European Union - Product Liability Reform (2024/2853)
Directive (EU) 2024/2853 on liability for defective products (revising product liability to cover software and AI)
European Union
RAI-EU-NA-E2LDPXX-2024Directive (EU) 2024/2853 modernises EU product liability rules to include software, digital manufacturing files and AI systems as 'products', expands the range of liable economic operators, creates presumptions to assist injured natural persons, and requires Member States to transpose the Directive by 9 December 2026. It repeals Council Directive 85/374/EEC and introduces obligations related to post-sale defects, cybersecurity updates and disclosure in court proceedings.
Summary
Directive (EU) 2024/2853 (adopted 23 October 2024; published in the Official Journal L 2024/2853 on 18 November 2024) revises and modernises the EU Product Liability Directive to address the challenges posed by digitalisation, software, artificial intelligence (AI) and new circular economy models. The Directive preserves the principle of strict (no-fault) liability for defective products while expanding the definition of 'product' to explicitly include software (operating systems, firmware, applications and AI systems), digital manufacturing files and electricity. It clarifies that information and media files are not products, and exempts non-commercial free and open-source software (OSS) developed or supplied outside the course of a commercial activity.
Key legal changes include: (i) treating developers and providers of software and AI systems as 'manufacturers' for liability purposes; (ii) widening the set of liable economic operators to include manufacturers of components, importers, authorised representatives and fulfilment service providers for non-EU manufacturers; (iii) extending liability to certain defects that come into being after placing on the market where the manufacturer retained control (for example, harmful software updates or machine-learning changes under the manufacturer's control); (iv) expanding compensable damage to include medically recognised psychological injury, damage to property used for non-professional purposes and the destruction or corruption of non-professional data; (v) removing the previous monetary threshold for property damage claims and providing new presumptions in favour of injured persons in circumstances where technical complexity would otherwise render proof excessively difficult.
The Directive introduces procedural measures to ease claimants' access to evidence: where an injured person presents sufficient evidence to make a plausible claim, Member States must ensure disclosure duties on manufacturers to provide necessary technical information in court. It also requires Member States to publish appellate-level judicial decisions in an accessible electronic format and tasks the Commission with maintaining an EU database of such judgments. The Directive explicitly addresses cybersecurity: manufacturers may be liable where a product's defectiveness results from their failure to supply necessary software updates or upgrades to address cybersecurity vulnerabilities, except where installation or supply was beyond the manufacturer's control (e.g., where the owner refuses to install an available update). The Directive does not itself create obligations to provide updates but conditions liability on the manufacturer's control and failure to act when necessary for safety.
Transposition and timing: the Directive entered into force 20 days after publication (8 December 2024) and applies to products placed on the market or put into service after 9 December 2026; Member States must transpose the Directive into national law by 9 December 2026. Directive 85/374/EEC is repealed with effect from 9 December 2026 but continues to apply to products placed on the market before that date. The Commission is required to evaluate the Directive by 9 December 2030 and every five years thereafter. The Directive aligns and interacts with other recent EU instruments governing digital products and AI, notably Regulation (EU) 2024/1689 (Artificial Intelligence Act) and Regulation (EU) 2024/2847 (Cyber Resilience Act), and explicitly preserves the applicability of EU data-protection law (e.g., Regulation (EU) 2016/679).
Full article
Read full text ↗Overview
Directive (EU) 2024/2853 updates the EU product liability framework to the digital age by redefining the notion of 'product' to cover software, including AI systems, and digital manufacturing files. The full text is available on EUR-Lex: Directive (EU) 2024/2853. The Directive keeps strict (no-fault) liability as its core principle but adapts substantive and procedural rules to address new technical complexities, cross-border supply chains and post-sale product evolution (e.g., updates and learning systems). It aims to ensure injured natural persons can obtain compensation while providing clearer rules for economic operators and aligning with other EU digital-technology laws such as the Artificial Intelligence Act (Regulation (EU) 2024/1689) and the Cyber Resilience Act (Regulation (EU) 2024/2847).
Definitions
The Directive establishes modernised definitions to remove ambiguity. 'Product' means all movables and specifically includes electricity, digital manufacturing files and software (operating systems, firmware, computer programs, applications and AI systems). 'Digital manufacturing file' is a digital template enabling automated control of machinery to produce tangible items. The Directive distinguishes software-as-product from mere information: media files and source code as content are not treated as 'products', and non-commercial free and open-source software (OSS) developed outside the course of a commercial activity is excluded. These definitions align with Decision No 768/2008/EC principles and with the AI Act where appropriate, providing cross-regulatory consistency.
Governance and Institutional Framework
The Commission retains an oversight and coordination role. Member States are required to designate competent national authorities (consumer protection and market surveillance authorities) to implement and enforce the Directive and to exchange information. The Commission must establish and maintain a public, easily accessible database of final appellate judgments published by Member States, facilitating transparency and case-law harmonisation; see the Commission summary on product liability EU Single Market: Liability for defective products. The Directive requires Member States to notify national transposition measures to the Commission and cooperate on enforcement and information exchange. It also sets time-bound obligations for evaluation (first report due by 9 December 2030) and regular five-year reviews.
Key Focus Areas
The Directive focuses on several substantive areas: (1) Scope and product definition—explicitly including software, AI and digital manufacturing files; (2) Economic operators and chain of liability—designating manufacturers, component manufacturers, importers, authorised representatives and, where relevant, fulfilment service providers as liable parties; (3) Defectiveness—safety expectations consider presentation, technical features, labelling and instructions; (4) Post-sale defects and updates—liability can extend to defects emerging after placing on the market when products remain under the manufacturer’s control or when related services (updates, upgrades or authorised third-party services) are part of the product lifecycle; (5) Damages covered—death, personal injury (including medically certified psychological harm), property damage (with certain exclusions), and destruction or corruption of non-professional data; (6) Evidence and disclosure—new duties to disclose technical information in litigation to remedy information asymmetry and technical complexity; and (7) Exemptions and proportionality—non-commercial OSS is excluded, while micro and small enterprises receive limited safeguards to avoid disproportionate burdens. The Directive is intended to work in tandem with the AI Act and the Cyber Resilience Act, aligning safety and liability expectations across regulatory instruments.
Implementation Framework
Member States must transpose the Directive into national law by 9 December 2026. The Directive applies to products placed on the market or put into service after 9 December 2026; products placed before that date remain governed by Directive 85/374/EEC (repealed with effect from 9 December 2026 but continuing to apply to earlier products). Transposition must include mechanisms to ensure the availability of compensation, the special disclosure duty in court proceedings and publication of appellate judgments in an accessible electronic format. National authorities responsible for consumer protection and market surveillance will coordinate enforcement and exchanges of information. The Commission will maintain the EU judgment database and perform periodic evaluations (first by 9 December 2030) to assess effectiveness, costs and the need for further measures.
Monitoring and Evaluation
The Commission is required to evaluate the Directive by 9 December 2030 and every five years thereafter, using efficiency, effectiveness, relevance, coherence and added-value criteria. Member States must report on transposition measures and send the texts of national laws to the Commission. National consumer protection authorities and market surveillance authorities are urged to exchange information, and the Commission database of appellate judgments is intended to improve transparency and support harmonised interpretation. The evaluation will include data on insurance availability, litigation burdens, and comparative analysis with OECD countries.
Penalties, Liability, and Appeals
The Directive sets substantive rules on strict liability and compensable damage but leaves penalties and sanction levels to Member States. Injured natural persons can claim compensation for death, personal injury (including certified psychological damage), property damage (with exclusions) and corruption/destruction of non-professional data. The Directive introduces presumptions (e.g., presumption of defect or causation in defined circumstances) to ease claimant burdens where technical complexity would otherwise prevent proof. Member States must provide judicial procedures and ensure remedies; administrative fines, civil damages and other national sanctions apply for failure to comply with national measures implementing the Directive or for misleading consumers. The Directive also mandates publication of appellate judgments and an EU database to assist appeals and harmonised jurisprudence.
Relationship to Other Instruments
The Directive interacts closely with other EU instruments. It preserves application of data-protection rules (e.g., GDPR). It aligns definitions and obligations with the AI Act (Regulation (EU) 2024/1689) and complements the Cyber Resilience Act (Regulation (EU) 2024/2847) by addressing liability for safety and cybersecurity defects. The Directive repeals Council Directive 85/374/EEC (with transitional arrangements) and retains national special liability regimes that pre-existed (e.g., certain pharmaceutical systems), so long as they achieve equivalent protection for natural persons.
International Alignment
The Directive was drafted to harmonise internal market rules and to reduce divergences between Member States that distort competition. Its modernised approach to digital and AI products aligns with international efforts to regulate AI and cybersecurity risk (OECD, Council of Europe, ISO standards) and facilitates interoperability for trade. The Commission's evaluation requirement includes a comparison with OECD countries to assess competitiveness and transnational impacts. Liability rules for manufacturers established outside the Union target importers, authorised representatives and fulfilment service providers to ensure enforceability across borders.
Implementation Timeline
| Event | Date |
|---|---|
| Official Journal publication | 18 November 2024 |
| Entry into force (20 days after publication) | 08 December 2024 |
| Application to products placed on market / put into service after | 09 December 2026 |
| Member States transposition deadline | 09 December 2026 |
| Repeal of Directive 85/374/EEC effective | 09 December 2026 |
| Commission evaluation (first) | 09 December 2030 |
Sources and References
| Source | Type |
|---|---|
| Directive (EU) 2024/2853 — Official Journal (EUR-Lex) | Primary Source |
| EU Commission — Liability for defective products (single market) | Primary Source |
| Regulation (EU) 2024/1689 — Artificial Intelligence Act (Official) | Primary Source |
| Regulation (EU) 2024/2847 — Cyber Resilience Act (Official) | Primary Source |
Requirements for a company
What an organisation has to do under European Union - Product Liability Reform (2024/2853), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
7- Determine if your software or AI system qualifies as a 'product'.Economic operators providing software or AI systems.
- Identify your specific liable role under the Directive.Economic operators involved in the supply chain of products.
- Establish protocols for secure disclosure of technical information in litigation.Economic operators liable for defective products.
- Document control over updates, security patches, and third-party services.Manufacturers of products with post-sale updates or services.
- Ensure products meet safety expectations regarding presentation, features, labeling, and instructions.Manufacturers and other liable economic operators.
- Determine if your open-source software is developed in a commercial activity.Developers and providers of open-source software.
- +1 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under European Union - Product Liability Reform (2024/2853), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Economic operators providing software or AI systems. | Determine if your software or AI system qualifies as a 'product'. “'Product' means all movables and specifically includes electricity, digital manufacturing files and software.” | Before placing on market | Definitions | Critical |
| 2 | Economic operators involved in the supply chain of products. | Identify your specific liable role under the Directive. “designating manufacturers, component manufacturers, importers, authorised representatives and, where relevant, fulfilment service providers as liable parties” | Before placing on market | Key Focus Areas (2) | Critical |
| 3 | Economic operators liable for defective products. | Establish protocols for secure disclosure of technical information in litigation. “new duties to disclose technical information in litigation to remedy information asymmetry and technical complexity” | Before placing on market | Key Focus Areas (6) | Critical |
| 4 | Manufacturers of products with post-sale updates or services. | Document control over updates, security patches, and third-party services. “liability can extend to defects emerging after placing on the market when products remain under the manufacturer’s control or when related services” | Before placing on market | Key Focus Areas (4) | Critical |
| 5 | Manufacturers and other liable economic operators. | Ensure products meet safety expectations regarding presentation, features, labeling, and instructions. “safety expectations consider presentation, technical features, labelling and instructions” | Before placing on market | Key Focus Areas (3) | Critical |
| 6 | Developers and providers of open-source software. | Determine if your open-source software is developed in a commercial activity. “non-commercial free and open-source software (OSS) developed outside the course of a commercial activity is excluded.” | Before making software available | Definitions | Important |
| 7 | Economic operators liable for defective products. | Review product liability policies for software/AI and data-corruption damages. | — | — | Important |
Related Regulations
Proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive) — Commission proposal withdrawn
European Union89% similar
Commission Cybersecurity Resilience and Capabilities Package 2026
European Union86% similar
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act)
European Union86% similar
European Commission Guidelines on the scope of obligations for providers of General‑Purpose AI models
European Union85% similar
General-Purpose AI Code of Practice
European Union85% similar
© Regulations.AI · updated on 13-Jun-2026