The new EU Product Liability Directive: what it really means for my software company

On 9 December 2026, new product liability rules take effect in the EU. The headlines sound alarming: software is now liable like a toaster, AI is a product, caps are gone. As an entrepreneur whose company has been developing and running software for years, I took a closer look at the directive. My conclusion: for us it is less dramatic than it sounds, but it changes what matters in day-to-day work.

What changes

Directive (EU) 2024/2853 replaces rules dating from 1985. Back then, nobody was thinking about apps, cloud services or artificial intelligence. From now on, software is explicitly a product, whether it is installed or runs as a cloud service. Updates are included, and so are AI features.

On top of that, there are three points worth knowing. The previous €500 threshold for property damage disappears. Besides the manufacturer, importers, distributors, fulfilment service providers and platforms can also be liable. And injured parties get an easier burden of proof: courts can order the disclosure of documents, and with complex technology a defect can be presumed.

Why B2B is the decisive distinction

With 1Tool, we work almost exclusively for businesses. And that is exactly the point that gets lost in most summaries: product liability protects private individuals. What is compensated is personal injury, damage to property used for private purposes and the loss of private data.

Not covered are property and data used exclusively for professional purposes, and pure economic loss. If one of our customers loses business data because of a software bug, or an invoice is calculated incorrectly, that is not a product liability case. As before, the contract, the statutory warranty and general damages law apply.

Where it still becomes relevant

As a B2B provider, you are not entirely off the hook. As soon as private individuals stand at the end of the chain, the directive applies again. That is the case with customer portals, with apps our customers offer to their own customers, and with sole traders who also use a device or their data privately.

Towards these injured parties, liability cannot be excluded by contract. What can be settled by contract is recourse between the businesses in the chain.

What it changes day to day

For me, the most important sentence in the directive is not the one about AI but the one about security updates. Anyone who fails to close a known vulnerability supplies a defective product. Software is therefore never simply delivered and done; it remains the responsibility of whoever maintains it.

The second point is traceability. If a court may presume a defect as soon as a company cannot produce documents, documentation becomes protection. Which version was in use when, which change came when, which vulnerability was closed when: you have to be able to prove it, not just know it.

My conclusion

I find the new rules reasonable. Software today controls devices, vehicles and health data, and it would be hard to explain why a toaster is liable and an app is not. For a B2B software company, the risk remains manageable if two things are in place: a fixed process for security updates and complete documentation of what was delivered.

Anyone who offers software to private individuals, imports goods from outside the EU or modifies products should use the time until December to clarify with their insurer and legal advisers where they stand. This post is my assessment as an entrepreneur and is not legal advice.

More background for SMEs (in German) is on the 1Tool blog: https://www.1tool.com/blog/neue-produkthaftung-2026-software-ki-kmu/

Youth Entrepreneurship Week Leibnitz: from idea to pitch in four days →