|
시장보고서
상품코드
2109330
자동차 사이버 보안 및 데이터 보안 시장(2026년)Automotive Cybersecurity and Data Security Research Report, 2026 |
||||||
사이버 보안 및 데이터 보안에 관한 조사 - 지능형 커넥티드 차량이 '체계적인 공방과 AI 주도형 보안'의 시대를 맞이합니다.
이 보고서는 2026년 스마트 커넥티드 카의 사이버 보안 및 데이터 보안 전반을 중심으로, 차량의 모든 영역에 걸친 공격 시나리오와 AI가 초래하는 공격 대상 영역의 확대, 취약점 현황 분석, 전체 링크 보호 시스템, 데이터 분류 및 등급 지정, 국경을 초월한 규정 준수 등 핵심 주제를 분석하고 있습니다. 또한 7개 데이터 보안 기업(Agile Technology, Eagle Cloud 등), 7개 대표적인 OEM(Seres, NIO, BYD 등), 자동차 보안 하드웨어 공급업체 8개사(UniSentry Intelligent Technology, ThinkTech 등), 자동차 보안 소프트웨어 공급업체 7개사(Software Security Technology, Anban Tech 등) 및 차량 인터넷(IoV) 보안 서비스 제공업체 12곳(Vecentek, Callisto Technology, GoGoByte 등)의 보안 보호 실천 사례를 통해 규정 준수 인증, 기술 도입, 공급망 보안 거버넌스 분야에서 업계의 최첨단 발전 동향을 체계적으로 소개하고 있습니다. 또한 이 보고서에서는 차량에 AI를 도입함으로써 발생하는 새로운 위험(공급망 변조 및 프롬프트 하이재킹 등)을 규명하고, 스마트 커넥티드 카를 위한 보안 솔루션을 정리하며, 업계의 발전 동향을 예측하고 있습니다.
주요 포인트
정책에 힘입은 컴플라이언스 향상 - 검사 통과에서 체계적인 운영으로
빈번히 발생하는 공급망 침해 - 보안 거버넌스는 모든 영역 및 전체 수명주기를 포괄해야 합니다.
양날의 검으로서의 AI - 공격 대상 영역이 의도 계층까지 확대, 방어에는 'AI 대 AI' 접근 방식이 필요
사이버 보안은 수동적인 대응에서 능동적인 위협 헌팅으로 진화하고 있습니다.
데이터 보안은 개인정보 보호 규정 준수를 넘어 전체 링크에 걸친 거버넌스로 전환되며, 국경을 초월한 데이터 관리가 필수 과제가 됩니다.
보안은 비용 센터에서 핵심적인 경쟁 우위로 변혁되어야 합니다.
2026년, 지능형 커넥티드 차량(ICV) 업계는 중요한 전환점에 서 있습니다. 한편, GB 44495/44496으로 대표되는 국가 강제 기준의 전면 시행에 따라 업계는 규정 준수 모색 단계에서 본격적인 규정 준수 관리 단계로 공식적으로 전환했습니다. 다른 한편으로는 차량에 대한 대규모 AI 모델 도입과 국경을 초월한 데이터 흐름의 일상화로 인해 차량의 공격 표면이 급속히 확대되고 있으며, 이는 전례 없는 보안 문제를 야기하고 있습니다. 자동차 제조사에게 있으며, 단순한 수동적 규정 준수 대응이나 단일 지점에서의 방어만으로는 더 이상 복잡한 사이버 위협에 대처할 수 없습니다. 전체 수명주기과 공급망을 아우르며, AI를 활용한 능동적 방어를 특징으로 하는 체계적인 공방 체제로의 전환이 이제 필수적입니다.
2026년, 중국의 자동차 사이버 보안 및 데이터 보안에 관한 규제 체계는 폐쇄형 루프를 형성했습니다. GB 44495-2024 ‘자동차 사이버 보안에 관한 기술 요건’ 및 GB 44496-2024 ‘ 자동차 소프트웨어 업데이트에 관한 일반 기술 요건' 등의 강제 기준, 그리고 '자동차 데이터의 해외 이전 보안에 관한 지침(2026년)'의 시행에 따라 자동차 제조사에 대한 컴플라이언스 요건은 기존의 권장 참조 기준에서 강제력이 있는 최소한의 규칙으로 상향 조정되었습니다. 기업은 보안 전략, 조직 체계 및 업무 워크플로우를 포괄적으로 재구축해야 합니다.
또한 규제는 막대한 벌금을 통해 집행되고 있습니다. 2026년 5월, 유럽 데이터 보호 당국은 차량 호출 앱 ‘Yango’의 운영 사업자가 EU 법률에서 의무화한 보호 조치를 취하지 않고 사용자의 개인 데이터를 러시아로 전송했다는 이유로 1억 유로(약 8억 100만 위안)의 벌금을 부과했습니다. 같은 달, 제너럴 모터스(GM)는 사용자의 동의 없이 운전 데이터를 수집·판매했다는 이유로 약 9,000만 위안(人民元)의 벌금을 부과받았습니다. 이는 캘리포니아주 소비자 개인정보 보호법(CCPA) 시행 이래 최대 규모의 벌금입니다. 이러한 제재 조치 뒤에 숨겨진 논리는 명확합니다. 데이터는 자동차 제조사가 제멋대로 취득하거나 판매할 수 있는 자산이 아닙니다.
엄격한 규제 압력에 직면한 주요 자동차 제조사들은 수동적인 규정 준수를 넘어 능동적인 위험 예방 및 관리로 전환하는 속도를 높이고 있습니다. Seres사는 그 전형적인 사례입니다. 이 회사는 ‘클라우드·파이프·디바이스·칩’을 아우르는 다층 방어 시스템을 구축하고, 중국 최초로 ‘자동차 데이터 보안 관리 시스템 인증’ 및 ‘국가 데이터 보안 성숙도 모델(DSMM) 레벨 3 인증’을 획득하여 업계를 선도하는 체계적인 보안 역량을 입증했습니다. 한편, BYD는 자체 개발한 ‘iDDog’ 지능형 보안 플랫폼을 활용하여 ‘데이터 우회, 정화, 활성화’라는 3단계 논리에 따라 데이터 사일로를 해소하고 고품질 데이터 인프라를 구축하고 있습니다. 또한 3가지 주요 AI 에이전트를 도입하여 보안 운영의 효율성을 높이고, 규정 준수 요건을 견고한 운영 역량으로 정착시키고 있습니다. 중국자동차공업협회(CAAM)가 주도하는 ‘5대 규정 준수 검사’는 계속해서 진전되고 있으며, 3차 검사에서는 13개사의 49개 차종, 4차 검사에서는 9개사의 43개 차종이 검사를 통과했습니다. 차량 외부에서 수집된 사람의 얼굴 데이터 익명화나 콕핏 데이터의 차량내 처리와 같은 요건은 업계의 표준적인 구성으로 자리 잡고 있습니다.
사실이 증명하듯이, 규정 준수는 어디까지나 출발점에 불과합니다. 보안 역량을 지속가능한 운영상의 강점으로 전환하는 것야말로 기업이 산업사이클을 극복하기 위한 경쟁 우위가 됩니다.
2025년 자동차 업계에서 가장 가슴 아픈 교훈이 무엇이냐는 질문을 받는다면, 그 대답은 아마도 다음과 같을 것입니다. '공격자는 더 이상 무차별 대입 공격을 통해 침입을 시도하지 않고, 신뢰받는 파트너의 채널을 통해 잠입한다'는 것입니다. 스마트 커넥티드 카의 공급망은 지극히 복잡하여, 어느 한 고리에 단 하나의 취약점만 있어도 개미집 때문에 둑이 무너지는 것과 같은 파멸적인 결과를 초래할 우려가 있습니다.
2025년 3월, 해커 ‘Rey’가 소스 코드, 개발 로그, 직원 데이터베이스를 포함한 재규어 랜드로버의 내부 문서 약 700건을 다크웹에 유출했으나, 이는 단순한 서막에 불과했습니다. 같은 해 8월, 해커 집단 ‘Scattered Lapsus$Hunters’가 이 회사의 전 세계 생산 시스템에 침입하여 영국 제조 공장의 전면 가동 중단과 3만 3,000명의 직원에 대한 강제 휴가를 초래했습니다. 또한 8월에는 닛산 산하의 설계 자회사가 위협 행위자 ‘ Qilin'에 의한 랜섬웨어 공격을 받아 4TB에 달하는 핵심 설계 데이터가 도난당했습니다. 클라우드 스토리지 서비스 제공업체인 Snowflake도 해킹을 당해, 자동차 부품 소매업체인 Advance Auto Parts를 포함한 165개 하류 기업에 2차 피해가 미쳤습니다. 2025년 말까지 세계 유선 하네스 대기업인 야자키 그룹은 랜섬웨어 공격자로부터 350GB의 데이터를 도난당했으며, 그 안에는 BMW와 닛산에 공급되는 부품의 전체 문서가 포함되어 있었습니다. 태국의 OEM인 TRU의 사례는 더욱 전형적입니다. 1TB의 데이터가 도난당했고, ESXi 서버가 암호화 공격의 표적이 되어 ERP 및 물류 시스템이 광범위하게 오프라인 상태가 되었으며, 일부 생산 라인은 수동 스케줄링으로 전환할 수밖에 없었습니다.
이러한 사고들을 종합해 보면, 공격 패턴에서 세 가지 뚜렷한 변화가 드러납니다. :
표적의 구체화 - 공격자들은 단순한 데이터 절도에서 지적 재산 유출 및 생산 활동의 직접적인 마비로 방법을 격상시키고 있습니다;
공급망을 표적으로 한 공격 경로 - 전체 사고의 절반 이상이 클라우드 서비스 제공업체, IT 자회사 및 제3자 공급업체를 통해 간접적으로 실행되고 있으며, 공급망이 가장 취약한 부분으로 드러났습니다;
표적형 랜섬웨어 - 악의적인 공격자는 설계 도면 등 고가치 데이터를 특히 표적으로 삼고 있습니다.
이러한 취약점이 드러남에 따라 업계의 대책 강화가 진행되고 있습니다. 자동차 제조사는 공급망 보안에 대한 주요 책임 주체로 널리 인식되고 있으며, ‘사이버 보안 인터페이스 협정(CIA)’을 체결함으로써 Tier 1 공급업체에 책임을 전가하고 있습니다. ISO/SAE 21434 인증은 Tier 1 공급업체에게 필수적인 진입 요건이 되었으며, 이 ‘보안 신용장’ 가 없으면 기업은 핵심 공급망에 진입할 수 없습니다. 유럽 시장을 목표로 하는 기업에게 TISAX 인증은 피할 수 없는 요건입니다. 그럼에도 불구하고 전반적인 상황은 여전히 ‘대형 OEM이 주도권을 쥐고 있는 반면, 중소 공급업체는 뒤처져 있다’는 특징을 보이고 있습니다. 중소 Tier 2 및 Tier 3 공급업체에 대해서는 대부분의 자동차 제조사가 서류 감사만을 시행하고 있으며, 현장 검증의 적용률은 극히 낮고, 추적성 체인도 불완전한 상태입니다.
전 영역·전 수명주기에 걸친 공급망 보안 시스템 구축은 업계의 공통된 인식이 되었습니다. 지리(Geely)는 이에 대한 모범적인 벤치마크를 제시하고 있습니다. 이 회사는 중국 최초로 CNAS 인증을 받은 IoV 사이버 보안 연구소 중 하나를 설립하여, 시스템 보안, 통신 보안, 데이터 보안 등 12가지 주요 시험 항목에 대해 공격자의 관점에서 200개 이상의 정기적인 시험을 시행하고, 그 연구 성과를 선행 연구개발 워크플로우에 반영하고 있습니다. 2025년 12월, 지리(Geely)는 ‘세계 전 영역 보안 센터’ 및 ‘전 영역 보안 2.0’ 기술 시스템을 공식 출범시켰습니다. 이 2.0 시스템은 관점을 ‘차량 전체의 보안’에서 ‘사람·차량·도로·클라우드·위성’이라는 생태계적 관점으로 확대하고 있습니다. 생명 안전, 건강 안전, 재산 안전, 개인정보 안전이라는 4가지 핵심 보안 영역을 유지하면서, 9가지 주요 보안 시스템을 반복적으로 업그레이드하여 모든 시나리오와 수명주기를 아우르는 보호 네트워크를 구축하고 있습니다.
한편, 공급망 제조업체에 대한 보안 적합성 평가의 정교화가 지속적으로 진행되고 있으며, 다음과 같은 엄격한 요건이 도입되었습니다. 타사 제조 부품에는 6개월 이상 전에 공개된 수정되지 않은 고위험 취약점이 포함되어서는 안 됩니다. 고위험 취약점은 72시간 이내에 수정되고 재검증되어야 합니다. OTA 업데이트 패키지에는 OEM 고유의 키로 서명해야 하며, 특정 시나리오에서는 공급업체와 OEM의 이중 서명이 요구됩니다. 또한 차량용 단말기는 서명이 누락되거나 위조, 변조된 업데이트 패키지를 식별하여 차단해야 합니다. 예를 들어 Seres사는 300개에 달하던 1차 공급업체를 100개로 압축하고, CATL사 및 Bosch사와 깊이 통합된 보안 협력을 구축함으로써 보안 관리 범위를 관리 가능한 규모로 축소했습니다. 기반이 되는 하드웨어 계층에서는 예를 들어 ThinkTech사의 Alioth TTA8 시리즈 MCU는 ASIL-D 기능 안전 규격과 EVITA FULL 사이버 보안을 통합하여, 섀시 도메인의 마스터 제어 칩 분야에서 국내의 공백을 메우고, 공급망의 독립적인 제어성과 안전성을 근원부터 보장하고 있습니다.
공급망 보안의 본질은 보안 경계를 '자사의 차량'에서 '차량 내의 모든 코드 줄, 모든 칩, 모든 공급업체'로 확대하는 데 있습니다. 모든 영역 및 전체 수명 주기를 포괄하는 것이 필수적이며, 어떤 연결 고리도 생략해서는 안 됩니다.
차량에 대규모 모델을 도입하면 콕핏의 스마트화를 가져올 뿐만 아니라, 완전히 새로운 차원의 공격도 초래합니다. 공급망 오염, 프롬프트 하이재킹, 과도한 프록시 등 AI 특유의 위험이 급속도로 차량 단말기로 이동하고 있습니다. 차량의 대규모 모델이 내비게이션, 결제, 충전, 차량 제어를 위한 툴체인과 연결되면, 원래 클라우드 챗봇에 한정되었던 공격 체인이 그대로 차량으로 이식될 가능성이 있습니다. 특히 MCP 연결 생태계 내에서는 툴 포이즌링(tool poisoning)과 같은 고위험 공격 벡터가 리눅스나 안드로이드를 실행하는 IVI 시스템을 직접 위협하고 있습니다.
OpenClaw로 대표되는 새로운 에이전트는 높은 수준의 시스템 권한을 활용하여, 의도 이해부터 작업 완료에 이르는 폐쇄 루프를 형성하는 데 탁월합니다. 그러나 차량 환경에서는 이것이 시스템 내에 영구적인 디지털 엔티티가 존재함을 의미하며, 해당 엔티티는 차량 데이터에 대한 부분적인 접근 권한이나 차량 제어 명령을 호출할 수 있는 권한을 보유하게 됩니다. 프롬프트 주입을 통해 에이전트에게 의도하지 않은 조작을 실행하도록 유도할 수 있습니다. 변조된 타사 내비게이션 플러그인은 운전 습관을 유출하는 영구적인 트로이 목마로 기능할 우려가 있습니다. 또한 Q&A 시나리오에서 무해한 ‘환각’도 프록시 시나리오에서는 중요 데이터 삭제와 같은 위험한 조작으로 비화될 가능성이 있습니다. 더욱 골치 아픈 문제는 규제상의 모순입니다. ISO 26262, UN R155/R156, GB 44495 등의 규격은 결정론적이고, 예측 가능하며, 검증 가능하고, 추적 가능한 시스템 동작을 의무화하고 있지만, 에이전트는 본질적으로 비결정론적이며, 자기조직적 특성을 갖추고 있습니다. 업계의 해결책은 ‘완전한 위임이 아닌 권한 부여’입니다. 즉, 권한 샌드박스나 기능 펜스를 도입하여 에이전트의 동작을 인포테인먼트나 기타 저위험 영역으로 제한합니다. 모든 차량 제어 요청은 보안 미들웨어 계층을 통한 중재를 의무화해야 합니다. 또한 고위험 조작에 대해서는 HMI를 통해 확인을 수행하고, 안전상 중요한 모든 결정에 있으며, 인간이 루프 내에 머물도록 보장합니다.
공격 표면이 진화함에 따라 방어 메커니즘도 이에 맞춰 진화시켜야 합니다. 업계의 해결책은 명확합니다. AI에는 AI로 대응한다는 것입니다.
AI가 초래하는 ‘창’에 직면하여, 업계는 더욱 날카로운 ‘방패’를 세워야 합니다. 예를 들어 Anban Tech는 새로운 지능형 커넥티드 차량(ICV)의 보안 패러다임을 ‘AI 대규모 모델 기반 에이전트 보호 + 차량 통신 프로토콜 보안 + 폐쇄 루프형 공급망 보안’으로 정립하고 있습니다. 이를 통해 보안 기능은 기존의 사후 패치 적용 방식에서 수명주기 전반에 걸친 선제적 거버넌스로 전환됩니다. :
대규모 모델을 활용하여 자연 언어를 통해 차량의 EE 아키텍처 문서 전체, 모델 간 데이터베이스 및 VSOC 자산 인벤토리를 분석하고, ECU, 센서, 통신 인터페이스, 기타 중요 자산을 자동으로 식별하여 자산 상관관계 프레임워크를 매핑합니다. LLM을 활용한 지능형 TARA 플랫폼은 보안 대상, 보안 요구사항, 위협 시나리오, 공격 경로를 자동으로 생성하여 자동화된 시각적 위험 평가를 가능하게 합니다.
리스크 시정 시, 본 플랫폼은 영향의 심각도, 공격의 실현 가능성 및 리스크 평가 매트릭스를 종합하여 시정 조치 결정을 자동으로 생성하고 작업 지시를 발행합니다. 이를 통해 ‘AI에 의한 탐지-AI에 의한 분석-AI에 의한 결정-AI에 의한 폐쇄 루프’라는 운영 워크플로우를 형성하여, 차량 보안 평가 주기를 대폭 단축합니다.
QAX AISOC는 이러한 접근 방식의 대표적인 사례입니다. 본 시스템에는 데이터 수집, 위협 탐지, 지능형 판단, 지능형 조사, 지능형 대응, 사고 근절, 최적화 피드백, 보고서 생성이라는 8가지 운영 링크를 담당하는 8개의 에이전트가 내장되어 있습니다. OODA 루프에 기반하여 자율적인 방어 시스템을 구축하고, 보안 운영을 ‘인간 주도의 위협 헌팅’에서 ‘자동화된 위협 알림’으로 혁신합니다. 실증 데이터에 따르면 AISOC을 도입한 전 세계 고급 자동차 제조사에서는 알림 1건당 분석 및 평가 시간을 9초 미만으로 단축했으며, 유효한 알림의 식별 정확도는 93.1%에 달해 기존 수동 모드에 비해 2.7배의 개선을 실현했습니다.
기존의 보안 분석 프로세스인 TARA 역시 AI를 통해 재구축되고 있습니다. GoGoByte DefenseWeaver에는 GoGoAI 에이전트가 내장되어 있으며, 모델, 학습 및 추론 데이터, 프롬프트 진입점, 지식 기반, 툴 호출 체인 등 모든 새로운 위험 벡터를 TARA의 범위에 통합하고 있습니다. 이 툴은 위험이 단순히 코드의 취약성뿐만 아니라, 잘못된 모델, 오염된 데이터, 오용된 툴에서도 발생한다고 판단합니다. 이 툴은 FAW Bestune 및 Luxshare Precision과 같은 고객 기업뿐만 아니라 CATARC, 중국招商자동차기술연구원, CEPREI와 같은 국가 검사 기관에서도 사용되고 있으며, TARA의 효율을 80% 향상시키고 있습니다. Callisto S3-TARA는 다른 접근 방식을 채택하고 있습니다. 10개 이상의 에이전트가 협력하여 16개의 후보 ‘사고 사슬(Chains of Thought - CoT)’ 중에서 최적의 해결책을 선별합니다. 이는 10만 건 이상의 인과 연쇄 데이터세트, 300만 건 이상의 보안 시나리오 샘플, 그리고 100만 건 이상의 지식 기반 Q&A 쌍을 바탕으로 구축된 데이터베이스에 의해 지원됩니다.
자동차 제조사들도 가만히 있지 않습니다. BYD의 iDDog 플랫폼은 이메일 피싱, 단말기 데이터 유출, 비정상 트래픽을 대상으로 하는 3가지 AI 에이전트를 구현하여 보안 사고 대응 시간을 45분에서 5분으로 단축했습니다. Li Auto는 Volcano Engine과 제휴하여, Feishu 그룹 채팅에서 지시를 받으면 작업 지시서 자동 작성, 코드 스캔, 취약점 수정, 재검증을 수행할 수 있는 AI 지능형 어시스턴트를 개발했습니다. 이를 통해 사람의 승인을 받아 원스톱 폐쇄 루프 해결이 가능해졌습니다. AI 네이티브는 단순한 개념적 슬로건에서 일상적인 보안 운영으로 전환되고 있습니다.
사이버 보안 분야에서 기존의 수동적인 방어 방식은 급속히 진화하는 공격 벡터를 더 이상 따라잡을 수 없습니다. 2025년 한 해 동안만 206건의 자동차 보안 사고와 238건의 신규 취약점이 기록되었습니다. 위협 행위자들은 그 목적을 데이터 절도에서 지적 재산 유출, 나아가 생산·제조 업무의 직접적인 마비까지 확대하고 있습니다. 따라서 자동차 제조사는 위협의 탐지, 분석, 대응, 시정을 포괄하는 능동적인 위협 헌팅 기능을 갖춘, 실전 대응이 가능한 사이버 보안 시스템을 구축해야 합니다.
보안 전문가들이 제안하는 해결책은 체계적인 방어에 있습니다. Seres사는 ‘클라우드·파이프·디바이스·칩’이라는 다층적인 심층 방어 아키텍처를 전개하고, QAX사와 협력하여 CAN 버스, 차량 호스트, 이더넷 각 계층에 침입 탐지 시스템을 도입하고 있습니다. 이 회사의 VSOC 플랫폼은 약 20만 대의 차량을 모니터링하며, EU로 수출되는 차종에 대해 ‘사이버 보안 적합성 인증서’를 발급하고 있습니다. 이 지능형 보안 시스템은 200개 이상의 차량 사용 시나리오와 400개 이상의 보안 기능을 포괄하고 있습니다. 2026년 4월에는 'Security 4.0'을 출시하여 수동적·능동적 안전에서 지능형 보안으로 진화시켰습니다.
전문 보안 제공업체들도 툴키트을 업그레이드하고 있습니다. 차세대 지능형 커넥티드 차량(ICV) 보안 운영 플랫폼인 ‘ACT VSOC+’는 이러한 철학을 구현하고 있습니다. AI 스트리밍 컴퓨팅 엔진을 탑재하여 위협 탐지 성능을 500% 향상시키고, 2,800개 이상의 차량 신호를 기반으로 한 차량 보안 디지털 트윈 모델을 구축합니다. 또한 ECU, 신호, 시나리오라는 세 가지 측면에서 위협을 정확하게 식별함으로써, 위협 탐지 및 대응 주기를 ‘일 단위’에서 ‘분 단위’로 단축합니다.
기반이 되는 프로토콜 보안 계층에서는 TICPSH사의 'SmartRocket TestSec'이라는 자동화된 지능형 퍼지 침투 테스트 툴이 SOME/IP, DoIP, CAN/CAN FD 등 주요 차량 프로토콜에 대해 딥 퍼지 공격 및 침투 테스트를 수행하고, 잠재적 취약점을 선제적으로 발견함으로써 보안 방어선을 연구개발(R&D) 테스트 단계로 앞당기고 있습니다. UniSentry Intelligent Technology사의 SecIC-HSM 펌웨어는 약 30개 OEM에 채택되어 있으며, 인피니온(Infineon)의 AURIX TC4X 상에서 4.8Gbps의 AES 처리량을 실현하여, CAN 버스 전송을 중단하지 않고도 OTA 업데이트 검증과 보안 온보드 통신(SecOC)을 동시에 실행할 수 있게 합니다. 이러한 솔루션은 자동차 제조사가 단순한 규정 준수를 넘어, 미래를 내다보는 보안 수준으로 도약하는 데 도움이 됩니다.
OEM 및 공급업체들 사이에서는 고립된 독립형 보안 제품만으로는 체계적인 보안 문제를 해결할 수 없으며, 다층적인 심층 방어와 능동적인 면역 시스템이야말로 올바른 해결책이라는 공감대가 형성되고 있습니다.
데이터는 스마트 차량의 ‘혈액’이며, 그 보안은 수집, 전송, 저장, 이용, 공유, 폐기의 전체 수명주기에 걸쳐 있습니다. 자동차 데이터 보안의 독특한 특징은 데이터가 개인정보 보호와 규정 준수의 두 가지 속성을 모두 지니면서도, 지각 훈련, 지도 서비스, 모델 반복, 원격 제어, 사고 추적 가능성을 직접 지원한다는 점에 있습니다. 데이터의 부적절한 수집, 전송, 이용 또는 변조는 규제 당국의 과태료에 그치지 않고, 차량의 작동에 악영향을 미칠 가능성도 있습니다.
2026년 2월 3일, 공업정보화부 및 중국 사이버공간관리국을 포함한 8개 부처가 공동으로 ‘자동차 데이터 해외 이전 보안에 관한 지침(2026)’을 발표했습니다. 이 지침에서는 해외로 전송되는 데이터를 '일반', '중요', '기밀'의 3단계로 분류함과 동시에, 품질 보증·유지보수 데이터, OTA 업데이트 데이터, 보안 취약점 수정 자료 등 9가지 적용 제외 시나리오를 정의하고 있습니다. 또한 명확한 신고 기준이 마련되어 있으며, 기업은 ‘중요’ 데이터를 해외로 전송하거나 100만 명 이상의 개인정보·1만 명 이상의 기밀 개인정보를 외국 사업체와 공유할 경우, 국경 간 데이터 전송에 대한 보안 평가를 실시해야 합니다. 2026년 상반기에 전년 동기 대비 65.3%의 수출 증가율을 기록한 중국 자동차 산업에 있으며, 이 가이드라인은 국경을 넘는 데이터 흐름에서 존재하던 회색 지대를 해소하고, 업계의 대응을 '시도적인 모색'에서 '명확한 규정 준수'로 전환시키는 역할을 합니다. 동시에 해외 규제 또한 강화되고 있습니다. 수출을 주축으로 하는 OEM에는 12단계의 GDPR 준수 로드맵이 적용되고 있으며, 일본의 개정 개인정보보호법(APPI법)에서는 처음으로 이익에 기반한 과징금 산정이 도입되었고, 한국의 개인정보보호법(PIPA)은 엄격한 거버넌스 단계에 접어들었습니다. 국경을 넘는 데이터 흐름에 대한 거버넌스는 여러 법역에 걸쳐 필수적인 규정 준수 과제가 되고 있습니다.
각 자동차 제조사들은 독자적인 대응책을 마련하고 있습니다. NIO의 ‘Sentry Mode’ 원격 뷰 기능은 종단 간 암호화와 실시간 데이터 비식별화를 구현하여, 차량 번호판이나 인물의 얼굴을 자동으로 흐리게 처리하고 NIO조차도 복호화할 수 없는 영상을 구현함으로써, 규정 준수를 충족하는 원격 뷰 기능을 제공하는 중국 최초의 OEM이 되었습니다. 이 회사가 독자적으로 개발한 NPCC 프레임워크는 업계 최초의 디바이스-클라우드 통합형 AI 에이전트 보안 프레임워크로, 기밀 데이터에 대해 ‘계산 후 즉시 데이터 삭제’를 철저히 시행하고 있습니다. Leapmotor는 차량내 처리 원칙을 준수하고 있으며, 차량용 카메라는 로컬 연산을 위한 특징점만 수집하고 클라우드에 업로드하지 않으며, 모든 통신 트래픽은 AES-256을 통한 종단 간 암호화로 보호됩니다. ZEEKR의 ‘Data Safe’ 시스템은 제로 트러스트 방식의 다단계 접근 제어를 구현하고 있으며, 비정상적인 접근을 감지하면 20초 이내에 데이터 서킷 브레이커를 작동시키고, 저장 매체의 물리적 데이터 파괴 기능도 갖추고 있습니다. Xpeng은 Alibaba Cloud와 제휴하여 신형 모델 P7에 포스트 양자 보안 알고리즘을 도입했습니다. 이는 디지털 키, 차량 원격 제어 및 모든 주행 모드에서의 OTA를 포괄합니다.
NPCC(NIO가 업계 최초로 도입한 디바이스-클라우드 통합형 AI 에이전트 보안 프레임워크)의 'Sentry Mode'에 포함된 'Remote View'
각 데이터 보안 서비스 제공업체들은 솔루션을 더욱 정교하게 다듬고 있습니다. Eagle Cloud Hub AI-DLP는 거버넌스 대상을 ‘인간’에서 ‘인간 직원 + AI 직원’이라는 이중 주체로 확대하고, 양측에 대해 통일된 ID 관리, 일관된 보안 정책, 표준화된 감사를 시행하는 동시에, 외부로의 배포, 다운로드, 복사, 스크린샷 등 데이터 유출 경로에 대한 세밀한 제어를 실현하고 있습니다. 이 회사의 고객으로는 지리홀딩(Geely Holding), Li Auto, Leapmotor, Seres 등이 이름을 올리고 있습니다. Agile Technology사의 EDLP 솔루션은 암호화와 DLP를 깊이 통합한 혁신적인 아키텍처를 특징으로 합니다. 데이터 발생 원천부터 시작하여 ‘식별·분류·암호화·접근 제어·감사’를 아우르는 완전한 폐쇄 루프형 예방·제어 시스템을 구축함으로써, AI 시대에 설계 도면이나 연구개발 데이터 등 중요한 영업 비밀의 보안을 확보합니다. 2026년 5월, Agile Technology는 자동차 업계의 선도 기업으로부터 5,000노드 규모의 데이터 보안 프로젝트 입찰을 따냈습니다.
국경을 초월한 데이터 컴플라이언스와 관련하여, CATARC는 '경로 계획-위험 평가-정책 수립-평가 신고'라는 4단계의 포괄적인 서비스 워크플로우를 제공하여, 각 OEM사가 데이터 흐름의 전체 경로를 명확히 하고 예방·관리·추적이 가능한 컴플라이언스를 실현할 수 있도록 지원합니다.
명확한 동향이 파악된 지금, 어떻게 엔지니어링을 구현해야 하는가? 주요 기업의 사례를 참고하면, 자동차 제조사가 즉시 착수해야 할 몇 가지 조치가 있습니다. :
시스템을 표면적인 규정 준수 문서로 취급하지 말고, 핵심 워크플로우에 통합해야 합니다. ISO/SAE 21434 표준을 중심으로 한 전 생애 주기 CSMS/SUMS 시스템을 구축하고, TARA 위협 모델링을 개념 및 설계 단계로 앞당겨 보안의 ‘좌측 이동’을 실현해야 합니다. 공급업체에 SBOM 및 코드 보안 요건을 의무화하고, 사이버 보안 인터페이스 계약(CIA)을 통해 보안 책임을 하류로 전파해야 합니다.
VSOC(차량 보안 운영 센터)를 단순한 경보 대시보드에서 핵심 운영 허브로 전환합니다. 구체적인 효율화 방안은 다음과 같습니다. 모든 알림에 근본 원인 태그를 부여함으로써, 알림 거버넌스를 ‘건수 감소’에서 ‘근본 원인의 폐쇄 루프 관리’로 전환합니다. 정적 위험 등급을 동적 가중치 모델로 대체합니다. 원클릭 컨텍스트 인캡슐레이션를 통해 알림 1건당 15분이 소요되던 수동 분석 시간을 단축합니다. 시나리오 기반의 긴급 대응 카드를 작성하고, 발생 빈도가 높은 시나리오에 대해서는 반자동 SOAR(보안 오케스트레이션, 자동화 및 대응) 플레이북을 도입하여 증거의 자동 저장 및 보고서의 자동 생성을 실현합니다. 기반이 되는 차량 보안 데이터센터를 구축하여, 운영자가 단일 VIN을 조회하기 위해 5-6개의 별도 시스템에 로그인할 필요가 없도록 합니다. 팀 차원에서는 SOP 라이브러리와 지식 기반을 정비하고, 연 1회 실시하던 대규모 훈련을 정기적인 소규모 실전 세션으로 대체합니다.
풀 링크 데이터 보안 엔지니어링을 실시합니다. 데이터 분류 및 등급 부여를 기반으로, 암호화, 비식별화, 접근 제어, 국경을 넘는 모니터링을 핵심 운영 툴로 삼습니다. 국경을 넘는 사업에 대해서는 ‘경로 계획 → 위험 평가 → 정책 수립 → 규정 준수 선언’이라는 4단계 워크플로를 채택하여, 일회성 프로젝트 대응에서 표준화된 지속적인 운영으로 전환합니다.
적절한 시나리오에 따라 AI를 도입합니다. AI TARA 플랫폼을 활용하여 위협 모델링의 효율을 높이고, AI SOC 시스템을 활용하여 경보 분석의 오버헤드를 줄이며, 디지털 트윈 기술을 도입해 리스크의 세분화 수준을 정교화하는 동시에, 차량 에이전트에 권한 샌드박스 및 기능 펜스를 적용하여 모든 고위험 조작에 대해서는 반드시 인간의 승인 절차를 유지합니다.
보안 개발은 ‘비용 센터’에서 ‘핵심 역량’으로 전환되어야 합니다. 규정 준수가 기반이 되고, 보안 운영이 그 상한선을 결정합니다. 업계가 AI 주도 차량 시대로 더욱 깊이 진입함에 따라 이 원칙은 점점 더 중요해질 것입니다.
Cybersecurity & Data Security Research: Intelligent Connected Vehicles Enter the Era of "Systematic Offense-Defense and AI-Defined Security".
Centering on the panorama of intelligent connected vehicle cybersecurity and data security in 2026, this report analyzes core topics including vehicle full-domain attack scenarios and more attack surfaces brought by AI, vulnerability status analysis, full-link protection system, data classification & grading, and cross-border compliance. Furthermore, it systematically presents cutting-edge industry progress in compliance certification, technology implementation, and supply chain security governance through security protection practices of 41 enterprises of diverse types, covering 7 data security companies (Agile Technology, Eagle Cloud, etc.), 7 representative OEMs (Seres, NIO, BYD, etc.), 8 automotive security hardware suppliers (UniSentry Intelligent Technology, ThinkTech, etc.), 7 automotive security software suppliers (Software Security Technology, Anban Tech, etc.), and 12 Internet of Vehicles (IoV) security service providers (Vecentek, Callisto Technology, GoGoByte, etc.). Meanwhile, the report reveals new risks introduced by AI deployment on vehicles such as supply chain poisoning and prompt hijacking, summarizes security solutions for intelligent connected vehicles, and forecasts industrial development trends.
Highlights
Compliance upgrade driven by policies: From passing inspections to systematic operation
Frequent supply chain breaches: Security governance must cover full domains and full lifecycle
AI as a double-edged sword: Attack surfaces extend to the intent layer; defense requires "countering AI with AI"
Cybersecurity evolves from passive response to active threat hunting
Data security shifts from privacy compliance to full-link governance; cross-border data management becomes a mandatory task
Security needs to be transformed from a cost center into a core competitive edge
In 2026, the intelligent connected vehicle industry stands at a critical turning point. On one hand, the full enforcement of national mandatory standards represented by GB 44495/44496 marks the official transition of the industry from compliance exploration to in-depth compliance management. On the other hand, the deployment of large AI models on vehicles and normalized cross-border data flows are rapidly expanding vehicle attack surfaces, posing unprecedented security challenges. For automakers, simple passive compliance or single-point defense can no longer address complex cyber threats; transforming into systematic offense-defense operations featuring full-lifecycle, full-supply-chain, and AI-driven active defense has become inevitable.
In 2026, China's regulatory framework for automotive cybersecurity and data security has formed a closed loop. Based on mandatory standards including GB 44495-2024 Technical Requirements for Vehicle Cybersecurity and GB 44496-2024 General Technical Requirements for Software Update of Vehicles, plus the implementation of the Guidelines for Outbound Transfer Security of Automotive Data (2026), compliance requirements for automakers have been upgraded from previously recommended reference standards to enforceable bottom-line rules. Enterprises need to comprehensively reshape their security strategies, organizational structures, and operational workflows.
Regulation is also enforced through heavy fines. In May 2026, European data protection authorities imposed a fine of 100 million euros (approximately 801 million RMB) on the operator of ride-hailing app Yango for transferring users' personal data to Russia without implementing protective measures required by EU laws. In the same month, General Motors was fined nearly 90 million RMB for collecting and selling driving data without user consent, marking the largest penalty since the enactment of the California Consumer Privacy Act. The logic behind these penalties is clear: data is not the asset taken or sold arbitrarily by automakers.
Faced with stringent regulatory pressure, leading automakers are accelerating the shift from passive compliance to active risk prevention and control. Seres serves as a typical example. It has built an in-depth defense system covering "cloud-pipe-device-chip", and obtained China's first batch of Automotive Data Security Management System Certification and Level 3 National Data Security Maturity Model (DSMM) Certification, proving its industry-leading systematic security capabilities. Meanwhile, with its self-developed "iDDog" intelligent security platform, BYD follows a three-step logic of "diverting, purifying, and activating data" to break down data silos and build high-quality data infrastructure. It has deployed three major AI agents to boost efficiency in security operations, internalizing compliance requirements into robust operational capabilities. The "5 Compliance Inspections" initiated by the China Association of Automobile Manufacturers (CAAM) continue to advance; 49 vehicle models from 13 enterprises in the third batch and 43 vehicle models from 9 enterprises in the fourth batch have passed inspections. Requirements such as anonymization of human facial data collected outside vehicles and in-vehicle processing of cockpit data are becoming standard configurations in the industry.
Facts have proven that compliance is merely a starting point. Transforming security capabilities into sustainable operational internal strengths constitutes the competitive edges for enterprises to navigate industrial cycles.
If one were to ask for the most painful lesson of the automotive industry in 2025, the answer would likely be: Attackers no longer attempt brute-force intrusions, but infiltrate through trusted partner channels. The supply chain of intelligent connected vehicles is extremely complex; a single vulnerability in any link may trigger catastrophic consequences analogous to a dike collapsing due to an ant's nest.
In March 2025, hacker "Rey" leaked about 700 internal Jaguar Land Rover documents on the dark web, including source code, development logs, and employee databases-this was merely a prelude. In August of the same year, hacker group "Scattered Lapsus$ Hunters" intruded the company's global production systems, forcing full suspension of UK manufacturing plants and mandatory leave for 33,000 employees. Also in August, a design subsidiary under Nissan suffered a ransomware attack by threat actor "Qilin", resulting in the theft of 4TB of core design data. Cloud storage service provider Snowflake was breached, causing collateral damage to 165 downstream enterprises including auto parts retailer Advance Auto Parts. By late 2025, global wiring harness giant Yazaki Group had 350GB of data stolen by ransomware threat actors, containing complete documentation for components supplied to BMW and Nissan. The case of Thai OEM TRU is even more typical: 1TB of data was stolen, ESXi servers were targeted for encryption, ERP and logistics systems suffered widespread offline outages, and partial production lines were forced to switch to manual scheduling.
Collectively, these incidents reveal three clear shifts in attack patterns:
Target physicalization: Threat actors have escalated from data theft to intellectual property exfiltration and direct production paralysis;
Supply chain-oriented attack paths: Over half of all incidents are executed indirectly through cloud service providers, IT subsidiaries, and third-party suppliers, rendering supply chains the weakest link;
Targeted ransomware: Malicious actors specifically target high-value data such as design blueprints.
These exposed vulnerabilities have driven upgrades to industry countermeasures. Automakers are universally recognized as the primary responsible parties for supply chain security, transferring accountability to Tier 1 suppliers by signing Cybersecurity Interface Agreements (CIA). ISO/SAE 21434 certification has become a mandatory entry threshold for Tier 1 suppliers; without this "security letter of credit", enterprises cannot access core supply chains. For businesses targeting European markets, TISAX certification is an unavoidable requirement. Nevertheless, the overall landscape remains characterized by "leading OEMs take initiative while small and medium-sized suppliers lag behind". For small and medium Tier 2 and Tier 3 suppliers, most automakers only conduct documentary audits, with extremely low coverage of on-site verification and incomplete traceability chains.
Building a full-domain, full-lifecycle supply chain security system has been an industry consensus. Geely provides an exemplary benchmark. It constructed one of China's first national CNAS-accredited IoV cybersecurity laboratories, and conducts over 200 regular test items across 12 core testing dimensions including system security, communication security, and data security from an attacker's perspective, feeding research outcomes back into forward R&D workflows. In December 2025, Geely officially launched its Global Full-Domain Security Center and the Full-Domain Security 2.0 technical system. The 2.0 system expands its perspective from "whole-vehicle security" to an ecological view of "human-vehicle-road-cloud-satellite". While retaining four core security domains: life safety, health safety, property safety, and privacy safety, it iterates and upgrades nine major security systems to build a full-scenario, full-lifecycle protection network.
Meanwhile, the granularity of security acceptance evaluations for supply chain manufacturers is continuously refined, with several rigorous requirements implemented: Third-party components must not contain unaddressed high-risk vulnerabilities disclosed more than 6 months prior; high-risk vulnerabilities must be fixed and re-verified within 72 hours; OTA update packages must be signed with OEM proprietary keys, dual signatures by suppliers and OEMs are required in certain scenarios, and vehicle terminals must identify and intercept upgrade packages with missing, forged, or tampered signatures. For instance, Seres has streamlined its 300 Tier 1 suppliers down to 100, establishing deep embedded security collaboration with CATL and Bosch to narrow its security management radius to controllable scope. At the underlying hardware layer, for example, ThinkTech's Alioth TTA8 series MCUs integrate ASIL-D functional safety and EVITA FULL cybersecurity, filling domestic gaps in chassis domain master control chips and guaranteeing independent controllability and security of supply chains at the source.
The essence of supply chain security lies in extending the security boundary from "my vehicle" to "every line of code, every chip, and every supplier within my vehicle"-full domain and full lifecycle coverage are indispensable, with no links to be omitted.
The deployment of large models on vehicles brings not only smarter cockpits but also an entirely new attack dimension. AI-specific risks including supply chain poisoning, prompt hijacking, and excessive proxy are rapidly migrating to vehicle terminals. When vehicle large models connect tool chains for navigation, payment, charging, and vehicle control, attack chains originally limited to cloud chatbots can be intactly ported to vehicles. Particularly within MCP-connected ecosystems, high-risk attack vectors such as tool poisoning directly threaten IVI systems running Linux and Android.
Novel agents represented by OpenClaw excel at forming a closed loop from intent understanding to task completion thanks to their high-level system privileges. However, in vehicle environments, this translates to a persistent digital entity within the system that holds partial access rights to vehicle data and permissions to invoke vehicle control commands. Prompt injection can induce agents to execute unintended operations; a tampered third-party navigation plugin may act as a persistent Trojan horse leaking driving habits; benign hallucinations in Q&A scenarios can escalate to dangerous operations such as critical data deletion in proxy scenarios. What is even more thorny is the regulatory conflict: standards including ISO 26262, UN R155/R156, and GB 44495 mandate deterministic, predictable, testable, and traceable system behavior, while agents inherently feature non-determinism and emergent characteristics. The industry's solution is "empowerment rather than full delegation": deploy permission sandboxes and functional fences to restrict agents to infotainment and other low-risk domains; all vehicle control requests must be mandatorily arbitrated by a security middleware layer; high-risk operations must be confirmed via HMI, ensuring humans remain within the loop for all safety-critical decisions.
As attack surfaces evolve, defense mechanisms must advance in tandem. The industry's solution is straightforward: counter AI with AI.
Faced with the "spear" brought by AI, the industry must forge an even sharper "shield". For example, Anban Tech centers its new intelligent connected vehicle security paradigm on "AI large model-driven agent protection + vehicle communication protocol security + closed-loop supply chain security". It shifts security capabilities from traditional post-hoc patching to full-lifecycle proactive governance:
Leverage large models to parse full vehicle EE architecture documents, cross-model databases, and VSOC asset inventories via natural language, automatically identifying ECUs, sensors, communication interfaces, and other critical assets to map asset correlation frameworks. The LLM-powered intelligent TARA platform automatically generates security targets, security requirements, threat scenarios, and attack paths, enabling automated, visualized risk assessment.
During risk remediation, the platform combines impact severity, attack feasibility, and risk rating matrices to automatically generate remediation decisions and push work orders, forming an operational workflow of "AI detection - AI analysis - AI decision - AI closed-loop", drastically shortening vehicle security assessment cycles.
QAX AISOC is a representative example of this approach. It embeds 8 agents responsible for eight operational links: data collection, threat detection, intelligent judgment, intelligent investigation, intelligent response, incident eradication, optimization feedback, and report generation. Based on the OODA loop, it establishes an autonomous defense system transforming security operations from "human-initiated threat hunting" to "automated threat notification". Practical data demonstrates that a global luxury automaker utilizing AISOC has reduced the analysis and assessment time for a single alert to less than 9 seconds, with valid alert identification accuracy reaching 93.1%, a 2.7x improvement over traditional manual mode.
TARA, a traditional security analysis link, is also being rebuilt with AI. GoGoByte DefenseWeaver embeds the GoGoAI Agent, incorporating all new risk vectors such as models, training and inference data, prompt entry points, knowledge bases and tool invocation chains into the scope of TARA. Its judgment holds that risks stem not merely from code vulnerabilities, but also from misleading models, contaminated data and misused tools. This tool serves clients including FAW Bestune and Luxshare Precision, as well as national inspection institutions like CATARC, China Merchants Testing Vehicle Technology Research Institute and the CEPREI, boosting TARA efficiency by 80%. Callisto S3-TARA adopts a different approach: over ten agents work collaboratively to screen optimal solutions from 16 candidate Chains of Thought (CoT), supported by a data foundation built upon more than 100,000 causal chain datasets, over 3 million security scenario samples and over 1 million knowledge base Q&A pairs.
Automakers haven't been sitting idle, either. BYD's iDDog platform implements three AI agents targeting email phishing, terminal data leakage, and abnormal traffic, cutting security incident response time from 45 minutes to 5 minutes. Li Auto collaborated with Volcano Engine to develop an AI intelligent assistant capable of automatically creating work orders, scanning code, remediating vulnerabilities, and conducting re-verification upon receiving instructions in Feishu group chat, enabling one-stop closed-loop resolution with human authorization. AI native has transitioned from conceptual slogans to daily security operations.
Within the cybersecurity domain, traditional passive defense idea can no longer keep pace with rapidly evolving attack vectors. 206 automotive security incidents and 238 newly discovered vulnerabilities were recorded in 2025 alone. Threat actors have escalated objectives from data theft to intellectual property exfiltration, and even direct paralysis of production and manufacturing operations. Automakers therefore must build combat-ready cybersecurity systems with active threat hunting capabilities covering threat detection, analysis, response and remediation.
The solution proposed by defenders lies in systematic defense. Seres deploys a multi-layer in-depth defense architecture of "cloud-pipe-device-chip", collaborating with QAX to deploy intrusion detection systems across CAN bus, on-board hosts, and Ethernet layers. Its VSOC platform monitors about 200,000 vehicles and issues "cybersecurity compliance certificates" for vehicle models exported to EU. Its intelligent security system covers over 200 vehicle usage scenarios and more than 400 security functions. In April 2026, it released Security 4.0, evolving from passive and active safety to intelligent security.
Professional security providers have also upgraded their toolkits. ACT VSOC+, a next-generation intelligent connected vehicle security operation platform, embodies this philosophy. Powered by an AI streaming computing engine, it delivers a 500% performance improvement in threat detection, constructs a vehicle security digital twin modeling over 2,800 vehicle signals, and enables triple precise threat localization across ECUs, signals, and scenarios, shortening threat detection and response cycles from day-level to minute-level.
At the underlying protocol security layer, TICPSH's SmartRocket TestSec automated intelligent fuzzy penetration testing tool executes deep fuzzy attacks and penetration testing against mainstream vehicle protocols including SOME/IP, DoIP, and CAN/CAN FD to proactively uncover latent vulnerabilities, shifting the security defense line forward to the R&D testing phase. UniSentry Intelligent Technology's SecIC-HSM firmware serves nearly 30 OEMs, achieving AES throughput of 4.8Gbps on Infineon AURIX TC4X, enabling parallel execution of OTA update verification and secure on-board communication (SecOC) without interrupting CAN bus transmission. These solutions help automakers make the leap from mandatory compliance to proactive security.
Consensus has formed across OEMs and suppliers: isolated standalone security products cannot resolve systemic security issues, and multi-layer in-depth defense and active immune systems represent the correct solutions.
Data is the "blood" of intelligent vehicles, with its security spanning the full lifecycle of collection, transmission, storage, utilization, sharing, and destruction. The unique characteristic of automotive data security is that data carries both privacy and compliance attributes while directly supporting perception training, map services, model iteration, remote operations, and accident traceability. Improper collection, transmission, utilization, or tampering of data carries consequences extending far beyond regulatory fines, potentially exerting adverse impacts on vehicle behaviors.
On February 3, 2026, eight ministries including the Ministry of Industry and Information Technology and the Cyberspace Administration of China jointly issued the Guidelines for Outbound Transfer Security of Automotive Data (2026). The guidelines categorize outbound data into three tiers: general, important, and sensitive, while defining nine exemption scenarios including quality assurance maintenance data, OTA update data, and security vulnerability remediation materials. Clear filing thresholds are established: enterprises must conduct cross-border data transfer security assessments if transmitting important data overseas, or sharing personal information of over 1 million individuals / sensitive personal information of over 10,000 individuals with foreign entities. For China's automotive industry, which recorded a 65.3% year-on-year export growth in the first half of 2026, these guidelines eliminate the gray zone for cross-border data flows, shifting industry practices from tentative exploration to definitive compliance. Overseas regulation has simultaneously tightened: the 12-step GDPR compliance roadmap applies to export-focused OEMs; Japan's revised APPI Act introduces profit-based penalty calculations for the first time; South Korea's PIPA has entered a strict governance phase. Cross-border data flow governance has become a mandatory multi-jurisdictional compliance task.
Automakers have their own ways of responding. NIO's Sentry Mode remote view function implements end-to-end encryption and real-time data desensitization, automatically blurring license plates and human faces, with footage even NIO itself cannot decrypt, making it China's first OEM to deliver compliant remote view function. Its self-developed NPCC framework, the industry's first device-cloud integrated AI agent security framework, enforces "immediate data erasure post-computation" for sensitive data. Leapmotor adheres to an in-vehicle processing principle: in-vehicle cameras only collect feature points for local computing without cloud uploads, with all transmission traffic protected via AES-256 end-to-end encryption. ZEEKR's "Data Safe" system implements zero-trust tiered access control, activating data circuit breakers within 20 seconds upon detection of unauthorized abnormal access, with physical data destruction capabilities for storage media. Xpeng partnered with Alibaba Cloud to deploy post-quantum security algorithms on its new model P7, covering digital keys, remote vehicle control, and OTA for all vehicle modes.
"Remote View" in the "Sentry Mode" of NPCC (NIO's Industry-first Device-cloud Integrated AI Agent Security Framework)
Data security service providers have refined their solutions. Eagle Cloud Hub AI-DLP expands governance subjects from humans to dual entities of "human staff + AI staff", implementing unified identity management, consistent security policies, and standardized auditing for both, with refined control over data leakage vectors including external distribution, downloads, copying, and screen capture. Its clients include Geely Holding, Li Auto, Leapmotor, and Seres. Agile Technology's EDLP solution features an innovative architecture with deep integration of encryption and DLP. Starting from the source of data, it builds a full closed-loop prevention and control system covering "identification - classification - encryption - access control - audit", ensuring the security of core commercial secrets such as design drawings and R&D data amid the AI era. In May 2026, Agile Technology just won a 5,000-node data security project bid from a leader in the automotive industry.
For cross-border data compliance, CATARC delivers a full four-step service workflow: path planning - risk assessment - policy formulation - assessment declaration, enabling OEMs to clarify complete data flow routes and implement preventable, controllable, traceable compliance.
With clear trends identified, how to implement engineering? Drawing on the practices of leading companies, there are several actions automakers should take immediately:
Embed systems into core workflows rather than treating them as superficial compliance documentation. Build full-lifecycle CSMS/SUMS systems centered on ISO/SAE 21434 standards, shifting TARA threat modeling forward to concept and design phases to realize security left-shifting. Mandate SBOM and code security requirements for suppliers, cascading security accountability down via Cybersecurity Interface Agreements (CIA).
Transform VSOC (Vehicle Security Operations Center) from a mere alert dashboard into a core operations hub. Concrete efficiency improvement measures are as follows: shift alert governance from volume reduction to root-cause closed-loop management by tagging all alerts with root causes; replace static risk grading with dynamic weighting models; cut the 15-minute manual analysis time for each alert via one-click context encapsulation. Develop scenario-based emergency response cards and deploy semi-automated SOAR (Security Orchestration, Automation and Response) playbooks for high-frequency scenarios to auto-preserve evidence and generate reports automatically. Build an underlying vehicle security data center to eliminate the need for operators to log into five or six separate systems just to retrieve a single VIN. At the team level, establish SOP libraries and knowledge bases, and replace annual large-scale drills with regular small-scale practice sessions.
Implement full-link data security engineering. Data classification and grading serve as the foundation, with encryption, desensitization, access control and cross-border monitoring as core operational tools. Adopt a four-step workflow for cross-border businesses: route planning -> risk assessment -> policy formulation -> compliance declaration, shifting from ad-hoc project responses to normalized continuous operation.
Deploy AI in appropriate scenarios. Utilize AI TARA platforms to boost threat modeling efficiency, leverage AI SOC systems to reduce alert analysis overhead, and adopt digital twin technology to refine risk granularity, while enforcing permission sandboxes and functional fences for vehicle agents, retaining mandatory human approval gates for all high-risk operations.
Security development must shift from a "cost center" to a "core capability". Compliance serves as the foundation, while security operations determine the upper limit. As the industry advances deeper into the AI-defined vehicle era, this principle will grow increasingly weighty.
Definitions