Brussels: Europe’s rewritten product liability regime starts biting on 9 December, and most national parliaments have yet to pass the laws that make it work. Directive (EU) 2024/2853 replaces a 1985 text that predates the smartphone, and it gives member states until that date to transpose the rules and apply them to everything placed on the market afterwards.
The change that matters commercially is short. Software counts as a product. A firmware update, a cloud-hosted service, a machine-learning model that steers an industrial robot: each now falls inside a no-fault regime that previously covered only tangible goods. The directive carves out free and open-source software supplied outside any commercial activity, but it catches almost everything a company sells or monetises.
Manufacturers also lose an old comfort. Under the previous rules, exposure effectively ended once a product left the factory gate. The new text keeps a producer on the hook for defects that its own updates introduce, and for security flaws it fails to patch while it still controls the software. A cyber vulnerability now sits alongside a snapped bracket as a plain defect.
Claimants get lighter work too. National courts must order disclosure of evidence once a claimant presents a plausible case, and judges may presume a defect when technical complexity makes proof unreasonably hard. Defence lawyers read that as an invitation to litigate. Consumer groups read it as the entire point of the exercise, and the text published in the Official Journal backs the second reading.
Importers and authorised representatives carry the risk whenever the manufacturer sits outside the Union, and online marketplaces inherit it when nobody else in the chain can be identified. That clause aims squarely at the parcel flood from Asian platforms, and it hands enforcement to whichever national court a buyer in Poznan or Porto decides to use.
The transposition record explains the nervousness in industry. Governments must decide how far to push disclosure orders, how to run the extended long-stop period for latent injuries, and whether to scrap the national compensation ceilings the directive removes. Each choice lands inside ordinary civil procedure, which parliaments rarely rewrite quickly, and the calendar leaves roughly fifteen sitting weeks. The European Parliament’s own legislative file on the revised directive shows how long the negotiation itself took.
Companies cannot wait for capitals to catch up. Contracts signed this autumn will govern goods sold after December, and indemnity clauses drafted for the 1985 regime allocate risk that no longer sits where the parties assumed it would. Supplier agreements covering components, software libraries and update services need reopening before the deadline rather than after the first writ.
Insurers face the same arithmetic from the other direction. Product liability cover priced against physical goods must now absorb software failure, and underwriters have almost no claims history to price from, because the old rules kept these disputes out of court entirely.
Expect a quiet first year and a loud second one. Claims can only concern products placed on the market after 9 December, so the pipeline fills slowly. When it does fill, the early cases will show whether a European judge treats a bad model output the way courts have long treated a cracked weld.





