necessary to keep the truck controllable when something does not work as intended.

Failure is not the same as loss of control

A failure is an event, while a loss of control is a possible consequence. Such an event may be that camera malfunctions or a steering actuator receives the correct command but fails to produce the requested movement. Redundancy is designed to prevent such failure from becoming a loss of control.

If a safety-critical failure occurs, the truck must first detect the fault and determine whether normal operation can continue. If it cannot or should not, the remaining systems must preserve enough capability to perform a minimal risk maneuver, leaving the active traffic lane rather than stopping immediately. The truck assesses the surrounding traffic, identifies a suitable place to stop, and maintains control while reaching it.

 Simultaneously, hazard warnings are activated while the truck communicates its location and status to the fleet-management system. The supporting operations team can then respond. Service personnel may be dispatched, the customer can be informed, and the remaining freight operation can be adjusted. 

A minimal risk maneuver is therefore more than applying the brakes. It is a coordinated response involving the vehicle, its warning systems, and the wider operational ecosystem.

The health of the backup must also be monitored. If the primary system still works but the secondary system becomes unavailable, the vehicle has lost its protection against a potential future failure. That change in risk may itself be enough to trigger a controlled stop.

Duplication is not enough

When a safety-critical function fails, the truck relies on another part of the system to preserve control. But that backup only works if it is protected from the same failure.

A truck may have primary and secondary steering systems, but if both depend on the same power source, one electrical fault could disable them together. This is known as a common-cause failure: two systems appear separate but share a dependency that can take both of them out. Avoiding common-cause failures means looking beyond the duplicated component itself. Engineers must examine the full chain behind every safety-critical function, including power, communication, software, wiring, and control paths.

That is why true redundancy is only achieved by designing the primary and backup paths so that one fault cannot remove both at the same time.

The risk profile determines the architecture

The required level of redundancy depends on the vehicle’s risk profile. This reflects where and how the vehicle operates, the failures it may encounter, and the potential consequences of those failures. For example, a truck traveling among other road uses requires different safeguards from one operating at low speed in a confined area. This operating context is known as the operational design domain. It includes factors such as speed, road type, traffic conditions, and the surrounding environment.

There is therefore no universal redundancy architecture that applies equally to every autonomous vehicle. The design must reflect the intended operation and the levels of risk involved. The greater the potential consequences of a failure, the more important it becomes to preserve the functions required to maintain control.

Commercially viable

Redundancy adds weight, cost, and complexity as the additional systems require space, validation, and maintenance. At highway speed, a single point of failure in a safety-critical function could lead to a loss of control. The goal is not to choose between safety and commercial viability, but to build a truck that is safe by design and efficient enough to deliver value in real freight operations.

That means applying redundancy where the risk requires it, rather than duplicating every component that could possibly be duplicated. The architecture must protect the functions needed to maintain control, while keeping weight, cost, and serviceability within practical limits. We believe a vehicle that is deemed unsafe will not be commercially viable.

That is why the Volvo VNL Autonomous has been purpose-built for autonomous operation, with redundant capabilities integrated into its design from the outset. Its architecture includes six key areas of redundancy: braking, steering, communication, computation, energy and power, and vehicle motion control.

The Volvo VNL Autonomous brings these capabilities together in a platform designed around the realities of autonomous freight.

Autonomous trucks can operate for longer periods, maintain more consistent speeds for higher fuel efficiency, and avoid hours of service constraints. On long, repeatable highway routes, those advantages help offset the additional complexity of the autonomous platform.

Failure is part of the process

Redundancy does not prevent every failure. It ensures that a failure does not become a loss of control. By preserving critical functions, separating shared dependencies and enabling a coordinated response, redundancy allows an autonomous truck to reach a safe condition even if part of the system stops working.

For autonomous trucking, this is the difference between demonstrating that a vehicle can drive itself and proving that it can operate safely and reliably in the real world. By designing for failure from the outset, redundancy makes it possible to combine safety with dependable, commercially viable freight operations.

Failure may be unavoidable, but losing control does not have to be.