I realize I might have been overzealous in my need to stress that drivers should be held liable for "auto-pilot", when it's possible that there are situations when a vehicle system truly malfunctions / does not disengage even after driver input.
In those situations, the manufacturer should be held 100% liable, and the NTSB / other authorities would need a way to determine that - probably the same way they determine it when other car's systems fail - like, when some cars' accelerator peddle got jammed.