EU Product Liability Directive 2024/2853: New Liability for Software & AI Starting in 2026
The new EU Product Liability Directive (EU) 2024/2853 reforms strict liability and legally classifies software and artificial intelligence (AI) fully as products. This marks a new era for the tech industry, as existing liability caps will disappear entirely as of the cutoff date of December 9, 2026. In particular, the reversal of the burden of proof for complex systems, along with expanded liability for updates and cybersecurity, shifts risk dramatically in favor of consumers. Affected businesses must adapt their risk management now to stay legally compliant alongside the AI Act, GDPR, and NIS2. This guide shows in practical terms what massive changes are coming for businesses and how to close compliance gaps in time.
Background and Timeline of the EU Product Liability Directive 2024/2853
The EU's previous Product Liability Directive dated back, at its core, to 1985 — a time when smartphones, cloud solutions, or generative AI were unimaginable. Until now, strict liability focused almost exclusively on physical goods. Consumers harmed by pure software defects found it extremely difficult to claim damages.
With the new directive (EU) 2024/2853 (often referred to as the Product Liability Directive or PLD), which entered into force on December 8, 2024, the EU is replacing the nearly 40-year-old framework.
The implementation timeline:
- September 11, 2025: Germany's Federal Ministry of Justice (BMJ) has already presented an official draft bill to amend the German Product Liability Act (ProdHaftG).
- December 9, 2026: By this deadline, Germany must have fully transposed the EU requirements into national law.
- Important transitional rule: For all products and software versions placed on the market up to and including December 8, 2026, the previous, older ProdHaftG continues to apply. The new, stricter law applies exactly to products that come to market on or after December 9, 2026.
Software & AI Are Explicitly "Products"
The decisive lever of the reform is the fundamental expansion of the definition of "product." Under the new law, a "product" no longer has to be a physical, tangible item.
The new definition now explicitly covers:
- Software of all kinds: Operating systems, mobile apps, traditional embedded software, and stand-alone programs.
- Cloud services & SaaS: It's legally irrelevant whether the software is stored on a local device or accessed purely virtually from the cloud.
- Artificial intelligence: AI systems are treated as a subcategory of software and are fully subject to strict product liability.
The one exception: Free and open-source software is exempt from the directive — but only if it's not developed or provided as part of a commercial activity. As soon as a company earns money from it or integrates open-source components into a commercial product, full liability applies.
The Three Biggest Changes Under the New Liability Law
The new law dramatically shifts the balance of power between software manufacturers and consumers. These are the three most significant changes for businesses:
1. Elimination of All Liability Caps
Previously, manufacturers' financial risk was capped: there was a deductible of €500 for property damage and a liability ceiling of €85 million for personal injury. Both limits disappear entirely. This means consumers and injured parties will, in theory, be able to file unlimited claims for damages going forward.
2. Liability for Data Loss, Updates, and Cybersecurity
The scope of compensable damage is being massively expanded. Going forward, product liability will also cover the loss, destruction, or corruption of data, provided the data is not used exclusively for professional purposes. Companies can be held directly liable when damage results from inadequate or entirely missing software updates, or when insufficient cybersecurity protection (e.g., missing encryption) allows hackers to tamper with a system.
3. Easing the Burden of Proof for Complex Technology
Since it's impossible for an average consumer to see inside the "black box" of an algorithm or an AI system, a far-reaching reversal of the burden of proof applies. If the plaintiff cannot prove the exact programming error due to technical complexity, the court will presume the defect lies with the manufacturer. The company must then actively prove that the system was defect-free.
The Revolution of the Reversed Burden of Proof for AI Systems
The directive raises the stakes especially for artificial intelligence: manufacturers are also liable for defects that arise from a system's continuous learning and autonomous evolution after it has been placed on the market.
This reform is directly linked to the European AI Act. Through explicit legal cross-references, the safety and transparency requirements defined there are pulled directly into the civil-law "defect" concept underlying product liability. If you violate the AI Act, your AI product is automatically considered defective in court — making liability nearly impossible to avoid.
Expanded Scope of Liability: Who Will Be Held Accountable Going Forward?
The new directive drastically increases accountability and expands the pool of potential defendants who can be held liable for a defective digital product.
Going forward, this includes:
- The software developer (even as a subcontractor, if their defective code corrupts the overall system).
- Authorized representatives of the manufacturer and fulfillment service providers.
- Quasi-manufacturers, who distribute software under their own name or brand.
The directive also ensures there's always a liable party within the EU. If the actual software manufacturer is based outside the EU (e.g., in the US or China), the importer or the EU-based authorized representative automatically becomes liable for any damage caused.
Fitting Into the Compliance Landscape: AI Act, GDPR, NIS2 & Co.
The Product Liability Directive is part of a complex, interlocking regulatory framework in the EU:
- AI Act: Defines preventive quality and risk standards for AI systems.
- GDPR: Protects personal data. If a software defect leads to a data breach, GDPR damages claims and product liability apply in parallel.
- NIS2 Directive: Defines the legal minimum standard for cybersecurity in 2026. Companies that neglect their NIS2 obligations will automatically have their software treated as defectively designed in a liability case.
Practical tip: The interplay of these laws forms a compliance thicket that's nearly impossible for mid-sized companies to navigate alone. To effectively avoid liability traps, forward-thinking tech companies rely on holistic digital platforms like heyData. heyData brings together the necessary expert knowledge and helps companies centrally manage the status of their data protection, whistleblowing, and IT security compliance, close gaps transparently, and keep legally required documentation audit-ready.
Practical Steps: What Businesses Should Do Now
Manufacturers and distributors of digital products should make intensive use of the time remaining before the final effective date in December 2026 to:
- Review documentation processes: Complete documentation of training data, algorithm logic, and quality assurance is your only line of defense against the reversed burden of proof.
- Adjust insurance coverage: Since the €85 million liability cap is being eliminated, coverage limits for IT liability and product liability insurance must urgently be reviewed and increased.
- Establish monitoring and recall systems for software: Set up processes to track vulnerabilities in the field in real time and roll out over-the-air (OTA) updates in a legally sound, error-free way.
- Negotiate recourse agreements with third-party suppliers: Contracts with API providers, cloud vendors, and external code suppliers must precisely define how product liability risk is allocated internally in the event of damage.
Conclusion
The EU Product Liability Directive 2024/2853 ends the era in which software providers could hide behind the argument that "software just has bugs." Alongside the new product liability rules, manufacturers should also keep an eye on upcoming plans for a dedicated EU AI Liability Directive, which will soon complete the civil liability framework for AI providers.
In practice, this reform hits at the core of an entirely new reality: as of December 2026, the statement "a prototype is not software" is no longer just a design opinion — it carries direct, existential liability consequences. Especially for the current trend of rapidly building immature SaaS products with AI tools and launching them onto the market unchecked, a new era of legal responsibility begins now.
FAQ
Do small startups have to follow the same rules as tech giants?
Do small startups have to follow the same rules as tech giants?
Yes. The Product Liability Directive does not distinguish by company size. Anyone who commercially places a defective digital product on the EU market is liable without limitation for the resulting damage.
What happens if a German law hasn't been finally passed by December 2026?
What happens if a German law hasn't been finally passed by December 2026?
Even if the final German law is delayed beyond the current draft bill: once the implementation deadline expires on December 9, 2026, consumers can, under certain conditions, invoke the consumer protection provisions of the EU directive directly in court (direct effect of the directive). Relying on delays is therefore highly risky.
Does the liability also apply to AI systems offered free of charge?
Does the liability also apply to AI systems offered free of charge?
What matters is whether the system is provided in the course of a "commercial activity." If a tool is free but serves lead generation, is monetized through advertising, or is meant to promote a paid pro version, product liability applies in full.







