La stratégie L2++ à L4 de NVIDIA : la plateforme, l'architecture et ce qui est déjà en production
If you’re evaluating NVIDIA DRIVE as a platform decision, not just a component choice, this article gives you the system-level view. We cover what L2++ actually delivers in production today, how the Hyperion platform scales from L2++ to L4 on a consistent software and integration architecture, and why the choices that look like constraints are actually deliberate strategy.
Le L2++ est déjà en production
Au premier trimestre 2026, Mercedes-Benz a lancé la production en série de la nouvelle CLA. Il s'agit d'un véhicule grand public capable de naviguer de point à point sur les autoroutes, les zones périurbaines et dans un trafic urbain dense – sans lidar, sans cartes HD préconstruites et avec une puce unique consommant moins de 45 W.
Il ne s'agit pas d'un véhicule conceptuel ni d'un programme pilote – c'est en production aujourd'hui.
L2++ is a widely used industry term for highly advanced consumer driver assistance, and NVIDIA’s implementation of it is a fundamental rethink of how autonomous driving software is built. And it scales directly to the L4 robotaxis that Uber and Mercedes-Benz plan to operate in San Francisco and Los Angeles by H1 2027.
The CLA earned Euro NCAP’s Best Performer award for 2025. It runs on NVIDIA Hyperion – a scalable reference platform designed to take the same architecture from L2++ all the way to L4. The L4 configuration, Hyperion 10, runs on roughly 8× the compute (dual Thor SoCs at 1,000 INT8 TOPS each), adds lidar, and is already committed to multiple OEM programmes.
Même plateforme, mais plus de puissance de calcul, plus de capteurs et un modèle de responsabilité différent.
Ce que le L2++ apporte concrètement
Traditional L2 maps detected objects to predefined responses. NVIDIA’s L2++ works differently. It navigates point-to-point through urban environments, handles dynamic obstacles with context rather than reflexes, executes unprotected turns, and tracks multiple actors simultaneously.
In a live demonstration through San Francisco, the system spotted double-parked delivery vehicles and worked out the gap and timing to get through – it didn’t just flag an obstacle. It yielded when a vehicle reversed towards it, avoided an open car door, and completed an unprotected left turn while managing oncoming traffic and a crossing pedestrian at the same time.
Dans des conditions normales, la pile neuronale de bout en bout génère la trajectoire active la plupart du temps. La pile classique fonctionne parallèlement à elle comme une frontière de sécurité appliquée en continu, et non comme un mécanisme de secours attendant que l'IA échoue.
Découvrez pourquoi investir dans un centre de delivery IA externalisé est une bonne idée >>
Eliminating lidar cuts the bill-of-materials enough to deploy this in a mainstream consumer vehicle. Dropping pre-built HD maps removes geographic fencing entirely – the system works in cities that have never been pre-mapped. Instead, the classical stack builds an HD map on the fly from raw camera input and navigation data: lane lines, connectivity, direction-of-travel, traffic light rules, and turn-lane associations – all generated on board, at runtime.
The driver interaction model is just as intentional. The driver can apply steering input mid-manoeuvre and the system doesn’t disengage. It treats the input as cooperative, keeps operating, and resumes full authority when you take your hands off the wheel. There’s no engage/disengage cycle; the driving software stays active throughout.
Cette configuration L2++ est déjà en production dans la Mercedes-Benz CLA. Jaguar Land Rover suivra à partir de 2026, avec d'autres programmes de constructeurs déployés sur la plateforme jusqu'en 2028.
L'architecture qui le rend possible
Hyperion
At the centre of NVIDIA’s automotive offer is DRIVE AV: the full autonomous driving software stack. Hyperion is the production-ready reference platform built around it, combining validated compute hardware, a qualified sensor suite, and a defined integration boundary against the host vehicle. OEMs can build directly on Hyperion or work with NVIDIA on a fully customised implementation – as Mercedes-Benz, JLR, and Lucid are doing.
Trois configurations partagent une même lignée architecturale :
| Configuration | Calcul | Caméras | Radar | Lidar | Niveau |
| CLA (L2++) | 1× Orin – 254 TOPS | 10 | 5 | – | L2++ |
| Hyperion 8 | 2× Orin – 508 TOPS | 12 | 9 | 1 | Développement L4 |
| Hyperion 10 | 2× Thor – 2×1 000 TOPS | 14 HD | 9 | 1 | Production L4 |
The shared architecture is what makes the L2++ to L4 path realistic. An OEM that has already validated sensor mounting, time synchronisation, calibration, and harness routing for Hyperion 8 doesn’t need to redesign the integration for Hyperion 10. Same E/E architecture, but with scaled compute and sensors.
DRIVE OS
Beneath DRIVE AV sits DRIVE OS – TÜV SÜD-certified to ISO 26262 ASIL D, ASPICE-compliant, and aligned with ISO/SAE 21434 for cybersecurity engineering. It provides a deterministic, certifiable execution environment for the AV stack and exposes the heterogeneous compute of Orin and Thor to higher-level software.
Le silicium sous-jacent va encore plus loin : DRIVE AGX Orin détient sa propre certification ISO 26262 ASIL D au niveau de la puce, ce qui réduit considérablement la charge de justification en matière de sécurité pour les OEM qui s'appuient sur la plateforme. Thor suit le même parcours de certification.
Les éléments qui comptent le plus au moment de l'intégration :
- Hyperviseur avec isolation du système d'exploitation invité. NVIDIA’s Type-1 hypervisor runs QNX and Linux simultaneously in isolated partitions: QNX as the ASIL-D certified safety partition, Linux as the compute partition running the AI/ML stack, DriveWorks, and TensorRT. This lets you host ADAS, IVI, cluster, and DMS workloads on the same SoC without compromising the safety case.
- NvMedia et NvStreams. NvMedia loads camera frames straight into GPU memory with no buffer copies and no added latency. NvStreams extends that zero-copy guarantee across the GPU, DLA, PVA, and image signal processors. The result is a deterministic perception pipeline, which is a precondition for any credible ASIL argument.
- Redondance hétérogène. Les charges de travail critiques peuvent s'exécuter sur différents types de processeurs – un chemin de perception principal sur le GPU et un chemin redondant plus léger sur le DLA, réduisant le risque qu'une seule défaillance de silicium élimine entièrement la fonction.
- Continuité CUDA et TensorRT. Les mêmes API fonctionnent depuis l'entraînement sur le cloud DGX jusqu'à l'inférence embarquée dans le véhicule. Les modèles sont déployés dans le véhicule sans réimplémentation, ce qui garantit la cohérence du comportement entre l'entraînement et l'inférence.
La double pile et le Safety Force Field
DRIVE AV exécute deux piles de conduite parallèles en même temps, avec une priorité de sécurité définie mathématiquement au-dessus des deux :

The classical stack gives you a certifiable safety envelope – formally analysable, traceable to ISO 26262 work products. The end-to-end stack handles the long tail of real-world edge cases that rules can’t enumerate. Both stacks produce candidate trajectories simultaneously. An arbiter picks the safer and more comfortable one, with the SFF providing the hard outer bound.
Halos : la sécurité comme propriété transversale
Au-dessus de DRIVE OS et de la double pile se trouve Halos. C'est le cadre de sécurité global de NVIDIA, organisé en trois niveaux :
| Niveau | Périmètre |
| Technologie | SoC ASIL D + DRIVE OS + Hyperion (plateforme) ; API de données de sécurité, pile modulaire + E2E (algorithmique) ; jeux de données sélectionnés, évaluation automatisée, volant d'inertie des données (écosystème) |
| Développement | Contraintes de sécurité à la conception lors de l'entraînement des modèles ; moniteurs d'exécution au déploiement ; rejeu et simulation à grande échelle à la validation |
| Calcul | DGX (entraînement cloud) + OVX (simulation Omniverse) + DRIVE AGX (déploiement véhicule) – les trois font partie du système de sécurité ; les preuves de validation sont générées sur les trois. |
One of its applications is the Safety Force Field (SFF), which sits downstream of both stacks as the last override before actuation. It’s a physics-based policy layer that computes a zero-collision envelope frame-by-frame. It’s mathematically deterministic (braking and steering evaluated jointly, not separately) and it overrides any upstream output that would breach the envelope.
La sécurité ici n'est pas ajoutée au moment de l'intégration. C'est une propriété de la triade cloud-simulation-véhicule. Si vous entraînez hors plateforme et importez des modèles sans revalidation OVX, le dossier de sécurité s'effondre.
Une décennie de croissance de la puissance de calcul
The DRIVE platform has grown roughly 500× in TOPS at single-chip level since 2015 – from the original Drive PX (~2 TOPS, Maxwell) through Xavier (30 TOPS, Volta + DLA, 2017), Orin (254 TOPS, Ampere, 2022), to Thor (1,000 INT8 TOPS / 2,000 FP4 TOPS, Blackwell, 2025).

Two moments stand out. Xavier (2017) was the first NVIDIA chip designed from scratch for production AV. It introduced the DLA, a fixed-function neural-network accelerator separate from the GPU. Atlan, the planned Ada Lovelace-based AV chip announced in 2021, was cancelled in September 2022 in favour of jumping directly to Thor (Blackwell) – a clear signal of how fast the post-Ampere AI compute roadmap moved.
Thor (2025) consolidates all vehicle compute domains onto a single SoC: autonomous driving, parking, driver and occupant monitoring, instrument cluster, infotainment, rear-seat entertainment. It pairs an ARM Neoverse V3AE CPU with a Blackwell GPU, integrates a Transformer Engine for LLM- and VLA-class workloads, and uses NVLink-C2C for chip-to-chip bandwidth in dual-Thor Hyperion 10 configurations. Hardware partitioning keeps the ASIL D ADAS workload and the QM-rated infotainment workload isolated on the same die.
Thor makes centralised, software-defined-vehicle compute possible. It replaces the distributed ECU topology that’s defined automotive E/E architecture for decades. That transition is its own multi-year programme, separate from the AV stack running on top.
L4 : ce qui est engagé et quand
Avant les échéances, la définition importe. Le L4 désigne un système qui gère toutes les tâches de conduite dans un domaine de conception opérationnelle spécifique – une zone géographique délimitée, des conditions définies, sans intervention humaine requise.
La feuille de route commerciale de NVIDIA saute entièrement le niveau L3. La raison est pratique : le L3 exige que le conducteur soit prêt à reprendre le contrôle instantanément sans surveiller activement. Ce problème de responsabilité lié à la reprise du contrôle a tenu la plupart des constructeurs à l'écart.
Honda’s world-first L3 approval in 2021 covered just 100 lease-only vehicles in Japan. Mercedes-Benz’s Drive Pilot is one of the very few OEMs globally to have taken on L3 liability. NVIDIA positions L2++ and L4 because both have clean liability models – L2++ keeps the human actively in the loop, L4 takes full responsibility within a defined ODD. L2++ and L4 both have clear answers to ‘who’s responsible’. L3 doesn’t, and that’s why NVIDIA skips it.
Ce que le L4 exige au niveau architectural au-delà du L2++ :
- Calcul redondant : 2× Thor plutôt que 1× Orin
- Le lidar ajouté comme voie indépendante de validation de la perception
- Cartes HD certifiées pour la sécurité avec une étape de vérification manuelle
- Halos OS comme couche de système d'exploitation de sécurité embarquée
Déploiements engagés avec des partenaires nommés et des calendriers publics :
| Partenaire | Véhicule / rôle | Calendrier |
| Mercedes-Benz | Classe S – robotaxi premium | Annoncé en janvier 2026 |
| Uber | Opérations de flotte – LA + San Francisco | H1 2027 |
| Uber | Expansion mondiale – 28 villes, 4 continents | 2028 |
| Stellantis | K0 Van + STLA Small – 5 000 unités | SOP 2028 |
| BYD, Geely, Isuzu | Véhicules L4 sur pile NVIDIA complète | 2025+ |
| Nissan | robotaxi L4 (matériel Hyperion + logiciel Wayve) | Pilote Uber à Tokyo, fin 2026 |
| MCP | Tous les nouveaux véhicules sur la plateforme DRIVE | À partir de 2026 |
| Lucid | Gamme de véhicules électriques de taille moyenne – DRIVE AGX Thor | Fin 2026 |
Plus de 20 des 30 plus grands fabricants mondiaux de véhicules électriques ont adopté DRIVE Orin. Chaque OEM de la plateforme alimente le volant d'inertie des données partagées. C'est un effet de réseau où les capacités de la plateforme se cumulent, quel que soit le partenaire qui croît le plus rapidement.
Le développement piloté par l'IA dans le secteur de l'innovation
Découvrez comment nous pouvons vous aiderCe que cela signifie pour vous
Hyperion gives OEMs and Tier 1s a validated path from today’s L2++ production reality to committed L4 deployments, on a consistent software and integration architecture. The L2++ choices that may look like limitations (no lidar, no pre-mapped HD maps, online map construction, cooperative driver interaction) are the conditions that make mainstream deployment possible.
Understanding the platform at this level matters most when you’re deciding whether to build around it, integrate into it, or validate against it. That decision gets harder (and the safety obligations get more complex) once AI-based components enter the stack.
Partie 2 de cette série d'articles couvre exactement cela : le saut dans l'IA derrière le modèle VLA Alpamayo, le volant de données, les calendriers réels du L4, et ce que le travail pratique de Spyrosoft sur la stack signifie pour votre programme d'intégration.
Lire la partie 2 : NVIDIA Alpamayo et l'argument IA en faveur de l'autonomie de niveau L4
En savoir plusSi vous évaluez déjà l'intégration de NVIDIA DRIVE et souhaitez un échange technique sur l'avancement de votre programme, contactez notre équipe automobile via le formulaire ci-dessous.
arrow_circle_rightContactez-nous
Contactez-nous pour discuter de vos besoins
arrow_circle_right Nos articles