Runtime governance above control, below intelligence.

The regulatory perimeter inside which AI-driven actuation in safety-critical systems now has to operate, and the per-decision evidence the certifier asks for.

  • 01AI-driven actuation in safety-critical systems (ADAS, automated driving, aerospace, industrial autonomy) operates inside ISO 26262 ASIL-graded development, verification, and production requirements. ISO 21448 SOTIF extends the obligation to functional insufficiencies and reasonably-foreseeable misuse, not just failure. ANSI/UL 4600 specifies the safety-case framework for autonomous products end-to-end.
  • 02UN Regulation No. 155 (vehicle cybersecurity, in force July 2024) and No. 156 (software update management, same date) are mandatory for type approval in EU, Japan, South Korea, and other WP.29 signatories. Adaptive ML updates in the drive stack must produce tamper-evident evidence of safe parameter changes per OTA cycle. UN R157 Phase 2 (1 Sept 2026) expands ALKS to higher speeds and lane changes with the same CSMS and SUMS submission.
  • 03EU General Safety Regulation Phase 2 (in force July 2024) and Phase 3 (7 July 2026) require driver-monitoring, automated emergency braking, intelligent speed assistance, and event-data recording on every newly registered EU vehicle. Each intervention surface adds an actuation-governance scope. The EU Machinery Regulation 2023/1230 (20 Jan 2027) brings AI-driven safety functions and autonomous robotics under unified conformity assessment.
  • 04NHTSA Standing General Order 2021-01 requires reporting of serious crashes involving SAE Level 2 ADAS or Level 3 to 5 ADS within strict windows. DO-326A and DO-356A airworthiness security are required by FAA and EASA for new aircraft type certification. EU AI Act Article 6 (deferred under Omnibus VII to 2 Dec 2027 standalone, 2 Aug 2028 embedded) classifies road, aviation, and certain industrial safety-critical AI as high-risk; Article 9 risk-management obligations apply.
  • 05The per-decision audit record satisfies all of the above on one chain: runtime bounded authority, pre-instability intervention, cryptographically chained intervention records, and per-OTA CSMS / SUMS evidence. Every intervention is signed to a tamper-evident chain the type-approval authority and the certifier can both read. Deploys in the cloud, on-premise, or embedded on-target through a C++17 variant for safety-critical environments.

The autonomy regulatory surface, by the calendar.

Every framework below is enforceable today or about to be. Velma evidence is the format both sides expect.

7
8

Open deadlines

7 approaching

Sorted by soonest deadline first.

25days to enforcement
Effective Jul 07, 2026
Last synced ...

General Safety Regulation: Phase 3 Expansion

Second wave of mandatory safety technologies (including expanded driver-monitoring, automated emergency braking refinements, and reverse-detection) required on all newly registered vehicles.

Each additional intervention surface adds a new actuation-governance scope.

81days to enforcement
Effective Sep 01, 2026
Last synced ...

UN R157: Automated Lane Keeping Systems Phase 2

Expanded scope of ALKS. Higher speeds, lane changes, full traffic conditions. OEMs continue to submit Cybersecurity Management System and Software Update Management System evidence per OTA cycle.

Pulls Level 3 autonomy into the same evidence regime as Level 2, with new audit surface per OTA update.

180days to enforcement
Effective Dec 09, 2026
Last synced ...

Product Liability Directive (Revised)

Member states must transpose the revised PLD into national law. Software, AI systems, and digital services are treated as products. Strict-liability for defects, with reversed burden of proof in many AV / industrial-autonomy scenarios.

Strict-liability exposure on autonomous-system manufacturers and integrators. Tamper-evident decision evidence is the affirmative defense.

222days to enforcement
Effective Jan 20, 2027
Last synced ...

Machinery Regulation 2023/1230

Replaces the 1989/2006 Machinery Directive. Covers AI-driven safety functions, autonomous machinery, and robotics, with new conformity-assessment and risk-management requirements.

Industrial autonomy and robotics fall under the same evidence regime as automotive functional safety. CE-marking requires governance proof.

538days to enforcement
Effective Dec 02, 2027
Last synced ...

EU AI Act: High-Risk Autonomy

AI used in road vehicles, aviation, and certain industrial safety-critical systems is classified high-risk under Article 6. Article 9 risk-management obligations apply.

Original 2 Aug 2026 deadline deferred by the Omnibus VII provisional agreement (May 2026). Standalone systems now 2 Dec 2027; embedded systems (which captures most automotive and aerospace AI) 2 Aug 2028. Aligns automotive and aerospace AI governance with insurance-grade evidence requirements.

547days to enforcement
Effective Dec 11, 2027
Last synced ...

Cyber Resilience Act: Phased Application

Products with digital elements (including in-vehicle software, autonomous systems, and embedded controllers) must meet essential cybersecurity requirements and provide vulnerability disclosure.

Brings embedded automotive and industrial autonomy under a unified EU cybersecurity baseline.

782days to enforcement
Effective Aug 02, 2028
Last synced ...

EU AI Act: Phase 3 Final Conformity (Article 6 Type-2)

Full conformity obligations for high-risk AI embedded in safety-critical products (including ADAS, ADS, aerospace, and industrial autonomy) take effect after the Article 111 grandfather window closes.

Original 2 Aug 2027 deadline deferred to 2 Aug 2028 by the Omnibus VII provisional agreement (May 2026). Embedded AI systems lose the legacy carve-out on this date. Evidence-grade governance across the in-service fleet becomes mandatory.

Already in force

8 examinable

The examiner can cite any of these on first request.

704days examinable
Effective Jul 07, 2024
Last synced ...

General Safety Regulation: Phase 2

All new vehicles sold in the EU must include driver-attention monitoring, emergency lane-keeping, intelligent speed assistance, and event data recording.

Autonomy-governance evidence is required for each assisted-driving function that can intervene in control.

710days examinable
Effective Jul 01, 2024
Last synced ...

UN Regulation No. 155: Vehicle Cybersecurity

All new vehicle types sold in EU, Japan, South Korea, and other WP.29 signatories must ship with a certified Cybersecurity Management System and evidence of ongoing risk management.

Vehicles without valid R155 type-approval cannot be sold. Runtime governance evidence fits directly into the CSMS submission.

710days examinable
Effective Jul 01, 2024
Last synced ...

UN Regulation No. 156: Software Update Management

Mandatory Software Update Management System with documented authorization, verification, and audit for every over-the-air software update.

Adaptive ML updates in the drive stack must produce tamper-evident evidence of safe parameter changes.

1,471days examinable
Effective Jun 01, 2022
Last synced ...

ISO 21448: SOTIF (Safety of the Intended Functionality)

Address hazards from functional insufficiencies and reasonably-foreseeable misuse (not just failure) in ADAS and automated driving functions.

Runtime-governance evidence of envelope awareness and bounded authority directly supports the SOTIF argument.

1,808days examinable
Effective Jun 29, 2021
Last synced ...

Standing General Order 2021-01: ADAS / AV Crash Reporting

Manufacturers and operators of vehicles with SAE Level 2 ADAS or Level 3-5 ADS must report serious crashes to NHTSA within strict reporting windows.

Evidence-grade incident traceability is non-negotiable. Tamper-evident decision logs answer the SGO directly.

2,262days examinable
Effective Apr 01, 2020
Last synced ...

ANSI/UL 4600: Standard for Safety for Autonomous Products

Safety case framework specifically for autonomous products. Covers hardware, software, lifecycle, and operational design domain governance.

Increasingly cited by insurers and procurement officers as a baseline for autonomous product safety claims.

2,749days examinable
Effective Dec 01, 2018
Last synced ...

ISO 26262: Road Vehicle Functional Safety

Establishes ASIL-graded development, verification, and production requirements for automotive electrical/electronic systems.

The baseline automotive safety standard. All governance evidence feeds the safety case.

2,925days examinable
Effective Jun 08, 2018
Last synced ...

DO-326A / DO-356A: Airworthiness Security

Security risk management for airborne systems. Required by FAA and EASA for type certification of new and modified aircraft.

Aerospace integrators must produce signed evidence of secure-by-design behavior. Runtime governance maps directly.

Start with a conversation.

Thirty minutes. Architecture, not sales. On the regulatory surface you already know.