AI Assurance Institute Logo AI Assurance Institute

Product Liability Directive:
What Changes on 9 December 2026?

AI Governance Series

From 9 December 2026, a new set of product liability rules applies across the European Union. Directive (EU) 2024/2853 replaces the 1985 Product Liability Directive for products placed on the market or put into service on or after that date. Products already on the market before 9 December 2026 continue to be governed by the older regime.

For risk, IT and executive teams, the practical question is straightforward: what is different, and why does it matter?

Software and AI are clearly products

The most important clarification is that software is expressly treated as a product. This includes applications, operating systems, software supplied as a service, and artificial intelligence systems. It does not matter whether the software is installed on a device, accessed over a network, or delivered from the cloud.

Under the old rules, the status of pure software was often disputed. That uncertainty is removed. Developers and providers of AI systems are treated as manufacturers for the purposes of these rules.

Liability can continue after the product is placed on the market

Traditional product liability focused heavily on the state of the product at the moment it was put into circulation. The revised rules recognise that digital products often remain under the manufacturer's control after that point.

Manufacturers can be liable for defects that arise from:

In short, placing an AI system on the market does not necessarily end the manufacturer's exposure if the system continues to change under their control.

Damage categories are broader

The classic heads of damage - personal injury and damage to private property - remain. The revised Directive also addresses damage to data in defined situations. This reflects the reality that loss or corruption of data can cause real harm in a digital environment.

Pure economic loss suffered in a business context is still largely outside the harmonised strict-liability regime, although other national law claims may be available.

Claimants face a lower practical barrier in complex cases

The basic structure remains: the injured person must still establish defect, damage and a causal link. However, the revised rules make this significantly easier in practice, especially with technically complex products such as AI systems.

Courts can order disclosure of relevant technical information. Where a product fails to meet mandatory safety requirements laid down in law, defectiveness may be presumed. In cases of scientific or technical complexity - a description that will often fit AI - courts may presume defect and/or causation if the claimant shows that these are likely. The manufacturer then has to rebut those presumptions.

For organisations, this changes the risk calculation. Defending a claim will often depend on the quality of technical documentation, design and testing records, update history, monitoring data and the ability to explain how the system was controlled.

More parties in the chain can be exposed

Liability still centres on the manufacturer. Other economic operators can also be brought in, including importers and, in certain conditions, authorised representatives, fulfilment service providers or parties that substantially modify a product. Online platforms can face exposure where their role goes beyond that of a mere intermediary.

This makes contractual allocation of responsibility and the flow of technical information along the supply chain more important.

National implementation by the same date

Member States must transpose the Directive into national law by 9 December 2026. From that date, the new rules apply to relevant products placed on the market or put into service. Organisations placing AI systems or software-based products on the EU market need to assume that the modernised strict-liability regime will apply to those products from day one of the new framework.

Why this matters operationally

These changes are not only of interest to lawyers. They affect product design, documentation standards, update and monitoring processes, cybersecurity practices, and the evidence an organisation can produce if something goes wrong. Because AI systems are now clearly inside the regime, and because liability can attach to post-market behaviour under the manufacturer's control, the operational disciplines that support safety and traceability become part of liability preparedness.