Buried in the compliance procedure for a United States federal safety standard is a short instruction addressed to whoever is running the test. It does not tell them what to break. It tells them what they are not allowed to break.
The standard is 49 CFR 571.138, which governs tire pressure monitoring systems. A car of ordinary size, sold new in the United States since the phase-in finished in 2007, carries a monitor that watches something dull, continuously, without being asked, and has to produce one useful sentence on the day it matters. That is also a fair description of a camera left running in a room with nobody in it.
The interesting part of the standard is which half of that job it treats as the hard one.
The definition will not let the sensing stand on its own
The standard defines its subject as "a system that detects when one or more of a vehicle's tires is significantly under-inflated and illuminates a low tire pressure warning telltale".
Read the noun rather than the requirements. The illumination sits inside the definition; it is not a feature bolted onto a sensing device. A box that detects a soft tire flawlessly and tells nobody has not built a deficient tire pressure monitoring system under this standard. It has built something the standard has no name for.
A second kind of news
A monitor has two things it might need to say, and they are not versions of each other. One is about the world: a tire is soft. The other is about itself: it can no longer tell you whether a tire is soft. The standard separates them and puts a clock on the second. A telltale has to warn the driver not more than 20 minutes after the occurrence of "a malfunction that affects the generation or transmission of control or response signals".
Twenty minutes is a driving-time budget, not a piece of wisdom. What matters is that the second message has a deadline at all. In most arrangements a person owns, the news that the monitor has stopped monitoring arrives whenever somebody happens to check.
No quiet recovery
A manufacturer who fits a dedicated fault lamp must keep it lit, whenever the ignition is on, "for as long as the malfunction exists" - not for an attention-getting interval and then off.
A manufacturer who folds both messages into a single lamp has to make that lamp speak a different grammar for each. On detecting a fault it flashes "for a period of at least 60 seconds but no longer than 90 seconds", then stays continuously illuminated as long as the malfunction lasts, and it repeats that performance at every start "until the situation causing the malfunction has been corrected".
The point of the persistence rule is that a fault which cleared its own indicator would be reported once and then look, to the next person in the seat, exactly like a system in good health.
Both lamps are made to prove they work
The low tire pressure telltale must "illuminate as a check of lamp function" when the ignition is turned on with the engine not running, or at a check position the manufacturer designates between on and start. Where a dedicated malfunction telltale is fitted, the standard uses its own separate wording for that one: it must be "activated as a check of lamp function" under the same conditions. Each gets its own provision in the text, and the only carve-out is the case where a starter interlock is operating.
This is written against a specific and rather bleak observation. A dark warning lamp with a dead bulb behind it looks precisely like a dark warning lamp with nothing wrong behind it. Both are silence, and silence is what the equipment produces most of the time anyway.
The order of the compliance test
Here is the part I had missed on a first reading, and it is the part worth stealing.
The compliance test is a road test, but it does not start on the road. Step (a) is inflating the tires. Step (b), before the vehicle has moved at all, is this: activate the ignition, and the system "must perform a check of lamp function for the low tire pressure telltale". Where a separate malfunction telltale is fitted, the standard adds that the system "also must perform a check of lamp function" for that one.
Only after the lamps have demonstrated that they can light does the procedure go on to the calibration drive, the deflation, and the detection phase.
The standard satisfies itself that the warning can be delivered before it asks whether the fault can be found. That ordering is not an accident of drafting. A test that checked the sensing first would be building every later result on an instrument nobody had confirmed was connected.
And the procedure says what happens when the lamp stays dark. If the telltale does not illuminate during the detection phase, the instruction is to "discontinue the test", and the same instruction appears again for the malfunction phase. There is no partial credit for a monitor that found the fault and said nothing. The test stops.
The instruction that gives the game away
Part of the procedure requires the tester to manufacture a fault. The standard lists the permitted methods: "disconnecting the power source to any TPMS component, disconnecting any electrical connection between TPMS components, or installing a tire or wheel on the vehicle that is incompatible with the TPMS". Every one of them is aimed at the monitoring side.
Then comes the sentence I would keep if I could keep one line of the whole standard:
"When simulating a TPMS malfunction, the electrical connections for the telltale lamps are not to be disconnected."
Permitted ways to break the sensing, and none to break the telling. The test is not asking whether a vehicle copes with a monitor that has died; it is asking whether a monitor that has died can still get a message out, and it holds the wires carrying that message outside the blast radius on purpose. A test that was allowed to cut the lamp would be measuring nothing, because the result would be dark either way.
The paragraph the manufacturer is required to print
The standard also writes text for the owner's manual and requires it in English. Two sentences are worth reading as a piece of institutional honesty. The first: "the TPMS is not a substitute for proper tire maintenance, and it is the driver's responsibility to maintain correct tire pressure, even if under-inflation has not reached the level to trigger illumination of the TPMS low tire pressure telltale". The second, about the fault indicator: "When the malfunction indicator is illuminated, the system may not be able to detect or signal low tire pressure as intended."
That second one is the regulator putting the limits of its own creation into the manufacturer's manual, in the manufacturer's voice. The system announces its own failure, and the paperwork announces what the announcement means: from here, treat the monitor as absent.
Detection first, self-diagnosis afterwards
The self-diagnosis requirement did not arrive with the rest. Under the phase-in schedule, a manufacturer in the first two periods could count a vehicle toward its quota "except for the provisions of S4.4 unless the manufacturer elects to also certify to those provisions" - that is, with the fault-telltale rules set aside unless it chose otherwise. It is the final tier that binds the whole standard to everything, and even that has a carve-out for vehicles manufactured in two or more stages or altered after certification. The agency that wrote the self-reporting requirement still shipped the sensing before it.
Reading it across to a phone on a shelf
An unattended recorder owes its owner the same two messages, and most arrangements are fluent in the first and mute in the second. Failure gets expressed as absence: no clips, no thumbnail, a live view that will not load. Absence is also what an uneventful fortnight looks like.
Restated with the car taken out, five of the standard's moves are worth stealing:
- A deadline on the fault message. Not merely that a fault gets reported, but that it gets reported inside a bounded time, measured from the fault rather than from the next time a human looks.
- Persistence. The fault message stands while the fault stands, so a lasting problem cannot pass itself off as a blip.
- Exercise that does not wait for a fault. The reporting channel is fired on a schedule of its own, so its health is not inferred from its silence.
- The messenger verified first. The channel is confirmed working before anything it reports on is tested.
- Protection of the channel inside the test. Whatever else the procedure may break, it may not break the messenger.
Where the analogy gives out
A driver is within arm's reach of the lamp at the moment the lamp has something to say. The owner of a camera in another building may be a day away from any indicator it can light. So the announcement problem for an unattended recorder is harder than the car's, not easier: a lamp with nobody in front of it has warned nobody. The persistence rule transfers well, because a message that waits is the one a distant person can still collect. The assumption of an audience does not transfer at all.
Questions I left open
- The fault the standard reaches is one affecting the generation or transmission of signals. A sensor that reports plausible but wrong pressures does not obviously fall inside that language, and I did not find text that reaches it. The equivalent for a camera would be the worst case of all: an arrangement recording steadily, and recording the wrong thing.
- Whether any consumer camera product implements anything resembling a lamp check, I do not know. I did not survey the market and this piece makes no claim about one.
- The 20-minute figure belongs to a road test on a named course. It is not a target for anything that is not a car, and nothing here asks it to be one.
What this is worth to somebody with a phone in a window
The number worth knowing about an unattended recorder is how long it takes to tell you it has stopped. Nobody publishes that number for a home setup, and it cannot be looked up, because it is a property of your particular arrangement of app, phone, network and habits.
It can be measured, though, and the standard shows the shape of the measurement: pick an ordinary afternoon when nothing is at stake, break the thing on purpose - pull the power, drop it off the network, take the card out - and time how long it is before you hear about it without going to look. Whatever that interval turns out to be is your real warning time.
Trust in a recorder that has never been interrupted is built entirely out of afternoons when nothing happened. The interval you measure on purpose is the only part of it made of evidence.
Try it: Background Camera RemoteStream on Google Play - record with the screen off, keep footage on the device, watch it over your own network. More at superfunicular.com.
Sources, all first-party: 49 CFR 571.138, Standard No. 138: Tire pressure monitoring systems, as published by the Office of the Federal Register in the Electronic Code of Federal Regulations (Title 49 current as of 10 September 2026). Quotations are verbatim standard text: the definition from S3, the malfunction deadline and persistence rules from S4.4, the lamp checks from S4.3.3 and S4.4(b)(4), the owner's manual paragraphs from S4.5, the test procedure from S6, and the phase-in from S7.
Top comments (0)