09/10 2026
541
The autonomous driving sector is approaching a pivotal turning point in technological competition.
With the widespread implementation of global autonomous driving laws and regulations and the comprehensive establishment of compliance guidelines, the industry has definitively transitioned away from a rough model characterized by 'no rules to follow, testing first, and wild trial and error.'
Core challenges that have long hindered industry development—such as defining accident liability, establishing commercial operation boundaries, enabling cross-regional supervision, and setting product access standards—are being systematically addressed through global compliance frameworks. The United Nations' unified technical regulations, China's new rules for intelligent connected vehicles, and specialized regulatory policies in Europe and the United States are being implemented simultaneously, clearing institutional barriers for the large-scale commercialization of autonomous driving.
The implementation of policies and regulations has fundamentally altered the competitive logic of the industry. Systematic capabilities—comprising local compliance, scenario implementation, commercial operation, and full-chain risk control—have become critical determinants of success for autonomous driving companies.

The prerequisite for the large-scale implementation of autonomous driving is the bidirectional adaptation of technological maturity and legal compliance.
The year 2026 marks a critical turning point in global autonomous driving legislation, with China, the United States, and Europe synchronously completing top-level legislation and upgrading supporting details, forming differentiated regulatory logics. Simultaneously, the United Nations' 'Global Technical Regulation on Autonomous Driving Systems' (ADS GTR) establishes a unified global safety baseline, reducing redundant certification costs in cross-border markets.

China: Rule-First Approach, Practical Implementation, Leading Global Standardization
Domestic autonomous driving legislation adopts a graded regulatory approach, prioritizing scenarios, pilot programs, and fault tolerance.
The national standard GB/T 40429, 'Classification of Driving Automation Levels for Motor Vehicles,' defines L0-L5 driving automation levels, laying the foundational framework for all regulations. The 'Pilot Management Measures for High-Level Autonomous Driving Vehicle Product Access' is the core regulation for the mass production of L3 and above autonomous vehicles in China, fully supporting L3 autonomous vehicles in applying for motor vehicle product access and official license plates. More importantly, the regulation clarifies that when an L3 system is activated, the system assumes driving responsibilities, and in the event of an accident, liability follows product defect logic, while drivers have an obligation to take over upon receiving a request. For L4 vehicles operating in designated areas, the operator bears primary responsibility.
The 'Road Traffic Safety Law (Revised Draft)' specifically adds provisions related to autonomous driving, formally recognizing the legal status of autonomous driving systems at the legislative level, resolving the past legal ambiguity of 'who is the driver,' and clarifying the boundaries of accident liability among vehicle manufacturers, operators, and users.
The 'Provisions on the Administration of Automobile Data Security' regulate the high-frequency collection of external images, geographic information, and pedestrian data by autonomous driving systems, requiring desensitization, minimal necessary collection, and cross-border transfer approvals, directly constraining the compliance boundaries of autonomous driving data loops.
Simultaneously, China is leading the development of the world's first global technical regulation for autonomous driving—the 'United Nations Global Technical Regulation on Autonomous Driving Systems.' This regulation defines mandatory requirements for the minimum safety performance, risk assessment, system safety verification, human-machine interaction, and failure detection of ADS (Autonomous Driving Systems), covering L3 and L4 autonomous vehicles. It is the world's first unified technical regulation for high-level autonomous driving. China has incorporated its complex mixed-traffic scenarios (non-motorized vehicles, pedestrians, electric bicycles) into the global standard text, moving away from directly adopting rules for high-speed/simple urban road conditions in Europe and the United States.
The core logic of domestic legislation neither blindly relaxes restrictions nor conservatively lags behind. It supports the large-scale commercialization of autonomous driving through standardized systems, ensures healthy industry iteration with compliance baselines, maintains safety redlines, and opens up policy space for the full-scenario implementation of Robobus, Robotaxi, unmanned freight, and automated parking.
United States: Liberal Access, Simplified Regulation, Favoring Market Competition
The United States has long faced contradictions between federal and state dual regulation, with significant variations in state rules. California allows fee-based Robotaxi operations, while some states prohibit L4 passenger vehicles from operating on roads. The new 'Autonomous Vehicles Act' attempts to establish federal regulatory priority and weaken the power of individual states to set separate limits.
At the federal level, the '2026 Autonomous Vehicles Act' (SELF DRIVE Act, 2026 new congressional review draft), the National Highway Traffic Safety Administration's (NHTSA) 'Exemption Regulations for Autonomous Vehicles,' and the 'Federal Motor Vehicle Safety Standards' (FMVSS) provide institutional frameworks for accelerating the implementation of autonomous driving. At the state level, the California Department of Motor Vehicles' (DMV) new autonomous driving regulations and Texas's specialized bill for unmanned freight have liberalized road testing and commercial deployment of autonomous driving for heavy trucks and medium-sized passenger vehicles, while comprehensively strengthening safety regulation and enforcement measures.
In January of this year, the U.S. House of Representatives reviewed the draft of the '2026 Autonomous Vehicles Act,' proposing to increase the annual exemption cap for vehicles without steering wheels or pedals from 2,500 to 90,000 units and to establish federal priority. Both parties reached a rare consensus, potentially breaking a nearly decade-long legislative deadlock.
Notably, the exemption clauses in this regulation are no longer limited to test vehicles but directly apply to mass-produced commercial vehicles. If the NHTSA does not issue a rejection ruling within 12 months of a company submitting an exemption application, the application automatically takes effect, significantly shortening the approval cycle. In terms of liability rules, the regulation clearly distinguishes between L3/L4 and L4 vehicles without safety operators, designating the operator as the liable party and no longer mandating the presence of a human driver in the vehicle. Additionally, the regulation formally lifts the federal ban on autonomous heavy trucks, further opening up commercial channels for mainline unmanned freight.
The U.S. regulatory approach is characterized by corporate self-certification, with regulatory agencies not conducting pre-market full-process verification. Companies are responsible for proving safety, retaining safety reports, and providing evidence after accidents, placing the burden of safety proof on automakers/operators. However, a drawback is that states retain local powers over road access, insurance, and operational permits, creating barriers to cross-state operations. Data security and algorithm transparency requirements are weaker than those in the European Union.
European Union: Stringent Regulation, Safety First, Tied to AI Compliance
In June of this year, the Contracting Parties Conference of the United Nations World Forum for Harmonization of Vehicle Regulations (WP.29) approved DCAS UNR 171 series 02 (corresponding to urban NGP functionality regulations) and UNR ADS (corresponding to L3-L5 autonomous driving regulations).
Among them, DCAS UNR 171 series 02 will become mandatory in the EU six months later, meaning that by the end of 2026, autonomous driving technology will be legally allowed to enter global markets, including the EU. UNR ADS, currently a framework regulation, will accelerate the approval and implementation of Robotaxi (L4) services in various regions.
The EU classifies L3 and L4 autonomous driving systems as high-risk AI systems, subjecting them to strict regulation under the 'AI Act,' a unique legislative framework globally.
According to this act, autonomous vehicles must complete risk assessments, system testing, algorithm traceability verification, and human-machine safety verification before market launch, establishing a continuous monitoring system. After launch, safety incidents must be continuously collected, and significant risks must be reported to regulatory authorities. Algorithms cannot be black boxes and must have accident traceability capabilities.
This year, the EU's 'General Safety Regulation' (GSR) continues to upgrade, further raising safety access thresholds for commercial vehicles. Event data recorders (EDRs) and advanced driver monitoring systems (ADDWs) are now mandatory. For L3 autonomous driving, mandatory provisions include system failure warnings, takeover boundaries, and minimum risk strategies (MRS), requiring safe stopping in the event of system failures.
The 'Autonomous Driving Special Regulation' (ADS Regulation) distinguishes between passenger-carrying Robotaxis and unmanned freight for L4 autonomous driving. In 2026, it will lift the commercial quantity cap for L4 automated valet parking (AVP).
In terms of data and privacy, regulated by the 'Data Governance Act,' pedestrian images and personal biometric information collected by external perception systems must comply with the 'General Data Protection Regulation' (GDPR). At the cybersecurity level, autonomous vehicles are considered critical digital assets and must adhere to the NIS2 cybersecurity directive to prevent remote intrusions and system hijacking.
EU regulations impose extremely high access thresholds, with strict pre-market regulatory reviews and mandatory obligations for algorithm explainability, data retention, cybersecurity, and accident record preservation. The advantage is the unification of the EU's 27-nation market, allowing products with EU type approval to be sold and operated in all member states. However, the cost of compliance is high, product iteration cycles are longer, and industry implementation is slower.
A review of the global legislative landscape reveals that regulatory gaps are narrowing, and technological gaps are shrinking. Companies that once relied on single-algorithm or single-scenario advantages to break through will find it difficult to establish long-term barriers under unified compliance standards and mature market conditions. When everyone has a 'ticket to enter,' the true differentiator will be the ability to build a complete system adapted to regulations, scenarios, and commercialization.
In the past, capital markets and industry discourse heavily believed in the 'myth of single-vehicle intelligence.' Companies competed on the number of LiDAR sensors, computational chip parameters, the number of cities covered by urban NOA, and algorithm iteration speed, believing that technological superiority alone would win the market.
However, the commercial reality following regulatory implementation has shattered this perception: technologies that perform well in test environments may not succeed in real markets; products capable of intelligent driving may not be compliant or profitable.
Single-vehicle intelligence addresses the question of 'whether it can drive,' while systematic capabilities address the full spectrum of issues: compliance, implementation, profitability, and continuous iteration.
The so-called systematic capabilities for autonomous driving have long transcended the realm of single technologies, encompassing a complete ecosystem covering regulatory adaptation, technological self-sufficiency, data iteration, operational services, safety risk control, and industrial collaboration.

This includes the following six core capabilities:
Rapid Regulatory Adaptation Capability: Global regulations are continuously evolving, with significant differences in policy details across countries and regions. Leading companies are no longer passive rule-followers but actively participate in standard-setting and early compliance adaptation. They can align with the United Nations' UN R171 global unified standard while swiftly implementing localized compliance requirements in China, the United States, and the EU. Companies with strong systematic capabilities can establish a global compliance platform to uniformly conduct risk assessments, documentation systems, and safety evidence, enabling localized adaptation for different markets and significantly reducing international compliance costs.
Full-Scenario Technological Self-Sufficiency Capability: Autonomous driving technology will no longer be limited to single scenarios like urban roads or highway assistance but will develop universal capabilities covering Robobus, Robotaxi, mainline freight, last-mile delivery, and specialized driving in mining areas and ports, rapidly adapting to the safety standards and operational needs of various scenarios. Relying on a systematic technological foundation, the same core algorithm and perception architecture can be scenario-specifically tailored without requiring zero-based development for different scenarios, effectively controlling R&D costs and investments.
Lawful Data Iteration Capability: The core of autonomous driving is data iteration, but under new regulations, data can no longer be 'freely collected and infinitely used.' National regulations impose strict constraints on the collection, storage, cross-border transfer, and labeling training of vehicle-end perception data. China's 'Provisions on the Administration of Automobile Data Security' require desensitization of sensitive personal information such as facial and pedestrian images, with important data prohibited from arbitrary cross-border transfer. The EU's 'General Data Protection Regulation' and 'AI Act' require traceability of training data and retention of accident-related data for multiple years. U.S. states have varying requirements for video data storage. Companies with systematic capabilities can complete data collection, desensitization, labeling, training, and closed-loop iteration within a compliance framework, building a lawful data flywheel that meets data security regulations in various countries while continuously optimizing algorithms and forming a positive cycle of technological iteration.
Scalable Compliant Operation Capability: National regulations impose mandatory obligations on commercial operation entities: remote monitoring centers, safety officer allocation, emergency response plans, vehicle maintenance, user notification, accident traceability, insurance claims, and passenger protection. For example, California's new autonomous driving regulations require operators to record every takeover and system anomaly, regularly submit safety reports to regulators, and purchase specialized autonomous driving liability insurance. This operational system, encompassing personnel, platforms, processes, insurance, and work order systems, is the core support for large-scale commercialization and a barrier that small and medium-sized players struggle to overcome.
Comprehensive Safety Risk Control Capability: A multi-dimensional, traceable, and evidence-based safety risk control system must be established, covering vehicle hardware safety, algorithm decision-making safety, network data security, and scenario safety for extreme weather, sudden road conditions, and human-machine interaction, perfectly aligning with stringent safety regulatory requirements in various countries. The EU's 'AI Act' mandates the establishment of safety risk classification, continuous monitoring, and incident reporting. China's 'Pilot Management Measures for High-Level Autonomous Driving Vehicle Product Access' requires products to have failure monitoring and minimum risk strategies. The U.S. 'Federal Motor Vehicle Safety Standards' impose mandatory testing for collision safety and system failures. Safety risk control is not a one-time test but product lifecycle management.
Industrial Chain Collaboration and Implementation Capability: Leveraging upstream and downstream resources, including chips, sensors, vehicle manufacturing, high-definition maps, operation and maintenance services, and regulatory platforms, to achieve optimal matching of technology, cost, and production capacity, addressing the industry pain point of 'technological feasibility but high costs and difficulty in mass production' for high-level autonomous driving.
From industry practice, different companies are developing differentiated systematic construction paths. L4 autonomous driving companies such as Mushroom Autonomous Driving, WeRide, and Pony.ai are building multi-scenario technological foundations, compliant data loops, remote operation platforms, and collaborating with vehicle manufacturing industrial chains while participating in the formulation of domestic and international autonomous driving regulations and standards to support the commercialization and international expansion of Robobus, Robotaxi, and unmanned freight services.
Take Mushroom Autonomous Driving as an example: its 'factory-installed mass production + fusion of vision and solid-state LiDAR' technological route has been continuously validated. Relying on engineering capabilities honed from deployments in over 20 domestic cities, it achieves rapid market adaptation and cost control for autonomous driving solutions while accumulating large amounts of vehicle-specific data for buses, effectively shortening algorithm training and vehicle adaptation cycles. Its technical team deeply understands the traffic regulations, road rights, and local driving habits of target markets, integrating compliance requirements into system decision-making logic, safety boundaries, and operational processes. It also collaborates with leading local public transportation operators to jointly expand markets.
Under the industrial consortium model, autonomous driving companies act as connectors, coordinating vehicle manufacturing, autonomous driving technology, local operations, and policy resources to package complete solutions for external delivery. This ecosystem integration model is highly replicable and can support rapid international expansion of autonomous driving.
Automakers and intelligent driving solution providers, such as Huawei ADS and XPENG, focus on the mass-produced passenger vehicle sector, emphasizing industrial collaboration across vehicle manufacturing, chips, software, and data governance. While meeting domestic access and data compliance requirements, they promote the large-scale integration of high-level intelligent driving in vehicles.
Overseas companies such as Waymo and Tesla are also building their own systems. The former focuses on refining its full-chain safety risk control and commercial operation systems, while the latter relies on massive vehicle-end data to form an iterative flywheel. However, both need to continuously adapt to stringent data and AI regulatory requirements across the EU, Asia-Pacific, and other regions.
It is evident that the Autonomous driving industry (Note: retained as-is for context, should ideally be translated as 'autonomous driving industry' in a full translation) can no longer rely solely on algorithmic breakthroughs. Regardless of the technical route, the ability to address shortcomings in compliance, operations, safety, and ecosystems directly determines a company's growth ceiling.
The autonomous driving industry has now entered a stage of homogenization, with mainstream companies showing minimal differences in vehicle intelligence. Computing power, sensors, and algorithms are largely on par. While technology can be quickly replicated and parameters rapidly caught up, systemic capabilities cannot be duplicated in the short term.
Algorithms can be swiftly optimized by technical teams, and hardware can be rapidly sourced through supply chains. However, building an industrial system that complies with global regulations, has undergone tens of thousands of scenario validations, possesses a mature operational closed loop , and a complete risk control framework requires years of effort, massive real-world experience, and sustained resource investment—making it extremely scarce and irreplaceable.
The trend toward regulatory normalization will only lead to stricter oversight, with data compliance, safety compliance, and operational compliance becoming the survival baseline for companies. Future competitive barriers will no longer be technological lag but systemic deficiencies. Hefty fines under the EU's Artificial Intelligence Act (up to 6% of global revenue) and domestic penalties for automotive data violations mean that compliance failures could easily topple a company.
Commercialization competes on efficiency, while systemic capabilities determine profitability ceilings. The ultimate goal of autonomous driving is commercial profitability. Companies with strong systemic capabilities can leverage scaled operations to reduce per-vehicle costs, enhance revenue potential through cross-scenario reuse, and mitigate operational risks via compliance and risk control—achieving a virtuous cycle of 'technological iteration, compliant implementation, and commercial profitability.'
From the moment global regulations accelerate their rollout, autonomous driving has entered a deep-level game of comprehensive, systemic, and ecological competition. Previously, vehicle intelligence was the entry ticket, determining whether a company could join the race. In the future, systemic capabilities will be the decisive factor, determining whether a company can stay in the race and win the overall game.
Technology can be chased, data can be accumulated, and teams can be built. However, a complete system integrating compliance, technology, operations, safety, and industry expertise is the ultimate barrier forged by time, battle-tested experience, industrial resources, and strategic vision. Today, technology alone secures only temporary wins—only companies with complete systemic capabilities can withstand the industry's cyclical waves of elimination.