The EU's Revised Product Liability Directive: A Guide to New Strict Liability for Software, AI, and Digital Services
The European Union has fundamentally overhauled its product liability rules, extending strict, no-fault liability to software, artificial intelligence, and digital services for the first time. The new directive, which takes full effect in December 2026, also expands compensable damages to include data loss and holds global supply chains accountable.
By Factlen Editorial Team
- European Policymakers
- Argue that modernizing the 1985 rules is essential to protect citizens from the unique harms of AI and digital ecosystems.
- Legal & Compliance Experts
- Focus on the sweeping expansion of compensable damages and the shifting burden of proof that will drive new tech litigation.
- Supply Chain Operators
- Highlight the heavy new burdens placed on EU-based importers and distributors who must now shoulder the legal risk for non-EU manufacturers.
What's not represented
- · Open-source software maintainers who fear the chilling effect of potential liability on volunteer-driven projects.
- · Small-to-medium enterprise (SME) app developers facing increased compliance and insurance costs.
Why this matters
For decades, software developers and tech companies have shielded themselves from liability using complex licensing agreements. This directive strips away those shields in the EU, meaning a defective software update, a hacked smart device, or a flawed AI decision can now trigger the same direct financial liability as a faulty car brake.
Key points
- The EU's revised Product Liability Directive classifies software, AI systems, and digital manufacturing files as products.
- Software developers now face strict, no-fault liability for defects, bypassing traditional contract-based liability shields.
- Compensable damages have been expanded to include the destruction or corruption of data and medically diagnosed psychological harm.
- A new liability hierarchy ensures that EU-based importers or fulfillment centers can be sued if a non-EU manufacturer is unreachable.
- The directive eases the burden of proof for consumers, allowing courts to presume a defect exists in complex AI cases.
- The new rules apply to all products placed on the EU market after the December 9, 2026 deadline.
For nearly four decades, the European Union’s approach to product liability was anchored entirely in the physical world. If a toaster caught fire or a car’s brakes failed, the 1985 Product Liability Directive provided a clear, standardized path for consumers to seek compensation. But as global commerce shifted to the digital realm, that legacy framework began to fracture, leaving massive gaps in consumer protection when software failed.[1]
Now, the EU has fundamentally rewritten the rules to close those gaps. Directive (EU) 2024/2853, commonly known as the revised Product Liability Directive (PLD), officially modernizes the bloc's liability regime for the digital age.[1]
The most consequential shift in the revised PLD is its expanded definition of what constitutes a "product." For the first time, software, digital manufacturing files like 3D printing blueprints, and artificial intelligence systems are explicitly classified as products under EU law.[2]
This classification introduces strict, no-fault liability to the software industry. Previously, software developers largely managed liability through complex licensing agreements and contract law, often requiring claimants to prove negligence. Under the new regime, consumers only need to prove that the software was defective and caused damage, bypassing the need to establish developer fault entirely.[2]

The directive also captures "related services" that are integral to a physical product's function. If a smart refrigerator relies on a cloud-based temperature control service, or an autonomous vehicle depends on a continuous navigation data stream, those digital services are treated as core components of the product itself.[1]
Defining a "defect" has also been modernized to reflect the realities of connected devices. A product can now be deemed defective if it fails to meet mandatory cybersecurity standards, or if the manufacturer fails to provide the necessary software updates required to maintain safety.[2][3]
Furthermore, the directive accounts for products that evolve after they are sold. If an AI system learns new behaviors post-deployment, or a substantial over-the-air software update fundamentally alters a device's functionality, the manufacturer remains liable for any resulting defects introduced by those changes.
Furthermore, the directive accounts for products that evolve after they are sold.
The scope of compensable damage has seen a similar, sweeping expansion. Historically limited to physical injury, death, or tangible property damage, the revised PLD now covers the destruction or corruption of data.
This means that if a defective software update wipes a consumer's hard drive, corrupts essential business files, or bricks a device, the developer can be held strictly liable for the material losses. The directive also explicitly recognizes medically diagnosed psychological harm as a compensable damage.
To ensure that consumers always have a viable target for legal recourse, the EU has established a strict liability hierarchy targeting the global supply chain. The primary target remains the original manufacturer. However, if the manufacturer is located outside the EU, the liability automatically cascades down the chain.
Importers, authorized representatives, and even fulfillment service providers can now be held liable if the original manufacturer cannot be reached. This ensures that non-EU companies cannot shield themselves behind international borders, forcing EU-based distributors to take a much harder look at the compliance of the products they handle.[2]

Recognizing the sheer technical complexity of modern digital systems, the revised PLD also alters the burden of proof. In cases involving "black box" AI or highly intricate software architectures, it can be nearly impossible for an average consumer to pinpoint exactly how a defect occurred.[1]
To remedy this imbalance, the directive allows national courts to presume a defect exists if the claimant can demonstrate that the product did not comply with safety requirements, or if the damage is clearly consistent with a suspected defect. Courts can also order manufacturers to disclose necessary technical evidence to the claimant.
While the directive officially entered into force in December 2024, the critical enforcement date is December 9, 2026. Member states have until then to transpose the directive into their national laws.[1][3]

Crucially, the new rules will only apply to products placed on the market or put into service after that December 2026 deadline. Products sold before that date will remain governed by the legacy 1985 framework, creating a bifurcated liability landscape for several years.[3]
For global tech companies, software developers, and cross-border distributors, the 2026 deadline represents a ticking clock. The next two years will require a massive overhaul of supply chain contracts, indemnity clauses, and liability insurance to prepare for an era where a line of code carries the exact same legal weight as a physical machine part.
How we got here
1985
The EU adopts the original Product Liability Directive, focusing exclusively on physical goods.
September 2022
The European Commission proposes a sweeping revision to adapt liability rules to digital technologies and AI.
November 2024
The revised Product Liability Directive is officially published in the EU's Official Journal.
December 9, 2024
The new directive officially enters into force, starting the two-year transposition clock.
December 9, 2026
The deadline for EU member states to implement the rules; the directive begins applying to all new products.
Viewpoints in depth
European Policymakers
Argue that modernizing the 1985 rules is essential to protect citizens from the unique harms of AI and digital ecosystems.
EU regulators emphasize that the legacy product liability framework was fundamentally ill-equipped for the digital age. By classifying software and AI as products, policymakers argue they are simply closing a massive legal loophole that allowed tech companies to evade the strict liability standards imposed on traditional manufacturers. They view the inclusion of data loss and psychological harm as necessary updates to reflect how modern consumers actually experience damage in a connected world.
Legal & Compliance Experts
Focus on the sweeping expansion of compensable damages and the shifting burden of proof that will drive new tech litigation.
Legal analysts warn that the revised directive will trigger a surge in complex litigation, particularly around the shifting burden of proof. Because courts can now presume a defect exists if a claimant demonstrates non-compliance with cybersecurity standards, experts predict a wave of data-loss and software-failure lawsuits. They are advising tech firms to urgently overhaul their end-user license agreements (EULAs), as traditional liability waivers will no longer hold up against strict statutory liability.
Supply Chain Operators
Highlight the heavy new burdens placed on EU-based importers and distributors who must now shoulder the legal risk for non-EU manufacturers.
For distributors, authorized representatives, and fulfillment centers, the revised PLD represents a massive transfer of risk. Because the directive ensures an EU-based entity is always liable, domestic importers can now be sued directly for defects in software or hardware produced in the US or Asia. Supply chain operators argue this will force them to demand sweeping indemnification clauses from their overseas partners and drastically increase the cost of liability insurance for anyone bringing foreign tech into the European market.
What we don't know
- How national courts will interpret the threshold for 'psychological damage' caused by digital products.
- The exact extent to which open-source software developers might still face liability if their code is commercialized by third parties.
- How the insurance industry will price liability coverage for highly autonomous, self-learning AI systems.
Key terms
- Strict Liability
- A legal standard where a party is held responsible for damages caused by their product regardless of whether they were negligent or at fault.
- Related Services
- Digital services that are integrated into or interconnected with a product, without which the product cannot perform its core functions (e.g., cloud connectivity for a smart device).
- Burden of Proof
- The obligation to present evidence to support a legal claim; the revised PLD eases this burden for consumers facing highly complex technologies like AI.
- Authorized Representative
- A person or business established within the EU appointed by a non-EU manufacturer to handle specific compliance and legal tasks.
Frequently asked
Does the new directive apply to free and open-source software?
In most instances, free and open-source software developed outside of a commercial context is excluded from the strict liability scope. However, if that open-source code is integrated into a commercial product, the manufacturer of that product assumes liability.
What happens to products I bought before 2026?
Products placed on the market before December 9, 2026, will continue to be governed by the old 1985 Product Liability Directive. The new rules only apply to products introduced after the deadline.
Can I sue a developer if a software bug deletes my personal files?
Yes. Under the revised PLD, the destruction or corruption of data is explicitly recognized as compensable material damage, allowing consumers to seek redress for wiped hard drives or corrupted files.
Who do I sue if the software developer is located outside the EU?
The directive establishes a liability hierarchy. If the non-EU manufacturer cannot be reached, consumers can sue the EU-based importer, the authorized representative, or even the fulfillment service provider.
Sources
[1]European ParliamentEuropean Policymakers
Revised Product Liability Directive
Read on European Parliament →[2]24hour-ARSupply Chain Operators
EU Product Liability Directive 2026: What Is Changing
Read on 24hour-AR →[3]EU VerifySupply Chain Operators
EU Product Liability Directive 2026: What Is Changing and What Stays the Same
Read on EU Verify →
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.





