The SAFE Act's Automated Detection: A Case Study in Algorithmic Due Process
- Authority
- US Congress
- Rule type
- statute
- Jurisdiction scope
- US federal
- Source text
- Read primary rule text ↗
Deploy automated screening for chameleon carriers with human review, appeals, data sharing, and OIG audit
The SAFE Act is worth watching less because Congress has found another trucking-safety acronym than because it tells a federal agency, in unusually concrete terms, to automate part of an enforcement screen. As of Q3 2026, the stand-alone House bill is H.R. 7539, introduced by Rep. Harriet Hageman on Feb. 13, 2026, referred to the Subcommittee on Highways and Transit, and later incorporated by amendment into the BUILD America 250 Act, with the usual caveat that merged legislative language may not track the stand-alone text word for word.[1][2] On July 28, 2026, Sen. Todd Young and Sen. Andy Kim announced a Senate companion, although the Senate bill number was not yet published in the public sources reviewed for this article.[3]
That status matters, but it is not the center of the story. The center is the mandate: FMCSA would have to deploy an advanced automated tool to identify “chameleon carriers,” the trucking companies that attempt to continue operating under a new identity after safety orders, penalties, or other enforcement consequences make the old one inconvenient. The bill pairs that screening mandate with human review, an appeals process, information sharing with privacy protections, and a two-year Office of Inspector General audit.[3] For lawyers tracking government AI enforcement, the SAFE Act analysis starts there: Congress is not merely encouraging responsible automation; it is specifying a detection job, naming the relationships to be screened, and requiring a later record of performance.

Why the automation mandate has a real safety predicate
A chameleon-carrier law is not a solution in search of a problem. In 2012, GAO reported that FMCSA’s vetting process reviewed only about 2% of new freight-carrier applicants, while the number of identified reincarnated carriers rose from 759 in 2005 to 1,136 in 2010.[4] GAO also found a severe-crash disparity that is hard to dismiss: 18% of reincarnated carriers were involved in severe crashes, compared with 6% of applicants with no chameleon-carrier indications.[4]
Those numbers do not prove that every shared address, reused truck, or related manager signals fraud. They do show why a regulator would want to look beyond the face of a new application. A carrier that has been ordered out of service should not be able to shed that history by moving assets, shifting a manager, letting one USDOT number go inactive, and presenting a newly formed company as a clean entrant. The safety consequence falls on the road, not in a filing cabinet.
The recent political momentum also has a concrete backdrop. Reporting on the Senate bill tied the proposal to a February 2026 Indiana crash that killed four people, involving a carrier allegedly linked to a broader network with 2,993 inspections, 1,552 violations, 439 out-of-service orders, and 91 crashes.[5] That is a case, not a frequency table. But it is the kind of case that makes a purely name-based registration system look willfully underpowered.
The unresolved middle chapter: GAO to ARCHI
The SAFE Act is best read as the third point in a 14-year administrative arc. The first point was GAO-12-364. The second was FMCSA’s automated chameleon-carrier prototype, commonly discussed as ARCHI. After GAO’s findings, FMCSA reportedly allocated $3.5 million for the system, which screened roughly 90,000 applicants and flagged about 8,000 potential chameleon carriers under a match-score and motive framework.[6][7]

The reported ARCHI figures are useful, but they also mark the limits of the public record. The approximately 90,000 screened and 8,000 flagged figures come from FMCSA’s 2013 congressional-report account as recounted in secondary sources; the record available in the 2024–2026 materials does not provide a public annual series of flag volumes, denial rates, enforcement outcomes, or error rates.[6][7] That gap matters as much as the technology itself. A flagging system that never publishes how many applications it tags, how often humans reject the tag, or how often a flagged applicant later wins a redetermination may improve internal triage while leaving regulated parties inside an unexplained suspicion architecture.
The methodological caution should extend to newer safety claims as well. A Fusable finding, cited in a 60 Minutes investigation and repeated in secondary coverage, says chameleon carriers are four times more likely to be involved in severe crashes; however, the original study methodology and sample size were not independently verified in the available materials.[6] That does not make the claim useless. It makes it a claim that should not carry more procedural weight than the record can bear.
What the SAFE Act would tell the machine to look for
The bill’s most important drafting choice is that it does not stop at “use technology.” It identifies the relationship fields that would feed the automated screen. The tool would examine common ownership, common managers, common drivers, equipment, addresses, telephone numbers, email addresses, facilities, insurance continuity, lapsed insurance coverage, transferred assets, inactive USDOT numbers, and company formation dates.[3]
| Screening field | Enforcement logic | Due-process concern |
|---|---|---|
| Ownership and managers | A banned or unsafe operator may reappear through a nominally new company. | Family businesses, former employees, or ordinary industry movement can create ambiguous associations. |
| Drivers and equipment | The same trucks or personnel may show operational continuity between old and new carriers. | Used-equipment markets and driver mobility can produce links that are real but not culpable. |
| Addresses, phones, emails, and facilities | Contact and location data may reveal that a new carrier is operating from the same business infrastructure. | Shared yards, virtual offices, brokers, consultants, and stale records can overstate common control. |
| Insurance continuity and lapsed coverage | A policy trail may show that the business never truly stopped operating. | Insurance data can reflect administrative timing rather than an evasion plan. |
| Transferred assets, inactive USDOT numbers, and formation dates | A new entity may be built immediately around an old carrier’s operating assets. | Asset purchases and company formation dates need context before they become adverse evidence. |
This is the proper level of specificity for an automated enforcement mandate. Each field has an obvious fraud-detection rationale. Each also has a false-association pathway. A small carrier may buy a tractor from a failed operator, lease space at the same yard, hire a former safety manager, or use the same compliance consultant. If the agency’s model treats those ties as cumulative suspicion without a readable explanation, the operator may not know whether to contest a factual error, an outdated record, or the inference drawn from a true fact.
Existing law already gives FMCSA a reincarnation framework. The agency’s rule at 49 CFR 386.73 uses a multi-factor analysis to determine whether a carrier is operating as a reincarnated or affiliated carrier, and MAP-21 added statutory prohibitions against operating under a new identity to avoid penalties, orders, or compliance obligations.[8] Penalties for out-of-service-order violations can reach up to $29,980 per day.[8] The SAFE Act would not invent the idea that continuity matters. It would change the front end: more of that continuity analysis would begin with automated association.
The safeguard architecture is more than decoration
The legally interesting part of the SAFE Act is that the same bill that directs automated detection also requires procedural counterweights. The Senate announcement describes a human-review requirement, an appeals process, privacy-protected information sharing, and a two-year OIG audit after implementation.[3] Those elements do not guarantee fairness. They do, however, give lawyers the hooks they usually have to infer from agency guidance, procurement documents, or litigation.

Human review before consequence
Human review is only meaningful if it happens before the automated flag hardens into a legal consequence. A reviewer who merely confirms that the data fields match is not performing the same function as one who evaluates business context, document age, ownership reality, and innocent explanations. The statutory phrase matters, but implementation will decide whether the review is a genuine adjudicative layer or a quality-control checkbox.
For regulated entities, the practical question is simple: when FMCSA acts on a flag, will the carrier be told which relationships mattered? A notice that says only that an applicant resembles a prior carrier leaves counsel guessing. A notice that identifies the shared manager, transferred equipment, insurance continuity, and inactive USDOT link lets the applicant produce records, declarations, sale documents, lease agreements, or corporate-formation evidence that respond to the actual basis for suspicion.
Appeals that can correct both data and inference
An appeal process is not just a place to upload PDFs. It has to let a carrier challenge two different things. The first is data accuracy: the address is stale, the phone number was reassigned, the truck was sold at auction, the manager left years ago. The second is inference: the link is real, but it does not show evasion, common control, or continuation of the unsafe business.
That distinction is often where algorithmic enforcement becomes procedurally thin. Data correction does not cure an inference problem. If an agency can say, “all of the facts are accurate, and our model still treats them as suspicious,” the affected carrier needs a route to contest the agency’s reasoning, not only the database entries.
Information sharing with a wider government footprint
The SAFE Act also would authorize information sharing involving DOJ, Treasury, DHS, USPS, state partners, and other entities, with privacy protections.[3] That is a serious expansion of the detection environment. A carrier-identity investigation may need tax, border, postal, corporate, insurance, and enforcement data to see through deliberate evasion. But broader data access also increases the chance that old, partial, or purpose-specific records migrate into a safety-enforcement decision without the applicant knowing where the adverse association came from.
The privacy language therefore should be read alongside administrative-process obligations, not as a separate compliance ornament. Scope of use, record provenance, retention, correction, and disclosure rules will determine whether the automated tool becomes an accountable investigative screen or a multi-agency suspicion pool.
The OIG audit is the bill’s most important transparency device
The SAFE Act’s two-year OIG audit requirement is the feature that most directly answers the ARCHI opacity problem. The audit would measure flagged applications, rejection rates, errors, redeterminations, and reductions in severe crashes.[3] Those are not all the metrics one might want, but they are the right category of metrics. They ask not only whether the tool found targets, but what happened after the finding.
- Flagged applications show the size of the automated suspicion pipeline.
- Rejection rates show how often flags become adverse registration outcomes.
- Errors show whether the system is producing incorrect associations or unreliable outputs.
- Redeterminations show whether appeals are changing results after review.
- Severe-crash reductions test whether the screening program is connected to the safety rationale that justified it.
The redetermination measure deserves particular attention. An agency can claim high accuracy by counting only confirmed enforcement actions. Redeterminations expose a different fact: how often the system or its reviewers initially got it wrong, or at least failed to sustain the initial conclusion after the carrier had a chance to respond. If OIG reports redeterminations in the aggregate but not by reason, the public will still know too little. A reversal based on stale address data is different from a reversal based on a misread asset transfer or an unsupported inference of common control.
The severe-crash metric also needs careful handling. A decline after implementation would be relevant, but it would not by itself prove that the automated tool caused the decline. Enforcement intensity, market conditions, insurance practices, inspection priorities, and ordinary fluctuation can all affect crash outcomes. The audit should therefore be read as an accountability record, not as a magic causal instrument.
Industry support does not answer the process question
The bill’s support is broad enough to be politically notable. Reported endorsers include the American Trucking Associations, Owner-Operator Independent Drivers Association, Truckload Carriers Association, National Tank Truck Carriers, Indiana Motor Truck Association, Wyoming Trucking Association, and American Truckers United.[5][9] That alignment is unsurprising. Law-abiding carriers have a direct competitive interest in preventing unsafe operators from reentering the market under a new name.
But industry support does not resolve the administrative-law issue. The same system that helps honest carriers by catching evasive operators can burden honest carriers if it treats ordinary business overlap as evidence of reincarnation. The relevant line is not between automation and no automation. It is between a screen that produces reviewable, contestable reasons and a screen that produces a score no one outside the agency can effectively interrogate.
What legal professionals should watch in implementation
If the SAFE Act becomes law, the most important documents may not be the first press releases after enactment. They will be the implementing guidance, notice templates, appeal procedures, data-sharing agreements, OIG audit plan, and any public reporting FMCSA issues before the two-year audit. Those documents will show whether the agency has treated the automated tool as an investigative aid or as a quasi-adjudicative filter.
Counsel for carriers will need to know what the agency discloses when an application is flagged, how quickly the carrier can respond, whether operations are paused during review, what evidence FMCSA treats as rebuttal, and whether the appeal record includes the model’s material inputs. Counsel for shippers, insurers, lenders, and acquirers will have a different problem: how to diligence carrier identity and continuity risk without assuming that every automated flag is correct or that every clean registration is conclusive.
For government-AI risk committees, the bill is a useful benchmark because it names several elements that should appear in any serious enforcement automation program: a defined screening purpose, specified data relationships, human review, appeal rights, interagency privacy limits, and audit metrics tied to both accuracy and program outcomes. The bill does not answer every question. It does, however, give later oversight something to measure.
A benchmark, if the record becomes public enough to use
There is a disciplined way to defend the SAFE Act: GAO identified a narrow vetting rate and a severe-crash disparity; FMCSA experimented with automated screening; Congress is now considering a statutory production system that includes review, appeal, data-sharing limits, and audit measures. There is also a disciplined way to criticize it: ARCHI’s public record never matured into a visible accounting of flags, denials, errors, and outcomes, and the new mandate will repeat that defect unless implementation produces contestable evidence.
The SAFE Act is a strong candidate for a benchmark in algorithmic due process because it names the tool, the data relationships, the human-review layer, the appeal channel, and the audit metrics. It will become a model only if those features create a public record that lets carriers, courts, Congress, and the public see not just that FMCSA’s system flagged someone, but why the flag mattered, how it was reviewed, how often it was wrong, and whether it improved safety without burying lawful operators in unexplained suspicion.
References
- Bill aims to prevent chameleon carriers from blending in, Land Line Media
- SAFE Act press release, Rep. Harriet Hageman
- SAFE Act press release, Sen. Todd Young, July 28, 2026
- Motor Carrier Safety: New Applicant Reviews Should Expand to Identify Freight Carriers Evading Detection, U.S. Government Accountability Office
- Senate bill takes aim at chameleon carriers, CDL Life
- Has FMCSA's Decade-Old Chameleon Carrier System Been Running on Autopilot?, FreightWaves
- Chameleon Carriers, Fraud Detection, and FMCSA's Evolving Data Strategy, TruckSafe
- Chameleon Carriers—FMCSA's Reincarnated Rule and Enforcement, Benesch Law
- ATA press release on the SAFE Act, American Trucking Associations
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →