Definition: Product Liability Directive (EU)
The Product Liability Directive (EU) 2024/2853 is the revised EU law that makes manufacturers and providers of products, including software and AI systems, strictly liable for damage caused by defects, regardless of fault.
Core characteristics of the Product Liability Directive
The directive replaces the 1985 Product Liability Directive, which never explicitly covered intangible software, and applies no-fault liability across the full product lifecycle.
- Covers software, AI systems, digital manufacturing files and AI-generated outputs as products
- Applies strict liability: claimants must prove defect and damage, not negligence
- Extends liability to updates and machine-learning behavior after deployment
- Lets courts order disclosure of technical documentation in litigation
Product Liability Directive (EU) vs. AI Liability
The Product Liability Directive is one specific, binding EU law with a fixed deadline. AI Liability is the broader concept covering every route by which an AI system’s damage reaches a manufacturer or operator, including national tort law and the EU AI Act. Since the Commission withdrew its separate AI Liability Directive proposal in October 2025, Directive (EU) 2024/2853 is now the primary EU instrument for no-fault AI liability.
Importance of the Product Liability Directive in enterprise AI
For any company that builds, resells or embeds AI, the directive is a fixed date, not a future risk. Germany’s implementing bill passed its first Bundestag reading on 4 March 2026 (Deutscher Bundestag, 2026). Bitkom’s 2026 AI survey found that 53 percent of German companies cite legal uncertainty as their biggest obstacle to AI adoption, and unresolved liability exposure is a direct contributor.
Methods and procedures for compliance with the Product Liability Directive
Three practical steps help manufacturers, integrators and AI providers prepare before the deadline.
Classify every software and AI component as a product
Standalone software, embedded firmware, AI models and digital manufacturing files now qualify as products in their own right, so companies must inventory which systems could plausibly cause injury, property damage or data loss.
- Map components shipped as standalone products versus internal tools
- Flag AI systems whose outputs or later training could change safety-relevant behavior
- Document who counts as manufacturer when a component is bought in and integrated
Build an evidentiary disclosure process
Article 9 lets a court order disclosure of technical documentation once a claimant presents plausible facts and evidence. A company unable to produce model cards, test protocols or update logs on request risks an automatic presumption of defectiveness.
Track the national transposition timeline
All 27 member states must pass an implementing law before 9 December 2026, and the wording of defenses and disclosure procedures can vary between them. Companies selling into several EU markets should follow the relevant national drafts in parallel.
Important KPIs for Product Liability Directive compliance
Compliance progress is easiest to track across three categories.
Operational readiness metrics
- Inventory coverage: 100% of externally supplied software and AI classified
- Documentation retrieval time: technical files available within 5 business days
- Update logging: 100% of safety-relevant software updates version-tracked
- Contract review: 100% of AI vendor contracts checked for liability clauses
Strategic risk metrics
The directive changes the shape of liability exposure itself. With the previous 85 million euro cap on personal-injury damages removed, and latent-injury claims possible up to 25 years after market entry, finance teams need multi-year loss projections rather than single-incident estimates (European Commission, Directive (EU) 2024/2853).
Documentation quality metrics
Courts assess disclosure requests against what a manufacturer “can reasonably be expected to have.” Model cards and test reports meeting EU AI Act conformity standards double as litigation defense material, avoiding duplicate work.
Risk factors and controls for the Product Liability Directive
Three risk areas deserve particular attention from companies that build or deploy AI.
Liability for post-deployment software behavior
Because the directive holds manufacturers liable for defects emerging through later updates or learned behavior, control does not end at shipment.
- AI systems that keep learning from live data after deployment
- Delayed security patches for known vulnerabilities
- Cloud-delivered updates pushed without adequate testing
Evidentiary disclosure in litigation
Article 9 fixes the historic imbalance where claimants could not access a manufacturer’s internal test data. Companies that withhold documentation entirely, rather than redacting it carefully, risk a court presuming the product defective outright.
Expanded claimant pool and uncapped damages
The directive removes the option to cap total liability and extends compensable damage to destroyed or corrupted data. This raises the tail risk finance teams must model, and it strengthens the case for reviewing AI vendor risk management before 2026.
Practical example
A 210-employee manufacturer of industrial control systems in Baden-Wurttemberg sells a predictive-maintenance AI module as a paid add-on. Before the reform, it treated the module as a service, so liability sat mostly with the machine operator. After review, the company reclassified the module as a product component and renegotiated supplier contracts to clarify who is the AI provider and who is the AI deployer at each customer site.
- Documented change log for every model update pushed to customer machines
- Model cards and test protocols retrievable within days of a request
- Contract clauses clarifying manufacturer versus operator liability
- Shared documentation between AI Act and product liability files
Current developments and effects
Three developments will shape how the directive plays out over the next two years.
National transposition laws take shape
Germany’s draft law for a modernized Produkthaftungsgesetz reached Bundestag committee hearings in April 2026, with other member states at similar stages.
- German draft law under Bundestag committee review as of April 2026
- France and other large markets running parallel national consultations
- Divergent national defenses possible until December 2026 harmonizes core rules
Interaction with the EU AI Act
Under Article 10, non-compliance with EU AI Act safety requirements can trigger a legal presumption of defectiveness. Companies already running AI Act conformity assessments gain a head start on liability defense.
Insurance market response
Insurers are beginning to price AI-specific product liability separately from general cover, since standard policies predate software counting as a product. Manufacturers embedding AI into physical goods should expect renewal talks to include new exclusions.
Conclusion
The Product Liability Directive (EU) 2024/2853 turns a once-theoretical question, whether AI counts as a product, into settled EU law with a fixed compliance date. Companies that build, resell or meaningfully modify AI systems now carry strict liability for defects that surface long after deployment, including those introduced by later updates. The practical response is manageable: classify AI components correctly, keep documentation disclosure-ready, and align it with existing AI Act work. Finishing before 9 December 2026 means far less exposure than treating it as a future problem.
Frequently Asked Questions
What does the directive change for companies that use AI, rather than build it?
Companies that only deploy AI tools built by someone else are usually the AI deployer, not the manufacturer, so strict liability generally falls on the AI provider. A company that meaningfully customizes or rebrands a third-party system, however, can become a manufacturer itself.
Does this also apply to smaller Mittelstand companies, or only large manufacturers?
Yes, the directive applies regardless of company size. Any company that places an AI-containing product on the EU market, or substantially modifies one, falls within scope, so a 50-person machinery supplier faces the same rules as a multinational.
What exactly do we need to do before 9 December 2026?
Inventory which products or software include AI, update technical documentation so it can be disclosed on short notice, and clarify in contracts who counts as manufacturer. Companies already running AI Act conformity assessments can reuse most of that work.
How does this relate to the EU AI Act and GDPR?
The EU AI Act sets safety and conformity requirements, GDPR governs personal data processing, and the Product Liability Directive decides who pays when a defective AI system causes damage. Non-compliance with AI Act requirements can directly trigger a defectiveness presumption.
Do we need external legal support, or can our internal team handle it?
Most mid-sized companies need one round of legal review to map which products are in scope and how their national transposition law implements disclosure and defenses. After that, maintaining documentation is manageable with existing legal and compliance staff.
Is there funding available for Mittelstand companies preparing for this deadline?
No dedicated EU or German funding program covers product liability compliance specifically, since it is a legal obligation rather than a digitalization investment. General digitalization funding for AI governance and documentation tooling can, however, often help build the processes this directive requires.