When a product causes harm, someone has to answer for it. The Product Liability Directive is the European Union's main set of rules that decides when the maker of a product is responsible for damage caused by a defect in that product - and how an injured person can claim compensation.
It is not about blaming someone for being careless. It is built on a simpler idea called strict liability. Under strict liability, the injured person does not have to prove that the manufacturer was negligent or made a mistake on purpose. They mainly need to show three things:
- The product was defective.
- They suffered damage of a type the rules cover.
- The defect caused that damage.
If those points are established, the manufacturer can be held liable, subject to certain defences.
Why these rules exist
The original Product Liability Directive dates from 1985. It was written for a world of physical goods - cars, machinery, household appliances, medicines and similar products. The goal was to give people across the EU a clear and relatively uniform way to seek compensation when a defective product caused personal injury or damage to private property, without every case turning into a long fight over whether the manufacturer had been careful enough.
That framework worked reasonably well for traditional products. It became much harder to apply cleanly once software, connected devices and artificial intelligence became common. Questions arose that the 1985 text did not answer clearly:
- Is software a "product"?
- What if the product changes after it is sold because of updates or machine learning?
- How can an ordinary person prove what went wrong inside a complex digital system?
The revised Directive - formally Directive (EU) 2024/2853 - was adopted to answer those questions and to modernise the regime for the digital age. It will apply to products placed on the market or put into service from 9 December 2026. Until then, the older rules continue to apply to products already on the market before that date.
Who the rules protect and what they cover
The rules are designed to protect natural persons (individuals) who suffer certain types of harm. The classic categories are personal injury (including death) and damage to property used for private purposes. The revised Directive also addresses damage to data in defined circumstances.
Business-to-business pure economic loss is generally outside the harmonised strict-liability regime, although other legal routes may still exist under national law.
Who can be held liable
The primary focus is the manufacturer - the person or company that made the product or who presents themselves as the manufacturer (for example by putting their name or brand on it). In the digital context, this can include the developer or provider of software, including AI systems. Other parties in the supply chain can also face liability in specific situations, for example where the manufacturer is outside the EU or where someone substantially modifies the product.
What "defective" means
A product is defective when it does not provide the safety that a person is entitled to expect, taking into account all the circumstances. This is an objective test. It is not about whether the manufacturer tried hard; it is about the safety that users are entitled to expect in the real world.
For digital and AI products, the assessment can take into account factors such as the product's ability to learn or change after it is placed on the market, the effect of software updates, cybersecurity, and how the product interacts with other products or digital services.
Why this matters to risk, AI and executive teams
Product liability is not only a legal topic for the litigation team. It affects how products are designed, documented, updated, monitored and supported. When something goes wrong and causes harm, the organisation that placed the product on the market may need to show what the product was, how it was intended to work, what controls and testing existed, and how changes after placement were managed.
The revised Directive makes these questions more direct for software and AI. From December 2026, AI systems placed on the EU market are clearly within the product liability regime. That changes both the risk profile and the practical need for clear technical evidence and controlled processes.