Analysis · AI for Business

What the EU’s new product liability rules mean for software, AI and connected devices

13 August 2026 · 8 min read

The EU has rewritten product liability for the digital age. Software, AI systems and connected devices are now clearly inside the scope of strict product liability, which means businesses can face compensation claims even where no one needs to prove negligence in the old sense.

Key takeaways

What changed in the law

The new regime is set out in Directive (EU) 2024/2853, which states that software is a product for no-fault liability purposes, regardless of whether it is stored locally, accessed over a network or supplied as software-as-a-service. The European Parliament’s briefing says the Directive entered into force on 9 December 2024, and industry guidance consistently says Member States must transpose it by 9 December 2026. For business readers, that means the legal perimeter has moved from physical goods to the software layer that increasingly controls them.

The practical shift is not just definitional. The European Commission says the revised framework is meant to make it easier for victims to obtain compensation for damage caused by defective products, including those whose safety depends on software updates, AI or digital services. In plain terms, a connected product can now create liability exposure through code, model behaviour, updates, integrations and service dependencies, not just through broken hardware.

Why software and AI are now treated like products

The decisive change is that software is no longer treated as a peripheral service in the product liability analysis. The Directive text says software qualifies as a product irrespective of how it is supplied, including through cloud technologies and SaaS. The European Parliament briefing also notes that the proposal covered software, including AI systems, and digital services that affect how a product works, such as navigation services in autonomous vehicles. That matters because many modern products are only partly physical: their safety depends on code, remote updates and data flows.

This is especially relevant for AI-enabled systems. The Commission’s liability material frames the reform as part of a broader effort to address AI-related harm, while legal commentary on the final Directive says AI systems fall within the expanded software definition. The result is not a separate “AI damages law”, but a product liability rulebook broad enough to catch AI outputs when they are embedded in a product that causes damage.

For connected devices, the logic is similar. If a smart-home system, industrial sensor, vehicle interface or medical device becomes unsafe because of a software update, a digital component or a connected service, the liability analysis now points back to the product chain. That is a meaningful change for firms that sell hardware plus software, or software plus support, because responsibility can attach to the combined system rather than to a single component in isolation.

The operational risk for businesses

The main business consequence is broader exposure across the product lifecycle. Freshfields’ analysis of the Directive says the framework extends strict liability to digital products and services, while Pinsent Masons notes that the previous liability cap has been abolished and that disclosure obligations now favour claimants. Together, those changes raise the cost of getting documentation wrong, incident response wrong, or product governance wrong.

That does not mean every software bug becomes a compensation case. Product liability still turns on defect, causation and damage. But the evidential balance has shifted. If a claimant cannot easily prove what went wrong inside a complex software stack, the Directive creates mechanisms that can lower that burden, including rebuttable presumptions and disclosure duties in certain circumstances. For operators, the practical lesson is that logs, change records, model versioning, patch histories and supplier terms are no longer just engineering artefacts. They are potential evidence.

The risk is highest where software is safety-critical or deeply embedded: medical devices, vehicles, industrial control, consumer IoT, security systems and AI decision-support tools. In those sectors, a failure can trigger not only product claims but also knock-on contractual, regulatory and reputational exposure. Firms that ship frequent updates or rely on third-party components will need tighter release controls, clearer incident attribution and better supplier traceability.

The date that matters most

The legal transition date is 9 December 2026. The European Parliament briefing says the Directive entered into force on 9 December 2024, and legal firms analysing the final text say Member States must implement it by 9 December 2026. Gibson Dunn adds that products placed on the Union market or put into service after that date fall under the new regime, while older products remain under the prior rules. That means the compliance burden is now a planning issue, not a distant policy debate.

For businesses, the timing matters in a second way. Software and AI products are often continuously updated after launch. Even if a product was first sold before the cut-off, later modifications, substantial changes or connected services can still complicate the liability picture. Firms should therefore treat December 2026 as the point at which new launches, update policies and support contracts need to be aligned with the revised framework.

What to do now

The right response is not panic, but product governance. Companies selling software, AI or connected devices into the EU should map which offerings sit inside the Directive’s expanded definition of product, identify the entities in the supply chain that may be exposed, and review whether their documentation would stand up if a claimant asked for evidence of defect, causation or warnings. The Directive has moved the legal focus from the device alone to the full system, including software updates and connected services.

That in practice means better release discipline, stronger supplier contracts, clearer allocation of responsibility for updates and patching, and logs that can support an investigation months later. The businesses that will cope best are not the ones with the most legal memos. They are the ones that can show what changed, when it changed, who approved it and what testing was done before release.

Comparison with the old regime

IssueBefore the revised DirectiveNow
SoftwareOften treated as outside or at the edge of product liability analysisExpressly treated as a product for no-fault liability purposes
AI systemsUnclear or indirectly coveredCovered through the expanded software definition and related liability rules
Connected servicesHarder to capture if the harm came through digital dependenciesCan fall within scope when they are necessary for the product to function safely
EvidenceClaimants faced the full burden of proof in more casesDisclosure duties and presumptions can ease the claimant’s burden
Implementation deadlineOld framework in force since 1985Member States must transpose by 9 December 2026

Different perspectives

The optimistic case

The reform gives the market a cleaner rulebook. By stating openly that software, AI and cloud-delivered products are in scope, the Directive reduces legal ambiguity that had built up as products became more digital. That clarity should help serious vendors, because buyers, insurers and regulators can now see a more coherent liability structure. It may also push companies towards better testing, better traceability and safer update practices, which is exactly what users expect from connected products.

The sceptical case

The hardest criticism is that the law may over-correct for complexity. Digital products evolve quickly, depend on third-party code and often generate harm through intricate chains of events that are difficult to reconstruct. In that setting, broad disclosure duties and presumptions may increase litigation costs and encourage claims even where causation is contested. Open-source communities and smaller software vendors may also worry that the boundary between commercial software and non-commercial contribution is not always easy to draw, especially where code is reused inside paid products. The result could be more defensive engineering, higher insurance costs and slower release cycles.

Comparison

What changes for businesses selling into the EU

AreaPractical effect
Standalone softwareNow clearly inside the product liability framework when placed on the EU market or put into service after 9 December 2026
AI systemsCovered through the Directive’s express treatment of software and related legal commentary
Connected devicesGreater exposure where safety depends on software, updates or connected services
Evidence and claimsMore pressure to keep logs, versioning, testing and supplier records
Launch planningNew products need liability reviews before the 2026 cut-off

Our view

Snip.work’s operator view is simple: this is what happens when software stops being a sidecar and becomes the product itself. The businesses that win will not be the ones making grand claims about AI. They will be the ones that can explain every release, every patch and every supplier dependency without scrambling for missing records.

We see the same pattern in the A Batina build: one system across POS, online store and stock, invoicing automated; 10 hours a week saved, customer acquisition up 15%, EUR 200 a month in software cut. The lesson is not just efficiency. It is control. When the system is joined up, you can see where the risk sits, who owns each step and what changed before a problem hit the customer.

Cut the busywork, build the system, keep the growth.

What to do

Where is your business leaking time?

Tell us where your business leaks time. We come back within a day with a concrete first system to build and a rough scope. No commitment.

Sources

  1. EUR-Lex, "Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products", 23 October 2024. eur-lex.europa.eu
  2. European Parliament, "Revised Product Liability Directive", 2023. www.europarl.europa.eu
  3. European Commission, "Liability Rules for Artificial Intelligence", n.d.. commission.europa.eu
  4. Gibson Dunn, "EU Product Liability Directive: Responding to Software, AI and Complex Supply Chains", 2024. www.gibsondunn.com
  5. Freshfields, "Product Risks Today: The EU Product Liability Directive - Key Implications for Software, AI and Connected Products", 2024. www.freshfields.com
  6. Pinsent Masons, "How new EU product liability rules will impact the healthcare sector", 2024. www.pinsentmasons.com