AI Assurance Institute Logo AI Assurance Institute

Leveraging EN 18286 to Prepare for the EU Product Liability Directive

On 9 December 2026, the revised Product Liability Directive (Directive (EU) 2024/2853) will bring software and AI systems fully within Europe's long-standing strict-liability regime for defective products. Member States must transpose the Directive by that date. It applies to products placed on the market or put into service from 9 December 2026; products placed on the market earlier remain under the previous regime of Directive 85/374/EEC.

Claimants will no longer need to prove negligence. They need only show that the product was defective and caused harm. The definition of "product" expressly includes software, including AI systems, regardless of delivery model. Manufacturers remain liable for defects that arise after placement on the market where those defects stem from updates or upgrades under their control, or from continuous learning of an AI system that remains under their control. Non-compliance with mandatory safety requirements under Union law, including relevant obligations under the AI Act, can support a rebuttable presumption of defectiveness. Enhanced disclosure mechanisms further shift the practical burden toward organised technical evidence. Evidence of the oversight, risk controls, and quality processes that were actually in place becomes critical - and that evidence is extremely difficult to assemble after a claim has been filed.

EN 18286:2026 - Artificial intelligence - Quality management system for EU AI Act regulatory purposes - offers one of the most practical tools available for addressing this exposure.

What EN 18286 provides

EN 18286 was approved by CEN/CENELEC in July 2026 and published as a European standard under the AI Act standardisation work of CEN/CLC/JTC 21. It is the first European standard delivered specifically to support AI Act implementation. It specifies requirements and guidance for establishing, implementing, maintaining and continually improving a quality management system for organisations that provide AI systems. It is primarily intended for organisations placing high-risk AI systems on the market or putting them into service, and is not sector-specific.

The standard translates the quality-management obligations in Article 17 of the AI Act into a structured, product-centric framework. It covers the full AI system lifecycle: regulatory strategy and management responsibility, risk management, data governance, design and development controls (including verification, validation and change management), technical documentation, supplier control, post-market monitoring, serious-incident reporting, and continual improvement. It is designed to be compatible with existing systems such as ISO 9001 and ISO 13485, yet it is deliberately more focused on the AI product itself than pure organisational standards.

Once the standard is cited in the Official Journal of the European Union, conformity with EN 18286 will confer a presumption of conformity with the corresponding AI Act requirements under Article 40. As of mid-2026 the standard has been published by CEN/CENELEC, but Official Journal citation has not yet occurred. Even before formal citation, the published text already supplies the clearest operational blueprint for what regulators, notified bodies and, in liability proceedings, courts will expect of a functioning AI quality management system.

Why the Product Liability Directive still bites in 2026

The Digital Omnibus on AI deferred the bulk of high-risk Chapter III obligations under the AI Act (Annex III systems to 2 December 2027; Annex I product-embedded systems to 2 August 2028). That deferral does not move the Product Liability Directive. Strict liability for defective software and AI products still applies from 9 December 2026. Organisations that treat AI Act high-risk readiness as a 2027 problem can still face product-liability exposure at the end of 2026 if they place software or AI systems on the EU market.

The link between the two regimes is direct. Under the Product Liability Directive, failure to meet mandatory safety requirements under EU law can create a presumption that the product was defective. A documented, functioning quality management system aligned with EN 18286 substantially reduces the likelihood of that presumption arising and, if a claim is brought, supplies the contemporaneous records needed to rebut it.

More specifically, EN 18286 helps organisations:

Practical illustration: controlled document ingestion

Consider a typical controlled process for approving documents into an AI knowledge base. The flow begins with formal approval for inclusion, branches according to whether the document is a new type or a version update, requires specific validation against defined SOPs, includes remediation and re-validation loops, and ends only after the vector database has been verified to contain solely current and effective procedures, with change control formally closed. This kind of rigorous, closed-loop control is exactly what EN 18286 expects for documentation, change management and operational integrity. When such processes are implemented and recorded under the standard, they become powerful contemporaneous evidence that the organisation maintained the safety and currency of the AI system throughout its lifecycle - evidence that is difficult to invent after a claim has been notified.

Preparing now

Organisations placing, or intending to place, AI systems on the EU market should treat EN 18286 as a core element of their December 2026 product-liability readiness programme, independently of the later high-risk AI Act application dates. Practical steps include:

Conclusion

The Product Liability Directive will apply from 9 December 2026 to software and AI systems placed on the market or put into service from that date. EN 18286 does not eliminate strict liability, but it converts the abstract need for defensible oversight into a concrete, auditable set of processes and records. By implementing the standard now, organisations create the contemporaneous evidence that will be decisive if a claim is ever brought, while simultaneously advancing genuine AI Act readiness - including for high-risk obligations that apply later under the Digital Omnibus timeline. In the new liability landscape, that combination of regulatory alignment and evidentiary strength is one of the highest-leverage preparations available.