VisualPro Field ReportChina’s Mandatory Standard Already Names STPA
Field report from AutoSoft Dialogue #23, Shanghai — 4 September 2026
Shanghai International Automobile City · Cloud Intelligent Driving Lounge | VWAY topic sharing
AutoSoft Dialogue #23GB 47955 C.2.7.1STPA · SOTIFMCP AI integrationShanghai, 4 Sep 2026
01Overview (TL;DR) — What We Went to Confirm, and What We Found
Date 2026.09.04 Shanghai Int’l Automobile City | STPA additional causes +38 same EPS system, vs FMEA | One working session 20 loss scenarios · 0 errors | At scale 483 loss scenarios · 10×+ productivity |
Group photo, AutoSoft Dialogue #23 · 4 September 2026, Shanghai International Automobile City
On 4 September 2026, VWAY presented at AutoSoft Dialogue #23 — “Driving in Safety”, hosted by Shanghai Intelligent Vehicle Software Park at Shanghai International Automobile City. The programme theme was functional safety and SOTIF AI analysis practice under the L2/L3/L4 regulatory framework.
In our pre-event brief we asked a question — “how do you build the Safety Case the new Chinese mandatory standards require?” The answer we found on site was clearer than expected.
GB 47955—2026 enumerates STPA by name in its annex. Not a vendor recommendation — a method named directly by a mandatory national standard.
02What We Confirmed On-Site — The Standard Names the Method
GB 47955—2026, Annex C.2.7.1 (Safety Analysis), reads as follows.
a) 整车层面的安全分析,可采用危害分析和风险评估、失效模式与影响分析(FMEA)、故障树分析(FTA)、系统理论过程分析方法(STPA)或适合整车安全分析的其他类似方法;
b) 系统层面的安全分析,可采用 FMEA、FTA、系统理论过程分析方法(STPA)…
At both vehicle level and system level, STPA is enumerated alongside HARA, FMEA and FTA. C.2.7.2 c) then asks for hazards arising from insufficient perception performance and foreseeable driver misuse — risks that presume no fault at all. That is the SOTIF domain.
For L3 and L4, GB 44721—2026 clause 6.1.6 governs functional safety and SOTIF management. International standards point the same way: ISO 21448 Annex B.4 addresses applying STPA in the SOTIF context for ADAS.
Put simply: “should we do STPA?” is no longer a matter of preference. It is a matter of choosing one of the options the clause itself lists.
03Why STPA — Accidents Happen With Nothing Broken
Accidents where nothing failed — explaining the SOTIF domain
This is where we spent the most time on stage. Look at publicly investigated driver-assistance collisions and a pattern appears — the sensors and the software behaved exactly as specified, and the accident still happened. Nothing broke. The situation and the judgement simply diverged.
| FMEA · FTA | STPA |
|---|
| The question | What if this part fails? | What if control goes wrong? |
| Subject | Component failure modes | Unsafe interactions between components |
| Quantities | Failure rate · FIT · PMHF | Performance limits · failure-free risk |
| Accident model | A chain of events | Inadequate control |
The two do not compete. They ask different questions. Which is precisely why the standard lists them side by side.
There is evidence, too. On the same automotive EPS (electric power steering) system, a published study found that STPA identified 38 causes that FMEA did not. ISO 21448 Annex B.4 treats STPA in the SOTIF context normatively.
04What We Presented — One Project, Five Methods
The VWAY session — A New Paradigm for AI-Assisted STPA Safety Analysis
VisualPro holds STPA, FMEA, FTA, HARA and TARA inside a single project file. No switching tools, no re-entering the same system model. GB 47955 C.2.7.1 enumerates FMEA, FTA and STPA together in one clause; VisualPro binds them into one project.
1UCA GenerationDifferentiator 1
Four UCA types — not provided (N), provided (P), wrong timing (T), wrong duration (S) — combined with process model variables, so the tool proposes unsafe control action candidates. Type-by-type manual enumeration for every control action disappears.
2Three Named Methods, One ToolDifferentiator 2
STPA covers interaction and performance limitation, FMEA structural failure, FTA quantitative analysis. The combination the clause asks for becomes a single project.
3TraceabilityDifferentiator 3
Loss → hazard → UCA → loss scenario → countermeasure, unbroken. The evidence chain a Safety Case demands emerges from the analysis itself.
Deliverables come out in one action as PDF (submission), MS-Word (editable) and Excel (data review). No copy-paste between the analysis and the report.
05What Changes When AI Is Added
Title slide — A New Paradigm for AI-Assisted STPA Safety Analysis
VisualPro connects AI clients to the VisualPro engine through MCP (Model Context Protocol). Because the protocol is open, there is no lock-in to a single model vendor, and every module — STPA, FMEA, FTA, TARA, HARA — is exposed.
Measured over one working session on a real project:
UCAs registered 7 from natural language only | Loss scenarios 20 generated and registered | Relations linked 50+ trace chain built | Schema errors 0 validated writes |
What the engineer actually typed was this — “Check the consistency of this analysis.” “Register these scenarios.” No screen navigation. No manual numbering.
| Gap the AI found | How it was found | Action taken |
|---|
| Hazard with no UCA and no scenario | One relation query | Broken trace chain restored |
| UCAs with no loss scenario | UCA ↔ scenario cross-check | Follow-up work identified |
| Control action never analysed | Control action ↔ UCA check | Analysis scope extended |
Coverage stops being a memory exercise and becomes a query. We also shared a larger case: an independent expert working with an AI in the loop produced 122 UCAs, 483 loss scenarios and 11 countermeasures, at 10×+ analyst productivity with 0 hallucinations observed.
06Passing Certification — The Conditions on AI
There is a question every certification body asks about AI. Our answer had three parts.
1Human in the LoopHuman in the loop
The AI proposes; the safety engineer accepts, edits or rejects. Authorship of the safety argument never leaves the engineer.
2Schema-Validated Writes OnlyValidated writes
Every command is described before it is executed, and the agent cannot write a record that violates the data model.
3Every Item Traces BackTraceability
Which hazard, which control action an item derives from stays in the data.
Hold those three, and AI becomes a rate of evidence production rather than an audit risk.
07From Clause to Capability — The Mapping
The closing part of the talk mapped regulatory clauses to tool capability, line by line.
| Clause | Requirement | VisualPro capability |
|---|
GB 47955 C.2.7.1 a) b) | Vehicle- and system-level safety analysis by FMEA / FTA / STPA | All three methods in one project |
GB 47955 C.2.7.2 c) | Hazards from insufficient perception and foreseeable driver misuse | STPA control-loop analysis, UCA derivation |
GB 44721 6.1.6 | Functional safety and SOTIF management | Single-database traceability, standard deliverables |
08The Room
The room — OEMs, automated driving developers and certification bodies
The room brought together practitioners from across China’s intelligent driving supply chain — vehicle manufacturers, automated driving developers, certification bodies, automotive research institutes and industrial park operators. The talks and breakout discussions covered boundaries of authority between OEM and Tier 1 in safety analysis, explainability and certification acceptance once AI enters the work, and the gaps that commonly appear in Safety Case evidence chains.
Our thanks to our partner IAE for making the session possible.
09Closing
We closed the talk like this.
System description → STPA analysis → structured safety model → traceable safety result
VisualPro AI does not replace safety engineers. It helps them build the analysis faster, and it makes what is missing visible.
The regulatory timetable is already fixed. GB 47955 takes effect on 1 January 2027; GB 44721 follows on 1 July 2027. Begin by putting your scattered analyses onto a single structure.
Event: AutoSoft Dialogue #23, Shanghai Intelligent Vehicle Software Park, 4 September 2026, Shanghai International Automobile City · Cloud Intelligent Driving Lounge. Clauses are quoted as presented; please confirm against the published standards before relying on them.
VisualPro & Demo Inquiries
On 4 September 2026, VWAY presented at AutoSoft Dialogue #23 — “Driving in Safety”, hosted by Shanghai Intelligent Vehicle Software Park at Shanghai International Automobile City. The programme theme was functional safety and SOTIF AI analysis practice under the L2/L3/L4 regulatory framework.
In our pre-event brief we asked a question — “how do you build the Safety Case the new Chinese mandatory standards require?” The answer we found on site was clearer than expected.
GB 47955—2026, Annex C.2.7.1 (Safety Analysis), reads as follows.
b) 系统层面的安全分析,可采用 FMEA、FTA、系统理论过程分析方法(STPA)…
At both vehicle level and system level, STPA is enumerated alongside HARA, FMEA and FTA. C.2.7.2 c) then asks for hazards arising from insufficient perception performance and foreseeable driver misuse — risks that presume no fault at all. That is the SOTIF domain.
For L3 and L4, GB 44721—2026 clause 6.1.6 governs functional safety and SOTIF management. International standards point the same way: ISO 21448 Annex B.4 addresses applying STPA in the SOTIF context for ADAS.
This is where we spent the most time on stage. Look at publicly investigated driver-assistance collisions and a pattern appears — the sensors and the software behaved exactly as specified, and the accident still happened. Nothing broke. The situation and the judgement simply diverged.
The two do not compete. They ask different questions. Which is precisely why the standard lists them side by side.
VisualPro holds STPA, FMEA, FTA, HARA and TARA inside a single project file. No switching tools, no re-entering the same system model. GB 47955 C.2.7.1 enumerates FMEA, FTA and STPA together in one clause; VisualPro binds them into one project.
Deliverables come out in one action as PDF (submission), MS-Word (editable) and Excel (data review). No copy-paste between the analysis and the report.
VisualPro connects AI clients to the VisualPro engine through MCP (Model Context Protocol). Because the protocol is open, there is no lock-in to a single model vendor, and every module — STPA, FMEA, FTA, TARA, HARA — is exposed.
Measured over one working session on a real project:
What the engineer actually typed was this — “Check the consistency of this analysis.” “Register these scenarios.” No screen navigation. No manual numbering.
There is a question every certification body asks about AI. Our answer had three parts.
The closing part of the talk mapped regulatory clauses to tool capability, line by line.
C.2.7.1 a) b)
C.2.7.2 c)
6.1.6
The room brought together practitioners from across China’s intelligent driving supply chain — vehicle manufacturers, automated driving developers, certification bodies, automotive research institutes and industrial park operators. The talks and breakout discussions covered boundaries of authority between OEM and Tier 1 in safety analysis, explainability and certification acceptance once AI enters the work, and the gaps that commonly appear in Safety Case evidence chains.
Our thanks to our partner IAE for making the session possible.
We closed the talk like this.
VisualPro AI does not replace safety engineers. It helps them build the analysis faster, and it makes what is missing visible.
The regulatory timetable is already fixed. GB 47955 takes effect on 1 January 2027; GB 44721 follows on 1 July 2027. Begin by putting your scattered analyses onto a single structure.