Analysis · AI for Business
What the EU’s new product liability rules mean for software, AI and connected devices
The EU has rewritten product liability for the digital age. Software, AI systems and connected devices are now clearly inside the scope of strict product liability, which means businesses can face compensation claims even where no one needs to prove negligence in the old sense.
Key takeaways
- The revised EU Product Liability Directive explicitly treats software as a product, including software supplied through cloud technologies and software-as-a-service, according to EUR-Lex.
- The Directive was adopted as Directive (EU) 2024/2853 and entered into force on 9 December 2024, with Member States required to transpose it by 9 December 2026, according to the European Parliament and legal commentary citing the text.
- The rules expand no-fault liability to digital products, including AI systems, and widen exposure for damage linked to connected or updateable products, according to the European Commission and the Directive text.
- Claimants get a procedural boost through disclosure obligations and a rebuttable presumption of defectiveness in some cases, according to the European Commission and specialist law-firm analyses.
- The most important practical date is 9 December 2026 for national implementation and application to products placed on the market or put into service after that date, according to Gibson Dunn and the Directive text.
What changed in the law
The new regime is set out in Directive (EU) 2024/2853, which states that software is a product for no-fault liability purposes, regardless of whether it is stored locally, accessed over a network or supplied as software-as-a-service. The European Parliament’s briefing says the Directive entered into force on 9 December 2024, and industry guidance consistently says Member States must transpose it by 9 December 2026. For business readers, that means the legal perimeter has moved from physical goods to the software layer that increasingly controls them.
The practical shift is not just definitional. The European Commission says the revised framework is meant to make it easier for victims to obtain compensation for damage caused by defective products, including those whose safety depends on software updates, AI or digital services. In plain terms, a connected product can now create liability exposure through code, model behaviour, updates, integrations and service dependencies, not just through broken hardware.
Why software and AI are now treated like products
The decisive change is that software is no longer treated as a peripheral service in the product liability analysis. The Directive text says software qualifies as a product irrespective of how it is supplied, including through cloud technologies and SaaS. The European Parliament briefing also notes that the proposal covered software, including AI systems, and digital services that affect how a product works, such as navigation services in autonomous vehicles. That matters because many modern products are only partly physical: their safety depends on code, remote updates and data flows.
This is especially relevant for AI-enabled systems. The Commission’s liability material frames the reform as part of a broader effort to address AI-related harm, while legal commentary on the final Directive says AI systems fall within the expanded software definition. The result is not a separate “AI damages law”, but a product liability rulebook broad enough to catch AI outputs when they are embedded in a product that causes damage.
For connected devices, the logic is similar. If a smart-home system, industrial sensor, vehicle interface or medical device becomes unsafe because of a software update, a digital component or a connected service, the liability analysis now points back to the product chain. That is a meaningful change for firms that sell hardware plus software, or software plus support, because responsibility can attach to the combined system rather than to a single component in isolation.
The operational risk for businesses
The main business consequence is broader exposure across the product lifecycle. Freshfields’ analysis of the Directive says the framework extends strict liability to digital products and services, while Pinsent Masons notes that the previous liability cap has been abolished and that disclosure obligations now favour claimants. Together, those changes raise the cost of getting documentation wrong, incident response wrong, or product governance wrong.
That does not mean every software bug becomes a compensation case. Product liability still turns on defect, causation and damage. But the evidential balance has shifted. If a claimant cannot easily prove what went wrong inside a complex software stack, the Directive creates mechanisms that can lower that burden, including rebuttable presumptions and disclosure duties in certain circumstances. For operators, the practical lesson is that logs, change records, model versioning, patch histories and supplier terms are no longer just engineering artefacts. They are potential evidence.
The risk is highest where software is safety-critical or deeply embedded: medical devices, vehicles, industrial control, consumer IoT, security systems and AI decision-support tools. In those sectors, a failure can trigger not only product claims but also knock-on contractual, regulatory and reputational exposure. Firms that ship frequent updates or rely on third-party components will need tighter release controls, clearer incident attribution and better supplier traceability.
The date that matters most
The legal transition date is 9 December 2026. The European Parliament briefing says the Directive entered into force on 9 December 2024, and legal firms analysing the final text say Member States must implement it by 9 December 2026. Gibson Dunn adds that products placed on the Union market or put into service after that date fall under the new regime, while older products remain under the prior rules. That means the compliance burden is now a planning issue, not a distant policy debate.
For businesses, the timing matters in a second way. Software and AI products are often continuously updated after launch. Even if a product was first sold before the cut-off, later modifications, substantial changes or connected services can still complicate the liability picture. Firms should therefore treat December 2026 as the point at which new launches, update policies and support contracts need to be aligned with the revised framework.
What to do now
The right response is not panic, but product governance. Companies selling software, AI or connected devices into the EU should map which offerings sit inside the Directive’s expanded definition of product, identify the entities in the supply chain that may be exposed, and review whether their documentation would stand up if a claimant asked for evidence of defect, causation or warnings. The Directive has moved the legal focus from the device alone to the full system, including software updates and connected services.
That in practice means better release discipline, stronger supplier contracts, clearer allocation of responsibility for updates and patching, and logs that can support an investigation months later. The businesses that will cope best are not the ones with the most legal memos. They are the ones that can show what changed, when it changed, who approved it and what testing was done before release.
Comparison with the old regime
| Issue | Before the revised Directive | Now |
|---|---|---|
| Software | Often treated as outside or at the edge of product liability analysis | Expressly treated as a product for no-fault liability purposes |
| AI systems | Unclear or indirectly covered | Covered through the expanded software definition and related liability rules |
| Connected services | Harder to capture if the harm came through digital dependencies | Can fall within scope when they are necessary for the product to function safely |
| Evidence | Claimants faced the full burden of proof in more cases | Disclosure duties and presumptions can ease the claimant’s burden |
| Implementation deadline | Old framework in force since 1985 | Member States must transpose by 9 December 2026 |
Different perspectives
The reform gives the market a cleaner rulebook. By stating openly that software, AI and cloud-delivered products are in scope, the Directive reduces legal ambiguity that had built up as products became more digital. That clarity should help serious vendors, because buyers, insurers and regulators can now see a more coherent liability structure. It may also push companies towards better testing, better traceability and safer update practices, which is exactly what users expect from connected products.
The hardest criticism is that the law may over-correct for complexity. Digital products evolve quickly, depend on third-party code and often generate harm through intricate chains of events that are difficult to reconstruct. In that setting, broad disclosure duties and presumptions may increase litigation costs and encourage claims even where causation is contested. Open-source communities and smaller software vendors may also worry that the boundary between commercial software and non-commercial contribution is not always easy to draw, especially where code is reused inside paid products. The result could be more defensive engineering, higher insurance costs and slower release cycles.
Comparison
What changes for businesses selling into the EU
| Area | Practical effect |
|---|---|
| Standalone software | Now clearly inside the product liability framework when placed on the EU market or put into service after 9 December 2026 |
| AI systems | Covered through the Directive’s express treatment of software and related legal commentary |
| Connected devices | Greater exposure where safety depends on software, updates or connected services |
| Evidence and claims | More pressure to keep logs, versioning, testing and supplier records |
| Launch planning | New products need liability reviews before the 2026 cut-off |
Our view
Snip.work’s operator view is simple: this is what happens when software stops being a sidecar and becomes the product itself. The businesses that win will not be the ones making grand claims about AI. They will be the ones that can explain every release, every patch and every supplier dependency without scrambling for missing records.
We see the same pattern in the A Batina build: one system across POS, online store and stock, invoicing automated; 10 hours a week saved, customer acquisition up 15%, EUR 200 a month in software cut. The lesson is not just efficiency. It is control. When the system is joined up, you can see where the risk sits, who owns each step and what changed before a problem hit the customer.
Cut the busywork, build the system, keep the growth.
What to do
- Audit every software, AI and connected-device product for whether it falls inside Directive (EU) 2024/2853 before the 9 December 2026 cut-off.
- Tighten release, update and incident logs so you can prove what changed, when it changed and who approved it if a claim lands.