- The new Product Liability Directive (EU) 2024/2853 must be transposed into national law by 9 December 2026 and applies to products placed on the market from that day.
- Software, apps and AI systems count as products for the first time, and missing security updates can trigger liability.
- Claimants benefit from easier rules of proof, and in the supply chain importers and, in some cases, fulfilment providers are liable alongside manufacturers.
Affects you if you offer software, apps or smart products, or if you import goods from outside the EU as a merchant.
01Why the law was rewritten
The old rules date from a time without apps, cloud and AI: the EU directive from 1985, the German Product Liability Act from 1990. The new Directive (EU) 2024/2853 catches up. It has been in force since December 2024, member states must transpose it by 9 December 2026, and it applies to products placed on the market from that day.
In Germany the legislative process is under way: the draft for a modernised Product Liability Act reached the Bundestag in March 2026 and, as of August 2026, sits in the legal affairs committee.
02Software is now a product
For the first time software, apps, AI systems and digital manufacturing files explicitly count as products. Damage caused by defects falls under strict liability, so nobody has to prove fault. Recoverable damage now also includes the destruction or corruption of privately used data, alongside personal injury and property damage. Free open source software outside a commercial activity remains exempt.
03Missing updates become a liability case
Until now the state at the time of sale was what counted. In future: as long as the manufacturer controls the software of a product, for example through updates or a cloud connection, it is also responsible for defects that appear later. A product can become defective simply because a necessary security update never ships. And whoever substantially modifies a third-party product takes on liability like a manufacturer.
04Who is liable in the supply chain
- First the manufacturer, and for component defects also the maker of the component.
- If the manufacturer sits outside the EU: the importer or the authorised representative in the EU.
- If neither exists: the fulfilment provider that stores and ships the goods.
- If a distributor or platform does not name, within one month of a request, who stands before it in the chain, it is liable itself.
For online merchants this is the key point: if you buy goods directly from outside the EU and sell them here, you are the importer and carry the liability yourself, with your business assets.
05Easier proof for injured customers
- Courts can order the manufacturer to disclose technical documentation.
- If disclosure is refused, the product defect is presumed.
- For technically complex products, AI being the prime example, the presumptions of defect and causation apply more easily.
- The old 500 euro deductible for property damage is gone.
The new rules only cover products placed on the market from 9 December 2026. Document cleanly when a product entered the market, that decides between old and new law.
- Sort your portfolio: what is software, what is smart, what is purely physical, and where you act as importer.
- For imported goods, clarify who counts as manufacturer, importer or authorised representative in the EU: that role carries the liability.
- Define and document update processes for software and smart products, including security patches.
- Keep technical documentation ready to present in a dispute, gaps will count against you.
- Have supplier and fulfilment contracts checked for liability and indemnity clauses.
- Directive (EU) 2024/2853 in the Official Journal ↗
- German Ministry of Justice: product liability reform ↗
- German Product Liability Act (ProdHaftG), full text ↗
Carefully researched and kept up to date, but not legal advice. For binding questions, talk to a law firm.
Wondering what this means for your project?
Let's talk