Regulatory Framework
The regulatory surface for L4 and L5 deployment is now multi-jurisdictional and converging on common architectural expectations. SAE J3016 establishes the level taxonomy and the operational design domain (ODD) construct, with L4 defined by autonomy within a declared ODD and L5 defined by autonomy across all conditions a competent human driver could handle. NHTSA's Standing General Order on Crash Reporting and the AV TEST Initiative establish federal expectations for incident reporting and operational transparency. Functional-safety obligations are governed by ISO 26262 for E/E systems and extended by ISO 21448 (SOTIF) to address the limitations of intended functionality, including the foreseeable misuse and triggering-condition envelope that L4/L5 systems must demonstrate they have characterized. Cybersecurity obligations are governed by ISO/SAE 21434 with type-approval consequences under UNECE WP.29 R155.
Operational authority is granted at the state and national level. UNECE WP.29 R157 (Automated Lane Keeping Systems) establishes the type-approval baseline for automated driving in Contracting Parties and is the architectural precedent for higher-level rulemaking. The California Public Utilities Commission Phase 1 Driverless Deployment program, the California DMV autonomous-vehicle permitting framework, and the Texas, Arizona, and Nevada operational regimes each issue authority that is contingent on continued conformance with declared operational parameters. The European Union AI Act classifies driving-automation systems under Annex III as high-risk AI, imposing post-market monitoring, serious-incident reporting, and human-oversight obligations that operate alongside type approval. Across these regimes, the regulator's instrument of authority is increasingly fine-grained: route-restricted authority, time-of-day-restricted authority, weather-restricted authority, supervisor-presence-restricted authority. The architectural assumption that the actuation layer is binary is now in active tension with the regulatory assumption that authority is graduated.
Architectural Requirement
The architectural requirement that follows is a single one with several aspects. The execution layer of an L4/L5 stack must be capable of operating in modes that correspond to the granularity of regulatory authority. A vehicle authorized for full ODD operation under nominal conditions, restricted operation pending a fleetwide investigation, route-restricted operation in a specific city, or remote-supervised operation following an incident must each correspond to a structural mode of the actuation gate, not to a fleet-management overlay that deactivates the system entirely outside its narrowest authority. The selection of mode must be driven by composite admissibility, a function over the credentialed observations available to the vehicle at the moment of action, evaluated against credentialed governance policy issued by the relevant authority.
The architectural requirement extends to cross-system visibility. WP.29 R157 already requires data-storage-system-for-automated-driving (DSSAD) records that an authority can audit. SOTIF expects characterization of the triggering-condition envelope and demonstration that the system reduces residual risk to acceptable levels. The EU AI Act expects post-market monitoring that detects emerging risk before it manifests. None of these obligations are satisfied by a binary actuation log. They require that the authorization state of the fleet, current mode, recent mode transitions, the credentialed observations and governance evaluations that drove each transition, be observable to the authority and to neighboring fleet units in something close to real time. Propagating the confidence governor's authorization state across the fleet through a shared, credentialed context is the architectural form that obligation takes.
Why Procedural Compliance Fails
The dominant industry pattern has been to layer procedural overlays onto fundamentally binary actuation. Operational design domain definitions are documented in policy manuals and enforced through pre-trip checks; incident response is handled through fleet-wide remote disable; regulatory restrictions are translated into geofencing and route-blacklisting at the mission-planning layer. Each of these is a procedural workaround for the absence of a structural primitive, and each fails under predictable pressure. ODD enforcement at the mission-planning layer cannot adjudicate edge cases that develop mid-mission, a fog bank rolling in, a construction zone appearing, a sensor degradation that crosses an ambiguous threshold, because the actuation gate downstream is binary and cannot accept a partial answer.
Incident response illustrates the failure most starkly. When a driverless fleet has produced a serious pedestrian incident, the documented regulatory outcome has been a fleet-wide operating-permit suspension, because there was no architectural mode between full deployment and full halt. The regulator's reasonable instrument, restrict the fleet to specific routes, require a remote supervisor for a defined period, require enhanced post-event reporting until a corrective action lands, was not consumable by the actuation layer. The fleet's choices were continued full operation or full suspension, and the regulator selected the only non-catastrophic option available. The same pattern repeats at smaller scale across operating L4 fleets whenever a state DOT, a city authority, or a federal investigator wishes to apply graduated pressure. Procedural compliance fails because the actuation primitive does not admit graduation, and graduated authority is what the regulator now requires.
What the Confidence Governor Provides
The confidence governor of United States Patent Application 19/647,395 treats execution as a revocable permission rather than a default assumption, and gates it on a confidence value that is a first-class computed state variable rather than a heuristic score. The disclosure computes that value from agent-state and task-state inputs, and for embodied agents that drive physical actuators it incorporates sensor reliability inputs (the accuracy and reliability of visual, proximity, force-torque, and proprioceptive sensing), so that degraded perception lowers confidence in the ability to act safely. The value is continuous, capturing gradations of sufficiency that the governor uses to implement graduated gating rather than a single on-off decision.
Applied to a driving stack, the actuation gate inherits the disclosure's three authorization states. In the authorized state the confidence value is above the authorization threshold and the trajectory triggers no alarm, and full actuation is permitted. In the suspended state the confidence value has fallen below the authorization threshold, or trajectory projection has triggered a pre-emptive suspension, and actuation is prohibited while cognition continues in a non-executing cognitive mode where the stack may forecast, plan, and inquire rather than act. In the locked state a governance-mandated halt has occurred and recovery requires external authorization. The disclosure further specifies, for embodied agents, a physical safety floor that is set higher than the general authorization threshold and that cannot be overridden by the agent's own deliberation or by delegation commands from a parent; below it the agent transitions to a predefined safe physical state in which actuators are brought to a controlled stop. These are the structural modes that an L4 actuation gate exposes, in place of the binary permit-or-halt primitive.
Mode selection is driven by composite admissibility evaluated against credentialed governance policy. The composite is computed from the observations available at the moment of action: perception confidence, localization integrity, sensor-health attestation, environmental-condition envelope, ODD residency, recent-incident state, supervisor-presence credential, route credential, and authority-policy credential. The selection is deterministic, not a heuristic, and a tampered policy or a forged observation is not admissible into the evaluation. Two consequences follow. First, a regulator can express graduated authority as policy that the actuation layer consumes directly, without a procedural overlay. A state DOT issuing route-restricted authority pending investigation issues a credentialed policy that admits full actuation on the approved routes and supervised or suspended operation elsewhere; a federal investigator imposing enhanced post-event reporting issues a policy that admits full actuation but requires confidence-state broadcast at finer granularity. The vehicle, the fleet operator, and the authority share a single object, the policy, that determines what the actuation layer will do.
Second, the disclosure's multi-agent confidence propagation makes a vehicle's authorization state observable beyond the vehicle. In the cited application, agents publish their confidence to a shared confidence context and incorporate the confidence of their peers into their own computation, and a parent agent's suspension propagates to its children. Mapped onto a fleet, a vehicle that enters suspended operation following a sensor degradation broadcasts that transition; neighboring vehicles consume it as a credentialed observation that may modulate their own admissibility evaluation; and the authority receives the same state through its credentialed channel without a separate fleet-management integration. The recovery of authorization carries the disclosure's hysteresis: the confidence value must exceed the authorization threshold by a configurable margin before a vehicle returns to a less restricted mode, so that a fleet does not oscillate between authorized and suspended operation when conditions fluctuate near the threshold.
Harm ordering enters through the same evaluation rather than as a separate ethics layer. The disclosure's composite admissibility evaluation integrates signals from a plurality of cognitive domain fields under policy-specified weights; in the driving application those weights are an authority-issued credential the operator can refine within authority constraints, for example a jurisdictional preference for protecting vulnerable road users above smooth flow under degraded conditions, or for elevating remote-supervisor confirmation above autonomous decision under ambiguous pedestrian intent. Harm ordering is a credentialed input to the same gate, not a parallel mechanism operating outside it.
Compliance Mapping
The mapping from confidence-governed actuation to specific regulatory artifacts is direct. WP.29 R157 DSSAD records are emitted as the actuation-state stream, with each mode transition bound to the composite-admissibility evaluation, the credentialed observations that drove it, and the governance policy under which it was authorized. The auditor's question of whether a specific actuation was within the type-approved envelope is answered by reading the record rather than reconstructing it. ISO 21448 SOTIF triggering-condition characterization is supported structurally: the modes that the system enters under degraded perception, degraded localization, or out-of-ODD conditions are observable in the actuation-state stream, and the residual-risk argument is grounded in the recorded distribution of mode transitions across operational hours.
ISO 26262 functional-safety claims are unaffected at the lower levels and strengthened at the system level, because the safety case can reference the actuation gate as a structural element rather than as a procedural assertion. ISO/SAE 21434 cybersecurity obligations are met by the credentialing of governance policy and observations: a tampered policy or a forged observation is not admissible into the composite-admissibility evaluation. NHTSA Standing General Order incident reporting is satisfied by a scoped query over the actuation-state stream around the incident time, including the modes the vehicle was in, the policies under which those modes were authorized, and the observations that drove transitions. CPUC Phase 1 Driverless Deployment reporting and California DMV operational reporting consume the same stream under the policies the relevant authority has issued. EU AI Act post-market monitoring and serious-incident reporting under Annex III are scoped queries over the same stream filtered by the EU operator's policy envelope.
Adoption Pathway
The adoption pathway is brownfield-compatible and incremental. The first phase introduces actuation-state recording: every actuation decision in the existing stack emits a credentialed observation describing the current mode (initially binary), the composite of observations that supported the decision, and the policy under which it was taken. No mode graduation is yet exposed, but the stream and the credentialing are now in place, and DSSAD-, SOTIF-, and SGO-aligned reporting can already be served from the stream rather than from ad-hoc telemetry. The second phase introduces graduated modes for a constrained slice of the operational envelope, typically the modes corresponding to perception or localization degradation, where the safety case is most clearly improved by stage-gated or supervised operation rather than by binary disengagement.
The third phase introduces credentialed governance policy as a first-class operational input. The authority, state DOT, federal investigator, EU type-approval authority, issues a policy object that the fleet loads, and the actuation layer consumes the policy directly in admissibility evaluation. This is the phase at which graduated regulatory authority becomes architecturally available: route-restricted, time-restricted, supervisor-restricted, and weather-restricted modes are not procedural overlays but credentialed-policy-driven mode selections. The fourth phase opens propagation of the authorization state to neighboring fleet units, V2X infrastructure, and the authority's monitoring channel through the shared credentialed context, completing the cross-system visibility that the EU AI Act and the post-WP.29-R157 rulemaking trajectory expect. At the end of the pathway, the operator's relationship with regulators is mediated by a shared, credentialed substrate; an incident produces a policy adjustment rather than an operational catastrophe; and the commercial path from constrained L4 deployment to broader L4 and eventually L5 operation runs through accumulating policy-mediated authority rather than through binary regulatory boom-bust cycles.
Disclosure Scope
This article is an application of the confidence governor disclosed in United States Patent Application 19/647,395. The technology it relies on, confidence as a first-class computed state variable; execution as a revocable permission; the three authorization states (authorized, suspended, and locked); the non-executing cognitive mode; trajectory-based pre-emptive suspension; hysteresis on recovery; the physical safety floor and safe physical state for embodied agents; composite admissibility against credentialed policy; and multi-agent confidence propagation through a shared confidence context, is described in that application and is not reproduced or extended here. The automated-driving deployment scenarios, the regulatory mappings to SAE J3016, UNECE WP.29 R157 and R155, ISO 26262, ISO 21448 (SOTIF), ISO/SAE 21434, the NHTSA Standing General Order, the EU AI Act, and the state and national permitting regimes, and the four-phase adoption pathway are an enabling application of that disclosure to the L4 and L5 automated-driving domain. Where this application draws on credentialing and policy-evaluation mechanisms, those mechanisms are likewise grounded in the cited application. Nothing here should be read to disclose driving-stack mechanisms, thresholds, latencies, or numerical benchmarks beyond those traceable to United States Patent Application 19/647,395.