Revised Product Liability Directive (PLD)

PLD applies to your AI system if it’s a product, a component of one, or software that shapes how one behaves. Most product teams haven’t mapped it.

PLD applies to your AI system if it's a product, a component of one, or software that shapes how one behaves. Most product teams haven't mapped it.
EU compliance consultancy

How Revised Product Liability Directive works for AI products

Directive (EU) 2024/2853 entered into force on 8 December 2024. Member States must transpose it by 9 December 2026, and from that date it applies to every product placed on the EU market or put into service after it — replacing the 1985 framework that never contemplated software as a product at all.

Product Liability Directive covers manufacturers, authorised representatives, importers, fulfilment service providers, distributors, and — under specific conditions — online platforms that enable the sale of a defective product, regardless of where any of them are established.

If your AI system is sold as a standalone product, embedded as a component in someone else’s product, or delivered as a digital service integral to a product’s function, PLD reaches you the moment that product is placed on the EU market.

PLD’s core demand is strict liability without fault: a claimant who suffers death, personal injury, medically recognised psychological harm, property damage, or destruction of personal data doesn’t have to prove the manufacturer was negligent — only that the product was defective and that the defect caused the harm.

For AI systems this creates specific exposure around opaque decision-making, post-sale software updates, and self-learning behaviour that changes after the product has already shipped, all of which sit alongside and frequently compound EU AI Act risk-management obligations rather than replace them.

Product Liability Directive Compliance Assessment for Your AI System

Fixed price · AI and software liability specific · Delivered in 5 working days

How PLD works for AI products

Product Liability Directive (PLD)
Product Liability Directive (PLD)

PLD organises its requirements across five areas. Each creates specific exposure for AI systems placed on the EU market as products, components, or integral digital services.

Expanded product definition
Software, including AI systems and firmware, is now explicitly a product in its own right, alongside digital manufacturing files and digital services that are integrated into or interconnected with a physical product.

A standalone model, an API-delivered inference service, or an AI feature bundled into hardware all fall inside this definition — there is no carve-out for products that are “just software.”

Economic operators and liable parties
Liability runs to the manufacturer first, but where the manufacturer is outside the EU, it shifts to the EU-based importer or authorised representative, and where neither exists, to the fulfilment service provider that handled the product for an EU consumer.

Distributors carry secondary liability if they cannot identify the manufacturer or importer on request.

Online platforms that present a product as their own, or that fail to identify the actual supplier where the platform enables the transaction, can be held liable as if they were that supplier.

Presumptions of defectiveness and causation
Where technical or scientific complexity makes it excessively difficult for a claimant to prove a defect or a causal link — the standard case for an AI system’s internal logic — courts may presume both, shifting the practical burden onto the defendant to disprove them.

A defendant that cannot explain why its system behaved the way it did is now the party expected to close that gap, not the injured party.

Expanded damage and disclosure obligations Recoverable damage now includes medically recognised psychological harm and the destruction or corruption of personal, non-professional data, with no minimum damage threshold.

Courts can order a defendant to disclose relevant evidence, including technical documentation, at the claimant’s request, and refusal to disclose triggers a presumption of defectiveness.

Post-market liability for updates and self-learning behaviour
A manufacturer remains liable for defects introduced after the product is placed on the market where it retains control over software updates, upgrades, or the AI system’s continued learning.

For example, an AI feature that behaves safely at launch and later develops a defect through a manufacturer-controlled update or through learning the manufacturer allowed to continue is still the manufacturer’s liability, not a subsequent, unrelated event.

Who Product Liability Directive applies to

PLD applies directly to every economic operator in a product’s supply chain, and it explicitly reaches AI systems whether they are sold standalone, embedded as a component, or delivered as an integral digital service — regardless of where any operator is established.

Entity typeIn scope?Key obligation
AI software or model provider placing a standalone product on the EU marketYes — as manufacturerStrict liability for defects, full exposure under the expanded product definition
Non-EU AI manufacturer with an EU-based importer or authorised representativeYes — liability shifts to the importer/ARImporter or AR bears manufacturer-level liability in the manufacturer’s place
Non-EU AI manufacturer with no EU importer or authorised representativeYes — liability falls to the fulfilment service providerFulfilment provider bears liability where no other EU-established party can be identified
AI component or model supplier integrated into another company’s productYes — as component manufacturerJoint and several liability alongside the integrating manufacturer
Distributor of an AI-embedded productYes — secondary liabilityLiable if unable to identify the manufacturer, importer, or AR on request
Online platform enabling the sale of a defective AI-embedded productYes — under specific conditionsLiable as if it were the supplier, where it presents the product as its own or fails to identify the actual supplier
GPAI model provider with no specific product placed on the EU marketUnclear — depends on whether the model itself is deemed a product or componentTreat as in scope until the specific deployment is assessed
Company running AI purely internally, never placed on the market or put into serviceNo — until it isDocument the determination and revisit at the point of any market placement

Post-market and burden-of-proof exposure: what AI companies miss

PLD’s two most consequential mechanisms for AI companies are the ones least visible at product launch: liability that survives the sale, and a burden of proof that shifts toward the defendant precisely where AI systems are hardest to explain.

Three things AI companies consistently misunderstand:

Liability doesn’t stop at delivery. Where a manufacturer retains control over software updates, model upgrades, or an AI system’s continued learning after it reaches the user, any defect introduced through that ongoing control is still the manufacturer’s liability.

Shipping a model that behaves safely and then degrades through a manufacturer-pushed update, or through learning the manufacturer chose not to constrain, is not a supervening event that breaks the liability chain — it’s the same liability, later.

The presumption of defectiveness is designed for exactly the “black box” defence AI companies reach for first. Where the technical complexity of an AI system makes it excessively difficult for a claimant to prove what went wrong, courts can presume the defect and the causal link, and the defendant carries the practical burden of disproving them.

“The model is too complex to explain” is not a defence under this regime, it is close to the trigger condition for the presumption applying against you.

Component suppliers don’t get to hide behind the integrator. An AI model or API provider embedded into someone else’s product is a component manufacturer with its own liability, running jointly and severally alongside the company that built the final product. Contract terms that assume “we just supply the model, the liability is theirs” do not bind an injured claimant, whatever they say between the parties.

What PLD compliance requires from AI products

These are the PLD requirements that apply most directly to AI products placed on the EU market as standalone products, embedded components, or integral digital services.

Product classification review — a determination of whether your AI system is a standalone product, a component, or an integral digital service under the expanded product definition, and which economic operator role you occupy.

Economic operator mapping — identification of the manufacturer, importer, authorised representative, fulfilment provider, and any platform in your supply chain, and confirmation of who bears liability where the manufacturer is outside the EU

Explainability and documentation readiness — technical documentation sufficient to rebut a presumption of defectiveness, given that opacity itself now works against the defendant rather than protecting it.

Disclosure preparedness — a process for responding to court-ordered evidence disclosure requests without triggering a defectiveness presumption through refusal or delay.

Post-market update governance — a defined boundary for which software updates, upgrades, or learning behaviour remain under your control after sale, since that boundary determines how long your liability exposure continues.

Damage and data-harm assessment — a review of your AI system’s exposure to the newly recoverable categories of harm, particularly destruction or corruption of personal, non-professional data with no minimum threshold.

Component liability terms — contract terms with integrators or component suppliers that reflect joint and several liability accurately, rather than allocations that don’t bind an injured third party.

Insurance and reserve review — confirmation that product liability cover reflects the expanded product definition, the removed damage threshold, and the extended limitation periods for latent personal injury claims.

One engagement. Every PLD obligation mapped for your AI system.

A lawyer-built assessment of your AI system’s PLD obligations — product classification, economic operator mapping, explainability and disclosure readiness, post-market update governance, and component liability review — and a documented compliance record you and your counterparties can rely on.

Frequently Asked Questions About PLD Compliance

What is Product Liability Directive and who does it apply to?

The revised Product Liability Directive, Directive (EU) 2024/2853, entered into force on 8 December 2024 and applies from 9 December 2026 to products placed on the EU market or put into service after that date.

PLD applies to manufacturers, importers, authorised representatives, fulfilment service providers, distributors, and, under specific conditions, online platforms, regardless of where they are established, provided the product reaches the EU market.

Does the PLD apply to software and AI that isn’t sold as a physical product?

Yes. The revised Directive explicitly includes software, AI systems, firmware, and digital services integral to a product’s function within the definition of “product.” A standalone model or an API-delivered inference service can be a product in its own right, not only a component of hardware.

What’s the difference between the PLD and the EU AI Act for AI liability?

The AI Act governs the AI system before and at market placement — risk classification, technical documentation, conformity assessment. The PLD governs what happens after something goes wrong: who is liable when a defective product causes harm, and how the burden of proof is allocated in court.

Compliance with the AI Act’s documentation obligations is one of the strongest defences available under the PLD’s presumption mechanism, but the two regimes are enforced through entirely different routes: regulatory supervision for the AI Act, civil litigation for the PLD.

What is the presumption of defectiveness and why does it matter for AI?

Where technical or scientific complexity makes it excessively difficult for a claimant to prove a product was defective or that the defect caused their harm, a court can presume both are true, shifting the practical burden onto the defendant to disprove them.

AI systems are the paradigm case this mechanism was written for — internal model behaviour is exactly the kind of complexity that has historically protected manufacturers from claims they couldn’t be forced to explain.

Am I liable for an AI defect introduced by a software update after the product was sold?

Yes, if you retained control over that update, upgrade, or the system’s continued learning. The PLD extends manufacturer liability to defects arising after the initial sale wherever the manufacturer remains in a position to control the product’s software behaviour, which is the normal operating condition for most commercial AI systems.

Does the PLD apply to non-EU AI companies?

Yes. Liability follows the product to the EU market regardless of where the manufacturer is established. Where the manufacturer is outside the EU, liability shifts to the EU-based importer or authorised representative, and where neither exists, to the fulfilment service provider that handled the product for an EU consumer — so non-EU AI companies cannot assume distance from the EU removes exposure.

Can an AI model or API provider be liable if its model is embedded in someone else’s product?

Yes. A component manufacturer, including a supplier of an AI model or API integrated into another company’s product, carries its own liability under the PLD, running jointly and severally with the integrating manufacturer. Contractual allocation of responsibility between the two companies does not bind a claimant who was harmed by the finished product.

What damages are recoverable under the revised PLD?

Death, personal injury, medically recognised psychological harm, damage to property, and destruction or corruption of data that is not used exclusively for professional purposes. The previous minimum damage threshold has been removed, and limitation periods have been extended to allow claims for latent personal injuries discovered many years after the product was placed on the market.

How do I start PLD compliance for my AI product?

Four steps in order. First, classify your AI system as a standalone product, a component, or an integral digital service, and identify your economic operator role in the supply chain.

Second, assess your technical documentation against the presumption-of-defectiveness standard — can you explain the system’s behaviour well enough to rebut a presumption if one arises?

Third, define the boundary of your post-market control over updates and learning behaviour, since that boundary sets the outer limit of your ongoing liability.

Fourth, review contracts with integrators, component suppliers, and insurers against the expanded product definition and removed damage threshold.

A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your system and your supply chain.