Autonomous driving has long been answering one question: can cars drive themselves? However, given that autonomous driving is now entering a more explicit legal and standard framework, the question the industry needs to answer has evolved into: if cars can indeed complete driving tasks on their own, what exactly will be used to prove they are safe? On August 25, 2026, the draft revision of the Road Traffic Safety Law was submitted for the first time to the deliberation of the Standing Committee of the National People's Congress. A new chapter on special provisions for autonomous vehicles was added, clarifying the conditions for autonomous vehicles to drive on roads, the principles for handling violations, and the insurance system.
Just a month prior, the GB 44721-2026 "Safety Requirements for Autonomous Driving Systems of Intelligent Connected Vehicles" was officially released and is scheduled to take effect on July 1, 2027. One is establishing a legal liability framework, while the other is beginning to set mandatory safety requirements. This also means that proving the safety of autonomous driving has shifted from a theoretical proposition to an absolute necessity.
01. Why Is Simply Stating the Number of Kilometers Driven Not Enough?
In autonomous driving testing, the cumulative number of kilometers driven has always been a crucial metric, as a massive amount of real-world road data can indeed reflect the actual performance of the system in various environments. However, mileage itself cannot be directly equated with safety. A vehicle might drive millions of kilometers continuously without encountering a certain low-probability dangerous scenario, but this does not prove that the system has demonstrated its ability to handle such a scenario correctly.
For instance, if a car operates continuously on normal urban roads, it can easily accumulate a large amount of data on driving straight, following other vehicles, changing lanes, and passing through intersections. However, what truly affects the safety capability of the system is often those situations with low frequency, complex combinations, and severe consequences.
Therefore, the safety validation of autonomous driving cannot merely answer how many kilometers have been driven; it also needs to answer what scenarios the testing has covered. This is why current autonomous driving safety systems increasingly emphasize scenarios, Operational Design Domain (ODD), and risks, rather than simply comparing test mileage.
02. What Exactly Does Autonomous Driving Need to Prove?
What automakers truly need to prove is not that the vehicle will never make a mistake, but whether the system can complete the corresponding dynamic driving tasks under specified ODD, and whether it can take reasonable risk control measures when anomalies occur or when it can no longer operate safely. GB 44721-2026 requires vehicles equipped with Level 3 (L3) and Level 4 (L4) autonomous driving systems to establish a full life-cycle safety assurance mechanism covering design and development, production and manufacturing, as well as post-deployment.
It also requires the system's safety level to be at least equivalent to that of a competent and attentive human driver performing the dynamic driving task, and it must not pose unreasonable safety risks to users and other road users. This involves several different levels. One is the capability boundary. The system needs to clarify on which roads, in what environments, and under which traffic conditions it can operate, and which situations exceed its capabilities. Enterprises need to make these boundaries and limitations clear. The standard also explicitly requires enterprises to inform users about the autonomous driving level, capability scope, limitations, control strategies, and information regarding human-machine handover. Then there is the driving task itself.
An autonomous driving system cannot merely prove that it can detect vehicles, pedestrians, or roads; it also needs to prove that it can complete the corresponding driving tasks based on this information. Moving forward, what happens after a failure? If the system can no longer complete the dynamic driving task, it cannot simply hand the problem over to the driver or directly exit control. GB 44721-2026 explicitly proposes the triggering and execution requirements for the minimum risk strategy.
For L3 systems, it is also required to have a driver takeover capability monitoring function. Therefore, safety proof actually consists of two parts: proving that the system can drive safely under normal conditions, and also proving that when the system encounters its own capability boundaries or abnormal situations, it can keep the risks under control.
03. What Exactly Do Simulation, Proving Ground, and Road Testing Prove Respectively?
If simple mileage cannot prove safety, what should be relied on for validation? Actually, to prove the safety of intelligent driving, it is necessary to combine different testing methods. Simulation solves the problem of scenarios that are difficult to reproduce in large quantities and stably on real roads. The GB/T 47025-2026, which came into effect in January 2026, has established methods and requirements for simulation testing of autonomous driving functions. It is not simply using computers to replace real roads, but rather repeatedly constructing a large number of specific conditions in a virtual environment, allowing the system to repeatedly validate against the same type of risk. This is especially important for low-frequency, high-risk, or complex combined scenarios.
Proving ground testing solves another type of problem. In a closed testing ground, road structures, traffic participants, and testing conditions are more controllable. Specific scenarios can be repeatedly constructed, and vehicle behavior can be measured more precisely. It sits between pure simulation and open-road testing, capable of validating many system capabilities while reducing the uncertainty of open-road testing. Of course, it ultimately has to return to real roads. Traffic participants on real roads do not act according to test scripts, and the road environment is constantly changing. Vehicles face real drivers, pedestrians, non-motorized vehicles, road construction, weather changes, and various traffic interactions that are difficult to fully pre-define.
Therefore, road testing undertakes the crucial validation of the system's real operational capabilities. These three methods do not replace each other; rather, they complement each other. GB 44721-2026 has explicitly required enterprises to conduct corresponding simulation, proving ground, and road tests during the R&D and validation of autonomous driving systems, and to further establish an inspection and testing system comprising enterprise assurance capability inspection + safety file inspection + confirmatory testing. Confirmatory testing can comprehensively adopt methods such as proving ground, road, and simulation. In other words, true safety proof is not a single exam, but a set of combined validations.
04. Who Proves It, and Is Proving It Once Enough?
Another easily overlooked issue is who exactly completes the safety proof for autonomous driving. From the perspective of the new standard system, enterprises must first bear the responsibility for safety assurance. GB 44721-2026 requires vehicle manufacturers to establish a safety assurance mechanism covering the entire life cycle of the product, and sets requirements for safety policies, risk management, safety assurance, and safety improvement. At the same time, the standard also introduces third-party confirmatory testing.
Third-party testing institutions can conduct confirmatory tests on autonomous driving systems in aspects such as proving ground, road, and simulation based on relevant national standards. It should be noted here that third-party testing does not mean that the third party proves the absolute safety of the vehicle on behalf of the enterprise. Its more accurate role is to provide independent testing evidence on whether the product meets the corresponding safety requirements through standardized inspection and testing.
The draft revision of the Road Traffic Safety Law solves another layer of issues. The draft revision submitted for deliberation on August 25 added a special chapter on autonomous vehicles, clarifying the concepts of autonomous vehicles and driver assistance functions, and making institutional arrangements for the conditions of autonomous vehicles driving on roads, violation handling, and the insurance system. The draft also proposes that if road traffic safety violations occur when the autonomous driving function is activated, the autonomous vehicle production enterprise or import enterprise shall accept the handling. It needs to be specially emphasized that it is currently still a draft revision, not a newly enacted law. However, looking at the law and standards together, the safety requirements for autonomous driving are becoming increasingly clear. The law solves institutional issues such as whether they can get on the road and who bears the corresponding responsibility when problems occur, while safety standards further solve technical issues such as what safety requirements the product needs to meet and how enterprises should conduct safety assurance and validation.
It needs to be explained that this kind of proof is not something that can be completed just once before the vehicle goes on the market. The autonomous driving system itself is still undergoing continuous iteration; software will be updated, operational scenarios will change, and system capabilities may also evolve. Therefore, safety assurance also needs to cover the post-deployment stage, rather than concentrating all safety work before the market launch. This is the true safety logic that needs to be established after autonomous driving enters large-scale application.
What autonomous driving truly needs to prove has never been how many kilometers it has driven, nor that the system has never had an accident. What it needs to prove is that within clear ODD and capability boundaries, the system can meet the corresponding safety requirements; in the face of identified risks, the validation is sufficiently adequate; and when the system can no longer operate safely, there are also corresponding risk control measures. As autonomous driving truly begins to enter the legal and mandatory standard system, what the industry competes on is no longer just the size of the test fleet and cumulative mileage, but whether it can establish a safety proof system that can be validated, inspected, and traced.
#AutonomousDriving #AutonomousDrivingSafetyValidation