EU / Liability

Software is a "product" now — and the burden of proof just shifted toward you.

EU member states must transpose the revised Product Liability Directive (EU) 2024/2853 by 9 December 2026. It replaces the 1985 original and, for the first time, brings software, firmware, digital manufacturing files and AI systems squarely within scope as "products" subject to no-fault liability — with an expanded set of circumstances in which a court can presume the product was defective and shift the evidential burden onto the manufacturer.

Last updated 18 August 2026

9 Dec 2026national transposition deadline (Directive (EU) 2024/2853)
1985 → 2024first substantive rewrite of EU product liability law in 40 years
2new compensable damage categories: data loss, psychological harm

Why this is a rewrite, not an update

The original Product Liability Directive (85/374/EEC) predates the internet-connected product. It was built around physical goods, and for four decades courts and manufacturers alike treated software's liability status as genuinely unsettled — was a firmware update a "product," was a standalone app, was a cloud service that controlled a physical device? Directive (EU) 2024/2853 answers that question directly: software, whether embedded or supplied on its own, digital manufacturing files, and AI systems are now explicitly "products," on the same no-fault liability footing as a physical device. Member states have until 9 December 2026 to have this transposed into national law.

Source: Nemko Digital, "New EU Product Liability Directive"; Directive (EU) 2024/2853, Official Journal of the EU.

No-fault liability was already the rule — what changes is how easy it is to invoke

EU product liability has been no-fault since 1985: a claimant proves the product was defective and that the defect caused the damage, not that the manufacturer was negligent. What the revised directive adds is a set of presumptions that make establishing defectiveness and causation materially easier for a claimant, particularly in cases involving technical or scientific complexity — a category that covers most software, connected devices and AI systems by default. Courts can also order manufacturers to disclose relevant technical evidence, and refusing or failing to disclose can itself trigger a presumption of defectiveness.

Source: Outlex, "Product Liability Directive 2026: Software & AI".

Two new categories of damage that didn't exist under the old rules

Alongside death, personal injury and property damage carried over from 1985, the revised directive adds two categories aimed squarely at connected and software-driven products: loss or corruption of data not used for professional purposes, and medically recognised psychological harm. Neither had a clear route to compensation under the old directive, because neither was a foreseeable consequence of a defective toaster or ladder — they are foreseeable consequences of a defective connected device or app.

Source: Directive (EU) 2024/2853, Article 6 (definition of damage).

Transposition is still in progress, and timing will vary by member state

9 December 2026 is the deadline for member states to have implementing legislation in place — it is not a single EU-wide date on which the substantive rules suddenly apply uniformly everywhere. Some member states are expected to transpose close to the deadline; national implementing texts can also add member-state-specific procedural detail on top of the directive's floor. A manufacturer selling into multiple EU markets should expect to track transposition state by state through the rest of 2026, not assume one law applies identically everywhere the day after the deadline.

Source: Faegre Drinker, member-state transposition tracker.

Questions

What is the deadline for the revised Product Liability Directive?

EU member states must transpose Directive (EU) 2024/2853 into national law by 9 December 2026, and it applies to products placed on the market from that date onward. It repeals and replaces the original 1985 Product Liability Directive (85/374/EEC).

Does software really count as a "product" now?

Yes. The revised directive explicitly extends the definition of "product" to include software, whether embedded in a device or supplied standalone, plus AI systems and digital manufacturing files. Under the old 1985 directive, software's status was unclear and largely untested in court; the new directive removes that ambiguity.

What does "no-fault liability" mean in practice?

A claimant does not need to prove the manufacturer was negligent — only that the product was defective and that the defect caused the damage. This has always been the basic model of EU product liability; what changes is that it now applies squarely to software and connected products, and the directive adds a rebuttable presumption of defectiveness in specified circumstances, making it structurally easier for a claimant to succeed.

What's new about the burden of proof?

The directive introduces a disclosure obligation: a court can order the manufacturer to disclose relevant evidence, and a manufacturer's failure to do so can trigger a presumption that the product was defective. It also expands the situations in which defectiveness or causation is presumed, particularly where establishing the technical or scientific complexity of a case would be excessively difficult for the claimant — a category that includes most software and AI systems.

What kinds of damage does the directive now cover?

Alongside death, personal injury and property damage carried over from the 1985 directive, the revised directive adds two new compensable categories: the loss or corruption of data not used for professional purposes, and medically recognised psychological harm. Both are relevant to connected products and software in a way the original directive never anticipated.

Where we fit

Product liability exposure isn't a certification you obtain — it's a risk profile shaped by the documentation, testing evidence and defect-tracking a manufacturer already has (or doesn't) by the time something goes wrong. We fold a liability-exposure review into the same market-access engagement as CE/UKCA, RED cybersecurity and CRA work, rather than treating it as a separate legal exercise bolted on afterward.

Book a scoping call