What hidden dangers of intelligent driving does the cross-border vehicle-locking controversy reflect?
Can you believe that a fully paid smart driving vehicle was completely locked immediately after leaving the country?
In July 2026, Mr. Liu, a car owner from Henan Province, was traveling on a planned cross-border self-driving trip in his fully paid ZEEKR vehicle. After entering Kazakhstan, the vehicle immediately triggered the manufacturer's remote risk control, and the infotainment system functions were restricted for more than 30 hours.
During the period of restricted risk control, the entire vehicle's intelligent system was completely paralyzed. The storage compartment and electronically controlled fuel tank cap could not be unlocked, leaving all personal documents and belongings trapped inside the car. The vehicle only retained the most basic mechanical driving capability, almost becoming a scrap car that could not be used normally.
ZEEKR, the automaker, responded: The vehicle's positioning showed it was in an overseas area, which triggered the built-in safety protection mechanism of the infotainment system. This mechanism is an anti-theft and anti-damage measure widely adopted in the industry, aiming to protect the property safety of car owners.
This short statement immediately ignited public opinion, making countless smart driving car owners sigh with emotion. We used to think that buying a car is a one-off property right transfer. After paying the full amount, completing all procedures, and getting the vehicle license, the car completely belongs to the buyer, and it is the car owner's full freedom to decide where to go and how to use the vehicle. But in the current era of software-defined vehicles, what car owners purchase may only be a time-limited, region-restricted and threshold-bound usage license.
Why do I not own the right to use the car that I paid for in full? Does the logic that applies to traditional fuel vehicles still work in the smart driving era?
Widespread Public Anxiety Triggered by a Single Car Locking Incident
It is widely believed that the vast majority of car owners hold a deep-rooted perception when purchasing a vehicle: after paying the full price and completing vehicle registration, the car is 100% their private property. From ancient times to the present, the core logic of motor vehicle transactions has always been the same: cash is exchanged for the vehicle on the spot, and once the hardware delivery is finished, the rights to use, dispose of and handle the vehicle all belong to the car owner, which is an unquestionable common sense of property rights.
However, this cross-border car locking incident has overturned this long-established perception.
The involved car owner purchased a domestic-spec vehicle with complete procedures and legal property rights. After the vehicle drove out of the Chinese border and entered the territory of Kazakhstan, it immediately triggered the automaker's cloud-based risk control mechanism. The intelligent functions of the vehicle were restricted in batches, with no advance notice, no temporary buffer mechanism, and no emergency unlock channel throughout the whole process. It should be clarified that this functional restriction is not caused by vehicle hardware failure, and the car owner has no violation of vehicle usage rules. It is purely a remote intervention triggered by the regional control rules preset in the automaker's backend system.
Stuck in an unfamiliar foreign country, with the infotainment system paralyzed, navigation failed, and all belongings trapped in the car, even refueling and supply replenishment were severely restricted. Smart vehicles, which are supposed to make travel more convenient, have now become shackles that restrain users. Is the vehicle transaction in the smart era still a complete transfer of ownership?
After the incident spread, public opinion across the entire internet heated up rapidly. Some netizens joked: Isn't this equivalent to buying the latest Apple smartphone that turns into a Nokia as soon as you go abroad? Others drew an analogy: Today's smart cars seem to be fully purchased, but their intelligent services are just like game accounts, with permissions always in the hands of the operator.
At the same time, some people can understand the automaker's consideration of setting up the risk control mechanism. Supporters believe that there are large differences in car prices and taxes at home and abroad. Fully opening up cross-border usage will easily give rise to the chaos of reselling for arbitrage, which will impact the brand's market order. In addition, different countries have different data compliance standards, the domestic infotainment system cannot adapt to overseas regulations, and restricting functions after leaving the country is a common operation for enterprises to avoid risks.
However, the core demands of more car owners and consumers have always focused on the two bottom lines of property right boundary and consumer right to know. Netizens generally believe that risk control and rights protection should distinguish the boundary of rights and responsibilities. If there are illegal acts such as smuggling and reselling vehicles, enterprises can completely pursue responsibility through judicial channels, and cannot directly use remote technical means to restrict the use of legal car owners' private property.
They worry that if automakers can lock the infotainment system and disable functions on the grounds of cross-border travel today, will they arbitrarily restrict the legitimate car usage rights of car owners tomorrow under the pretext of compliance, risk control or system upgrade?
After the incident spread, ZEEKR quickly made multiple rounds of public responses, and quickly launched a rectification plan: the self-service unlock entry of "Cross-border Protection" was launched on the App. When car owners encounter restricted infotainment system functions overseas, they only need to submit an application with one click to quickly get the verification code and complete self-unlocking. At the same time, the automaker simultaneously opened a 24-hour priority customer service channel for car owners traveling abroad, trying to fix the experience loopholes exposed by the risk control mechanism.
Although ZEEKR has launched emergency remedial measures, the issue of smart driving usage rights has triggered more intense discussions. Where is the legal boundary of automakers' remote control? When consumers buy smart vehicles, do they get full ownership, or only the hardware property right plus a limited-term software usage license?
Who Holds the Switch of Smart Driving Functions?
After the cross-border car locking incident was exposed, many people immediately tried to understand the logic behind the automaker's operation: why would a regular legitimate vehicle be forced to lock as soon as it leaves the country? Is the automaker's risk control rule a reasonable and compliant industry guarantee, or an excessive and overreaching power control?
Looking back at the whole incident with these questions, we will find that the automaker's risk control logic seems reasonable, but it hides many hidden problems that cannot stand scrutiny, which are also the most common permission chaos in the current smart driving industry.
From the business perspective of automakers, setting up regional risk control and building digital fences do have practical considerations. On the one hand, there are price differences and policy differences in the domestic and foreign automotive markets. The phenomenon of cross-border reselling of new cars and parallel arbitrage has been repeatedly banned, and regional risk control can effectively prevent the chaos of vehicle smuggling and protect the brand's global sales system. On the other hand, the on-board data compliance regulations and smart driving function access standards of different countries and regions are completely different. The domestically adapted intelligent system and data collection mode cannot meet overseas compliance requirements, and there will be compliance risks when used abroad. From the perspective of commercial risk control and compliant operation, it is understandable for automakers to set regional usage restrictions.
But the key problem is that the automaker did not inform users in advance or state in the user manual that driving out of the country will trigger the safety risk mechanism and lock the vehicle. Is it necessary to realize a reasonable risk control demand in a rude way that sacrifices the rights and interests of ordinary car owners? Is the original intention of risk control to avoid risks and standardize order, or to unilaterally override users' rights and interests?
In this Kazakhstan car locking incident, all the costs of risk control were borne by ordinary law-abiding car owners. The car owner was on a normal cross-border self-driving trip, with no smuggling, no violation of regulations and no breach of contract, but suddenly encountered infotainment system paralysis. During the restriction period of nearly two days, there was no emergency unlock channel and no quick verification process, users could only passively wait for the automaker's manual review and unlock, and had no right to speak throughout the whole process.
Looking back at the era of traditional fuel vehicles, after the transaction is completed and the vehicle is delivered, the handover of the key represents the complete transfer of the right to use. Automakers cannot remotely intervene in the operation of the vehicle, and the control of the vehicle is completely in the hands of the car owner. But "software-defined vehicles" has reconstructed the relationship of rights and responsibilities: consumers buy physical hardware such as the vehicle body, chassis and motor, while the infotainment system, smart driving programs, cloud backend and remote control switches all belong to the automaker.
Up to now, public opinion and capital have always been chasing the technical iteration, computing power upgrade and function update of smart driving, but few people face up to the imbalance of rights and responsibilities behind the technology. Every convenience brought by OTA upgrades comes with an unstated transfer of permissions; while every paid subscription service is activated, users also implicitly acquiesce to the automaker's deeper control over vehicle functions.
Automakers have enjoyed the profit dividend brought by software-defined vehicles, but have not yet established a corresponding user rights and interests protection system. All the technical conveniences seem to come with hidden permission shackles.
Furthermore, cross-border geographical restriction is just the tip of the iceberg. There are a series of permission risks with unclear boundaries hidden in the current intelligent connected vehicle and smart driving system.
In the Fast-growing Era of Smart Driving, Clearer Rights and Responsibilities Are More Needed
The reason why this seemingly ordinary cross-border car locking incident can spread rapidly, ignite the whole network and trigger collective empathy and heated discussions among countless car owners is not the single issue of "whether car owners can drive out of the country", but the reflection on the power of automakers.
Sorting out the current usage scenarios of intelligent connected vehicles, there are at least several types of permission disputes that have not been clarified: Should OTA upgrades obtain the explicit consent of car owners? Why do hardware that has been paid for in full require continuous payment to unlock functions? For massive data such as real-time location and driving behavior, do car owners have the right to know and intervene in its flow and usage?
These seemingly scattered problems point to the same root cause: the automaker's absolute control over the digital layer of the vehicle, and the core of the digital layer control is data.
Cross-border car locking needs positioning data to judge whether the vehicle has left the country; paid subscription needs to identify vehicle configuration and usage status to determine the permission switch; the push strategy and version adaptation of OTA upgrades also rely on continuous collection and analysis of vehicle operation data. However, the current data ownership pattern is unilaterally dominated by automakers.
These seemingly ordinary car usage experiences are essentially manifestations of the excessive expansion of automakers' permissions. Relying on cloud control rights, automakers have achieved absolute control over vehicle functions: they can arbitrarily adjust the open scope of smart driving functions, silently update system logic, restrict vehicle usage through account binding, and shrink intelligent services according to regional changes. Car owners spend hundreds of thousands of money to buy a car with a full set of tangible smart driving hardware, but they can never independently control the vehicle functions. Whether they can use the functions, how to use them, and which functions to use are all defined by the automaker's backend system.
When a privately purchased motor vehicle needs to rely on the manufacturer's cloud authorization at all times to be used normally, and when car owners cannot fully and independently control their own private property, the so-called ownership becomes a dead letter.
It can be said that this car locking incident after leaving the country has sounded the alarm for the entire smart vehicle industry. The maturity of smart driving is not only the maturity of technology, but also the maturity of rules, the maturity of rights and responsibilities, and the maturity of respecting users' rights and interests.
Technology can iterate infinitely, but power must have boundaries. In the future, automakers need to abandon the one-way control thinking, find a balance between risk control and user rights and interests, and establish a transparent, predictable and buffered permission mechanism. The regulatory authority also needs to fill the gaps in rules, clarify the red line of automakers' remote control, and clarify the boundary between hardware ownership and software usage rights.
This article is from the WeChat official account "Fantasy Auto", author: Shanhu, published with authorization from 36Kr.