Malmö: A Swedish start-up selling diagnostic software to physiotherapy clinics spent this summer rewriting its terms of service, and not because a customer complained. On 9 December 2026, the new Product Liability Directive replaces a regime that has governed defective goods in Europe since 1985, and it treats software as a product.
The old directive was drafted for toasters and tyres. Directive 2024/2853 extends no-fault liability to software regardless of how it reaches the user, whether installed on a device, streamed from a cloud service or delivered as a subscription. Digital manufacturing files and related services fall inside the perimeter too.
No-fault matters more than the expanded scope. A claimant does not need to prove that the developer was careless. They need to show a defect, damage and a causal link between them. For a sector accustomed to disclaiming everything in a licence agreement, that reverses a long-standing assumption, and the directive explicitly bars contracting out of the liability.
The recoverable heads of damage grew as well. Destruction or corruption of data now counts, provided the data was not used for professional purposes. So does medically recognised psychological harm. Neither category existed under the 1985 text, and insurers are still pricing them.
A quieter change concerns software updates. If a manufacturer retains control over a product after sale through updates or machine learning, a defect introduced later can still trigger liability. Connected devices that receive firmware for a decade therefore carry a liability tail that lasts as long as the support commitment does.
Member states must transpose the directive by 9 December 2026, and the new rules apply only to products placed on the market after that date. Older products stay under the 1985 regime, which means courts across the Union will run two liability systems in parallel for years. Litigators expect the boundary question, when exactly a continuously updated cloud service was placed on the market, to generate the first significant case law.
Industry groups warn about the burden on smaller developers. The directive answers partly through a disclosure mechanism that lets claimants demand technical evidence, which shifts effort onto defendants rather than removing it. Consumer organisations counter that the previous arrangement left users of defective software with almost no realistic route to compensation, and point to the difficulty of proving negligence inside a proprietary codebase.
Transposition progress is uneven. Several member states have published draft implementing laws, others have not started, and the Commission has signalled that it will treat late transposition seriously given the December deadline. Companies cannot rely on national delay, since the directive’s effects flow from the date of placing on the market rather than from any individual capital’s diligence.
The Malmö developer settled on the pragmatic response. It bought product liability cover, documented its testing regime, and stopped promising in marketing copy that the software was error free. Lawyers say that last step may prove the most valuable, because a defect is assessed against what a user is entitled to expect, and marketing shapes expectation.





