Why Shouldn't Autonomous Driving Be Deployed Yet? Mobility Data Sovereignty and Hacking Risk

Autonomous driving is nearly ready technically. Even so, there are two reasons not to rush its deployment: data sovereignty, and a hacking risk that sits in an entirely different category from the accident risk of autonomous driving itself.

A note on this piece: This article is one opinion and proposal about the pace of autonomous-driving deployment. The corporate developments and budget figures cited reflect public reporting as of September 2026, and the situation may change going forward.

The premise: it's nearly possible technically

Let's start with the premise. Level 4 autonomous driving (full autonomy under specific conditions) is no longer a distant future technology. Japanese autonomous-driving software company Tier IV listed on the Tokyo Stock Exchange's Growth Market on July 22, 2026, raising ¥21.7 billion in what became the second-largest domestic IPO of the year. Major Japanese automakers -- Toyota, Suzuki, and Isuzu among them -- have invested in the company. Toyota and Tier IV are targeting Level 4 autonomous driving using the battery-electric "e-Palette" within fiscal year 2027, and Toyota has also stated a goal of putting Level 4 commercial vehicles into practical use by 2030.

In other words, the premise that "autonomous driving is nearly possible technically" is no longer seriously in question. The real issue is a separate one: when, and under what conditions, it should be deployed.

MLIT's budget and a risk-averse regulatory posture

In Japan's Ministry of Land, Infrastructure, Transport and Tourism (MLIT) FY2026 budget request, ¥327 million was allocated for "social implementation of Level 4 autonomous trucks." The Logistics and Automobile Bureau's overall request came to ¥76.2 billion, up 13.1% year over year. The figures are growing year by year, but they read more as funding for incremental demonstration projects than as a bold push to accelerate deployment.

Japan's regulatory and budgetary approach to autonomous driving has consistently shown a fairly cautious posture: building up demonstration trials step by step while minimizing risk. This likely connects to a broader Japanese tendency toward risk aversion, but this article isn't arguing that posture is wrong on its own. As the sections below will show, on at least one dimension -- security -- that caution has real merit.

The gap with the US and China, and Waymo's arrival in Japan

Commercial robotaxi service is already running in multiple US cities via Waymo (Google's self-driving affiliate), and several operators run commercial service in China as well. By contrast, Japanese automakers' own timelines for practical Level 4 deployment run from fiscal 2027 through 2030.

Interestingly, Waymo itself is now moving to enter the Japanese market at a pace that outstrips that domestic timeline. In September 2026, Waymo announced a partnership with Nihon Kotsu (a taxi operator) and GO (a taxi-hailing app) to launch a robotaxi service in Tokyo in 2027. GO will bridge the partnership into Japan's taxi industry, while Nihon Kotsu will handle fleet operations; the plan starts with a small fleet and scales toward roughly 100 vehicles. Since 2025, Waymo's vehicles have been manually driven by Nihon Kotsu drivers while collecting detailed 3D mapping data across Tokyo wards including Minato, Shinjuku, Shibuya, Chiyoda, Chūō, Shinagawa, and Kōtō. Toyota itself has also reportedly been considering entering the robotaxi business alongside Waymo.

In other words, Japan's autonomous-driving market currently has two parallel tracks: domestic automakers building their own technology, and a partnership with a foreign entrant (Waymo). This is precisely the structure that raises the concern this article wants to highlight: mobility data sovereignty.

Concern 1: mobility data sovereignty risk

The data collected by autonomous vehicles and mobility networks -- location data, actual driving behavior, sensing data (raw camera, LiDAR, and radar feeds) -- carries extremely high informational value. This isn't limited to ordinary personal information about users; it can include the layout of urban infrastructure, traffic patterns, and geospatial information with real security significance.

If a country deploys autonomous driving by depending on a foreign company's platform, without building the domestic technical capacity to collect, process, and retain this kind of data itself, it structurally risks having critical data accumulate and transfer abroad. This concern echoes the same territory that's been repeatedly debated in the context of economic security around critical-infrastructure data more broadly, well beyond autonomous driving specifically. Seen from this angle, a domestic autonomous-driving software company like Tier IV going public, backed by investment from Japanese automakers, carries real significance.

Concern 2: hacking risk sits in a category apart from accident risk

This is the article's core claim. Discussion of autonomous-driving safety tends to focus almost exclusively on "accidents caused by AI misjudgment." But autonomous vehicles and mobility networks equipped with IoT, communications, and tracking carry an entirely separate accident risk: hacking by a malicious third party. These two risks arise through fundamentally different mechanisms and need fundamentally different countermeasures -- they should be evaluated independently, not conflated.

The reality of this hacking risk has already been demonstrated. In 2015, security researchers Charlie Miller and Chris Valasek exploited a vulnerability in a Jeep Cherokee's in-vehicle infotainment system (UConnect), reachable over its cellular connection, to remotely control the steering, brakes, and transmission of a vehicle while it was being driven. In response, Fiat Chrysler (as it was then known) recalled 1.4 million vehicles. That incident became an industry landmark, demonstrating that a vehicle with complex software and connectivity can have its entire control system hijacked from a single vulnerability.

The current international regulation, UNECE WP.29's R155 (Cybersecurity Management System, CSMS) and R156 (Software Update Management System, SUMS), has applied to new vehicle types in the EU, UK, Japan, and South Korea since July 2022, and was extended to all vehicles produced in those markets from July 2024. Japan's MLIT has incorporated these requirements into its vehicle type-approval system.

On the limits of R155/R156: What these regulations actually require is "maintaining a management system (a process) for cybersecurity" -- not "technically guaranteeing that no vulnerabilities exist across all 7 layers of the OSI model, or all 4 layers of the TCP/IP model." Having a management process in place and actually having sufficiently eliminated vulnerabilities are two different things.

This article's position is that maintaining such management processes alone isn't enough. For the core software directly tied to safety -- especially the foundational parts of the vehicle-control and communication stack -- testing and audits aren't sufficient; they should require formal verification: mathematically proving that a program satisfies a specific property (for example, "no unintended state transition occurs within this input range"). Of course, proving that an entire complex real-world system is completely free of any vulnerability is, in practice, extraordinarily difficult. But at minimum, for the boundaries directly tied to safety -- communication entry points, privilege boundaries, the control paths that reach actuators -- the scope of what can be verified should be made explicit, with as much effort as possible put toward approaching a mathematical guarantee.

The important point is that completing this formal and security verification should be set as an explicit precondition, established separately from the conditions for practical deployment of autonomous driving itself. No matter how much an AI's decision-making capability improves, the risk of an accident caused by hacking remains, entirely independent of that. What this article is most concerned about is the possibility of conflating these two risks and concluding, prematurely, that "autonomous driving has become safe enough."

Summary

  • Level 4 autonomous driving is nearly ready technically, backed by Tier IV's IPO (July 2026, ¥21.7 billion raised) and Toyota's 2027-2030 deployment targets
  • MLIT's FY2026 budget increases autonomous-driving line items, but a cautious, step-by-step demonstration-based posture continues
  • Waymo plans to launch a Tokyo robotaxi service in 2027 with Nihon Kotsu and GO, running in parallel with domestic automakers' own deployment timeline
  • Concern 1: deploying without domestic capacity to handle mobility data (location, driving behavior, sensing data) risks structurally letting critical data flow abroad
  • Concern 2: hacking-caused accident risk sits in a category entirely separate from accidents caused by autonomous driving's own misjudgment, as the 2015 Jeep Cherokee hack demonstrated
  • Current UNECE R155/R156 regulation requires a security management process but doesn't itself guarantee technical elimination of vulnerabilities; the parts directly tied to safety need formal verification

Related article

A look at dual-use technology and engineering ethics, including coordinated vulnerability disclosure as a working example.

Read: Dual-Use Technology and Engineering Ethics