From 9 December 2026, AI systems placed on the EU market or put into service fall squarely within the revised Product Liability Directive. For practical purposes, an AI system is treated as a product, and the organisation that develops or produces it (or that presents itself as the producer) is treated as a manufacturer.
This has direct consequences for how defect, evidence and ongoing control are understood.
AI systems are products
The Directive removes earlier uncertainty. Software is a product regardless of how it is supplied or used - whether installed locally, delivered through the cloud, or provided as a service. AI systems are explicitly included. Providers of AI systems under the EU AI Act are treated as manufacturers for product liability purposes.
That means strict liability can apply when a defective AI system causes covered damage. The injured person does not have to prove negligence. They need to establish defect, damage and causation - assisted, in many AI cases, by disclosure rules and legal presumptions.
What "defective" can mean for AI
A product is defective when it does not provide the safety that a person is entitled to expect, taking all circumstances into account. For AI and digital products, the assessment can include:
- The system's intended and reasonably foreseeable uses
- Its ability to learn or acquire new features after being placed on the market
- The effect of software updates and upgrades
- Cybersecurity
- Interaction with other products or digital services
- Whether the system remained under the manufacturer's control after placement on the market
A system that behaves unsafely because of the way it continues to learn, because necessary safety updates were not provided, or because of weaknesses that mandatory safety rules were meant to prevent, may be found defective under these factors.
Ongoing control creates ongoing exposure
Many AI systems are not static. They receive updates, rely on connected services, or adapt through machine learning. Where those changes occur under the manufacturer's control, liability can extend to defects that appear after the system was first placed on the market.
This is a significant shift from older product liability thinking that focused mainly on the product's condition at the moment of supply. For AI providers, the practical implication is that design, testing, release, update and monitoring processes remain relevant to liability exposure for as long as the system stays under their control.
Evidence and the burden of proof in AI cases
AI systems are often technically complex and difficult for an injured person to examine from the outside. The revised Directive responds to that reality.
Courts can order the disclosure of relevant technical information. If mandatory product safety requirements intended to protect against the relevant risk were not met, defectiveness may be presumed. In cases of scientific or technical complexity - which will frequently include AI - courts may presume defect and/or causation where the claimant shows these are likely. The manufacturer must then rebut the presumption.
In practice, this places a premium on the organisation's ability to produce clear, intelligible technical evidence: what the system was designed to do, how it was tested and validated, how data and models were managed, how updates were controlled, how risks were assessed, and how the system was monitored after deployment.
Failure to disclose required information, or inability to present it in an accessible way, can itself strengthen the claimant's position.
Link to regulatory safety requirements
Non-compliance with mandatory safety requirements laid down in Union or national law can support a presumption of defect. As AI-specific safety and cybersecurity requirements develop and apply, failures to meet those requirements may become directly relevant in product liability claims. This creates a practical connection between regulatory compliance disciplines and liability defence, even where the full set of high-risk AI Act obligations applies on a later timeline.
Who else may be exposed
While the manufacturer is the primary focus, other parties can face liability in defined situations - for example importers, certain authorised representatives, or organisations that substantially modify a product after it has been placed on the market. For AI, modifications, fine-tuning, or significant changes to operating conditions can raise questions about who carries manufacturer-type responsibility.
Contractual arrangements and the flow of technical information along the supply chain therefore matter. They do not remove statutory liability, but they affect risk allocation and the ability to respond when a claim arises.
Practical takeaway
For AI systems placed on the EU market from 9 December 2026, product liability is no longer a grey area. Strict liability applies, post-market behaviour under the manufacturer's control remains in scope, and claimants in complex cases benefit from disclosure rights and presumptions that shift pressure onto the organisation that put the system into circulation.
The organisations best placed to manage this exposure will be those that can explain and evidence how their AI systems were designed, controlled, updated and monitored. The next article examines how this liability timeline interacts with the later application dates of the EU AI Act's high-risk requirements.