Yet we sort of do accept a linear disincentive for putting dangerous drivers on the road, worst case we take that driver off the road and very rarely do anything to increase the standard all drivers need to meet such that it would weed out all the drivers that are as bad as or worse than the ones taken off the road.
I think you're letting perfect be the enemy of good. In an ideal world we'd stop everything for debugging. Realistically all we need to have a net benefit right now is for the cars to be safer drivers than human drivers on average. As long as the issue isn't suspected of being intentionally triggered or correlated with some sort of large scale event, the world is still paying less of a cost than now even when not grounding the fleet.
A reasonable compromise would be to require autonomous vehicles moving in especially risky areas like highways to have a human inside with at least a "stop or slow down safely" override. In places where the vehicle would be moving too slowly to cause serious injury we can allow them to be human-less. By defining clear and objective criteria, the decision to ground a fleet becomes much easier to make (particularly for the machine, since you don't need advanced AI to check GPS against a database and apply appropriate speed limiters). If the incident was a serious malfunction of a basic function like ignoring the criteria for human-less operation, the fleet should be grounded. In other cases it wouldn't justify preemptively grounding the entire fleet (but may justify it after the severity of the issue has been assessed, probably by a group independent of the company responsible for the vehicles).