In-depth analysis of published national standards for the decision-control and execution layers and their vertical safety pillars — standard objectives, core technical concepts, implementation highlights and challenge mitigation — with a China-US-EU technical indicator comparison. This edition covers the decisive first half of 2026: the three mandatory ICV standards entering force, China's first mandatory L2 standard (GB 47955-2026), the L3/L4 mandatory standard reaching draft-for-approval, the simulation-test gap closing, and the UN adopting the world's first harmonised ADS regulation.
Parts of this document were produced with the assistance of a large language model, including source research and aggregation, English drafting, and the comparative and engineering analysis. It has been reviewed by a human editor, but readers should treat it accordingly.
What that means in practice, by content type:
Do not use this document as the sole basis for a compliance decision, a type-approval submission, a supplier requirement or a contractual commitment. For those purposes, obtain the official standard texts and consult an accredited testing or certification body.
This document deliberately covers enacted standards, published-but-not-yet-effective standards, and drafts, because that is the real planning environment in 2026–2028. But those carry completely different weight, and so do the sources behind them. Two independent axes apply throughout: legal status (can it stop your type approval?) and source provenance (how well established is the claim?). A draft standard reported by industry media is not a compliance obligation, no matter how specific its numbers look.
Practical rule: anything at legal status A or B with provenance 1–2 is safe to base decisions on. Anything at status C, or with provenance 4–5, should drive architecture and monitoring, not commitments or supplier requirements. Where the two conflict — a specific-sounding number from a draft — the draft status governs.
China's ICV standard system has crossed from "standards being written" into "standards being enforced." The window 2026–2028 contains four separate mandatory gates, each with its own scope and transition rule. Anything a programme is designing today must clear the gate matching its start-of-production, not the gate in force at design time.
This comparison focuses on the EU (UNECE / EU regulations) and US (NHTSA / FMVSS framework) counterparts most relevant to China's published standards. China Ahead = China's standard is stricter or earlier; Gap = international rules more mature; Aligned = substantially equivalent. Rows marked NEW 2026 are new or materially changed during H1 2026. The structural story of 2026: the UN now has a harmonised ADS regulation, China is converting its recommended ICV standards into mandatory ones at speed, and the US is moving the opposite way — withdrawing its oversight programme while rewriting equipment standards.
Read the legal status before the content. This table deliberately places enacted requirements alongside draft ones, because that is the actual decision environment — but they carry very different weight. Every China cell citing a mandatory instrument is tagged below; cells citing GB/T recommended standards are unlabelled, since those bind no one at type approval regardless of effective date:
| Dimension / Indicator | 🇨🇳 China | 🇪🇺 EU / UNECE | 🇺🇸 US | Assessment |
|---|---|---|---|---|
| Regulatory Architecture — read this before comparing any individual requirement | ||||
Regulatory philosophy NEW 2026 Where the burden of proof sits |
Ex-ante, standard-based. Mandatory GB standards are a precondition of the product access announcement (公告). The state defines the technical baseline; the enterprise proves conformity before sale | Ex-ante, type approval. UN Regulations administered through EU type approval; conformity assessed by approval authorities and technical services against harmonised regulations | Ex-post, self-certification. Manufacturers self-certify to FMVSS; NHTSA polices through defect investigation, recall authority and the Standing General Order after deployment | Not comparable directly |
Instruments in play NEW 2026 Why like-for-like comparison misleads |
Three stacked layers: ① mandatory/recommended national standards (GB / GB/T), ② administrative licensing — product access, conditional licences, the ICV access-and-road-operation pilot, ③ industrial policy and work plans (标准化工作要点). A requirement can bind through any of the three | Largely one layer: UN Regulations and EU regulations operating through type approval, supplemented by the General Safety Regulation for fitment mandates | Two layers: FMVSS (equipment self-certification) and enforcement/reporting instruments (SGO, defect authority, Part 555 exemptions), plus state-level permitting for AV operation | Structural asymmetry |
What "compliant" means in practice NEW 2026 |
Documentation + third-party testing + audit, assessed before market entry. Increasingly a lifecycle obligation: CSMS/SUMS audits, safety-file refresh on each OTA, operational safety re-testing | Homologation against a regulation, with CSMS/SUMS audit under R155/R156 and, under the new UN ADS instruments, in-service monitoring and reporting extending the obligation past approval | A manufacturer's own determination of conformity, tested in practice by investigation and litigation after vehicles are on the road | Different burden of proof |
Consequence for the rows below NEW 2026 |
An "aligned" verdict on a technical parameter does not imply equivalent regulatory exposure. China and the EU can share a numeric requirement while differing entirely in who must prove it and when; the US can lack a requirement on paper while enforcing an equivalent expectation through defect authority. Read every row below as a comparison of technical content, and this block as the comparison of legal mechanism. Where the two diverge, the mechanism usually matters more to a programme plan than the parameter. | Interpretation key | ||
| Global ADS Framework — the 2026 Structural Change | ||||
Harmonised ADS Regulation NEW 2026 Type-approval framework for full-DDT systems |
ADS mandatory GB Draft Draft-for-approval (报批稿, public notice 17–24 Jun 2026), proposed effective 1 Jul 2027. Same "competent and attentive driver" benchmark and safety-case logic as the UN text; China is a GRVA participant | UN Reg + UN GTR on ADS Adopted by WP.29 on 24 Jun 2026 — first internationally harmonised ADS framework. Lifecycle Safety Management System, ODD-bounded operation, In-Service Monitoring & Reporting, multi-method validation (simulation + controlled testing + real-world data), "competent and careful human driver" benchmark | Signatory to the 1998 Agreement, so the GTR track (not the UN Regulation track) is the US-relevant instrument; NHTSA sought public comment on the draft GTR (23 Jan 2026). Adoption ≠ automatic FMVSS change | Converging All three now share one benchmark |
Safety performance benchmark NEW 2026 What "safe enough" means in law |
ADS mandatory GB (draft) Draft System shall reach the level of a competent and attentive driver and introduce no unreasonable risk; reported quantified residual-risk ceilings in the draft (see L3/L4 card) | UN ADS ADS must be free from unreasonable safety risk and perform at least at the level of a competent and careful human driver | No federal quantified benchmark; NHTSA relies on defect authority + SGO incident reporting. Benchmark debate happens in litigation and state permits, not in FMVSS | CN + UN Aligned US unquantified |
In-service safety monitoring obligation NEW 2026 |
GB/T 43766 + GB/T 44850 Operational safety testing framework (published 2024/2025) + DSSAD data + ADS mandatory GB safety-file update duty on every hardware change / algorithm OTA | UN ADS ISMR Manufacturers must monitor real-world ADS performance post-approval and report safety-relevant incidents and failures — approval becomes a continuing obligation | SGO 2021-01 Standing General Order crash reporting is the de facto in-service mechanism; broad but reporting-only, no approval linkage | Aligned in principle |
| L2 Combined Driving Assistance / DCAS | ||||
Mandatory L2 safety standard NEW 2026 The highest-volume regulatory gate |
GB 47955-2026 Published, pending Mandatory, published 27 Jun 2026, effective 1 Jan 2027. Three product classes with explicit permission envelopes (basic single-lane / basic multi-lane / NOA); driver-state monitoring, risk-mitigation strategy, data recording, manufacturer safety assurance, HMI + user manual + user training; proving-ground + road + documentation evaluation | UN R171 (DCAS) In force since 2024; 02 series of amendments finalised for vote on 24 Jun 2026. Type-approval based, requires effective warning strategy on loss of driver engagement; DCAS never transfers responsibility | No federal L2 standard. NCAP scoring includes driver monitoring; oversight is via defect investigations of specific L2 systems rather than a standard | China: product-classed approach UN R171 earlier |
NOA / system-initiated lane change NEW 2026 |
GB 47955-2026 Published, pending Permission envelope is explicit per class: basic single-lane may not auto lane-change; basic multi-lane requires driver-initiated (stalk) confirmation; NOA may auto lane-change and handle ramp on/off but not across solid lines | UN R171 02 series DCAS lane-change categories with confirmation requirements; system-initiated manoeuvres constrained and staged by amendment series | Unregulated at federal level; OEM-defined (FSD Supervised, BlueCruise, Super Cruise all differ) | China Most Prescriptive |
Driver monitoring (DMS) & misuse handling |
GB 47955-2026 / GB/T 44461 Published, pending Continuous hands/gaze monitoring above a low speed threshold; escalating warnings, then risk-mitigation strategy and temporary lockout of the function after repeated misuse. DMS itself moving to a mandatory standard (driver attention monitoring in consultation) | UN R171 / R157 Eye openness and head direction monitoring, seatbelt release detection; camera-based monitoring effectively preferred; EU GSR also mandates driver drowsiness/attention warning across the fleet | NCAP 2025 includes DMS in scoring; no federal mandate. Lockout-after-misuse exists in some products by OEM choice, not by rule | China Adds Lockout Duty |
AEB mandate NEW 2026 |
GB 39901-2025 Published, pending Upgraded from GB/T to mandatory GB, published 31 Dec 2025. Two stages: new M1/N1 type approvals from 1 Jan 2027, all newly produced light vehicles from 1 Jan 2028; scope widened from M1 to M1 + N1 ≤3.5 t (~30% more coverage); adds pedestrian, bicycle and step-through motorcycle targets | EU 2019/2144 (GSR) + UN R152 AEB mandatory for all new vehicles since July 2024; heavy-vehicle AEB via UN R131. Earliest and broadest in force | FMVSS No. 127 Final rule 2024, compliance from 1 Sep 2029 (small-volume/final-stage 2030), but under petitions for reconsideration and litigation — timing and content uncertain | EU Earliest EU 2024, CN 2027/2028, US 2029 (contested) |
| AD Classification, ODD & Speed | ||||
AD Classification System Reference standard |
GB/T 40429 0–5 levels, equivalent to SAE J3016 with China regulatory context additions | UN R157 / UN ADS Follows SAE J3016; the new UN ADS instruments are scoped by full DDT within an ODD rather than by level number | SAE J3016 Original source, L0–L5, industry self-regulation | Aligned |
L3 max activation speed Highway scenarios |
ADS mandatory GB (draft) / GB/T 44721 Draft No single speed cap in the standard — bounded by declared ODD/ODC. The two conditionally licensed products carry far lower caps as administrative licence conditions, not standard limits: 50 km/h (single-lane, congested highway/urban expressway) and 80 km/h (relatively free-flowing highway/urban expressway) | UN R157 01 series Up to 130 km/h (2022 amendment, raised from 60 km/h); motorways only, no pedestrians/cyclists | No federal L3 speed mandate; Mercedes DRIVE PILOT operates under state approvals (Nevada, California) | Framework vs. pilot-condition difference |
L3 applicable road types |
ADS GB (draft) + GB/T 45312 Draft Highways, urban expressways and general roads, bounded by ODD/ODC; the draft carries a dedicated annex for L3 expressway functions and a separate annex for L4 | UN R157 Motorways only with physical separation; UN ADS instruments are ODD-declared rather than road-type-fixed | No federal uniformity; state authorisation varies widely (CA/AZ/TX permit urban robotaxi) | China Broader |
| Takeover Request (TOR) & Minimal Risk Manoeuvre | ||||
TOR-to-driver response time |
GB/T 44721 / ADS GB (draft) Draft ≥10 s minimum transition before MRM; draft adds explicit takeover-capability monitoring and requires that ADS exit hand control back to the driver without disabling emergency-assistance functions | UN R157 ≥10 s minimum transition demand period; 2024 supplement added EMC robustness requirements | No quantitative federal requirement; OEM-designed (DRIVE PILOT ~10 s window) | Aligned |
MRM stop position |
GB/T 44721 / ADS GB (draft) Draft Safe stop with hazard lights; shoulder stop not mandated, defined by the ODC MRM strategy and justified in the safety file | UN R157 Controlled stop in the current lane; lane change to shoulder not required. UN ADS generalises this to a declared minimal-risk condition | No mandate; DRIVE PILOT executes in-lane stop plus emergency call | Aligned |
L4 without human fallback NEW 2026 |
ADS GB (draft) Draft L4 assessed on the system's own risk-handling capability; reported requirement that the system shall not depend on remote assistance to reach a minimal risk condition | UN ADS Scoped precisely at systems performing the entire DDT; SMS + ISMR carry the assurance load in place of a human fallback | Remote assistance is central to deployed US robotaxi operations and governed by state permits, not federal rule | China Strictest on remote reliance |
| Cybersecurity, OTA & Data Sovereignty | ||||
Vehicle CSMS mandatory requirement |
GB 44495 In force Mandatory and now in force — new types from 1 Jan 2026, all production from 1 Jan 2028; ~38 technical requirements in four categories; cross-border data transfer control + national cryptographic algorithm compatibility | UN R155 Mandatory (EU type-approval prerequisite) since July 2022 for new types; Annex 5 lists 7 categories / 32 sub-threats / 69 attack vectors. GRVA has now assigned AI-related cyber threats to the CS/OTA informal working group | NHTSA Cybersecurity Best Practices remains voluntary guidance; no federal CSMS mandate; indirect pressure via SGO reporting and defect authority | EU Earlier China now equivalent in force |
OTA / SUMS |
GB 44496 In force Mandatory, in force; upgrade records retained 10 years; user-comprehensible notification. Draft ADS GB adds a duty to file L3/L4 algorithm upgrades with the authority in advance and refresh the safety file on every OTA | UN R156 Mandatory SUMS framework; retention period left to national implementation | No federal SUMS mandate; OTA safety fixes regulated indirectly through recall procedures | China Strictest (10 yr + pre-filing) |
Data sovereignty / cross-border control |
GB/T 44464 → mandatory GB in drafting Draft Important data shall not leave China in principle; security assessment required; national cryptographic algorithms. ICV data security requirements and data interaction/management are now being drafted as mandatory standards (consultation stage) | GDPR governs personal data transfer; no vehicle-specific data-sovereignty instrument; data localisation relatively lenient | No federal vehicle data cross-border mandate; state privacy laws (CCPA et al.) apply; note the separate Commerce rule restricting PRC/Russian connected-vehicle hardware and software on national-security grounds | China Strictest |
| Crash / Automated-Driving Data Recording (EDR / DSSAD) | ||||
EDR / DSSAD mandate + trigger window |
GB 44497 In force In force since 1 Jan 2026; AD-specific, records the full ADS activation process rather than crashes only. For specified crash-event recording scenarios the window is ≥5 s pre + ≥0.5 s post — this window applies to triggered events, not to the continuous ADS-activation record, which is governed separately; conventional EDR remains under GB 39732-2020 | UN R160 Conventional EDR mandatory, 5 s pre-event; AD-specific recording addressed within R157 and now the UN ADS data-storage requirements | 49 CFR Part 563 Federal EDR mandate since 2012 (2019 data expansion), 5 s pre-crash; L3+ event data captured through SGO reporting, not hardware-mandated | China Broader |
Data read-tool standardisation Still the top forensic gap |
GB 44497 In force The standard does require the manufacturer to provide a secure, reliable data-access method with access control, integrity and privacy safeguards — so data is readable per model. What does not exist is a national read-tool interface standard making it readable across brands with one tool; accident-data-recording standards appear in the 2026 work points only at revision stage | UN R160 / IEEE 1616 / ISO 21806 Define EDR data format and read interface | NHTSA-specified data element format (Part 563); commercial standardised read tools (Bosch CDR and equivalents) widely available and court-tested | DSSAD Tool Gap Persists |
| Functional Safety & SOTIF | ||||
Functional safety standard |
GB/T 34590 Identical to ISO 26262:2018, all 12 parts. 2026 work points add dedicated functional-safety / SOTIF standards for driving automation, by-wire chassis, BMS and drive-motor systems | ISO 26262:2018 Original international standard; EU type approval expects compliance | ISO 26262 voluntarily adopted; ASIL development not FMVSS-mandated | Technically Equivalent |
SOTIF |
GB/T 43267 Identical to ISO 21448:2022; Chinese experts contributed to the quantification methodology. Now load-bearing: the draft ADS GB's safety-file logic is essentially a SOTIF-style argument made mandatory | ISO 21448:2022 Original. AI Act stacking now deferred (see AI row) | ISO 21448 voluntary; not referenced as a binding requirement | China Core Contributor |
| AI / Foundation Models in Vehicles | ||||
AI-specific vehicle rules NEW 2026 |
MIIT 2026 work points Work programme Automotive AI standards now a formal system-level work item: AI technology application, platform architecture and vehicle large-model capability evaluation guidance documents in review and approval; AI risk assessment/governance, driving-automation AI model evaluation and testing, AI information/data security and end-to-end model development framework in development; AI intelligence grading being proposed | UNECE GRVA Discussed AI definitions, a ban on online learning, and a draft resolution giving guidance on AI use in vehicles; AI-related cyber threats assigned to the CS/OTA IWG. EU AI Act high-risk conformity duties deferred — Annex III to 2 Dec 2027, Annex I embedded AI (type-approved ADS) to 2 Aug 2028. Prohibited practices (since Feb 2025), GPAI (since Aug 2025) and transparency duties remain applicable; new prohibitions apply from 2 Dec 2026 | No AI-specific vehicle rule; no federal AI safety mandate for ADS. Federal posture in 2026 favours removing regulatory barriers over adding AI-specific duties | China Most Systematic EU pressure delayed |
| V2X Communication Technology | ||||
V2X technology route |
GB/T 45315 C-V2X (PC5 / LTE-V2X); first direct-communication national standard; 2026 work points add direct-communication warning, platooning and connectivity-grading standards | Mandatory DSRC proposal abandoned in 2019; now technology-neutral, C-V2X and ITS-G5 coexist; Germany favours C-V2X | FCC reallocated 5.9 GHz from DSRC to C-V2X (2020); no single technology mandate; 3GPP path dominant in practice | China First |
| Testing & Validation Framework | ||||
Simulation test national standard NEW 2026 Long-standing gap — closed in Jan 2026 |
GB/T 47025-2026 Published and effective 28 Jan 2026. 7 test categories, 48 test items, ~887 scenarios; fixed-general-parameter + generalised-variable-parameter scenario construction; toolchain must pass a credibility evaluation; each scenario run 3× and all 3 must pass | UNECE NATM Multi-pillar methodology (FRAV/VMAD); ASAM OpenX the de facto format; UN ADS now requires simulation + controlled testing + real-world data in combination | ASAM OpenSCENARIO / OpenDRIVE widely used and referenced, but no standalone federal simulation standard | Gap Closed — China Now Most Prescriptive |
Three/four-pillar validation standardisation |
Complete set published Simulation (GB/T 47025) + proving ground (GB/T 41798) + road (GB/T 44719) + facility construction (GB/T 43119) + operational safety testing (GB/T 43766 / 44850), with audit assessment elevated alongside them in the ADS standard | UNECE NATM framework defines the pillars; individual pillar test-method standards are left to ASAM/ISO and national practice | Method frameworks adopted by reference; no federal proving-ground or road-test mandate; reliance on SGO reporting | China Most Complete Standard Set |
| Regulatory Posture & Deployment Oversight | ||||
Federal / national AV oversight programme NEW 2026 |
Access pilot + mandatory standards Type-approval pilot for L3 (first approvals Dec 2025) plus a hardening stack of mandatory GBs. Oversight is ex-ante and standard-based | Type approval UN R155/R156/R157/R171 plus EU 2022/1426 for fully automated vehicles; the new UN ADS instruments extend this to full-DDT systems with SMS + ISMR | AV STEP withdrawn 26 Jun 2026 The proposed voluntary ADS oversight/exemption programme is off the table; NHTSA instead issued FMVSS modernisation NPRMs (Nos. 102/103/104 on 16 Mar 2026; No. 135 brakes on 26 Jun 2026) to accommodate vehicles without manual controls, working toward a federal AV standard | US: no ex-ante programme |
Standards documents describe requirements; programmes need to know what work appears in the plan. This section maps each binding or imminent instrument onto the engineering deliverable it creates, who owns it, and where it connects to the safety lifecycle you already run. All entries in the "forces you to change" and "owner" columns are this document's own analysis (provenance level 5) — the regulatory facts behind them are sourced in the cards below.
| Instrument | Status | What it forces you to change | Primary owner | Safety-lifecycle hook |
|---|---|---|---|---|
GB 44495 Cybersecurity · in force |
A | Stand up a CSMS as an auditable organisation, not a document set: TARA per item, supplier DIA flow-down, vulnerability intake and response, national crypto compatibility. The 2028 extension to in-production models is the harder half — legacy platforms need retrospective evidence. | Product cybersecurity + purchasing (supplier flow-down) | ISO/SAE 21434 process; interfaces with ISO 26262 at the security-safety boundary |
GB 44496 OTA / SUMS · in force |
A | OTA governance becomes release engineering under audit: RXSWIN identity per ECU, dependency-aware version matrix, rollback to a defined safe state, 10-year records, comprehensible user notification. Split the release train so safety-critical autonomy code does not inherit cockpit cadence. | Software release / configuration management | Change management under ISO 26262-8; SUMS mirrors CSMS structure |
GB 44497 DSSAD · in force |
A | A crash-survivable, tamper-evident recorder with a secure manufacturer-provided access path, plus the data-governance policy around who may read what. Budget for the forensic-response process, not just the hardware — with no cross-brand read standard, every investigation runs through your own method. | E/E hardware + legal/forensics readiness | Feeds SOTIF field-monitoring evidence and the ADS safety file |
GB 47955-2026 L2 CDAS · effective 2027-01-01 |
B | Classify every shipped combined-assistance function into one of three product classes and constrain its manoeuvre set accordingly — this is a feature-scope decision, not a calibration task. Then: DMS sensing adequate for lockout, HMI redesign, user manual and a user-training deliverable, plus a documented manufacturer safety assurance package. | ADAS function owner + HMI/UX + homologation | ISO 21448 (SOTIF) for misuse and insufficiency; GB/T 44461 performance validation |
GB 39901-2025 AEB · new types 2027, all 2028 |
B | Sensor-suite decisions driven by the hardest mandated target — step-through two-wheelers — not by the car-to-car case. For N1 light commercial platforms this is often a platform-provisioning problem (radar mounting, camera calibration, braking authority) rather than a software one. | Active safety + platform engineering | ISO 26262 ASIL allocation for the braking intervention path; SOTIF for false activation |
GB/T 47025-2026 Simulation · in force (recommended) |
A (GB/T) | Two new obligations that most teams do not have: a toolchain credibility file for the simulator itself, and a documented sim-to-real correlation programme with per-model error budgets. The prescribed scenario set is a conformance floor; keep a separate, far larger internal programme for the residual-risk argument. | Validation / simulation platform team | Supplies the ISO 21448 verification and validation evidence base |
ADS safety GB L3/L4 · draft, proposed 2027-07-01 |
C | The largest structural change: a lifecycle safety case (claim → argument → evidence) that must be re-established on every hardware change, algorithm OTA and variant. Plus continuous ODD self-assessment as a runtime function, and — for L4 — an MRM that does not depend on remote assistance. Treat as architecture guidance now; do not commit to the reported numeric ceilings. | Systems safety / functional safety, at programme level | This is where UL 4600 becomes useful — it is the existing standard purpose-built for autonomous-product safety cases, and maps onto the required claim-argument-evidence structure more directly than ISO 26262 or 21448 alone |
GB/T 43766 / 44850 Operational safety · in force |
A (GB/T) | Post-OTA regression at fleet scale: change-impact analysis to scope re-testing, sensor health assessment, ODD capability spot checks. Becomes structural rather than optional once the ADS safety file must stay true after each release. | Field quality / operations | SOTIF field monitoring; closes the loop from DSSAD data back into the safety case |
Automotive AI standards Guidance docs · work programme |
D | Nothing to certify against yet, so the deliverable is architectural optionality: keep foundation models out of the safety-critical decision path, treat the deployed model as a frozen versioned artefact (aligning with the likely online-learning ban), and build model-layer threats into TARA before any threat-catalogue update lands. | AI/autonomy architecture + cybersecurity | SOTIF Zone 3 for model insufficiency; ISO/SAE 21434 for model-layer threats; ISO/IEC 42001 for AI management system |
Based on the SAE J3016 six-level framework, classification centres on "who executes the DDT" and "who bears responsibility for system failure." L0–L2: the driver is always the DDT executor; L3+: the system assumes the DDT but L3 still requires a driver ready to take over; L4: the system can autonomously execute an MRM; L5: no ODD limits. Key contribution: cleanly separating the responsibility boundary between "driver assistance" and "automated driving."
Until 2026 this was a marketing-versus-standard mismatch with no direct enforcement hook. It is now enforced from both sides: GB 47955-2026 defines what an L2 combined driving assistance product is permitted to do, and the draft ADS mandatory GB defines what an L3/L4 system must prove. A function that behaves like L3 while being sold as L2 now fails one standard or the other rather than merely misleading buyers.
Through Hazard Analysis and Risk Assessment (HARA), hazards are rated by Severity (S), Exposure (E) and Controllability (C) to determine ASIL (QM, A, B, C, D). Safety goals decompose into functional → technical → software/hardware safety requirements along the V-model. ASIL D requires diagnostic coverage ≥99% and PMHF ≤10⁻⁸/h. ASIL decomposition allows splitting high-ASIL requirements across independent redundant modules for engineering feasibility.
SOTIF sorts hazardous scenarios into four zones: Zone 1 (known hazardous, known trigger — eliminate); Zone 2 (known hazardous, unknown trigger — expose through testing); Zone 3 (unknown hazardous, unknown trigger — reduce to an acceptable level); Zone 4 (known safe). Core toolchain: insufficiency identification → trigger condition analysis → verification strategy → safety validation. Provides the framework for out-of-distribution inputs in AI perception systems.
Two-tier architecture. Upper tier: a full-lifecycle CSMS requiring risk identification → assessment → treatment → monitoring/response → vulnerability handling, with supply-chain dependency management. Lower tier: ~38 technical requirements in four categories — ① external connection security (TBOX/WiFi/OBD intrusion resistance), ② communication security (V2X signature verification, CAN/Ethernet isolation), ③ software update security (package integrity, rollback), ④ data security (sensitive data encryption, cross-border transfer control). TARA is the core methodology, with test cases individualised by each enterprise's TARA results.
Three mechanisms: ① RXSWIN — each software version carries a globally unique identifier bound to the ECU and readable for traceability; ② SUMS — the OTA analogue of CSMS, requiring full-process upgrade control including package verification, distribution control and rollback; ③ driving-safety assurance — updates affecting driving must not execute while driving, sufficient battery is required, and failure must roll back to the last usable version or a safe state. Users must be told the content, the operation method, and the post-failure safe state in comprehensible language.
Three tiers: ① classification — vehicle data split into personal information and important data, the latter including operation data, map data and road information, with enhanced protection where national security is implicated; ② full-lifecycle personal information protection — requirements across collection, storage, use, transmission and deletion, with anonymisation meeting an irreversibility criterion; ③ cross-border transfer control — important data shall not leave China in principle, with security assessment required for exceptions. A data-sovereignty clause with few parallels in international vehicle data standards.
Unlike conventional EDR, which captures only seconds around a crash, DSSAD requires recording the complete ADS activation process: activation/exit timestamps, TOR issuance time, driver response time, MRM execution status, perceived target information (position/velocity/type of surrounding objects), and path-planning and avoidance decisions. Data must be encrypted, tamper-evident and uniquely identified. Law enforcement and relevant parties may lawfully access it during accident investigation — addressing the global problem of AD liability determination.
The standard's central move is to stop regulating "L2" as one thing. Each class gets an explicit envelope of permitted manoeuvres: basic single-lane — longitudinal and lane-keeping control only, automatic lane change not permitted; basic multi-lane — lane change permitted but must be driver-initiated (stalk confirmation), the system may not initiate on its own; NOA — automatic lane change and ramp entry/exit permitted, but not across solid lane markings. Four requirement dimensions wrap this: functional requirements, data recording, manufacturer safety assurance, and user-facing obligations — HMI, user manual and user training. Evaluation is multi-level: proving-ground test + road test + documentation review. Driver-state monitoring is continuous while engaged, with escalating warnings on hands-off or eyes-off and, on repeated misuse, a risk-mitigation strategy plus temporary lockout of the function.
The AEB tension is unchanged — sensitivity versus false activation — and the standard still bounds it by prescribing test scenarios with defined target speed, relative speed, initial headway and background clutter, requiring both a minimum collision-speed reduction and a ceiling on false activation. What changes with the mandatory version is target coverage: alongside car-to-car, the standard requires warning and braking response for pedestrians, bicycles and step-through two-wheeled motorcycles crossing ahead. The last of those is a distinctly Chinese addition — the scooter-class two-wheeler is a dominant road user in Chinese cities and a notoriously hard radar target, with a small, low-RCS, laterally fast-moving signature.
With driver-in-the-loop as the premise, the system must continuously monitor takeover capability (hands-on-wheel, gaze direction) while active. Core requirements: ① hands-off or eyes-off beyond threshold must trigger escalating warnings; ② the system must not create a misconception of vehicle control — no "autonomous driving" illusion; ③ lane change assist requires driver intent confirmation and may not autonomously execute lane changes. Key parameters: hands-off detection sensitivity, maximum response time, post-exit system behaviour. Note how directly the GB 47955 per-class envelope inherits this logic — the recommended standard supplied the concepts that the mandatory standard made enforceable.
Evaluated on parking success rate (in both standard and tight spaces) and obstacle detection response. Key safety mechanisms: ① ultrasonic and visual obstacle detection front, rear and side, with a stop required within a specified distance; ② the driver may take over at any time (steering input or brake application exits immediately); ③ a safe default state when no action is preset (remains stationary after stopping). Note that the mandatory ADS standard explicitly excludes automatic parking from its scope — parking is being regulated on its own track, not folded into ADS.
① Performance benchmark. The system shall reach the level of a competent and attentive driver and introduce no unreasonable risk — replacing proxy metrics like test mileage or model parameter counts with a behavioural standard.
② Safety file (claim → argument → evidence). Every L3/L4 model must carry a lifecycle safety file: system architecture, full-scenario hazard identification, risk quantification criteria, software and hardware safety measures, simulation and real-vehicle validation evidence, internal audit records, residual risk assessment. It must be refreshed whenever hardware changes, the algorithm is upgraded by OTA, or a variant launches.
③ Continuous ODD awareness. The system must continuously determine whether it remains within its design operating conditions, and degrade or hand back before the boundary rather than at it — anticipating perception-degrading conditions such as heavy rain or fog by slowing or returning control early.
④ Unified verification. Simulation, proving ground and road testing are integrated into one framework that demands consistency between simulated and real-vehicle results — which is what makes GB/T 47025-2026 load-bearing rather than optional.
⑤ Split L3/L4 logic. L3 centres on the human handover: takeover-capability monitoring, user alerting, and execution of the minimal risk strategy if the driver does not respond. L4 is assessed on the system's own risk-handling capability, and reportedly shall not depend on remote assistance to reach a minimal risk condition. ADS exit must hand control to the driver without disabling emergency-assistance functions.
① ODC-constrained activation: ADS must define a clear ODC, activate only within it, and exit actively when exceeded.
② Driver takeover monitoring: ≥2 indicators (eye movement, head motion, etc.); TOR issued if the seat is left for >1 s or the seatbelt is unbuckled; MRM triggers automatically after 10 s without response.
③ MRM: hazard lights activated, system autonomously executes a safe stop.
④ Multi-pillar validation: audit assessment + simulation + proving ground + road testing — China explicitly elevates audit assessment alongside the UNECE NATM testing pillars — with DSSAD mandatory.
Every ODC element must be annotated "permitted" (does not affect activation) or "not permitted" (suppresses activation or forces exit), eliminating ambiguity. Hierarchy: Level 1 (road environment + vehicle status + occupant status) → Level 2 (specific parameters: max speed, min curve radius, minimum visibility) → Level 3 (sensor status, map update status). Key innovation: V2X availability and HD map coverage are ODC elements, reflecting China's vehicle-road-cloud integration approach — a more infrastructure-aware model than ISO 34503.
① Scenario construction uses fixed general parameters plus generalised variable parameters. For an S-curve item, for example, the initial speed limit, curve direction and sign height range are fixed while ego initial speed, curve radius and curve length sweep across defined ranges — this is what turns 48 test items into ~887 executable scenarios without hand-authoring each one.
② Two-tier pass criteria: generic traffic-rule compliance (no lane violation, speed limits observed, no collision with infrastructure) plus scenario-specific requirements (no collision with target vehicles or pedestrians, no spurious intervention requests, correct minimal-risk-strategy execution where required).
③ Repeat-run rule: each scenario is executed three times and all three must pass — a direct answer to the non-determinism of learning-based stacks, which can pass a scenario once by luck.
④ Toolchain credibility. The simulation toolchain must itself pass a credibility evaluation before it can be used for formal testing, under a management → analysis → verification → validation framework. This is the pivotal design choice: the standard regulates the instrument, not only the test.
Proving ground: standardised scenarios (cut-in, emergency braking, obstacle avoidance, intersection conflict) ensure cross-institutional comparability and reproducibility, with key items covering longitudinal/lateral control accuracy, perception range and takeover response time. Road testing: specifies route coverage (highway, urban, ramp), data recording (DSSAD required), test-operator safety procedures and incident reporting. With GB/T 47025-2026 these now form a genuinely complete three-pillar set rather than two pillars and a plan.
The key distinction from GB/T 41798/44719: those target pre-approval R&D validation, this pair targets post-production operational monitoring. The logic is that AD software is continuously updated by OTA, so safety must be reconfirmed after each update. Operational safety testing establishes periodic inspection covering functional regression, critical sensor health assessment and ODD capability spot checks, linked with GB 44497 so that anomalous events in operational data trigger targeted testing. This is the domestic analogue of what the UN ADS regulation now calls In-Service Monitoring and Reporting — China built the test-method side first, the UN has now added the reporting obligation.
Specifies a foundation scenario set (straight high-speed section, intersections, ramps, parking areas, pedestrian crossing zones) plus optional expansions (tunnels, signal-controlled intersections, complex weather simulation zones). V2X RSU coverage of core test areas is required, reflecting vehicle-road-cloud integrated testing needs, with a unified data acquisition and transmission interface supporting remote monitoring and data sharing.
China chose C-V2X on 3GPP cellular technology over DSRC/WAVE. Rationale: ① shared evolution path with 5G and future 6G — PC5 defined in Release 14, enhanced in Release 16 (5G NR-V2X); ② reuse of existing 4G/5G infrastructure via the Uu interface for beyond-line-of-sight cases; ③ supply chain maturity. This standard specifies the vehicle-side PC5 requirements — the compliance foundation for moving China's V2X from pilot to scale.
The positioning standard specifies BDS B1I/B2I/B3I band performance indicators and priority while remaining compatible with GPS/GLONASS/Galileo. Accuracy grades: standard (<5 m, navigation) → sub-metre (<0.5 m, L2 assistance) → centimetre (<0.1 m, L3+ precision). Infrared: passive IR addresses driver health and rear child presence (hot-car protection); active IR (NDIR/ToF) addresses short-range precise ranging, supplementing ultrasonic sensors.
This document maps the landscape. Turning it into a type-approval strategy for your specific product, market and timeline is the work we do — standards mapping, safety architecture design, safety case development, HARA / FMEA / FTA and SOTIF analysis, and organisational capability building for OEMs and Tier-1 suppliers.