VWAY

Newsroom
Company News


Event ParticipationField report from AutoSoft Dialogue #23, Shanghai — 4 September 2026

VisualPro Field Report
China’s Mandatory Standard Already Names STPA
Field report from AutoSoft Dialogue #23, Shanghai — 4 September 2026
Shanghai International Automobile City · Cloud Intelligent Driving Lounge  |  VWAY topic sharing
AutoSoft Dialogue #23GB 47955 C.2.7.1STPA · SOTIFMCP AI integrationShanghai, 4 Sep 2026
01Overview (TL;DR) — What We Went to Confirm, and What We Found
Date
2026.09.04
Shanghai Int’l Automobile City
STPA additional causes
+38
same EPS system, vs FMEA
One working session
20
loss scenarios · 0 errors
At scale
483
loss scenarios · 10×+ productivity
Group photo at AutoSoft Dialogue #23 — attendees holding the “Shanghai Intelligent Automotive Software Park · AutoSoft Dialogue” banner and AutoSoft Dialogue signs (4 September 2026, Shanghai)
Group photo, AutoSoft Dialogue #23 · 4 September 2026, Shanghai International Automobile City

On 4 September 2026, VWAY presented at AutoSoft Dialogue #23 — “Driving in Safety”, hosted by Shanghai Intelligent Vehicle Software Park at Shanghai International Automobile City. The programme theme was functional safety and SOTIF AI analysis practice under the L2/L3/L4 regulatory framework.

In our pre-event brief we asked a question — “how do you build the Safety Case the new Chinese mandatory standards require?” The answer we found on site was clearer than expected.

GB 47955—2026 enumerates STPA by name in its annex. Not a vendor recommendation — a method named directly by a mandatory national standard.
02What We Confirmed On-Site — The Standard Names the Method

GB 47955—2026, Annex C.2.7.1 (Safety Analysis), reads as follows.

a) 整车层面的安全分析,可采用危害分析和风险评估、失效模式与影响分析(FMEA)、故障树分析(FTA)、系统理论过程分析方法(STPA)或适合整车安全分析的其他类似方法;
b) 系统层面的安全分析,可采用 FMEA、FTA、系统理论过程分析方法(STPA)

At both vehicle level and system level, STPA is enumerated alongside HARA, FMEA and FTA. C.2.7.2 c) then asks for hazards arising from insufficient perception performance and foreseeable driver misuse — risks that presume no fault at all. That is the SOTIF domain.

For L3 and L4, GB 44721—2026 clause 6.1.6 governs functional safety and SOTIF management. International standards point the same way: ISO 21448 Annex B.4 addresses applying STPA in the SOTIF context for ADAS.

Put simply: “should we do STPA?” is no longer a matter of preference. It is a matter of choosing one of the options the clause itself lists.
03Why STPA — Accidents Happen With Nothing Broken
VWAY speaker in front of the “When Nothing Failed” slide — three driver-assistance accidents with no component failure (Williams, Brown, Banner cases) compared with photos
Accidents where nothing failed — explaining the SOTIF domain

This is where we spent the most time on stage. Look at publicly investigated driver-assistance collisions and a pattern appears — the sensors and the software behaved exactly as specified, and the accident still happened. Nothing broke. The situation and the judgement simply diverged.


FMEA · FTASTPA
The questionWhat if this part fails?What if control goes wrong?
SubjectComponent failure modesUnsafe interactions between components
QuantitiesFailure rate · FIT · PMHFPerformance limits · failure-free risk
Accident modelA chain of eventsInadequate control

The two do not compete. They ask different questions. Which is precisely why the standard lists them side by side.

There is evidence, too. On the same automotive EPS (electric power steering) system, a published study found that STPA identified 38 causes that FMEA did not. ISO 21448 Annex B.4 treats STPA in the SOTIF context normatively.
04What We Presented — One Project, Five Methods
VWAY speaker presenting in front of the Chinese title slide “AI-driven STPA — meeting L2/L3/L4 efficiently”
The VWAY session — A New Paradigm for AI-Assisted STPA Safety Analysis

VisualPro holds STPA, FMEA, FTA, HARA and TARA inside a single project file. No switching tools, no re-entering the same system model. GB 47955 C.2.7.1 enumerates FMEA, FTA and STPA together in one clause; VisualPro binds them into one project.

1UCA GenerationDifferentiator 1
Four UCA types — not provided (N), provided (P), wrong timing (T), wrong duration (S) — combined with process model variables, so the tool proposes unsafe control action candidates. Type-by-type manual enumeration for every control action disappears.
2Three Named Methods, One ToolDifferentiator 2
STPA covers interaction and performance limitation, FMEA structural failure, FTA quantitative analysis. The combination the clause asks for becomes a single project.
3TraceabilityDifferentiator 3
Loss → hazard → UCA → loss scenario → countermeasure, unbroken. The evidence chain a Safety Case demands emerges from the analysis itself.

Deliverables come out in one action as PDF (submission), MS-Word (editable) and Excel (data review). No copy-paste between the analysis and the report.

05What Changes When AI Is Added
VWAY speaker with microphone at the opening slide “A New Paradigm for AI-Assisted STPA Safety Analysis”
Title slide — A New Paradigm for AI-Assisted STPA Safety Analysis

VisualPro connects AI clients to the VisualPro engine through MCP (Model Context Protocol). Because the protocol is open, there is no lock-in to a single model vendor, and every module — STPA, FMEA, FTA, TARA, HARA — is exposed.

Measured over one working session on a real project:

UCAs registered
7
from natural language only
Loss scenarios
20
generated and registered
Relations linked
50+
trace chain built
Schema errors
0
validated writes

What the engineer actually typed was this — “Check the consistency of this analysis.” “Register these scenarios.” No screen navigation. No manual numbering.

Gap the AI foundHow it was foundAction taken
Hazard with no UCA and no scenarioOne relation queryBroken trace chain restored
UCAs with no loss scenarioUCA ↔ scenario cross-checkFollow-up work identified
Control action never analysedControl action ↔ UCA checkAnalysis scope extended
Coverage stops being a memory exercise and becomes a query. We also shared a larger case: an independent expert working with an AI in the loop produced 122 UCAs, 483 loss scenarios and 11 countermeasures, at 10×+ analyst productivity with 0 hallucinations observed.
06Passing Certification — The Conditions on AI

There is a question every certification body asks about AI. Our answer had three parts.

1Human in the LoopHuman in the loop
The AI proposes; the safety engineer accepts, edits or rejects. Authorship of the safety argument never leaves the engineer.
2Schema-Validated Writes OnlyValidated writes
Every command is described before it is executed, and the agent cannot write a record that violates the data model.
3Every Item Traces BackTraceability
Which hazard, which control action an item derives from stays in the data.
Hold those three, and AI becomes a rate of evidence production rather than an audit risk.
07From Clause to Capability — The Mapping

The closing part of the talk mapped regulatory clauses to tool capability, line by line.

ClauseRequirementVisualPro capability
GB 47955
C.2.7.1 a) b)
Vehicle- and system-level safety analysis by FMEA / FTA / STPAAll three methods in one project
GB 47955
C.2.7.2 c)
Hazards from insufficient perception and foreseeable driver misuseSTPA control-loop analysis, UCA derivation
GB 44721
6.1.6
Functional safety and SOTIF managementSingle-database traceability, standard deliverables
08The Room
The room — attendees on sofas and chairs watching the presentation screen at the AutoSoft venue in Shanghai International Automobile City
The room — OEMs, automated driving developers and certification bodies

The room brought together practitioners from across China’s intelligent driving supply chain — vehicle manufacturers, automated driving developers, certification bodies, automotive research institutes and industrial park operators. The talks and breakout discussions covered boundaries of authority between OEM and Tier 1 in safety analysis, explainability and certification acceptance once AI enters the work, and the gaps that commonly appear in Safety Case evidence chains.

Our thanks to our partner IAE for making the session possible.

09Closing

We closed the talk like this.

System description → STPA analysis → structured safety model → traceable safety result

VisualPro AI does not replace safety engineers. It helps them build the analysis faster, and it makes what is missing visible.

The regulatory timetable is already fixed. GB 47955 takes effect on 1 January 2027; GB 44721 follows on 1 July 2027. Begin by putting your scattered analyses onto a single structure.

Event: AutoSoft Dialogue #23, Shanghai Intelligent Vehicle Software Park, 4 September 2026, Shanghai International Automobile City · Cloud Intelligent Driving Lounge. Clauses are quoted as presented; please confirm against the published standards before relying on them.
VisualPro & Demo Inquiries
VWAY Co., Ltd.  |  sales@vwaycorp.com
Website www.vwaycorp.com  |  Free trial VisualPro Lite