Beyond 49 Seconds: What Motorsport Rescue Chains Tell Us About AV Chain Collisions

It happened in Shanghai. On 5 September 2026, during a China GT race, a car was caught in a multi-car collision, caught fire, and the driver was trapped in the cockpit. The first person to reach him was not a firefighter. It was not a medical team. It was another racing driver. He stopped, ran across, took a fire extinguisher, tore away damaged bodywork, and pulled the trapped driver out. ...

September 9, 2026 · 14 min · 2952 words · 张玉新 Yuxin Zhang · 0

Cybersecurity–Safety Integration: L2 ADAS · L3/4 ADS · Mobile Physical AI

Abstract: L2 driver assistance, L3/L4 autonomous driving, and humanoid and passenger-carrying quadruped robots share one cybersecurity methodology yet differ in who is responsible, how they are regulated, and how deeply cybersecurity couples with safety. This post systematically maps the requirements, differences, standards/regulations, and best practices across the three families, with a focus on how deeply cybersecurity integrates with functional safety (FuSa), SOTIF, and whole-machine safety. Key takeaways All three families have entered the “cybersecurity is an entry gate” stage, but with a clear gradient: L2 is enforced, L3/L4 has the highest bar, and mobile physical AI is weakest yet fastest-moving. The essence: L2 treats the network as an information asset, L3/L4 as a safety system, and physical AI as a physical safety device. Integration: L2 is coordinated, L3/L4 is integrated/converging, and mobile physical AI is mechanistically unified but method-empty. The adversarial AI surface (data poisoning, evasion, model theft) is the common new gap in 2026, under-covered by 21434/62443. Best practices are highly shared (TARA, defense in depth, SBOM, secure OTA, monitoring, pentest, PIA) and transferable across bodies. 1. Framework: three threads + two axes Three threads decide requirements: whether a human bails out, what physical environment the system operates in, and what the regulator can grab. L2 has a human fallback, L3/L4 has none, and mobile physical AI controls the physical body and balance — deciding whether cybersecurity is an “information asset problem,” a “safety system problem,” or a “physical safety device problem.” ...

September 3, 2026 · 9 min · 1732 words · 张玉新 Yuxin Zhang · 0

Book Recommendation | Building Foundations for the Future with An Introduction to System Safety Engineering

Nancy G. Leveson’s An Introduction to System Safety Engineering does two things unusually well. It gives a systematic account of the foundations of classical safety engineering, and it uses systems thinking to address the new problems created by software, automation, complex systems, and organizations. The Chinese edition, 《系统安全工程导论》, was translated jointly by two teams led by Professor Hong Wang and me. ...

August 23, 2026 · 5 min · 896 words · 张玉新 Yuxin Zhang · 0

CDV Crossing Domains: A Robot SOTIF Perspective

Abstract: Yoav Hollander is a world-class expert in chip verification. The company he founded, Foretellix, brought coverage-driven verification (CDV) into autonomous driving. Recently he wrote a post pushing the methodology into a much larger arena: AI alignment. This post reads that cross-domain migration from my own research field — the SOTIF four-quadrant model, the tree-like structure of Robot SOTIF, and the standards-driven Chinese context. The core question stays the same throughout: how do you know what you don’t know? ...

June 11, 2026 · 9 min · 1901 words · 张玉新 Yuxin Zhang · 0

ASIL E Is Not the Point. The No-Human-Fallback Safety Case Is.

Abstract: ASIL E is not a published standard. Its real value is not the name of a higher integrity level, but the question it forces Level 4 and Level 5 autonomous-driving safety arguments to answer: when there is no human fallback, can the safety case still credit a human controller? For me, the useful translation is not “ASIL E compliance.” It is a no-human-fallback review lens, four evidence fields in ADSafetyPilot, and a feedback loop connecting ROAM, DRIVEResearch, and a field-monitoring-backed safety case. ...

June 3, 2026 · 12 min · 2475 words · 张玉新 Yuxin Zhang · 0

Robots Need SOTIF Too

Abstract: On June 2, 2026, the Chinese national standard project 机器人预期功能安全实施指南 entered public notice, with the comment period scheduled to close on July 2, 2026. I have put this direction into OpenTopic as the second open research theme: Robot SOTIF. The goal is not to copy autonomous-driving SOTIF directly into robotics, but to build an evidence chain from standards, ODD, scenarios, triggering conditions, physical interaction, LLM/VLA decision safety, and finally to a defensible safety case. ...

June 3, 2026 · 7 min · 1393 words · 张玉新 Yuxin Zhang · 0

When the Robotaxi Fails, Who Catches It?

Abstract: When the AI in a driverless car can’t handle the situation, does the industry have a coherent emergency-management playbook? It doesn’t — and worse, no reference standard exists. Starting from the March 31, 2026 Wuhan Apollo Go incident, this post walks through three recent body blows to the Robotaxi industry, scans every gap in the ISO / SAE / IEC / China standards landscape on remote operations, traces the fundamental regulatory pivot after Wuhan, and introduces ROAM (Remote Operations & Anomaly Management) — an open-source reference architecture with four modules, ten future operating models, and a 52-standard scan that confirms the void. ...

May 4, 2026 · 8 min · 1700 words · 张玉新 Yuxin Zhang · 0

Harness Engineering: User Experience vs Safety Compliance — A Direction Mainstream Roadmaps Have Collectively Skipped

Abstract: In Q1 2026, “Harness Engineering” surfaced almost simultaneously at OpenAI, Anthropic, and the Chinese startup Nextie, and the “12 Primitives” converged in the open-source community as a shared taxonomy. This essay argues that essentially all mainstream investment in Harness has concentrated in a single dimension — user experience, performance, efficiency — while the dimension that actually determines market access in Safety-Critical domains (autonomous driving, medical AI, financial risk control) has been collectively skipped: safety compliance. By constructing a two-way mapping between the 12 Harness Primitives and SOTIF (ISO 21448), this essay identifies 12 concrete research directions, offered as a starting point for standardization bodies, corporate R&D, third-party institutions, and academic labs to jointly fill in this commons. A ~3000-word Chinese short form is available on the author’s WeChat channel. ...

April 19, 2026 · 24 min · 4944 words · 张玉新 Yuxin Zhang · 0

Applying Harness Engineering to Intelligent Driving

Abstract: In early 2026, Harness Engineering rose quickly in the AI engineering community, becoming a third-generation methodology after Prompt Engineering and Context Engineering. Starting from the core concept of Harness Engineering, this article systematically analyzes its deep correspondence with today’s end-to-end intelligent-driving systems across the full lifecycle. It argues that the two fields are structurally isomorphic in their control-theoretic framework, improvement loops, and philosophy of failure response. It also discusses the reference value of Harness Engineering for intelligent-driving user experience and safety engineering, especially SOTIF / ISO 21448. The central finding is that Harness Engineering and automotive safety engineering are not superficially similar metaphors. They are two independently evolved solutions to the same class of root problems, sharing the same underlying operating system. ...

April 9, 2026 · 26 min · 5373 words · Yuxin Zhang · 0

A Bosch Engineer Open-Sourced a Project That Could Change How Every Automotive Engineer Works

Abstract: Bosch Lead Engineer Thejeswarareddy R open-sourced an agent system that systematically injects automotive engineering standards into Claude Code, covering 75+ skill categories. I forked it and added autonomous driving safety standards (ISO 21448/34502/4804, etc.), upcoming mandatory Chinese national standards, and in-depth SOTIF engineering practices. This article breaks down the project’s architectural highlights and my additions. Figure 1 If you are a junior functional safety engineer in the automotive industry, you have almost certainly lived through this scenario: ...

April 6, 2026 · 7 min · 1451 words · 张玉新 Yuxin Zhang · 0