Directive (EU) 2024/2853 on liability for defective products replaces the 1985 regime that has governed EU product liability for four decades. Member states must transpose it by 9 December 2026, which is two months away.
Four changes carry most of the commercial weight:
- Software is a product, including standalone software and AI systems, which brings software companies into strict liability for the first time.
- Defectiveness now expressly covers cybersecurity vulnerabilities and the failure to supply security updates.
- Claimants gain a disclosure right against defendants and a set of rebuttable presumptions that shift the evidential burden.
- The development risk defence, which protected manufacturers where a defect was undiscoverable given the state of scientific knowledge, can be disapplied by member states.
The directive applies to products placed on the market or put into service after the transposition date, so the old regime continues to govern everything already on the market. That creates a dual-track position lasting years rather than months.
Transposition is uneven. As of late 2026 a small number of member states have completed it, roughly a dozen have draft legislation in progress, and a substantial group has taken no meaningful public steps.
Official text: Directive (EU) 2024/2853
Key Product Liability Directive Definitions
Definitions are drawn from Article 4 of the directive.
| Term | Definition |
|---|---|
| Product | All movables, even if integrated into, or interconnected with, another movable or an immovable. Includes electricity, digital manufacturing files, raw materials, and software |
| Digital manufacturing file | A digital version of, or digital template for, a movable, containing the functional information necessary to produce a tangible item by automated control |
| Related service | A digital service integrated into, or interconnected with, a product in such a way that its absence would prevent the product from performing one or more of its functions |
| Component | Any item, whether tangible or intangible, or any related service, that is integrated into, or interconnected with, a product by the manufacturer or within that manufacturer’s control |
| Defective product | A product that does not provide the safety which a person is entitled to expect, or which is required under Union or national law |
| Manufacturer | Any natural or legal person who develops, manufactures or produces a product, or who has a product designed or manufactured, or who presents the product as its own by putting its name or trade mark on it |
| Economic operator | A manufacturer of a product or component, a provider of a related service, an authorised representative, an importer, a fulfilment service provider, or a distributor |
| Placing on the market | The first making available of a product on the Union market |
| Substantial modification | A modification of a product after it has been placed on the market or put into service that is considered substantial under relevant Union or national rules on product safety |
What the Directive on Liability for Defective Products Replaces
Council Directive 85/374/EEC established strict liability for defective products across what was then the European Community. It worked on an assumption that no longer holds: that products are tangible objects, finished at the point of sale, with risks that are detectable by inspection.
The 1985 text was not designed for products that receive updates, that depend on external services to function, that learn from data after deployment, or that have no physical form at all. The European Commission’s revision addressed each of those, and in doing so moved the boundaries of strict liability considerably.
Directive 85/374/EEC is repealed with effect from 9 December 2026, though it continues to govern products placed on the market before that date.
Product Liability Directive: The Timeline
| Date | Event |
|---|---|
| September 2022 | Commission publishes the draft directive |
| March 2024 | Political agreement between Council and Parliament |
| 23 October 2024 | Directive adopted at Strasbourg |
| 18 November 2024 | Published in the Official Journal |
| 8 December 2024 | Entry into force |
| 9 December 2026 | Transposition deadline. Directive 85/374/EEC repealed |
| After 9 December 2026 | New regime applies to products placed on the market or put into service |
One point of precision worth noting. The directive as published states that it applies to products placed on the market or put into service after 9 December 2026. A corrigendum has been reported as correcting this to 8 December 2026.
The one-day difference will rarely matter, but for products placed on the market in that window it could, and practitioners should check the consolidated text in the relevant national transposing law rather than relying on the original publication.
PLD Change One: Software Is a Product
This is the structural change with the widest reach, and it brings an entire industry into a liability regime it has not previously faced.
Article 4(1) defines a product to include software. The definition does not distinguish between software embedded in a physical device, software supplied separately, and software delivered as a service where it forms part of a product. Standalone software, operating systems, applications, firmware, and AI systems all fall within scope.
| Category | Covered |
|---|---|
| Software embedded in a physical product | Yes |
| Standalone software sold or supplied to consumers | Yes |
| AI systems and AI-enabled applications | Yes |
| Digital manufacturing files | Yes |
| Related services integral to a product’s function | Yes, as components |
| Free and open-source software supplied outside a commercial activity | No |
| Open-source software supplied commercially or integrated into a commercial product | Yes |
| Information as such, for instance the content of a digital file | No |
The free and open-source carve-out mirrors the approach taken in the Cyber Resilience Act. Software developed and supplied outside the course of a commercial activity sits outside the regime. Once it is monetised, supported commercially, or shipped inside a commercial product, the exclusion falls away and liability attaches to whoever placed the resulting product on the market.
For a software company that has structured its risk around contractual limitation of liability, the significant point is that strict liability under the directive cannot be excluded or limited by contract. Article 15 makes any contractual derogation to the detriment of the injured person ineffective.
PLD Change Two: Defectiveness Now Covers Security and Updates
Article 7 sets out the circumstances relevant to assessing whether a product is defective. Several are new and each reflects a digital failure mode the 1985 directive could not have anticipated.
| Circumstance | Effect |
|---|---|
| The effect on the product of any ability to continue to learn or acquire new features after deployment | Machine learning behaviour post-deployment is relevant to defectiveness |
| The effect on the product of other products that can reasonably be expected to be used together with it | Interoperability failures can render a product defective |
| The moment in time when the product was placed on the market, or when it left the manufacturer’s control where the manufacturer retains control thereafter | Retained control extends the assessment window |
| Relevant product safety requirements, including safety-relevant cybersecurity requirements | Breach of CRA or similar obligations feeds directly into defectiveness |
| Any intervention by a regulatory authority or economic operator relating to product safety | Recalls and corrective action are evidence |
| The specific needs of the group of users for whom the product is intended | Vulnerable user groups raise the expected safety standard |
The cybersecurity limb is the one that connects the directive to the rest of the EU digital rulebook. A product with a known exploitable vulnerability, or one whose manufacturer has stopped supplying security updates within the period the user was entitled to expect, can be defective on that basis alone.
The retained control point extends liability in time. Where a manufacturer keeps control over a product after it has left its hands, through software updates, remote configuration, or a connected service, the relevant moment for assessing defectiveness moves with that control rather than freezing at the point of sale.
PLD Change Three: Disclosure and Presumptions
Under the 1985 regime, a claimant had to prove the defect, the damage, and the causal link. For a complex software-driven product, that burden was often insurmountable, because the evidence sat with the defendant.
The new directive addresses this in two ways.
Disclosure of evidence
Product Liability Directive’s Article 9 requires member states to ensure that national courts can order a defendant to disclose relevant evidence at the claimant’s request, where the claimant has presented facts and evidence sufficient to support the plausibility of the claim. The obligation is reciprocal, and courts must protect confidential information including trade secrets.
This is a substantial change in jurisdictions without broad civil disclosure. It means source code, design documentation, test results, and internal risk assessments can be ordered into evidence.
Rebuttable presumptions
Article 10 in Product Liability Directive sets out presumptions that operate against the defendant in defined circumstances.
| Presumption | Trigger |
|---|---|
| The product is presumed defective | The defendant fails to comply with a disclosure order |
| The product is presumed defective | The claimant demonstrates the product does not comply with mandatory safety requirements intended to protect against the risk that materialised |
| The product is presumed defective | The claimant demonstrates the damage was caused by an obvious malfunction during reasonably foreseeable use |
| Causation is presumed | The product is defective and the damage caused is of a kind typically consistent with that defect |
| Both defectiveness and causation are presumed | The claimant faces excessive difficulties due to technical or scientific complexity, and demonstrates it is likely the product was defective or that causation exists |
The excessive difficulty presumption is the one with the sharpest effect in practice. Where a claimant can show that establishing defectiveness or causation is excessively difficult because of technical complexity, and that the proposition is likely, the burden transfers. For AI and software claims, technical complexity is close to a given.
Change Four: The Development Risk Defence
Article 11 preserves the defences available to economic operators, including the development risk defence: that the objective state of scientific and technical knowledge at the time the product was placed on the market was not such as to enable the defect to be discovered.
Article 18 then permits member states to derogate and remove that defence from their national law. Member states wishing to do so must notify the Commission by 9 December 2026.
The practical consequence is that the development risk defence will be available in some member states and not others. For manufacturers selling across the EU, the defence becomes a jurisdictional question rather than a given, and forum will matter in a way it has not previously.
Who Can Be Liable
Product Liability Directive Article 8 widens the pool of potential defendants considerably.
| Economic operator | Basis of liability |
|---|---|
| Manufacturer of the defective product | Primary liability |
| Manufacturer of a defective component | Liable where the component caused the defect |
| Provider of a related service | Liable where the service is a component and is defective |
| Person who substantially modifies a product | Treated as the manufacturer of the modified product |
| Importer | Liable where the manufacturer is outside the EU |
| Authorised representative | Liable where the manufacturer is outside the EU |
| Fulfilment service provider | Liable where no importer or authorised representative is established in the EU |
| Online platform | Liable where it allows consumers to conclude distance contracts and presents the product in a way that leads a consumer to believe it is provided by the platform or a trader under its control |
| Distributor | Liable where it fails to identify a liable operator on request within one month |
Two of these are new and significant.
Substantial modification
A person who substantially modifies a product outside the original manufacturer’s control, and then makes it available, is treated as the manufacturer of the modified product. This catches refurbishers, system integrators, and anyone who materially alters a product before onward supply. It also means a product placed on the market before December 2026 can be pulled into the new regime by a substantial modification after that date.
Online platforms
Platform liability under Article 8 operates where the platform’s presentation leads consumers to believe the product comes from the platform itself or from a trader under its control. This sits alongside, rather than within, the Digital Services Act framework.
The distributor provision functions as a backstop. A distributor that cannot or will not identify the manufacturer, importer, or the distributor who supplied it, within one month of a request, becomes liable itself.
What Damage Is Recoverable
| Head of damage | Position under the new directive |
|---|---|
| Death and personal injury | Covered, including medically recognised damage to psychological health |
| Damage to property other than the product itself | Covered, with the previous exclusion of property used for professional purposes removed in part |
| Destruction or corruption of data not used for professional purposes | Covered. This is new |
| Pure economic loss | Not covered |
| Damage to the defective product itself | Not covered |
| Lower threshold of €500 | Removed |
Two changes here matter commercially. The express inclusion of medically recognised psychological harm in Product Liability Directive expands the category of recoverable personal injury.
The inclusion of data loss creates a head of damage that did not exist under the 1985 regime, with obvious application to software and connected device failures.
The removal of the €500 lower threshold means low-value claims are now actionable, which affects the viability of collective redress.
Product Liability Directive’s Limitation Periods
| Period | Length | Running from |
|---|---|---|
| Limitation period | 3 years | The day the claimant became aware, or should reasonably have become aware, of the damage, the defectiveness, and the identity of the liable operator |
| Long-stop | 10 years | The product being placed on the market or put into service |
| Extended long-stop | 25 years | Where the injury is latent and manifests after the 10-year period, for personal injury only |
The 25-year extended long-stop is new. It applies where symptoms are slow to emerge, and it creates record retention implications that most manufacturers have not yet addressed. Defending a claim at year 24 requires documentation that most retention schedules dispose of long before.
Product Liability Directive: EU Transposition Status
Transposition progress across the 27 member states is uneven, and with the deadline two months away a timely complete picture is unlikely.
| Category | Position |
|---|---|
| Transposition complete | A small number of member states, including those that moved early |
| Draft legislation advancing | Approximately twelve member states, including Germany and the Netherlands, whose proposals track the directive closely |
| No meaningful public steps as of mid-2026 | A substantial group, reported to include Belgium, Bulgaria, Cyprus, Estonia, France, Greece, Latvia, Lithuania, Luxembourg, Malta, Poland, Slovenia, and Spain |
France is the case most often cited as a likely late transposer. The 1985 directive took over a decade to transpose into French law, and the current transposition may be folded into a broader civil liability reform.
Where transposition is late, French courts are expected to interpret existing provisions in light of the directive, which produces an interim position that is neither the old regime nor the new one.
Late transposition does not remove the directive’s effect indefinitely. It produces uncertainty about which rules govern a claim brought in that jurisdiction in the intervening period, and it creates the possibility of state liability claims and Commission infringement proceedings.
Manufacturers should not wait for all 27 member states to finish before preparing. The substantive obligations are known, and the national variations will be at the margins rather than the core.
Product Liability Directive: Dual-Track Problem
Product Liability Directive applies only to products placed on the market or put into service after the transposition date. Everything already on the market remains under national law implementing the 1985 directive.
| Product situation | Governing regime |
|---|---|
| Placed on the market before 9 December 2026, unmodified | National law implementing Directive 85/374/EEC |
| Placed on the market after 9 December 2026 | National law implementing Directive (EU) 2024/2853 |
| Placed on the market before, substantially modified after | New regime applies to the modified product |
| Software update to a pre-December 2026 product | Depends on whether the update constitutes a substantial modification |
The software update question is unresolved and will be litigated. A routine security patch is unlikely to constitute a substantial modification. A major version release that adds functionality or changes the product’s behaviour is a different proposition. For software companies with long-lived products, the boundary determines which liability regime applies, and nobody can currently answer it with confidence.
Two practical consequences follow. Manufacturers need to date-stamp market placement precisely, because the governing regime turns on it. Plus, they need a view on which post-release changes they regard as substantial, documented before a claim arises rather than reconstructed afterwards.
How Product Liability Directive Interacts with Other EU Frameworks
The new product liability regime does not operate in isolation. It draws on other instruments for the standard against which defectiveness is judged.
| Framework | Interaction |
|---|---|
| General Product Safety Regulation (EU) 2023/988 | Breach of GPSR safety requirements supports a presumption of defectiveness under Article 10 |
| Cyber Resilience Act (EU) 2024/2847 | CRA essential requirements and support period obligations inform whether a product provides the security a person is entitled to expect |
| EU AI Act (EU) 2024/1689 | AI systems are products. AI Act compliance evidence is relevant to defectiveness, and non-compliance supports the presumption |
| Machinery Regulation (EU) 2023/1230 | Sector safety requirements feed into the defectiveness assessment |
| Representative Actions Directive (EU) 2020/1828 | Collective redress is available for product liability claims, and the removal of the €500 threshold makes low-value aggregated claims viable |
The CRA interaction deserves attention from software and connected product manufacturers. CRA full application is 11 December 2027, two days after the product liability regime’s second anniversary.
From that point, a manufacturer that fails to supply security updates within its declared support period faces a regulatory breach under the CRA and a defectiveness argument under the product liability directive arising from the same facts.
The regulatory penalty is capped. The civil liability is not, and it cannot be contracted out of.
What to Do Before 9 December 2026
| Step | Action |
|---|---|
| 1 | Identify which of your products will be placed on the market after the transposition date and will therefore fall under the new regime |
| 2 | Determine whether any of your software is a product in its own right under Article 4 |
| 3 | Map your role under Article 8. Manufacturer, component manufacturer, importer, authorised representative, fulfilment provider, or platform |
| 4 | Review contractual limitation of liability clauses, which cannot exclude strict liability under the directive |
| 5 | Define and document your support period and update commitments, which now bear on defectiveness |
| 6 | Audit record retention against the 25-year extended long-stop for latent personal injury |
| 7 | Establish a position on what constitutes a substantial modification to your products, before it is tested |
| 8 | Prepare for disclosure. Assume design documentation, test results, and risk assessments may be ordered into evidence |
| 9 | Check product liability insurance cover against the expanded heads of damage, including data loss |
| 10 | Track transposition in your principal markets, particularly whether the development risk defence survives in each |
| 11 | Align CRA, GPSR, and AI Act compliance evidence, since non-compliance under those regimes supports a presumption of defectiveness here |
Step 4 is the one most often underestimated. A software company whose entire liability position rests on a limitation clause in its terms of service has no protection against a strict liability claim under Product Liability Directive.
FAQ
What is the new EU Product Liability Directive?
Directive (EU) 2024/2853 on liability for defective products, adopted on 23 October 2024. It replaces Council Directive 85/374/EEC and must be transposed into national law by 9 December 2026. It establishes strict liability for damage caused by defective products, with software, AI systems, and digital services now within scope.
When does the European Product Liability Directive apply?
Member states must transpose it by 9 December 2026. It applies to products placed on the EU market or put into service after that date. Products already on the market remain under national law implementing the 1985 directive, unless they are substantially modified afterwards.
Does the Product Liability Directive cover software?
Yes. Article 4 defines a product to include software, covering embedded software, standalone software, operating systems, applications, and AI systems. Free and open-source software supplied outside a commercial activity is excluded, but open-source integrated into a commercial product is not.
Is AI covered by the new Product Liability Directive?
Yes. AI systems are products. Article 7 also makes a product’s ability to continue learning after deployment relevant to the assessment of defectiveness, which is directly aimed at machine learning behaviour. The separate AI Liability Directive proposal was withdrawn, leaving this directive as the principal civil liability instrument for AI in the EU.
Can liability under revised PLD be excluded by contract?
No. Article 15 renders ineffective any contractual provision limiting or excluding liability to the detriment of the injured person. Standard limitation of liability clauses do not protect against strict liability claims under the directive.
What is the development risk defence and is it still available?
It is the defence that the objective state of scientific and technical knowledge at the time the product was placed on the market did not allow the defect to be discovered. Article 11 preserves it, but Article 18 permits member states to remove it from national law. Member states doing so must notify the Commission by 9 December 2026, which means availability will vary by jurisdiction.
Who can be sued under the directive on liability for defective products?
Manufacturers, component manufacturers, providers of related services, anyone who substantially modifies a product, importers, authorised representatives, fulfilment service providers, certain online platforms, and distributors who fail to identify a liable operator within one month of request.
Is cybersecurity relevant to product defectiveness?
Yes. Article 7 expressly lists safety-relevant cybersecurity requirements among the circumstances relevant to assessing defectiveness. A product with a known exploitable vulnerability, or one no longer receiving security updates the user was entitled to expect, may be defective on that basis.
What damage can be claimed?
Death and personal injury including medically recognised psychological harm, damage to property other than the defective product itself, and destruction or corruption of data not used for professional purposes. Pure economic loss and damage to the product itself are not recoverable. The previous €500 lower threshold has been removed.
How long do claimants have to bring a claim?
Three years from the day the claimant became aware or should reasonably have become aware of the damage, the defectiveness, and the liable operator. A ten-year long-stop runs from the product being placed on the market, extended to twenty-five years for latent personal injury.
Do UK companies need to comply with PLD?
The directive is EU law and does not apply in the UK. UK companies placing products on the EU market are within its scope for those products, and a UK-established entity cannot discharge the role of EU importer or authorised representative. The UK’s own regime under the Consumer Protection Act 1987 continues to implement the 1985 rules.
Has every member state transposed the directive?
No. As of late 2026 a small number have completed transposition, roughly twelve have legislation in progress, and a substantial group has taken no meaningful public steps. France is widely expected to be late. Where transposition is late, national courts may interpret existing law in light of the directive, which produces an uncertain interim position.
Sources
- Directive (EU) 2024/2853, full text, EUR-Lex
- Council Directive 85/374/EEC, the repealed regime
- European Commission, product liability
- Reed Smith, member state transposition status
- Faegre Drinker, transposition progress report
Disclaimer
This guide reflects Directive (EU) 2024/2853 and the status of member state transposition as at October 2026. Transposition is incomplete across the EU and the operative rules in each member state will be those of its national implementing law, which may vary at the margins and on the availability of the development risk defence. Published by Grecta. It is regulatory analysis, not legal advice.