What leads to recent 4.3 Million EVs Recall – An analysis

In August 2026, nine vehicle manufacturers announced recalls covering approximately 4.276 million electric vehicles in China. The recalls centred on a safety mechanism that was already present in the affected vehicles: the mechanical emergency door release.

This was not simply a case of millions of defective door latches. The concern arose from what could happen during a serious collision, when several conditions occurred in sequence.

Advertisement

Under normal conditions, occupants open the doors electronically. A severe collision, however, can interrupt the vehicle’s low-voltage electrical supply. The electronic release may then become unavailable, leaving the occupant dependent on a separate mechanical emergency release.

Regulators found that some of these releases could be difficult to identify or operate. In certain affected vehicles, the release was close in colour to the surrounding interior trim and was not sufficiently obvious to someone unfamiliar with the vehicle.

The risk can be summarised as follows:

Severe collision → Loss of low-voltage power → Electronic release unavailable → Mechanical release required → Occupant cannot quickly identify or operate it → Escape or rescue is delayed

The same event can create problems outside the vehicle. If external access also depends on an electrically operated or concealed handle, rescuers may struggle to reach the occupants after power is lost.

The announced remedies include clearer identification of emergency releases and software updates that can lower the windows following a qualifying collision. China is also introducing stricter requirements for door handles and emergency releases from 2027.

The most important detail is therefore not that the vehicles lacked a backup. A backup existed. The problem was whether a real person could recognise and use it during the exact emergency for which it was provided.

Was It a Manufacturing Defect?

Based on publicly available recall information, this was primarily a design, usability and system-safety issue rather than evidence that millions of door-release components had been manufactured incorrectly.

A mechanical release may conform to its drawing, pass dimensional inspection and operate with the specified force. Yet the overall safety function can still fail if an injured or frightened passenger cannot find it within seconds.

This distinction is fundamental:

A component can work as designed while the system fails to protect its user.

Manufacturing quality asks whether the product was built according to its approved design. Design quality asks whether that design remains safe in reasonably foreseeable conditions. The recall draws attention mainly to the second question.

How Could the Risk Pass Through FMEA and Validation?

The manufacturers’ internal design records are not public. It would therefore be inaccurate to claim that this failure mode was missing from their Design Failure Mode and Effects Analyses.

It may have been considered in a form similar to this:

Failure modeExisting design control
Electronic door release becomes unavailable after loss of powerIndependent mechanical emergency release provided

On paper, the response appears reasonable. The electronic system fails, but a mechanical alternative remains.

The weakness is that the entry confirms only the presence of another mechanism. It does not prove that the mechanism will protect an unfamiliar occupant during an emergency.

An effective assessment should also have asked:

  • Can a passenger immediately identify the release?
  • Can it be found in darkness or smoke?
  • Can an injured person reach and operate it?
  • Will it remain accessible after structural deformation?
  • Can someone use it without reading instructions?
  • Can rescuers gain access from outside after electrical power is lost?

This is where a technically valid control can create a false sense of security. The design may answer, “Is a mechanical backup present?” while leaving a more important question unanswered: “Can the intended user successfully use it under the worst foreseeable conditions?”

Conventional component testing may not reveal this gap. An emergency release can pass operating-force, durability, temperature, vibration and cycle tests. Those tests establish whether the mechanism functions when it is located and deliberately operated. They do not establish whether a first-time passenger will discover it during a collision.

A real emergency may combine power loss, deformation, darkness, smoke, injury, restricted movement and panic. A trained test engineer who knows the release location cannot accurately represent an unfamiliar occupant facing those conditions.

The validation target must therefore change from “Does the lever move?” to “Can the occupant escape?”

Our Learnings…

1. Verify the effectiveness of a backup, not merely its existence

Adding a second mechanism does not automatically control a risk. Its effectiveness must be demonstrated with evidence.

Instead of recording only “mechanical release provided,” a stronger control would specify a measurable result, such as the percentage of unfamiliar users who can locate and operate the release within a defined time after loss of power.

A critical backup should be clearly visible, easy to reach, intuitive to operate, independent of the failed system and effective under realistic emergency conditions. If its success depends heavily on prior knowledge or instructions, the control remains weak.

2. Include human behaviour in risk analysis

When a person must act for a safety feature to work, human behaviour is part of the failure chain.

Risk reviews should consider first-time users, rear-seat passengers, children, elderly people, injured occupants and emergency responders. The assessment should also include low visibility, noise, panic, restricted movement and reduced hand strength.

“The user should know” is not a dependable safety control. Emergency actions must be obvious to someone encountering the product for the first time.

3. Validate the complete safety outcome

Component tests remain necessary, but safety validation should begin with the intended outcome.

In this case, the required outcome is not simply that the emergency release operates. It is that occupants can leave the vehicle and rescuers can gain access after the electrical system becomes unavailable.

A meaningful validation could disconnect the normal release, reduce visibility, impose realistic access restrictions and measure how quickly unfamiliar users escape. This type of scenario-based test can reveal weaknesses that thousands of ordinary operating cycles will never expose.

4. Examine combinations of failures

FMEA commonly evaluates failure modes individually. Serious accidents rarely occur so neatly.

Loss of power may coincide with structural deformation, smoke, injury and limited movement. Each condition may appear manageable on its own, while their combination makes the backup ineffective.

For safety-critical designs, FMEA may need to be supported by Fault Tree Analysis, Event Tree Analysis, misuse-case analysis and scenario-based testing. The purpose is to understand how multiple events can combine to defeat otherwise acceptable controls.

5. Treat compliance as a starting point

Standards are based on the risks understood when they are written. A new technology or unconventional interface can introduce hazards that existing requirements do not fully address.

A product may comply with every applicable standard and still contain a foreseeable safety weakness. Manufacturers introducing new ways of operating familiar functions must investigate the new failure modes rather than wait for regulations to catch up.

Innovation often moves faster than standards. Engineering judgement must close the gap.

6. Keep FMEA connected to field experience

Before launch, occurrence ratings depend on simulations, validation samples and engineering estimates. After launch, manufacturers receive evidence from actual accidents, customer complaints, warranty cases, service findings, near misses and emergency responders.

That evidence must flow back into the FMEA and design controls. A failure estimated at one occurrence per million products can still produce several incidents when millions of units are in service. Low occurrence cannot be considered in isolation when the possible consequence is catastrophic.

FMEA must remain a living risk-management tool, not a document closed after product approval.

A Practical Checklist for Safety-Critical Backups

For any emergency control in a vehicle, machine, medical device or factory system:

  1. Disable the primary system and observe what users actually do.
  2. Test the backup with people who have never seen the product.
  3. Measure the time required to locate and operate it.
  4. Repeat the test under poor visibility, noise and restricted access.
  5. Introduce reasonably foreseeable combinations of failures.
  6. Confirm that the control remains identifiable throughout the product’s life.
  7. Verify accessibility after damage or deformation.
  8. Include users, service personnel and emergency responders in risk reviews.
  9. Update the FMEA when field evidence changes an assumption.
  10. Redesign whenever safety depends excessively on memory, training or instructions.

These lessons extend far beyond electric vehicles. A machine may have an emergency stop that cannot be reached from the danger zone. An evacuation route may become blocked during the event for which it was created. A medical device may have a backup mode that staff cannot activate quickly.

In each case, the safety provision exists. The real question is whether it remains usable when the primary system fails.

Final Lesson

The recall of approximately 4.3 million electric vehicles teaches one fundamental engineering principle:

A safety mechanism is effective only when a real person can use it successfully during the failure it was designed to control.

The mechanical release may have met its component specification and passed conventional tests. The vehicle may also have complied with the standards applicable during development. None of those facts alone guarantees a successful escape.

Safety is ultimately determined by what happens when power is lost, the product is damaged and an unfamiliar person has only seconds to act.

We must find the difference between a backup that exists and a backup that can truly be depended upon.

Editorial note: This independent engineering analysis is based on publicly available recall notices and news reports. It does not claim access to any manufacturer’s internal design, testing or risk-assessment records. It is provided for professional learning and general informational purposes.

Now or Never

We’ve got your back on your manufacturing journey — Stay in touch

Follow us for step-by-step guidance, templates, and insights that save time and reduce mistakes.

Know Industrial Engineering Platform – Helping manufacturing industry professionals worldwide since 2019


Discover more from Know Industrial Engineering

Subscribe to get the latest posts sent to your email.

Leave a Comment

Your email address will not be published. Required fields are marked *