REVISED EUROPEAN PRODUCT LIABILITY DIRECTIVE

Product Liability Directive Pack

From 9 December 2026, the revised EU Product Liability Directive treats software and AI systems as products for the first time. Liability is strict — no fault required — and the exposure is uncapped, unlike any regulatory fine. There is nothing to file and no authority to satisfy. What exists is a civil claim, years down the line, and an evidentiary position you built in advance (or you didn’t).

This pack builds it.

For manufacturers, importers and other economic operators placing products — including software and AI — on the EU market. You get six documents that assemble, before any claim, the evidence a strict-liability regime will test.

What makes the revised Product Liability Directive dangerous for software and AI

  • Software and AI are products now inside strict product liability for the first time.
  • “Too complex to explain” no longer defends you. Article 10 lets a court presume both defectiveness and causation where technical complexity makes proof excessively difficult for the claimant. Complexity now helps the person suing you.
  • Failure to disclose is itself a presumption. If a court orders disclosure and you don’t comply, defectiveness is presumed on that basis alone.
  • Your responsibility doesn’t end at shipping. Defectiveness can arise after placement from an update, an unpatched vulnerability, or a system that learns — and the state-of-the-art defence doesn’t apply where the cause was within your control.
  • The exposure is uncapped unlike the fine ceilings of the regulatory regimes.

Who should care about European Product Liability Directive

  • Software and AI companies whose products reach EU users — now inside strict product liability for the first time.
  • Manufacturers of connected and digital products. Importers and fulfilment operators in the liability chain behind third-country products.
  • In-house counsel who have realised that the withdrawal of the separate AI Liability Directive leaves the PLD as the civil-liability route for AI harm.
  • Companies that would rather build the evidence now than reconstruct it under a court deadline.

What you get in this pack:

Six documents, each an explanatory notice paired with a ready-to-complete template:

Post-Placement Update & Cybersecurity Documentation — because defectiveness can arise from updates and unpatched vulnerabilities within your control.

Economic Operator Determination — whether you are manufacturer, importer, authorised representative, fulfilment service provider or distributor, per product. Free to download.

Placement-Date Register — because liability attaches per unit by reference to when it entered the market.

Defectiveness Evidence File — the state of the art at placement, the safety a person was entitled to expect, and what you tested — built to rebut the Article 10 presumptions.

Retention Schedule — reconciling the ten-year longstop, the twenty-five-year latent-injury extension, and GDPR minimisation.

Article 9 Disclosure Readiness Record — mapping what a court could order disclosed, so non-disclosure never becomes the reason you lose.

How the Product Liability Directive connects to everything else you comply with

The revised Product Liability Directive doesn’t define its own safety standard — it borrows one. A product that breaches mandatory EU safety law (the AI Act, the Cyber Resilience Act, the GPSR, the Machinery Regulation) can be presumed defective on that basis.

So your AI Act compliance, your CRA vulnerability handling, your product-safety documentation are no longer just regulatory obligations — they are your product-liability defence.

The Product Liability Directive sits on top of the entire EU digital rulebook as its civil-liability consequence layer. This pack turns the compliance evidence you already hold into litigation defence.

Start with the operator determination

Download the Economic Operator Determination free. Work through it and you’ll know, for each product, exactly where you sit in the liability chain and what exposure you actually carry.

Download the free Economic Operator Determination →

What the price covers

€1,900, including twelve months of updates as Member States transpose the Directive through 2026 and the case law develops.

A law firm assembling this evidentiary framework from scratch — operator analysis, defectiveness files, a disclosure-readiness strategy and a defensible retention position — will typically run €8,000–20,000, and that is before any claim.

The pack is the same framework at a fraction of the cost, built while there is still time to build it.

What this pack is not (important!)

This is not legal advice, and it is not a defence to any particular claim. It is an evidentiary framework that a qualified lawyer should adapt to your products, and that your litigation counsel will draw on if a claim arises.

Because the Directive is transposed by each Member State and the case law has not yet developed, the pack takes positions on how the regime will operate that warrant review as the national implementations and the courts clarify them. Holding this evidence reduces your exposure but does not eliminate it.

FAQ

When does the revised Product Liability Directive apply?

The revised Product Liability Directive, Directive (EU) 2024/2853, applies to products placed on the EU market from 9 December 2026. Member States must transpose it into national law by the same date. Products placed on the market before then remain under the 1985 Directive, 85/374/EEC, which means two liability regimes will run in parallel for years. The date that matters is when each individual unit was placed on the market, not when it was sold, manufactured or updated.

Does the Product Liability Directive apply to software?

Yes, the revised Directive treats software as a product in its own right, including standalone software, AI systems, firmware and software supplied as a service. This is the most significant change from the 1985 regime, which covered only tangible movables.

A software developer placing a product on the EU market is now a manufacturer for liability purposes, whether the software is embedded in hardware, downloaded, or delivered over a network.

What is the PLD Article 10 presumption of defectiveness?

Article 10 allows a court to presume that a product was defective, and that the defect caused the damage, where the technical or scientific complexity of the case makes it excessively difficult for the claimant to prove either. The presumption is rebuttable, but rebutting it requires the defendant to produce evidence about how the product actually behaved. For AI and complex software, “the system is too complex to explain” therefore works against the defendant rather than for them.

Is liability under the revised Product Liability Directive fault-based?

No. Liability under the Product Liability Directive is strict. A claimant does not need to show negligence, breach of a standard, or any failure of care. They must show the product was defective, that they suffered damage, and that the defect caused it — and Article 10 can supply the first and third of those by presumption.

Who is liable under the revised Product Liability Directive?

The manufacturer is primarily liable, and where the manufacturer is established outside the EU, liability extends to the importer, the authorised representative and, in defined circumstances, the fulfilment service provider. Distributors can become liable where they fail to identify an upstream economic operator on request. A company that substantially modifies a product outside the original manufacturer’s control can itself become the manufacturer of the modified product.

Does the revised PLD cover damage caused by software updates?

Yes. Where a manufacturer retains control over a product after it is placed on the market — through software updates, machine learning, or connected services — defects arising from that control fall within the manufacturer’s liability. The manufacturer cannot rely on the defence that the defect did not exist when the product was placed on the market if the defect resulted from something within its ongoing control.

What damage is recoverable?

Death and personal injury, including medically recognised harm to psychological health; damage to property other than the defective product itself; and the destruction or corruption of data that is not used for professional purposes. The data limb is new and reaches software products directly. The revised Directive also removed the €500 lower threshold that applied to property damage under the 1985 regime.

How long does liability last?

Liability runs for ten years from the date the product was placed on the market, extended to twenty-five years where a claimant could not bring proceedings within ten years because of a latent personal injury. A separate three-year limitation period runs from the date the claimant became aware, or should reasonably have become aware, of the damage, the defect and the identity of the liable operator.

Does the PLD conflict with GDPR retention limits?

In practice, yes. GDPR data minimisation encourages deletion, while the PLD’s ten-year longstop — twenty-five years for latent injury — means the evidence that would rebut an Article 10 presumption may need to survive far longer than a typical retention schedule allows. Companies that delete on a two or three year cycle can find they have lawfully destroyed the only records capable of defending a claim. Reconciling the two positions in writing is part of what this pack does.

Can a court order me to disclose evidence?

Yes. Article 9 allows a national court to order a defendant to disclose relevant evidence at its disposal, and failure to comply triggers the presumption of defectiveness in its own right. The practical consequence is that the question is not only whether you hold the records, but whether you are prepared to produce them.

Can a court order me to disclose evidence?

Yes. Article 9 allows a national court to order a defendant to disclose relevant evidence at its disposal, and failure to comply triggers the presumption of defectiveness in its own right. The practical consequence is that the question is not only whether you hold the records, but whether you are prepared to produce them.

Is there a regulator or filing requirement under the PLD?

No. The Product Liability Directive creates no supervisory authority, no registration, no conformity assessment and no filing. It creates a civil liability position that is tested in court, which is why the compliance work is evidentiary rather than administrative. There is no fine schedule and no cap on liability.

Does the PLD apply to non-EU companies?

Yes. Liability attaches to products placed on the EU market regardless of where the company is established. Where the manufacturer is outside the EU, the importer and the authorised representative carry liability alongside it, which is why non-EU manufacturers frequently need EU-established representation for reasons unconnected to the AI Act.

How does the PLD interact with the EU AI Act?

They operate independently and cover different populations. The AI Act regulates AI systems by risk tier through documentation and conformity assessment, with obligations for high-risk systems deferred to December 2027 and August 2028. The PLD applies to any product with software, regardless of risk tier or whether AI is present, from December 2026. A company entirely outside AI Act high-risk scope can still face an Article 10 presumption.

What is in the Product Liability Directive Compliance Pack?

Economic operator determination per product; a placement-date register, because liability attaches per unit by reference to when it entered the market; a defectiveness evidence file covering the state of the art at placement and what was tested; a retention schedule reconciling the ten-year longstop, the twenty-five-year extension and GDPR minimisation; an Article 9 disclosure readiness record; and post-placement update documentation covering defects arising from ongoing manufacturer control.

Is open source software covered?

Free and open-source software developed or supplied outside a commercial activity falls outside the Directive. Where open-source software is supplied in the course of a commercial activity, or integrated into a commercial product, the ordinary rules apply and the integrator carries the exposure.