We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The revised PLD makes software, AI included, a product. From 9 December 2026, liability for a defective AI system is strict and no-fault, defect can be presumed where you breached the AI Act or won't disclose your records, and the file you keep for the regulator becomes evidence in court.
The old product-liability regime was written for physical goods. The revision drags it into the software era: standalone software and AI systems are products, their updates and the digital services they depend on are in scope, and liability remains strict, so a claimant need not prove you were careless, only that the product was defective and caused harm.
For AI the decisive move is procedural. Recognising that proving a defect in a complex model is often impossible for a claimant, the directive lets courts presume defect and causation in defined situations, and lets claimants compel disclosure of your evidence. Your governance file stops being only a compliance artefact and becomes the centre of a liability case.
Standalone software, AI systems, and safety-relevant updates all fall within product liability.
Courts may presume defect or causation where set conditions are met, easing the claimant's proof.
Claimants can compel disclosure of relevant technical evidence; refusal triggers a presumption.
Death, personal injury including psychological harm, property, and destruction or corruption of data.
Strict liability already removes the need to prove fault. The revised directive goes further and lets a court presume the product was defective, or that the defect caused the damage, in situations that map directly onto AI governance failures:
The directive is adopted; the work is transposition. It applies to products placed on the market after the transposition date, so systems shipping into 2027 are squarely in scope.
Directive 2024/2853 adopted, replacing the 1985 regime.
The separate AI Liability Directive is withdrawn, leaving the PLD as the main route for AI harm.
Member states must transpose; the regime applies to products placed on the market after this date.
Source: Official Journal of the EU · Dir. 2024/2853 · applies to products placed on the market after transposition · confirm national implementing law
Liability follows the product along its economic chain, and a substantial modification can make the modifier the new manufacturer.
Primary liability, including for the software components and AI models you develop and the updates you push.
Where the manufacturer is outside the EU, liability can attach to the importer or the EU authorised representative.
Distributors and fulfilment service providers can be liable where an EU-based responsible party cannot be identified.
Substantially modify a product outside the original maker's control, and you can be treated as its manufacturer.
The PLD is civil liability, so the exposure is compensation rather than a regulatory ceiling, and the procedural changes make it easier to reach.
| Exposure | What it means |
|---|---|
| Uncappedcompensatory damages | Strict, no-fault liability for death, personal injury, property damage, and data loss caused by a defective AI product. |
| Presumptionburden shifts | Defect or causation can be presumed against you on non-disclosure, an AI Act breach, or excessive complexity. |
| Disclosureyour own records | Claimants can compel the technical documentation and logs you hold, turning your governance file into their evidence. |
Per Dir. 2024/2853 · damages and procedure are given effect through national law · confirm the transposing text
"Product liability is for physical goods, not our software."
The revised directive expressly makes standalone software and AI systems products. Your model, and its updates, are within strict product liability.
"A claimant has to prove our AI was defective, which they can't."
The directive presumes defect or causation where you won't disclose evidence, where you breached the AI Act, or where the technical complexity makes proof unreasonable.
"We'll wait for the AI Liability Directive to set the rules for AI."
The AI Liability Directive was withdrawn. The PLD is the primary route for harm caused by AI, and it applies from December 2026.
Yes. Directive (EU) 2024/2853 expressly brings software, including AI systems and standalone software, within the definition of a "product." Manufacturers, and in some cases those who substantially modify a product or provide related digital services, can be held liable for damage caused by a defect.
Member States must transpose it into national law by 9 December 2026, and it applies to products placed on the market or put into service after that date. The old regime (Directive 85/374/EEC) continues to apply to products placed on the market before 9 December 2026.
It is no-fault (strict) liability: an injured person does not need to prove the manufacturer was negligent, only that the product was defective, that they suffered damage, and the causal link between the two. The directive also introduces rebuttable presumptions of defectiveness and causation that lighten the claimant's burden in technically complex cases.
The PLD is a civil-liability instrument, not a regulatory-fine regime, so it does not set administrative penalties like GDPR or the AI Act. Exposure comes through civil damages claims for death, personal injury, property damage, and, newly, destruction or corruption of data that are not used for professional purposes.
The revised PLD lets national courts order a defendant to disclose relevant evidence at the claimant's request where a claim is plausible (Article 9). Failure to disclose can trigger a presumption that the product was defective. This materially shifts the evidential balance toward claimants in complex software and AI cases.
Potentially yes. The directive contemplates defects arising after the product is placed on the market where the manufacturer retains control, for example through software updates, upgrades, or machine-learning that changes behaviour. This can extend the relevant time window for liability beyond the point of sale.
An AI Act breach can presume a defect under the PLD, and the documentation you build for the Act is exactly what a claimant will compel. Governance done well is your defence; a gap in it is the presumption against you.