The UN GTR for ADS: A New Global Regulatory Framework

On June 24, 2026, the international regulatory landscape for autonomous driving reached a historic milestone when the World Forum for Harmonization of Vehicle Regulations (WP.29) formally adopted the United Nations Global Technical Regulation (UN GTR) on Automated Driving Systems (ADS) during its 199th session in Geneva (Link). Approved by a vote of contracting parties, the regulation establishes the world’s first globally harmonized technical framework for Automated Driving Systems (ADS), including vehicles capable of operating without a fallback user.

This article examines the evolution of the new framework through the official proposal documents for the UN GTR (ECE/TRANS/WP.29/2026/139) (Link) and the parallel UN Regulation (ECE/TRANS/WP.29/2026/137) (Link). It explores the decade-long journey to adoption, the regulation’s core technical requirements, and the broader implications for manufacturers, suppliers, regulators, and certification bodies as autonomous driving enters a new phase of global governance.

A Decade in the Making

The adoption of the ADS regulation represents the culmination of more than a decade of international collaboration. Rather than emerging from a single regulatory initiative, the framework reflects the convergence of technical, regulatory, and validation expertise into a single internationally harmonized standard.

ADS Regulation_Towards the Making of a Global Standard

The foundation for today’s regulation was established in 2015, when WP.29 launched its Automated Driving (AD) programme (Link) under the Informal Working Group on Intelligent Transport Systems (ITS). As autonomous driving technologies matured, the initiative evolved from defining core concepts to developing internationally harmonized safety principles.

A major milestone came in 2019, when the Framework Document on Automated/Autonomous Vehicles (ECE/TRANS/WP.29/2019/34/Rev.2) (Link) established the safety foundations for SAE Level 3 and above, dividing development into two complementary workstreams: Functional Requirements for Automated Vehicles (FRAV) and Validation Methods for Automated Driving (VMAD).

Between 2021 and 2026, these efforts converged through the development of the New Assessment/Test Method (NATM) (Link) and the formal establishment of the Informal Working Group (IWG) on Automated Driving Systems (ADS). This marked an important step toward integrating functional requirements, validation methodologies, and regulatory provisions into a comprehensive regulatory framework.

Following WP.29 GRVA’s adoption of the parallel UN Regulation in January 2026 (Link) and the resolution of remaining technical issues through international consultations, WP.29 formally adopted both the UN Global Technical Regulation on Automated Driving Systems (Link) and UN Regulation No. 185 (Link) during its 199th session, marking the world’s first globally harmonized technical framework for Automated Driving Systems.

Technical Foundations of the Framework

The UN GTR establishes a comprehensive technical framework to ensure that Automated Driving Systems (ADS) operate at a level of safety at least equivalent to that of a competent human driver. Rather than prescribing specific technologies, it defines the functional responsibilities, validation methods, and lifecycle requirements that manufacturers must demonstrate before deploying fully autonomous vehicles.

ADS Regulation_Technical Foundations of the ADS Framework

Defining ADS Responsibilities

A fundamental element of the regulation is the clear allocation of responsibility between an Automated Driving System (ADS) and the Dynamic Driving Task (DDT). The UN GTR defines an ADS as “the collective hardware and software capable of continuously performing the entire Dynamic Driving Task (DDT),” establishing it as the entity responsible for executing the vehicle’s driving functions. Accordingly, the ADS assumes continuous responsibility for perception, decision-making, planning, and vehicle control, whereas higher-level functions such as destination selection and route planning remain outside the scope of the DDT.

Establishing Safety Benchmarks

Building upon this allocation of responsibility, the regulation adopts a performance-based safety objective rather than prescribing how autonomous driving systems should be engineered. Within its defined Operational Design Domain (ODD), an ADS must achieve a level of safety at least equivalent to that of a competent human driver by preventing reasonably foreseeable and preventable fatalities or injuries.

Multi-Pillar Validation Framework

Recognizing that no single testing method can sufficiently demonstrate this level of safety, the regulation requires a multi-pillar validation framework known as the New Assessment/Test Method (NATM). The framework combines complementary sources of evidence — including virtual simulation, proving ground testing, public road testing, and technical assessments — to evaluate system performance across a broad range of operating scenarios and demonstrate that safety requirements have been consistently satisfied.

Managing Driver Transitions and Safe Fallback

Beyond validating system performance, the regulation also defines how responsibility should be managed during vehicle operation. It distinguishes between ADSF-1, which requires a fallback user to resume control when requested, and ADSF-2, which is designed to operate without requiring a fallback user. For ADSF-1, the system must verify the fallback user’s readiness before transferring control to prevent mode confusion. If no fallback user is available or if the user fails to respond, the vehicle must automatically transition to a Mitigated Risk Condition (MRC), bringing itself to a safe and controlled state.

Strengthening Lifecycle Accountability

Extending accountability beyond vehicle operation, the regulation introduces the Data Storage System for Automated Driving (DSSAD) to record operational data surrounding safety-related events, supporting post-incident analysis, regulatory oversight, and traceability throughout the vehicle lifecycle. It further recognizes cybersecurity as a lifecycle responsibility while remaining consistent with the cybersecurity principles established under UN Regulation No. 155 (CSMS) (Link) and UN Regulation No. 156 (SUMS) (Link).

ADS Regulation_From One Time Certification to Continuous Lifecycle Monitoring

Strategic Implications for the Mobility Industry

Beyond establishing technical requirements, the UN GTR provides strategic direction for the future development, validation, and governance of autonomous driving systems by advancing regulatory harmonization, shaping AI governance, and enabling continuous safety assurance throughout the vehicle lifecycle.

Advancing Global Regulatory Harmonization

The UN GTR reduces regulatory fragmentation by establishing a common set of technical requirements that contracting parties can incorporate into their domestic frameworks. It also marks one of the first instances in UNECE history that a Global Technical Regulation and a parallel UN Regulation have been developed simultaneously around a shared safety objective. This establishes a common regulatory foundation that supports more consistent implementation of autonomous driving technologies across international markets.

One Technical Standard, Two Regulatory Pathways

To support global adoption, the framework delivers a common set of technical requirements through two complementary regulatory pathways. Under the 1998 Agreement, the UN GTR provides a performance-based technical framework that contracting parties incorporate into their domestic legislation, allowing implementation through either self-certification or national type approval systems. In parallel, UN Regulation No. 185, adopted under the 1958 Agreement, enables international type approval with mutual recognition among contracting parties while applying the same technical requirements.

ADS Regulation: Two Regulatory Pathways

Enabling Continuous Safety Assurance

The framework ultimately extends the concept of safety beyond vehicle performance alone. By integrating harmonized technical requirements, standardized validation methods, lifecycle monitoring, it establishes a transparent basis for demonstrating the safety and reliability of autonomous driving systems. Consequently, future conformity assessment will increasingly depend on capabilities such as process auditing, simulation credibility evaluation, Safety Case assessment, and operational validation, strengthening both regulatory confidence and public trust in autonomous mobility.

Conclusion

The adoption of the UN Global Technical Regulation (GTR) for Automated Driving Systems (ADS) marks more than the introduction of another vehicle regulation. It establishes the world’s first globally harmonized framework for designing, validating, and monitoring fully autonomous vehicles throughout their operational lifecycle, providing a common foundation for the safe deployment of autonomous mobility.

As contracting parties begin incorporating the framework into national legislation, manufacturers, suppliers, and certification bodies must adapt their engineering processes, validation strategies, and lifecycle governance to meet evolving regulatory expectations. Organizations that embrace this lifecycle approach will be best positioned to accelerate the safe and scalable deployment of autonomous mobility.

 


Additional Resources

An Integrated Approach to Automated Driving System (ADS) Validation

As we enter an era increasingly populated by highly autonomous vehicles, there is a vast range of dynamic driving scenarios that Automated Driving Systems (ADS) may encounter. From hazardous environmental conditions to internal system failures and external cybersecurity risks, ensuring ADS safety across diverse operating situations is essential for enabling safe autonomous driving experiences 

The recent release of “ISO 34505: 2025”  underscores this need by providing a structured framework for generating, evaluating and managing test scenarios that reflect real world driving conditions. By standardizing how test scenarios should be defined and tested, the initiative aims to enable consistent, repeatable validation practices across the industry and thereby support development of robust ADS provision.  

As autonomous systems grow more complex, the need for robust, scalable validation practices become increasingly critical. In response, an integrated approach — combining regulatory audits, system-level testing and adversarial simulations — provides OEMs and Tier 1 suppliers a structured path for both vehicle safety and regulatory compliance. Focusing on cybersecurity, this blog outlines the key components and methodologies of ADS Validation, and demonstrates how an integrated approach can be effectively executed.  

Automated Driving System (ADS) Validation: Approach & Methodology  

According to “SAE J3016: 2021”, Autonomous Driving System (ADS) refer to the collective technology stack responsible for performing dynamic driving tasks (DDT) at SAE Level 3 and above. With the system taking full responsibility for autonomous decision-making and vehicle control, validating ADS safety calls for identifying diverse validation targets and a multidisciplinary process for executing them.  

I. Approach  

The UNECE WP.29 Working Group emphasizes ADS Validation should be approached from multiple angles, including audit and assessment, simulation and virtual testing, real-world testing and more. Drawing on key industry whitepapers (e.g. The Autonomous Working Group, Association for Standardization of Automation and Measuring Systems, Mercedes-Benz), validation efforts can be broadly categorized into three core pillars: functional performance, internal system reliability and external cybersecurity resilience. 

Automated Driving System (ADS) Validation Approach

The first pillar, Functional Performance, focuses on ensuring the embedded vehicle system behaves as expected across a full range of driving conditions — particularly under abnormal scenarios such as complex environments or sensor limitations. In alignment with the “ISO 34505: 2025” standard, which outlines scenario-based ADS testing, this pillar evaluates system capabilities in perception, decision making and control execution under realistic conditions.  

The second pillar, Internal System Reliability, addresses resilience against system-level faults. This includes the inspection of fault detection mechanisms, hardware failure mitigation strategies, and adherence with Automotive Safety Integrity Level (ASIL) grades. Relevant to the “ISO 26262: 2018” standard defining the framework around electrical/electronic (E/E) system failures, this pillar assesses the system’s ability to maintain safety in the presence of internal malfunctions.  

The third factor, External Cybersecurity Resilience, evaluates the system’s tolerance against external cybersecurity threats. Verification over secure communication and data integrity under potential attacks such as vehicle hacking, spoofing and denial-of-service (DoS)) is a key objective of this pillar. Associated with the “ISO/SAE 21434: 2021” standard illustrating cybersecurity risk management for vehicle E/E systems across the lifecycle, this phase assesses the system’s ability to proactively mitigate attack vectors targeting sensors, ECUs and OTA updates.   

II. Techniques   

While various techniques exist to evaluate functional performance, system reliability and external attack resilience, this blog focuses on three core cybersecurity validation methodsCompliance Auditing, Software-in-the-Loop (SiL) Module Testing, Hardware-in-the-Loop (HiL) Penetration Testingto better illustrate the differences across diverse validation approaches. 

Automated Driving System Validation Techniques

The first technique, Compliance Auditing, focuses on verifying whether development practices and system architectures align with established safety and cybersecurity regulations (e.g. ISO/SAE 21434, UN R155). This method is widely used by OEMs and Tier 1 suppliers to conduct gap analyses during early-development stages or in preparation for CSMS Certification audits, to check whether internal processes conform to regulatory requirements.  

AutoCrypt CSTP Compliance serves as a representative tool to accommodate these needs by validating vehicle vulnerabilities on a unified platform. It supports multiple testing domains including Security Validation, Functional Testing, Penetration Testing, Fuzz Testing and Vulnerability Testing and consolidates results into a comprehensive report suitable for regulatory submission. By combining testing execution and documentation, it reduces redundant tasks and streamlines the compliance process.  

Architecture of AutoCrypt CSTP Platform

Another key validation technique is Software-in-the-Loop (SiL) Module Testing, which assesses robustness of embedded security components in virtualized test environments before hardware integration. Commonly applied to TEE (Trusted Execution Environment) based key management testing and V2X certificate handling simulation, this technique enables rapid iteration and early validation of security logic in controlled conditions, before advancing to high-cost hardware testing.  

In accordance with these needs, the AutoCrypt CSTP Functional Tester  validates hardware-dependent security functions using virtual ECU models in a Software-in-the-Loop (SiL) environment. By integrating communication interfaces, debugging tools, ECU source code and test code, this solution facilitates early detection of design flaws and integration issues well before mass production.  

Testing Environment of AutoCrypt CSTP Functional Tester

Another core testing approach is Hardware-in-the-Loop (HiL) Penetration Testing, which evaluates cybersecurity resilience of physical ECUs by simulating real-world attack vectors in controlled HiL testing environments. Often applied for in-vehicle network fuzz testing and Telematics Control Units (TCUs) penetration testing, this technique identifies system vulnerabilities under actual runtime configurations, moving beyond theoretical scenarios.  

Serving this purpose, the AutoCrypt CSTP Fuzzer solution actively injects malformed, unexpected inputs into in-vehicle networks to test ECU-level resistance to cyber intrusions. Covering a broad spectrum of communication layers including the Network Layer (e.g. CAN, CAN-FD, Automotive Ethernet), Application Layer (e.g. UDSonCAN, UDSonCAN-FD) and Transport/Data Layer (e.g. VehicleCAN, VehicleCAN-FD), the tool enables precise testing of vehicle systems under a wide range of adversarial conditions. 

Operational Flow of AutoCrypt CSTP Fuzzer

 

Effective ADS Validation through an Integrated Approach  

With a wide range of checkpoints to address and multiple techniques available, establishing a cohesive and effective strategy for ADS validation is essential. To meet this need, a structured progression from Compliance Auditing to Software-in-the loop Testing and finally to Penetration Testing offers a practical pathway for comprehensive and efficient ADS validation.  

  • At the first stage, Compliance Auditing defines the baseline and sets the strategic direction through regulatory compliance and process control.  
  • Next, software design implementation and testing activities are supported through Software-in-the-Loop (SiL) Module Testing, which enables validation before hardware integration.  
  • Lastly, Hardware-in-the-Loop (HiL) Penetration Testing technique can be utilized to observe real-world cybersecurity readiness under adversarial conditions.  

This layered approach demonstrates how each phase builds upon and reinforces the next, enabling a robust and scalable validation framework.  

With AUTOCRYPT being an authorized Vehicle Type Approval (VTA) Technical Service (TS) Provider , the firm is uniquely positioned to integrate diverse testing techniques and facilitate comprehensive ADS validation through the AutoCrypt CSTP Platform. From the AutoCrypt CSTP Compliance, which ensures design-level safety, to the AutoCrypt CTSP Functional Tester, which verifies correct functional behavior and the AutoCrypt CSTP Fuzzer able to test attack resilience, the platform enables a unified security analysis by consolidating all validation layers into a single, integrated platform 

Integrated ADS Validation using AutoCrypt CSTP Platform

Supporting a streamlined process for Vehicle Type Approval from ADS validation to export of results into compliance documents (e.g. TARA Report, Cybersecurity Test Report), the whole approval process can be effectively managed.  

To learn more about the Autocrypt CSTP platform, check this page. For more information about our comprehensive suite of our automotive products & offerings, check this page 

AUTOCRYPT
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.