EDIT: On an additional reading of https://github.com/commaai/openpilot/blob/master/SAFETY.md Comma claim to be ISO 26262 compliant on the premise that there's no real risk model, because the driver is paying attention and will simply take back control. One could call this the "Elon Model" to safety compliance. I suppose it works for some manufacturers.
It does seem that starting around 2018, Comma added a C layer to their CAN intercept board (Panda) which audit-checks some safety-critical CAN messages to bounds-check the control inputs. That's... a start, but not really a detailed risk analysis model by any means.