Blog

From Walkman to AI: product liability in a new guise

The product liability rules we know today are almost 40 years old. The European directive[1] dates back to 1985, an era of the Walkman and fax machines. We now live in a digital and circular economy, in which products are often no longer purely tangible but contain complex software. Global supply chains have also made it more complicated to [...]

The product liability rules we know today are nearly 40 years old. The European Directive[1] dates back to 1985, an era of Walkmans and fax machines. We now live in a digital and circular economy, where products are often no longer purely tangible but contain complex software. Moreover, global supply chains have made it more difficult to identify the “manufacturer.” As a result, the current directive leads to inconsistencies and legal uncertainty. Affected parties often have a weak evidentiary position, especially in technically or scientifically complex cases. It was therefore time for a thorough revision.

The new directive[2] was adopted on October 23, 2024, and must be transposed into national law by the European member states no later than December 9, 2026. The Netherlands intends to do so through the Implementation Act on the Revision of the Product Liability Directive. The bill primarily amends Book 6 of the Dutch Civil Code. The public consultation period closed on May 22, 2025.[3] The draft bill was adopted by the Council of Ministers on October 10, 2025, and will now be submitted to the Council of State for advice.[4] In this article, we look ahead: what will the new rules mean for legal practice?

The basic principle remains: strict liability

The basic principle remains: manufacturers are liable without the need to prove fault or culpability. The injured party need only demonstrate that there is damage, a defective product, and a causal link.[5] The manufacturer cannot limit or exclude strict liability in a contract with the consumer. A product is defective if it does not provide the safety that one may reasonably expect or that is required by law.[6] The standard is objective and depends on all the circumstances of the case. The circumstances relevant to the assessment are explicitly extensive. Consider, for example, a product’s ability to continue learning or acquire new functions.[7] Self-learning AI systems thus fall directly within the scope of product liability. Furthermore, manufacturers’ liability continues as long as they retain control over the software. If defects result from the absence or malfunction of updates or upgrades, manufacturers may be held liable for them.[8]

A broader product concept

The definition of “product” has been significantly broadened.[9] It now encompasses all movable property, even after it has been integrated into or connected to other items. The term “product” now also includes electricity, raw materials such as gas and water, software, and digital manufacturing files. Software is defined broadly: operating systems, firmware, applications, and AI systems are included, regardless of whether they are delivered via download, the cloud, or embedded in hardware. Only standalone source code and digital content, such as e-books, are not considered software. Free and open-source software are also excluded from the scope of the new directive under certain conditions (!).[10] The new definition of “product” therefore also includes software, including artificial intelligence (AI) systems. The original manufacturer is liable for defects that arise after an update or upgrade carried out under its control. The manufacturer will also be liable for defects that arise from the continuous learning of the AI system, provided the manufacturer has control over the AI system. Digital manufacturing files are considered digital versions of or templates for a movable object. They contain the functional information necessary to produce a tangible object, for example, using 3D printers or CNC machines.[11]

Related Services

In addition to the new definition of “product,” the directive also covers so-called “associated services.”[12] These are digital services that are integrated into a product or interconnected with it in such a way that the product cannot function properly without that service. Examples include the continuous delivery of traffic data to a navigation system and a temperature control service that monitors and regulates the temperature of a smart refrigerator.[13] Services as such do not fall within the scope of the directive.

Expansion of damages

The definition of damages is also being expanded. In addition to bodily injury, death, and property damage, the loss or corruption of non-business data will now also be eligible for compensation. Examples include personal photos lost due to a defective hard drive, including the costs of recovering or restoring them.[14] This acknowledges the increasing relevance and value of data. The minimum threshold of €500 for property damage is being eliminated, so that even relatively minor claims are now covered by the regulation.[15]

The graduated system of liable parties

One of the most significant changes is the expansion of the group of liable market participants and the hierarchy established within that group.[16] In addition to the manufacturer, importers, authorized representatives, distributors, fulfillment service providers, and even online platforms can also be held liable. However, consumers cannot simply pick and choose at random from this “pool.” The directive introduces a tiered system:

  • In the first instance, the injured party must turn to the manufacturer;
  • If it is unknown or located outside the EU, the importer, authorized representative or fulfillment service provider come into the picture successively. To be liable as a fulfillment service provider, it must perform at least two core activities (storage, packaging, addressing, shipping). Postal and parcel delivery services and freight forwarding services are explicitly excluded from the definition as a fulfillment service provider;[17]
  • Distributors are next and only if they do not disclose the identity of another EU-based operator or their own distributor within a month;
  • Online platforms are only liable if their role goes beyond the mere passive transmission of information.

Drastic changes and circular economy

A product is considered "new" when it is substantially modified and placed on the market again.[18] Such modifications can lead to liability of the person making the modification.[19] Substantial modification includes, for example, modifications that materially alter the original performance, purpose or type of the product, and create new hazards or increase the level of risk. This has major implications for refurbishment and overhaul companies. They can be held liable as if they were the original manufacturer. However, there is an exception: if it can be shown that the damage is not related to the changed part, liability can be excluded.[20]

Improving the evidentiary position of injured parties

Victims of a defective product are given a stronger evidentiary position.[21] Courts can require producers to provide relevant information about the product. Confidential data and trade secrets must of course be taken into account, for example through shielded viewing. If a producer refuses to share information, the court may adopt a rebuttable presumption of product defect or causation. A presumption can also be assumed when a product does not comply with product safety regulations or is clearly dysfunctional.[22] Moreover, in cases that are technically or scientifically very complex (such as AI), the court can decide that the threshold of proof for injured parties is lowered. This avoids excessive evidentiary problems.

Time limits and expiration

Liability is limited in time. A claim becomes time-barred three years after the injured party became aware, or should have become aware, of the damage, the defect, and the identity of the liable party.[23] In addition, the right to bring a claim expires ten years after the (significantly modified) product was placed on the market.[24] A new provision is that this limitation period may be extended to 25 years in cases of physical injury with a long latency period.[25] This prevents victims with slowly developing health problems from being left empty-handed in legal terms.

The new regulation applies only to products placed on the market or put into service on or after December 9, 2026. For products delivered prior to that date, the current regime remains in effect.[26]

Conclusion

The revision of the Product Liability Directive modernizes a 40-year-old system and better reflects digital, global and circular realities. For companies, this means taking into account broader liability risks, more complex chains and stricter rules of evidence. The tiered system provides guidance, but requires careful contractual arrangements and chain management. New product categories such as software and related services also necessitate closer cooperation between legal and technical teams.

Although the rules will only apply to products or substantially modified products that will be introduced to the market as of Dec. 9, 2026, companies should still anticipate in time. This may involve adjustments to contracts and terms and conditions in conjunction with insurance coverage. Now that takes a lot of time. Furthermore, software vendors and AI companies, for example, need to prepare now. In doing so, they must also take into account obligations from other regulations that are thundering over us especially from Brussels, such as the AI Regulation and the Data Act. In many cases, it will still be a complicated puzzle.

This article was written by Ernst-Jan Louwers and Eva van Groezen and previously appeared in Juridisch up to Date.


[1] Directive – 85/374 – EN – EUR-Lex.

[2] Directive – 2024/2853 – EN – EUR-Lex.

[3] Overheid.nl | Consultation on the Implementation Act for the Directive on the Revision of Product Liability.

[4] List of Decisions of the Council of Ministers, October 10, 2025.

[5] Article 10 of Directive 2024/2853.

[6] Article 7(1) of Directive 2024/2853.

[7] Article 7(2)(c) Directive 2024/2853.

[8] Article 11(2)(c) of Directive 2024/2853.

[9] Article 4 of Directive 2024/2853.

[10] Article 2(2) and recitals 14 and 15 Directive 2024/2853.

[11] Recital 16 of Directive 2024/2853.

[12] Article 4(3) of Directive 2024/2853.

[13] Recital 17 Directive 2024/2853.

[14] Article 6(1)(c) of Directive 2024/2853.

[15] Article 6(2) of Directive 2024/2853.

[16] Article 8 of Directive 2024/2853.

[17] Article 4(13) of Directive 2024/2853.

[18] Article 4(18) of Directive 2024/2853.

[19] Article 8(2) Directive 2024/2853.

[20] Article 11(1)(g) of Directive 2024/2853.

[21] Article 9 of Directive 2024/2853.

[22] Article 10 of Directive 2024/2853.

[23] Article 16 of Directive 2024/2853.

[24] Article 17(1) of Directive 2024/2853.

[25] Article 17(2) of Directive 2024/2853.

[26] Article 21 of Directive 2024/2853.

Author

More blogs