New Product Liability Directive applies: strict liability extends to software, AI and digital services
What changes
Directive (EU) 2024/2853 must be transposed by 9 December 2026 and applies to products placed on the market after that date. Software (including SaaS and AI), digital manufacturing files and related services count as products; missing security updates can make a product defective. Courts can order disclosure of evidence and presume defectiveness in complex cases. Free open-source software outside commercial activity is excluded.
Who is affected
Manufacturers of any product, software developers and SaaS providers, importers, fulfilment providers and, where no EU manufacturer exists, online marketplaces and distributors.
Sizes: micro, small, medium, large · Sectors: Software / SaaS, Hardware / electronics, Manufacturing, E-commerce, Retail · Applies if: We make connected hardware / devices; We sell online; We import goods into the EU; We use or build AI systems
What to do
Review product liability insurance to cover software and cyber-related defects. Set up a security-update policy and document it. Keep technical documentation and test records so you can respond to disclosure orders. Importers: make sure non-EU suppliers have an EU authorised representative, otherwise you carry the liability.
Penalty
No fines – unlimited civil liability for death, injury, property damage and data loss
Sources
- EUR-Lex – Directive (EU) 2024/2853 on liability for defective products (eur-lex.europa.eu)
- Gibson Dunn – EU Product Liability Directive: software, AI and supply chains (www.gibsondunn.com)
Last verified 7 September 2026. Informational only, not legal advice.