Dispatch
R155 treats your backend as part of the vehicle. Can you prove it's governed?
UNECE R155 treats telematics and fleet servers as part of the vehicle attack surface. Those servers now run AI agents. Vantio helps you see and control them.
#AIAgents #AutomotiveCybersecurity #UNECE #PhysicalAI #Vantio #PhantomEngine #AgentSecurity
Vantio Newsroom
Vantio AI, Inc.
UNECE R155 does something most people miss: it explicitly treats the IT backend — your telematics platform and fleet servers — as part of the vehicle's attack surface. Those servers increasingly run AI agents. Vantio helps you see and control them.
The questions AV teams are actually asking
Autonomy is a compute problem as much as a driving problem. On-vehicle brains and fleet-coordination servers now run AI agents that call models, move telemetry, and act. The recurring questions:
- R155 Part C covers our backend. Can we demonstrate the AI agents on our fleet servers are observed and governed?
- Where is fleet telemetry actually going, and which external models are our agents calling?
- If an agent misbehaves on a coordination server, what stops it before it touches the fleet?
- Can we produce the ongoing evidence R155 asks manufacturers to keep current?
The landscape: binding regulation, already in force
This is the most heavily regulated market on our list, and the rules are not optional. UN Regulation No. 155 (Cyber Security Management System) and R156 (Software Update Management System) have been mandatory for all new vehicles in UNECE markets since July 2024 — across the EU, UK, Japan, South Korea, and 60-plus contracting parties. No valid CSMS certificate means no type approval, and no sale.
R155's annex is unusually concrete. Part A catalogs threats, Part B the mitigations inside the vehicle, and Part C the mitigations outside it — including the IT backends that telematics and update servers run on. Approval is not a one-off: manufacturers must keep monitoring for new attacks and report to the approval authority at least annually. ISO/SAE 21434 defines much of the process "how."
And the frontier just moved. In January 2026 the UNECE GRVA adopted a draft global regulation on Automated Driving Systems that would allow deployment of vehicles with no driver supervision — with data-collection provisions still being finalized. As unsupervised autonomy arrives, the compute governing it — and the evidence trail behind it — becomes a market-access requirement, not a nicety.
Where the real risk lives — the compute you own
Vantio does not certify your safety-critical control loop — that is a regulated engineering discipline of its own. We protect the general-purpose Linux compute around it: the fleet-coordination servers and analysis hosts where AI agents, planners, and data pipelines run. Reported automotive cyber incidents rose sharply between 2018 and 2023; the backend is squarely in scope.
For AV teams the hardest questions are about data and outbound behavior. A coordination server touches every vehicle, so a single misbehaving or compromised agent has fleet-wide reach. Knowing where agents connect, stripping sensitive telemetry, putting a ceiling on spend, and stopping a forbidden move on Linux you enroll is exactly the Part C story — made operational.
How Vantio answers these questions
For an AV program, Optics gives you the honest backend picture R155 assumes you have. Gate applies destination, redaction, and spend rules on that path. Phantom Engine protects coordination servers you enroll. Enterprise governance adds the durable ledger when annual evidence has to travel.
What Vantio does — and does not — do
- Does: observe and govern AI and LLM agents on fleet-coordination and analysis servers — the backend R155 Part C treats as in-scope.
- Does: produce connection-and-decision evidence that maps to the assessment themes R155 and ISO 21434 auditors expect.
- Does not: provide R155 type approval or a CSMS certificate — Vantio is product evidence that supports assessment, not a certification.
- Does not: govern the vehicle's safety-critical ECUs or ADS control loop — that is your functional-safety domain.
Get started
Optics is free visibility inside the agent process you wrap. Gate applies the rules you set. Phantom Engine protects Linux hosts you enroll — a Helm DaemonSet on Kubernetes you operate, or a Linux daemon on standalone machines. Talk to sales when you need governance on top.
Sources
- UNECE vehicle regulations — R155 (CSMS) and R156 (SUMS)
- ISO/SAE 21434 — the process framework R155 references
- UNECE GRVA draft global ADS regulation (January 2026)