The revised Product Liability Directive applies to AI systems and other products placed on the market or put into service from 9 December 2026. From that date, organisations can face strict liability claims if a defective AI system causes covered damage. The full high-risk obligations of the EU AI Act for many systems arrive later - from 2 December 2027 or 2 August 2028 depending on the category. The practical task is to be ready for the liability regime even where the complete regulatory framework is not yet mandatory.
This is not about bringing every future AI Act requirement forward in full. It is about ensuring that the systems you place on the market can be explained, evidenced and defended if something goes wrong.
1. Know which AI systems are in scope
Identify AI systems that will be placed on the EU market or put into service from 9 December 2026. Treat them as products for liability purposes. Be clear who is acting as manufacturer - including where your organisation develops, fine-tunes, brands or substantially modifies systems. Map the supply chain so that roles (provider, importer, distributor, modifier) are understood and contractual responsibilities are aligned with the statutory position.
2. Be able to show what the system is and how it was controlled
In a claim, the organisation will need to explain the system's intended purpose, its reasonably foreseeable uses, and how safety-related decisions were made. That requires maintained technical information: design and development records, data and model governance relevant to safety, testing and validation results, known limitations, and the rationale for key design choices.
For AI systems that continue to learn or that receive updates under your control, keep clear records of what changed, when, under whose authority, and with what verification. Liability can attach to defects that arise from post-market updates or continuous learning while the system remains under the manufacturer's control. If you cannot reconstruct that history, defending a claim becomes much harder.
3. Treat mandatory safety requirements as liability-relevant
Under the revised Directive, failure to comply with mandatory product safety requirements intended to protect against the relevant risk can support a presumption of defect. As AI-related safety, cybersecurity and transparency requirements apply, gaps in compliance can feed directly into liability exposure.
This does not mean every AI Act high-risk duty is already mandatory for every system in December 2026. It does mean that requirements that are in force - and any that qualify as mandatory safety rules protecting against the type of harm claimed - should be taken seriously as part of liability preparedness, not only as future regulatory tasks.
4. Build evidence that can be disclosed and understood
Courts can order disclosure of relevant technical information. In complex AI cases they may also presume defect and causation if the claimant shows these are likely. The organisation that can produce clear, ordered, intelligible evidence is in a stronger position to rebut those presumptions.
Evidence that typically matters includes risk assessments, design and validation records, instructions and limitations communicated to users, update and monitoring logs, incident and corrective-action records, and cybersecurity measures. Storing these in a controlled way - so they can be retrieved and explained - is a practical necessity from December 2026 onwards.
5. Align oversight, updates and monitoring with ongoing control
If the system remains under your control after placement on the market, the processes that govern updates, learning behaviour, monitoring and response to safety issues are part of the liability picture. Define who may release changes, what checks are required, how performance and safety-related events are monitored, and how problems are escalated and corrected. Record those activities.
6. Use management-system discipline even before full high-risk deadlines
A full Quality Management System under Article 17 of the AI Act and EN 18286 is timed to the high-risk regulatory deadlines. The logic of that system - clear ownership, risk management, documented design and change control, competence, monitoring and retained evidence - is already valuable for product liability defence.
Organisations that wait until 2027 or 2028 to build basic documentation, ownership and evidence trails create a window in which liability exposure exists without the operational backbone needed to respond. Starting earlier with proportionate, structured controls reduces that gap.
7. Review contracts and information flow
Statutory liability cannot be contracted away, but risk allocation, information sharing, cooperation on claims, and requirements for technical documentation along the supply chain can be clarified. Ensure that agreements with developers, integrators, cloud providers and distributors support the ability to obtain and present the evidence a claim may require.
The core point
From 9 December 2026, AI systems placed on the EU market sit inside a modernised strict-liability regime. Claimants in complex cases have stronger tools. Manufacturers and others in the chain need to be able to show how their systems were designed, controlled, updated and monitored.
That readiness is not identical to full high-risk AI Act compliance, which follows later for many systems. It is, however, closely related. The same disciplines - inventory, ownership, risk and design evidence, change control, monitoring and retrievable records - serve both liability defence and later regulatory obligations. Building them now addresses the earlier clock without waiting for the later one.