China’s New L3/L4 National Standard Puts Automated-Driving Strategies to a 10-Second Test
Featured

China’s New L3/L4 National Standard Puts Automated-Driving Strategies to a 10-Second Test

“The system disengaged one second before the crash.” It has become one of the most damaging phrases associated with advanced driver-assistance systems in China.

For drivers, it captures the fear that control can be handed back at precisely the moment when a machine can no longer cope. For carmakers, it exposes the unresolved boundary between a feature sold as intelligent and a product still legally defined as assistance.

China is now trying to draw that boundary more clearly. On July 30, regulators approved GB 44721-2026, the country’s first mandatory national safety standard written specifically for Level 3 and Level 4 automated-driving systems. The rules apply to passenger and commercial vehicles, but not automated parking systems, and are scheduled to take effect on July 1, 2027.

The standard establishes a common safety baseline for systems that can assume the driving task under defined conditions. Its most closely watched provision concerns the transition back to a human driver. After issuing a takeover request, a Level 3 system must allow at least 10 seconds before beginning its minimum-risk response. Alerts must intensify during the first four seconds and include a tactile warning, rather than relying only on a display or an audible signal. If the driver does not respond, the vehicle must initiate a minimum-risk manoeuvre, such as moving to the roadside and stopping without obstructing traffic.

 

 

This is more than a timing rule. It is an attempt to prevent an automated-driving system from abruptly withdrawing at the edge of its capability and transferring an immediate hazard to the person behind the wheel. The standard also requires driver-readiness monitoring, documented safety evidence and validation through simulation, closed-course testing and public-road trials.

For the industry, the message is clear: performance claims will no longer be enough. Carmakers will have to show regulators how a system behaves when sensors degrade, conditions move beyond its operating domain or a driver fails to respond. The competition is shifting from who can demonstrate the most functions to who can prove that those functions remain acceptably safe.

 

 

The Standard Does Not Choose an Algorithm, but It Changes the Burden of Proof

GB 44721-2026 is largely technology-neutral. It does not prescribe a particular sensor or require carmakers to adopt one software architecture. It focuses instead on outcomes: the system must perform the dynamic driving task at least as safely as a qualified and attentive human driver, avoid unreasonable risks and enter a minimum-risk state when it can no longer continue safely.

That neutral language does not mean every technical approach will face the same compliance challenge. Four broad generations of automated-driving architecture are now competing in China, and each produces a different kind of evidence for regulators.

The first is the modular architecture built around bird’s-eye-view perception, transformer models and separately engineered modules for prediction, planning and control. Its strength is traceability. Engineers can often identify whether a failure began in perception, object classification, planning or a rule-based decision. Its weakness is the scale of the work required. Human-written rules struggle to cover the enormous number of unusual road events that sit outside ordinary test cases.

The second is a more fully end-to-end approach, in which sensor inputs are converted more directly into driving decisions. These systems can reduce engineering complexity and learn behaviours that are difficult to encode manually. They also create an audit problem. When an abnormal decision emerges from an opaque chain of model weights, a manufacturer may find it harder to explain why the vehicle acted as it did and to demonstrate that equivalent failures have been systematically controlled.

 

 

That does not make end-to-end systems automatically non-compliant. It does mean their developers will need stronger logging, scenario reconstruction, independent safety monitors and evidence gathered outside the main neural network. A model’s driving performance and the safety case used to approve it are related, but they are not the same thing.

Vision-language-action models, promoted by companies including Li Auto and Xpeng, attempt to connect perception, reasoning and vehicle action within a broader model. Their potential advantage is a richer intermediate representation of what the vehicle has detected and intends to do. This could make abnormal behaviour easier to analyse and could support a more legible safety record. Language output alone is not proof of safe reasoning, though. Regulators will still need repeatable evidence that the vehicle responds correctly across the defined operating domain.

World models add another layer by learning how a driving scene may evolve over the next several seconds. NIO has already rolled out a system under that label. By generating and testing possible futures, a world model can support large-scale simulation of rare hazards without putting a physical vehicle into every dangerous situation. This is particularly useful under a standard that makes simulation part of the verification chain. Its advantage remains conditional on whether the simulated world is sufficiently representative of the real one.

Huawei, for its part, describes its latest ADS architecture in end-to-end terms while surrounding it with collision-avoidance and safety mechanisms. This illustrates why simple labels can mislead. A commercial system may combine neural decision-making, conventional safety logic, sensor fusion and redundant control. Compliance will be assessed on the complete system rather than the marketing name attached to its core model.

The same logic applies to sensors. The new framework places greater pressure on manufacturers to show how a vehicle remains aware of its surroundings when a primary sensing channel is impaired by glare, backlighting, rain or fog. Camera-only systems may therefore carry a heavier burden of proof. Vehicles combining cameras with millimetre-wave radar, lidar or ultrasonic sensors have more independent data sources available when visibility deteriorates, although adding hardware does not by itself guarantee safe performance.

The emerging dividing line is not simply modular versus end-to-end, or vision versus lidar. It is whether a manufacturer can produce an auditable safety case that connects design assumptions, test results, system limits and real-world behaviour.

 

 

Compliance Costs Will Begin to Shape the Vehicle Itself

The standard reaches beyond the automated-driving software. A compliant Level 3 vehicle must monitor whether the driver is seated, wearing a seat belt and capable of taking control. According to Sun Hang, chief engineer at the China Automotive Standardization Research Institute and one of the standard’s drafters, the system must use at least two indicators, such as closed eyes or a lowered head, to assess takeover readiness. Each assessment cycle must be no longer than 30 seconds.

If the system concludes that the driver is distracted or unable to respond, it must escalate its warnings and continue to manage the vehicle during the transition. That requirement turns the cabin-monitoring system from an optional convenience into part of the vehicle’s safety architecture. Camera placement, infrared performance, seat and belt sensors, warning design and the interaction between the cockpit and driving controller all become matters of regulatory evidence.

Manufacturers must also retain a detailed safety file covering the system’s design, risk analysis, test data and validation results. If an accident occurs, that record can help regulators reconstruct the vehicle’s state and examine whether the manufacturer’s safety claims were supported. The standard’s assessment framework combines corporate safety-capability checks, review of the product safety file and confirmatory testing by third parties.

Every Level 3 or Level 4 product must be validated through simulation, controlled-site trials and road testing. None of those stages can substitute entirely for the others. Simulation provides scale, closed courses make hazardous scenarios repeatable, and road tests reveal the disorder that engineered scenarios often miss.

 

 

The bill is likely to be substantial. Industry estimates cited in China suggest that completing a full advanced-driving compliance programme for a single vehicle model could cost about $1.475 million or more. That is a significant additional burden in a market where price competition has already compressed margins. Smaller brands may need to share platforms, buy systems from larger suppliers or restrict Level 3 capability to a narrower range of vehicles and operating conditions.

Compliance could therefore alter product planning as much as it changes software development. Carmakers may reserve certified Level 3 systems for higher-priced models that can absorb redundant sensors, additional computing, driver monitoring and the cost of validation. Others may retain Level 2 assistance, where the driver must continuously supervise the road, rather than accept the legal and engineering obligations attached to conditional automation.

Marketing will also face closer scrutiny. Labels such as “near-Level 3”, “L2.999” or “almost autonomous” have blurred the difference between assistance and automation. As China tightens oversight of how driving systems are described, the ability to obtain formal approval under the new standard is likely to carry more weight than an improvised badge. From July 2027, certification may become one of the clearest dividing lines in the market.

 

 

The Weakest Link in the 10-Second Window Is Still Human

Technology and compliance can define the transition process, but they cannot remove its central contradiction. Level 3 automation allows a driver to stop continuously performing the driving task within an approved operating domain. The same person must still remain capable of taking control when the system asks.

That is a difficult behavioural bargain. A person who has been reading a message, looking away from the road or simply allowing attention to drift must first notice the alert, understand why it was issued, rebuild a picture of surrounding traffic and then decide how to act. The physical movement of putting hands on the wheel may take only a few seconds. Recovering situational awareness can take longer.

Research into conditional automation has repeatedly shown wide variation in takeover performance. Reaction time depends on the secondary task, alert design, traffic complexity, driver experience and the amount of time spent outside the driving loop. Familiarity can create a further risk: repeated successful use may encourage a driver to trust the system more deeply, leaving that person less prepared when an unusual event finally occurs.

This is why 10 seconds should be understood as a regulatory floor rather than a guarantee of a safe transfer. On a clear road, it may be sufficient. In dense traffic, severe weather or a rapidly changing hazard, a driver may regain physical control without yet understanding the scene. The system must therefore remain responsible for a safe transition instead of treating the end of the countdown as permission to disappear.

Liability is equally complicated. The standard strengthens the manufacturer’s obligation while the automated-driving system is active and requires the driver to respond to a legitimate takeover request. It does not create a simple stopwatch that automatically allocates fault at five or 10 seconds. Accident responsibility will still depend on system status, warning records, driver behaviour, road conditions and the applicable legal and insurance framework.

 

 

That distinction matters. A crude liability rule could encourage both sides to game the boundary: a manufacturer might try to show that a warning was issued, while a driver might delay action in the belief that responsibility remains with the vehicle. A robust Level 3 regime needs event data, clear user training, consistent insurance treatment and alert systems designed around human limitations rather than legal convenience.

GB 44721-2026 closes one of the most obvious gaps left by the Level 2 era. A compliant automated-driving system should no longer be able to abandon the task at the last moment and leave the driver with an impossible rescue. It also replaces vague promises with a safety case that can be inspected, tested and challenged.

Yet the new standard does not solve the human-machine handover. It exposes how difficult that handover really is. The companies most likely to succeed will not be those with the most impressive algorithm in isolation. They will be the ones that build reliable sensing and control, document why the system is safe, and design a cockpit that gives an ordinary person a realistic chance of understanding and accepting control when it matters.

 

Image
©2026 AutoNewGen.com All Rights Reserved.