From December 9, 2026, the EU will implement the Product Liability Directive, which changes the rules for IT products. It introduces strict liability for software, requiring businesses to prove its safety.
The revised Product Liability Directive recognizes software and artificial intelligence as products, causing significant changes for businesses in the EU. Now companies need to prove that their products are free of defects if issues arise. This will impact various aspects, including cybersecurity and update procedures, which will become part of the legal process. Cybersecurity is now considered a defect, and companies that fail to prepare updates in time may face lawsuits.
Business owners should remember that the complexity of their technology can work against them in court. If a product is too complex for the claimant to prove its defect, the court may presume the existence of a defect. An important aspect is the disclosure of evidence: courts may require companies to provide all available information that supports the claimants’ demands.
Experts advise companies to immediately start preparing documentation that can become important evidence in case of litigation. This includes registering all AI components, risk assessments, and update logs. Transparency of user interaction with AI should also be ensured, and users must be informed about such interactions. Considering these changes, companies should carefully review their contracts with suppliers to clearly define liability for defects and ensure the release of security patches.
These changes can significantly impact not only regulatory compliance but also relationships with investors and clients. Therefore, companies should consider the new requirements today to avoid unpredictable situations in the future.




