VWAY

Newsroom
Company News


Event ParticipationPre-event brief for AutoSoft Dialogue #23, Shanghai, 4 September 2026 | VWAY session details inside

VisualPro Tech Brief
China’s Mandatory Standards for Intelligent Driving Are Here
Less than a year left — and the question is how you build the Safety Case
Pre-event brief for AutoSoft Dialogue #23, Shanghai, 4 September 2026 | VWAY session details inside
GB 47955 effective 2027.01.01GB 44721 effective 2027.07.01SOTIF (ISO 21448)AI-driven STPAShanghai, Sep 4
01Overview (TL;DR) — The Regulatory Clock Has Already Started
GB 47955 effective
2027.01.01
Combined driving assistance (L2)
GB 44721 effective
2027.07.01
Autonomous driving (L3, L4)
Fitment rate
70%
New passenger cars in China, 2026
VWAY session
Sep 4, 14:20
Shanghai Int’l Automobile City

In 2026 China moved intelligent-driving safety regulation from recommended to mandatory. Two mandatory national standards (GB) were released two months apart. GB 47955—2026 (safety requirements for combined driving assistance systems, SAE L2) was released on 27 June 2026 and takes effect on 1 January 2027; GB 44721—2026 (safety requirements for autonomous driving systems, L3 and L4) was released on 30 July 2026 and takes effect on 1 July 2027.

Both are mandatory (GB), not recommended (GB/T). The weight of these standards sits not on functional requirements but on the requirement to demonstrate: manufacturers must establish a full-lifecycle safety assurance system spanning R&D, production, and in-service operation, verified through simulation, proving-ground, and public-road testing.

The assessor’s question changes — from “is this function safe?” to “on what evidence do you argue that it is safe?”
02Why Now — Three Pressures
1Regulation — The Function Went Mainstream First, the Baseline Arrived SecondRegulatory pressure
In 2026, 70% of new passenger vehicles sold in China carried combined driving assistance functions, and more than 30% of models offered NOA. The capability went mainstream while the product safety baseline stayed empty; GB 47955—2026 fills that gap for the first time. This regulation does not govern “features to come” — it sets a mandatory baseline on features already on the road.
2Method — Risks That Component Failure Cannot ExplainSOTIF
ISO 26262 addresses risk from malfunctioning behaviour of E/E systems. ISO 21448 (SOTIF) addresses what remains when nothing has failed at all — sensor performance limits, perception errors, unspecified scenarios, driver misuse. When GB 44721—2026 regulates human-machine interaction logic, activation and deactivation procedures, and the duty to communicate capability and boundaries, it is legislating precisely in the SOTIF domain. FMEA and FTA handle the ways a component breaks, but structurally miss a controller issuing a formally correct command at the wrong moment.
3Evidence — A Safety Case Is a Traceable Chain, Not a Stack of ReportsSafety Case
The event’s official invitation states that the new national standards introduce quantitative indicators for the design, development, verification, and validation activities of functional safety and SOTIF, and explicitly require companies to build a systematic Safety Case — demonstrating through a complete and traceable chain of evidence that system risks have been adequately identified, assessed, and controlled. Where that chain is held together by manual links between spreadsheets, one design change breaks it.
03The Regulatory Clock in Numbers

Timeline of China's mandatory intelligent-driving standards from release to effect — GB 47955-2026 (combined driving assistance, effective 2027-01-01) and GB 44721-2026 (autonomous driving systems, effective 2027-07-01) with months remaining

China’s mandatory intelligent-driving standards — from release to effect

GB 47955—2026GB 44721—2026
ScopeCombined driving assistance (L2)Autonomous driving systems (L3, L4)
StatusMandatory national standardMandatory national standard
Released27 June 202630 July 2026
Effective1 January 20271 July 2027
Applies toBasic single-lane, basic multi-lane, NOACategory M and N vehicles (excl. automated parking)
SignificanceFirst product safety baseline for combined driving assistanceSupersedes recommended standard GB/T 44721—2024
Time remaining As of August 2026, roughly four months to GB 47955 and ten months to GB 44721. That is not a generous window in which to stand up a safety argumentation framework from scratch. For programmes already in development, the realistic task is not to start new analyses but to restructure existing ones into an evidence chain.
04STPA — One Method Aimed at SOTIF and the Safety Case at Once

STPA (System-Theoretic Process Analysis) treats an accident not as a chain of component failures but as inadequate control. It proceeds in four steps.

1Define losses and system-level hazardswhat must not be lost
2Model the control structurewho controls what, using which information
3Identify unsafe control actions (UCAs)provided / not provided / wrong timing / wrong duration
4Derive loss scenariosthe paths by which those UCAs actually occur

Coverage of safety analysis methods by hazard type — component failure, system hazard from failure combinations, vehicle-level hazard/ASIL, inadequate control interaction, SOTIF performance limits, and human-machine interaction rated for FMEA, FTA, HARA and STPA as primary scope, partially addressed or not applicable

Coverage of safety analysis methods by hazard type
It Addresses the SOTIF Domain Head-OnISO 21448
A UCA presumes no failure. If sensors and controllers all operate correctly but the perception result does not fit the situation, that is already an unsafe control action. In practice STPA is effectively the only method that puts failure-free risk inside the analysis scope.
HMI and Driver Misuse Become AnalysableGB 44721
In STPA the driver is a controller within the control structure. Activation and deactivation logic, takeover failures, and misunderstanding of functional boundaries are all identified as UCAs — a direct match to the human-machine interaction requirements in GB 44721—2026.
The Evidence Chain Emerges from the Analysis ItselfSafety Case
Loss ↔ hazard ↔ UCA ↔ loss scenario ↔ safety requirement ↔ verification item form a hierarchy, so “which hazard did this safety requirement come from?” is answered by a link, not by recollection. That answer is exactly what a Safety Case asks for.
05What AI Changes in STPA — and What Must Be Preserved

The practical difficulty with STPA is not difficulty, it is volume. Grow the control structure slightly and UCAs run into the hundreds, loss scenarios into the thousands. In organisations without dedicated safety staff, STPA always stalls at steps 3 and 4.

That is exactly where an AI agent pays off most. VisualPro connects directly to AI agents such as Claude through the Model Context Protocol (MCP): the agent reads the control structure and drafts UCA candidates and loss scenarios conversationally. For analyses that must survive certification, however, AI comes with conditions.

1AI Drafts, People DecideReview history
Who reviewed and approved, and when, must be recorded in the analysis data itself.
2Every Item Traces Back to Its BasisTraceability
The link to the originating control action and hazard must be preserved.
3AI-Generated Items Are DistinguishableExplainability
The assessor must be able to set their own review scope.
Hold those three and AI becomes a rate of evidence production rather than an audit risk.
06Where VisualPro Sits — Putting the Analyses on One Structure
One Structure Tree, Five AnalysesIntegrated
FMEA, FTA, HARA, TARA, and STPA share the same system structure database. No re-modelling per method, and no drift in terminology or scope between them.
Cross-Analysis Traceability = the Evidence ChainDigital Thread
Safety goal ↔ FTA top event ↔ DFMEA failure mode ↔ STPA loss scenario ↔ safety requirement are linked in a single database. A design change propagates across the related analyses, so the evidence chain survives the change.
MCP-Based AI Agent IntegrationAI Integration
AI agents such as Claude communicate directly with VisualPro, covering UCA, loss scenario, failure mode, and threat identification through draft scoring, conversationally. The thinner the analysis staffing, the more this shows.
Standard Deliverables in KR and ENKR/EN Reports
AIAG-VDA FMEA, ISO 26262 HARA (ASIL), ISO/SAE 21434 TARA, FTA, and STPA in standard formats, with bilingual reports generated from the same database for overseas customer audits.
07Frequently Asked Questions (FAQ)
Q1Does STPA replace HARA under ISO 26262?
It complements rather than replaces. HARA identifies hazards and assigns ASIL through S, E, and C; STPA derives which control interactions produce those hazards. In practice the cleanest approach is to align the HARA hazard list with the STPA loss and hazard definitions, then use STPA loss scenarios as the rationale for safety requirements. When both analyses sit on the same structure tree, that alignment work disappears.
Q2Will a certification body accept analysis produced with AI?
An audit looks at rationale, review history, and traceability, not at who produced the text. If AI drafted, a person approved, and every item traces back to a parent hazard, the result is judged by the same criteria as manual work. Conversely, an analysis with no rationale links draws findings even when a human wrote it. The question is not whether you use AI, but whether your tool can record that you did.
Q3We are addressing Chinese GB standards — can we use an ISO-based toolchain?
The new national standards layer quantitative indicators and testing requirements on top of the design, development, verification, and validation processes of functional safety (ISO 26262) and SOTIF (ISO 21448). The analysis methods themselves — HARA, FMEA, FTA, TARA, STPA — are common ground; there is no new methodology to learn. What is needed is a framework that organises and connects the analyses you already run into the evidence form the GB standards ask for.
08See It in Shanghai (Next Step)
Shanghai Intelligent Vehicle Software Park — AutoSoft Dialogue #23, “Driving in Safety”
ThemeFunctional safety and SOTIF AI analysis practice under the L2/L3/L4 regulatory framework
DateFriday, 4 September 2026, 13:00 – 17:00
VenueShanghai International Automobile City · Cloud Intelligent Driving Lounge
HostShanghai Intelligent Vehicle Software Park
The VWAY Session
Time14:20 – 14:50 (Topic Sharing 2)
TitleA New Paradigm for AI-Driven STPA Safety Analysis — Meeting L2/L3 Regulatory and Safety Case Requirements Efficiently
SpeakerDave Kim — VisualPro Product Specialist, VWAY (Korea)
Also on the programme
From standard to practice — ADS L3 development platform and commercial case studies (Chief Safety Expert, IAE)
AI safety analysis and quantitative safety requirements in the L3/L4 national standards (Functional Safety Expert, FAW Hongqi)
The safety baseline for advanced intelligent driving — a full walkthrough of ISO/PAS 8800 (Automotive Safety Assessor, DEKRA China)
Breakout discussions — OEM and Tier 1 boundaries of authority in safety analysis / explainability and certification acceptance of AI-assisted analysis / common gaps in Safety Case evidence chains

The regulatory timetable is fixed, and there is less than a year of preparation left in it. Rather than working it out alone, come and compare validated paths with the rest of the industry chain.

You are not buying an analysis — you are building an analysis asset you can argue from. Start with VisualPro.
Sources: SAMR / SAC release notices for GB 47955—2026 and GB 44721—2026, MIIT standard interpretation, Xinhua reporting, and the official invitation to AutoSoft Dialogue #23.
VisualPro & Demo Inquiries
VWAY Co., Ltd. | sales@vwaycorp.com
Website www.vwaycorp.com | Free trial VisualPro Lite