The Revised EU Product Liability Directive and Defective AI Software
11 min read · updated August 11, 2026
The 1985 product liability directive was written for physical goods, and for forty years the question of whether standalone software was a “product” had no clean answer. Directive (EU) 2024/2853 answers it: it is. That single definitional change is the most consequential thing the EU has done about AI liability, and it did not require an AI statute to do it.
Software is a product now
Directive (EU) 2024/2853 was adopted on 23 October 2024, published in the Official Journal on 18 November 2024, and entered into force twenty days later. Member states must transpose it by 9 December 2026, and it applies to products placed on the market after that date; Directive 85/374/EEC continues to govern products placed on the market before it. The consolidated text is at EUR-Lex, ELI dir/2024/2853.
Article 4(1) defines a product as all movables, including where integrated into or interconnected with another movable or an immovable, and expressly includes electricity, digital manufacturing files, raw materials and software. The recitals confirm that software covers operating systems, firmware, applications and AI systems, and that it is within scope regardless of how it is supplied — embedded in a device, downloaded, or accessed over a network as a service.
There is a carve-out. Free and open-source software developed or supplied outside the course of a commercial activity is excluded. That exclusion is about the mode of supply, not the licence: an open-source model integrated into a commercial product by a company that monetises the product does not carry the exclusion into that product.
Who is on the hook
Liability under the directive is strict: the claimant does not prove fault or negligence, only defectiveness, damage, and the causal link between them. The set of defendants is wider than “the manufacturer”.
- The manufacturer of the defective product, and the manufacturer of a defective component where the component caused the defect. A model provider whose model is a component of somebody else’s product is squarely within that.
- The importer and the authorised representative where the manufacturer is outside the EU, and a fulfilment service provider after them. Distributors and online platforms become liable where an identifiable upstream operator cannot be produced on request.
- Anyone who substantially modifies a product outside the original manufacturer’s control and then makes it available. Article 8 treats that person as the manufacturer of the modified product. Fine-tuning a model and shipping the result is the obvious case, and it is the provision integrators most often have not read.
The related concept in the AI Act is not identical, which is a trap worth flagging — substantial modification under the AI Act asks a different question about when a deployer becomes a provider, and you can be caught by one and not the other.
What makes AI software defective
A product is defective when it does not provide the safety a person is entitled to expect or that is required by law. Article 7 lists the circumstances a court weighs, and three of them were written with connected and learning products in mind.
The first is the effect on the product of its ability to continue to learn or acquire new features after it is placed on the market. This is the clause that stops a manufacturer arguing that whatever the model did after deployment is not attributable to the product it shipped. The second is the effect of other products that can reasonably be expected to be used together with it — relevant to any orchestrated system with retrieval, tools or a second model in the path. The third is compliance with cybersecurity requirements: a product that fails the security expectations placed on it can be defective for that reason alone, which links this regime directly to the Cyber Resilience Act.
Article 7 also treats the moment of assessment carefully. Where the manufacturer retains control — through updates, upgrades or a hosted service — the relevant time extends beyond the moment of supply. A model served by its provider is never really “placed on the market and finished”, and the directive is drafted so that this works against the party that kept control.
The presumptions that change litigation
Article 9 lets a national court order a defendant to disclose relevant evidence it has at its disposal, on a proportionate basis, with safeguards for confidentiality and trade secrets. Refuse, and Article 10 presumes the product defective. That is a substantial change: the asymmetry in AI litigation has always been that only the defendant knows what the system does.
Article 10 then adds presumptions. Defectiveness is presumed where the product fails to comply with mandatory safety requirements intended to protect against the risk that materialised, or where the damage was caused by an obvious malfunction during reasonably foreseeable use. The causal link is presumed where the damage is of a kind typically consistent with the defect in question.
The provision that matters most for AI is the complexity relief. Where the court judges that the claimant faces excessive difficulties, owing to technical or scientific complexity, in proving defectiveness or causation, both may be presumed if the claimant demonstrates that the product contributed to the damage and that it is likely the product was defective, or that its defectiveness is a likely cause. The defendant may rebut. “Excessive difficulty due to technical complexity” is exactly the position of somebody harmed by a model whose weights, training data and evaluations they cannot see, and how generously courts read it is one of the genuinely open questions in this area.
Damage, defences and time limits
The recoverable damage is death and personal injury, including medically recognised harm to psychological health; damage to property other than the defective product itself, where the property is not used exclusively for professional purposes; and destruction or corruption of data not used for professional purposes. The old lower threshold that excluded small property claims is gone. Pure economic loss and non-material harms outside those categories remain outside the directive.
The development risk defence — that the state of scientific and technical knowledge when the product was placed on the market did not allow the defect to be discovered — is retained, though member states may derogate from it. It is not available where the defect is due to a software update or upgrade under the manufacturer’s control, or to the absence of an update needed to maintain safety.
Limitation is three years from the day the claimant knew or should have known of the damage, the defectiveness and the identity of the liable operator. There is a long-stop of ten years from placing on the market, extended to twenty-five years where symptoms of personal injury are latent. Contractual attempts to limit or exclude this liability towards the injured person are ineffective.