Skip to main content
ExplainerAI RegulationExplainerAug 26, 2026, 7:22 AM· 5 min read· in meta

How the EU's New AI Product Liability Directive Rewrites the Rules of Corporate Liability for Software and AI Systems

The revised EU Product Liability Directive explicitly classifies software and AI as products, exposing developers to strict, no-fault liability for defects, cybersecurity failures, and data corruption.

By Lila Morgan

European Regulators 35%Corporate Legal Counsel 35%Technology Industry Analysts 30%
European Regulators
Argue that strict liability is necessary to protect consumers from the opaque, black-box nature of modern digital products.
Corporate Legal Counsel
Warn that the cascading liability and disclosure rules create massive, unquantifiable litigation risks for the entire software supply chain.
Technology Industry Analysts
Note that the withdrawal of the AI Liability Directive inadvertently subjected AI to a much harsher standard than originally intended.

Summary

  1. The revised EU Product Liability Directive explicitly classifies software and AI systems as "products."
  2. This reclassification subjects developers to strict, no-fault liability for the first time.
  3. The withdrawal of a separate AI-specific directive leaves this strict regime as the sole standard.
  4. Compensable damage now includes psychological harm and the corruption of personal data.
  5. Courts can order developers to disclose technical evidence to address information asymmetry.
  6. Liability cascades down the supply chain to importers, distributors, and online platforms.

For decades, the software industry has operated under a comfortable legal shield: software is a "service," not a "product." If a physical lawnmower breaks and injures a user, the manufacturer pays. If an algorithm hallucinates, corrupts a database, or causes financial ruin, the user is typically buried in terms of service and "as-is" disclaimers. The burden of proving the developer was negligent has historically been an insurmountable barrier for consumers.[3][5]

That shield has just been dismantled in the European Union. As of December 2024, the EU's revised Product Liability Directive (PLD)—officially Directive (EU) 2024/2853—entered into force. Member States are currently racing to transpose these rules into national law ahead of a hard December 2026 deadline.[1][2]

The core mechanism of the new directive is a single, profound reclassification. Article 4(1) of the PLD explicitly defines software, digital manufacturing files, and artificial intelligence systems as "products." This triggers strict, no-fault liability. A claimant no longer needs to prove that a developer was negligent or reckless; they only need to prove that the software was defective and that the defect caused them harm.[1][4]

To understand the severity of this shift, one must look at the EU's original regulatory roadmap. The European Commission initially proposed a dual-track approach to AI liability. The revised PLD was meant to handle physical goods and straightforward software, while a separate "AI Liability Directive" (AILD) was drafted to handle complex, fault-based claims arising from AI decision-making.[2][5]

The collapse of the dual-track strategy left the strict PLD as the primary liability framework for AI.

However, the dual-track strategy collapsed. In early 2025, the European Commission quietly withdrew the proposed AI Liability Directive after the legislative process stalled. The abandonment of the fault-based AILD left the revised PLD as the only harmonized liability framework in town. By default, AI developers are now caught in a strict liability net originally designed for exploding blenders and toxic pharmaceuticals.[3][5]

Under the new rules, the definition of a "defect" has been radically expanded to fit the digital age. A defect is no longer just a crash or a physical malfunction. It now explicitly includes cybersecurity vulnerabilities and the failure to provide necessary software updates. If an AI-driven medical application fails to patch a known vulnerability and patient data is subsequently corrupted, the developer is strictly liable for the fallout.[1][3]

The scope of compensable harm has ballooned alongside the definition of a product. The 1985 regime focused almost exclusively on physical injury and tangible property damage. The 2024 framework covers "medically recognized damage to psychological health" and the destruction or irreversible corruption of personal data. Furthermore, the previous €500 threshold for property damage has been eliminated, opening the door for mass representative actions over smaller, widespread software failures.[1][3]

The scope of compensable harm has ballooned alongside the definition of a product.

The liability net does not stop at the original coder. The directive creates a cascading chain of responsibility to ensure that European consumers always have a reachable target to sue. If the software manufacturer is established outside the EU, the importer becomes strictly liable.[1]

Liability cascades down the supply chain to ensure consumers always have a reachable target within the EU.

If there is no importer, the liability cascades further down the supply chain. Distributors, fulfillment service providers, and even online platforms—such as app stores or cloud marketplaces—can be held liable if they present the product as their own or fail to identify the upstream supplier within one month of a consumer's request.[3][4]

Perhaps the most potent new weapon handed to plaintiffs is the disclosure obligation. Historically, the "black box" nature of AI made it impossible for a consumer to prove a system was defective. They simply could not see how the algorithm weighted its inputs or arrived at a harmful output.[3][5]

The revised PLD reverses this information asymmetry. Under Article 9, national courts can now order companies to disclose "relevant evidence" at their disposal if a claimant presents a plausible case for damages. This evidence could include technical design documentation, training data logs, and potentially even source code, subject to trade secret protections that Member States must figure out how to enforce.[1]

Courts can now order developers to disclose technical documentation and training data to plaintiffs.

If a developer refuses to comply with a disclosure order, or if the technical complexity of the AI makes it "excessively difficult" for the claimant to prove their case, the directive introduces a rebuttable presumption of defectiveness. The court will simply presume the software was defective, forcing the developer to prove otherwise.[1][2]

In response, enterprise tech companies are clinging to the "development risk" defense. This provision allows a manufacturer to avoid liability if they can prove that the defect could not have been discovered given the state of objective scientific and technical knowledge at the time the product was deployed.[1][4]

But for modern AI, particularly machine learning models that evolve after deployment, this defense is exceptionally shaky. The directive explicitly states that if a manufacturer retains control over the product—such as through continuous software updates or continuous learning capabilities—they remain liable for defects that emerge post-sale.[1][3]

The new directive expands compensable harm beyond physical injury to include data corruption and psychological damage.

This creates a profound tension with how artificial intelligence is marketed. Tech companies routinely sell AI as autonomous, self-learning, and constantly improving. Yet under the PLD, that continuous connection and improvement is exactly what extends their liability window indefinitely.[5]

The compliance scramble is already underway. While the high-profile EU AI Act sets the regulatory safety standards for artificial intelligence, the Product Liability Directive provides the financial teeth. Non-compliance with the AI Act's safety requirements can now directly trigger a presumption of defectiveness under the PLD.[4][5]

As the December 2026 transposition deadline approaches, the era of "move fast and break things" is colliding with a legal framework designed to ensure that whoever breaks things pays for them. Software is finally being treated like the physical infrastructure it has become, and the corporate risk landscape will never be the same.[3][5]

Definitions

Strict Liability
A legal standard where a party is held responsible for their products causing damage, regardless of whether they were at fault or negligent.
Transposition
The process by which European Union Member States incorporate an EU directive into their own national laws.
Development Risk Defense
A legal defense allowing manufacturers to avoid liability if a defect could not have been discovered given the state of scientific knowledge at the time of release.
Information Asymmetry
A situation where one party (the developer) has vastly more information about how a product works than the other party (the consumer).
Rebuttable Presumption
A legal assumption made by a court that is taken to be true unless someone comes forward to contest it and prove otherwise.

Questions & answers

What is the EU Product Liability Directive?

It is a European Union law that allows consumers to claim compensation for damages caused by defective products. The 2024 revision explicitly includes software and AI as products.

Does this mean software companies can be sued without proving negligence?

Yes. Under strict liability, a consumer only needs to prove that the software was defective and caused harm, not that the developer was careless or negligent.

Are open-source developers liable under these new rules?

Free and open-source software developed outside the course of a commercial activity is generally excluded from the directive's scope, protecting independent hobbyists.

When do these new rules actually take effect?

The directive entered into force in December 2024, and EU Member States have until December 9, 2026, to transpose the rules into their national laws.

Sources

Source coverage

5 outlets

3 viewpoints surfaced

European Regulators 35%Corporate Legal Counsel 35%Technology Industry Analysts 30%
  1. [1]EUR-LexEuropean Regulators

    Directive (EU) 2024/2853 on liability for defective products

    Read on EUR-Lex
  2. [2]European ParliamentEuropean Regulators

    New Product Liability Directive

    Read on European Parliament
  3. [3]Gibson DunnCorporate Legal Counsel

    EU Product Liability Directive: Responding to Software, AI and Complex Supply Chains

    Read on Gibson Dunn
  4. [4]WikipediaTechnology Industry Analysts

    Product Liability Directive

    Read on Wikipedia
  5. [5]Factlen Editorial TeamTechnology Industry Analysts

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get meta stories with full source coverage and perspective breakdowns delivered to your inbox.