Aarhus: With just over six months left before national parliaments must transpose the recast Product Liability Directive, lawyers in Denmark’s second city say the Justice Ministry is racing to finalise the implementing statute that will, for the first time, treat software and artificial intelligence systems as defective products under harmonised European rules. Brussels gave Member States until 9 December 2026 to adapt Directive (EU) 2024/2853, the most consequential rewrite of liability rules since the original 1985 instrument, and the consensus among Aarhus practitioners is that very few capitals will hit the deadline on time.
The directive’s reach is what makes it different. Software, including standalone applications and embedded code, now sits inside the definition of a product. So do digital services that influence how a connected product behaves, integrating cloud-based machine-learning systems into the same chain of strict liability that historically covered toasters, ladders and pharmaceuticals. Producers can be held responsible for damage caused by defects that emerge after the product is placed on the market, provided those defects stem from updates, learning behaviour or a failure to deliver promised security patches.
The new instrument expands the universe of compensable harm. Beyond death, personal injury and damage to private property, the directive now permits claims for medically recognised psychological injury and for the loss or corruption of personal data that is not used for professional purposes. National courts may also order disclosure of evidence in proceedings, and the burden of proof can be reversed where the technical complexity of a product makes it excessively difficult for a claimant to establish defectiveness.
Legal departments are still wrestling with how the new framework will interact with the Artificial Intelligence Act. The Commission has signalled it intends to withdraw the parallel AI Liability Directive proposal, leaving the Product Liability Directive as the principal civil-law vehicle for damages flowing from AI systems. That means compliance with the AI Act’s safety obligations will, in practice, function as the benchmark for whether an AI product is defective, even though the two instruments were drafted with different objectives and timelines.
Danish industry associations are pushing for clarity on the so-called development-risk defence. The directive retains, in modified form, the possibility for a producer to escape liability where the state of scientific and technical knowledge at the moment a product was placed on the market did not allow detection of a defect. But the wording has been tightened, and Aarhus university researchers presenting a comparative analysis last week argued the threshold is now meaningfully higher than under the 1985 regime, especially for software whose risk profile evolves over time.
For the Commission’s services, the priority over the summer months is publishing implementation guidance that synchronises the directive with the General Product Safety Regulation, the Cyber Resilience Act and the AI Act. Officials have indicated that further infringement letters will follow shortly after the 9 December deadline for any capital that fails to notify a complete transposition. Aarhus lawyers expect a wave of strategic litigation in 2027 once the new rules apply to products placed on the market from that date onwards, particularly involving connected medical devices and autonomous transport systems already covered by separate sectoral safety regimes.




