F1Verified
EU product liability now expressly covers software.
Article 4(1) of Directive (EU) 2024/2853 defines 'product' as all movables, even if integrated into or inter-connected with another movable or an immovable, and states that it includes electricity, digital manufacturing files, raw materials and software. Recital 6 confirms the intent that no-fault liability apply to software, including when integrated into other movables.
F2Verified
The directive names a chain of liable operators, not a single defendant.
Article 8(1) makes liable the manufacturer of a defective product; the manufacturer of a defective component integrated within the manufacturer's control; and, where the manufacturer is established outside the Union, the importer, the authorised representative, and — failing both — the fulfilment service provider. Article 8(2) treats any person who substantially modifies a product outside the manufacturer's control and then makes it available as the manufacturer of that product.
F3Verified
The directive shifts the practical burden of proof in technically complex cases such as AI.
Article 9 requires a defendant to disclose relevant evidence where a claimant has presented facts sufficient to make the claim plausible. Article 10(2) presumes defectiveness where the defendant fails to disclose, where the product breached mandatory safety requirements, or where damage followed an obvious malfunction; Article 10(3) presumes causation where the damage is of a kind typically consistent with the defect. Article 10(4) requires a court to presume defectiveness or causation where the claimant faces excessive difficulties, in particular due to technical or scientific complexity, and shows that defectiveness or causation is likely. The recitals name machine learning and the inner workings of an AI system as examples of such difficulty, and add that the claimant need not prove those difficulties. Article 10(5) preserves the defendant's right to rebut every presumption.
F4Verified
The directive is not yet operative national law and does not apply retroactively.
Article 22(1) requires Member States to bring the implementing measures into force by 9 December 2026; Article 23 provides that the directive enters into force on the twentieth day after publication. It repeals and replaces Council Directive 85/374/EEC, whose regime continues to govern products placed on the market before the changeover date.
F5Verified
Under the AI Act, responsibility can move down the chain onto a deployer or distributor.
Article 25(1) of Regulation (EU) 2024/1689 provides that a distributor, importer, deployer or other third party is considered a provider of a high-risk AI system, and takes on the provider's Article 16 obligations, where it puts its name or trademark on the system, substantially modifies it, or modifies the intended purpose of a system — including a general-purpose AI system — so that it becomes high-risk. Article 25(2) then removes that status from the initial provider for that specific system, while requiring cooperation and information.
F6Verified
The deploying organisation carries its own operational duties, backed by administrative fines.
Article 26 requires deployers of high-risk systems to use them in accordance with the instructions for use, to assign human oversight to competent and adequately supported natural persons, to ensure input data within their control is relevant and sufficiently representative, and to monitor operation and notify the provider and market surveillance authority of risks. Article 99(3) sets fines of up to EUR 35 000 000 or 7 % of worldwide annual turnover for breach of the Article 5 prohibitions, and Article 99(4) up to EUR 15 000 000 or 3 % for other operator infringements, whichever is higher in each case.