Polestar, connected car cybersecurity and geopolitics

Staff
By Staff
4 Min Read

Just yards from the Leicester Tigers rugby ground, and within sight of both Sandicliffe and Vertu dealerships, a new Polestar dealership has opened its doors, writes Professor Jim Saker, president of the Institute of the Motor Industry.

On the face of it, there is nothing particularly remarkable about another automotive retailer joining one of the UK’s established automotive clusters. Yet the timing of the opening is difficult to ignore.

It comes as the United States has announced that it has effectively blocked Polestar from selling new vehicles from the 2027 model year onwards, following the US Commerce Department’s decision not to authorise the company under its Connected Vehicles regulations.

Technology linked to China and Russia

The American rules mark a significant change in the way governments are beginning to view the modern car.

The connected vehicle is no longer simply a means of transport; it is a computer on wheels, capable of collecting data, communicating with external systems and receiving software updates throughout its life.

The US regulations place particular emphasis on the potential national-security risks associated with connected-vehicle technology linked to China and Russia, including questions of ownership, control and the provision of software and hardware.

That approach contrasts sharply with the direction being taken in the UK.

Cybersecurity, software governance, safety

Questions have already been raised in Parliament about the potential risks posed by Chinese and Russian technology in connected vehicles. In response, the Government has said it is working with the Department for Transport, the National Cyber Security Centre and other departments to assess the risks associated with connected vehicles, including electric vehicles.

Rather than immediately adopting US approach, however, the UK has so far concentrated on cybersecurity, software governance and vehicle safety through the implementation of UN Regulations 155 and 156.

R155 establishes requirements for vehicle cybersecurity, including the identification, assessment and management of cyber threats. R156 introduces requirements governing software updates throughout a vehicle’s life, including the systems manufacturers must have in place to ensure that those updates are secure, controlled and properly managed.

Together, the regulations represent a fundamental shift in automotive regulation. The car is no longer being treated solely as a mechanical product; it is increasingly recognised as a connected, software-defined system that can evolve long after it has left the showroom.

Ironically, these requirements came into force for new vehicle types in Great Britain on June 1 this year, yet their significance has received remarkably little attention outside the specialist cybersecurity and regulatory sectors.

Who controls the technology?

The distinction between the British and American approaches is important. The US framework is concerned not simply with whether a vehicle is technically secure, but with who controls the technology and where that control originates.

The UK’s regulatory model, by contrast, is principally concerned with whether the vehicle and its supporting systems can demonstrate appropriate levels of cybersecurity, software governance and safety.

If governments are increasingly prepared to regard connected vehicles as potential national-security assets or liabilities, should the UK be considering a broader approach that goes beyond technical cybersecurity certification?

R155 and R156 ask an important question: is the vehicle secure?

The Americans are asking another: who ultimately controls the technology inside it?

As the distinction between the car, the computer and the connected network continues to disappear, that second question may become impossible for our industry to ignore.

Author: Professor Jim Saker, president, Institute of the Motor Industry

Ensure you always receive AM insights. Make us a preferred source of news on Google

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *