Listen to this post

If your company makes products, integrates software into products, or operates in a complex global supply chain that touches the European Union, a major overhaul of EU product liability law is coming. To guarantee consumer protection in the new age of AI and rapidly evolving digital technologies, the EU has adopted a new Product Liability Directive (EU) 2024/2853 (the Directive). Below, we break down what’s changing, who it affects, and what companies should be doing now to prepare.

“Product” Definition Now Includes Software and Digital Files

The definition of “product” has expanded to cover all movables, even when integrated into another movable or an immovable product, and now expressly includes electricity, digital manufacturing files, raw materials, and software. In practical terms, this means software developers and AI system providers can now be held liable under a strict product liability framework, just like traditional manufacturers of physical goods. Companies that build software into their products, or that supply standalone software or AI systems into the EU market, should treat this as a fundamental shift.

Timeline

The Directive rewrites the rules that have governed product liability claims in Europe for nearly four decades, and it applies to products placed on the EU market or put into service after December 9, 2026. Products placed on the market or put into service before that date remain subject to the prior regime, unless a later substantial modification or update brings them within the scope of the new Directive.

Liability Extends Across the Entire Supply Chain

The Directive casts a wide net over who can be held liable for a defective product. For companies operating across multiple jurisdictions, this means liability exposure is no longer confined to the entity whose name is on the box. Importers, distributors, refurbishers, and any party that materially alters a product before resale all need to reassess their risk position. Liable parties now include:

  1. the manufacturer of the defective product itself;
  2. the manufacturer of a defective component that caused the resulting product to be defective;
  3. for non-EU manufacturers, the importer of the product in the EU market, the manufacturer’s authorized representative, and if neither exists, the fulfilment service provider.

Further, anyone who substantially modifies a product outside the manufacturer’s control and then places it on the market or puts it into service is treated as a manufacturer.

New Tools Make It Easier for Claimants to Win

The Directive introduces several mechanisms designed to help injured parties bring successful claims, and companies should understand each one:

  1. Mandatory disclosure. Where a claimant has presented facts and evidence sufficient to support the plausibility of their claim, the defendant can be required to disclose relevant evidence in its possession.
  2. Presumptions of defectiveness. A product will be presumed defective if the defendant fails to comply with a disclosure order, if the claimant shows non-compliance with mandatory product safety requirements, or if the claimant shows the damage resulted from an obvious malfunction during reasonably foreseeable use.
  3. The “complexity” safety net. Courts must presume defectiveness or causation where a claimant faces excessive difficulties, particularly due to technical or scientific complexity, and the claimant demonstrates it is likely that the product was defective or that a causal link exists.

Together, these tools significantly lower the practical barriers claimants have historically faced in complex product liability cases, particularly those involving sophisticated technology, software, or multi-party supply chains.

The Development Risk Defense Has New Limits

Manufacturers have long relied on the “development risk” defense, arguing that the state of
scientific and technical knowledge at the time a product was placed on the market meant the defect could not have been discovered. That defense survives under the new Directive, but with important carve-outs.

An economic operator cannot rely on the development risk defense where the defect results from a related service, from software (including updates or upgrades), from a failure to provide software updates or upgrades necessary to maintain safety, or from a substantial modification of the product, provided each of these was within the manufacturer’s control. Companies that ship over-the-air updates, provide connected services, or maintain products post-sale should factor this directly into how they manage update and patching obligations.

Liability Cannot Be Contracted Away

The Directive is explicit: liability of an economic operator cannot be limited or excluded, as
against an injured person, by a contractual provision or by national law. This means limitation of liability clauses buried in consumer-facing terms and conditions will not shield a business from claims under this framework. Companies should not assume that contractual risk allocation strategies that work in commercial agreements will have any effect on liability to injured end users.

Key Time Limits

The Directive sets out three distinct time periods that companies should build into their record keeping and risk management planning:

  1. Three-year limitation period. A claim must generally be brought within three years of the date the injured person became aware, or reasonably should have become aware, of the damage, the defect, and the identity of the responsible economic operator.
  2. Ten-year absolute expiry. An injured person generally loses the right to compensation once ten years have passed from the date the defective product was placed on the market or put into service, unless proceedings were already initiated.
  3. Twenty-five-year long-latency exception. Where a personal injury has a long latency period that prevented the injured person from bringing a claim within ten years, the expiry period extends to twenty-five years.

For companies with long product lifecycles, or products where harm may not manifest for years, this extended tail of potential exposure is a critical planning consideration, particularly for insurance and document retention policies.

What This Means for Your Business

The bottom line is straightforward: the EU’s new product liability rules make it easier for injured persons to bring claims, and they significantly expand the range of businesses that can be held responsible. Software, AI systems, updates, and other digital features are now treated much more like traditional physical products. Liability reaches beyond the named manufacturer to importers, service providers, and any business that substantially modifies a product before it reaches the market.

For companies that manufacture products or operate within complex global supply chains
touching the EU, this translates into a materially higher risk of liability and a genuine need to
prepare well ahead of the application date. As a starting point, businesses should:

  1. Review how products, including embedded software and connected features, are designed, tested, updated, and documented.
  2. Revisit customer- and supplier-facing contracts, recognizing that liability to injured persons cannot be excluded or limited by contract.
  3. Confirm that product liability insurance coverage reflects the expanded scope of liable parties and the extended limitation periods.
  4. Map supply chain roles, including component manufacturers, importers, authorized
    representatives, and fulfilment providers, to understand where liability may attach.

If you have questions about how Directive (EU) 2024/2853 affects your products, your contracts, or your supply chain, our product safety team is here to help.