10-07-2026 Article

New Product Liability: What Providers of Digital Business Models Should Consider Now

Update Data Protection No. 268

Autonomous vehicles, AI chatbots and cloud-based software are shaping the product market, while the German Product Liability Act (Produkthaftungsgesetz) is still essentially based on a directive from 1985 and was last fundamentally revised in 1989. With Directive (EU) 2024/2853, the European legislator has adapted product liability law to digitalisation, resource-efficient reuse and global value chains; the Directive must be transposed by 9 December 2026. The German draft implementing act (Act on the Modernisation of Product Liability Law, Bundestag printed paper 21/4297) is currently in the parliamentary process and is intended to replace the existing Product Liability Act upon expiry of the transposition deadline. A final vote in the Bundestag could take place as early as 8 October 2026. For companies, the reform is likely to mean more than a technical adjustment, since strict (no-fault) liability will in future also apply to software and artificial intelligence systems, the group of potential defendants will be expanded, and the enforcement of claims is to be made easier.

This article outlines which companies are affected by the new rules, which obligations and liability risks they face, and which recommendations for action can be derived from this.

I. Affected Companies

The new rules significantly expand the group of potentially liable actors. The manufacturer remains at the centre, but in future the term will also cover anyone who develops or manufactures software, irrespective of whether it is embedded in a physical product or distributed on a stand-alone basis. As a result, manufacturers and providers of artificial intelligence systems will be subject to product liability for the first time.

According to the explanatory memorandum to the draft act, it is irrelevant how the software is provided, i. e. whether it is stored locally on a device, accessed via cloud technologies or used as software-as-a-service. The only exception is free and open-source software that is developed or supplied outside the course of a commercial activity. However, where such software is integrated by a company as a component into a commercial product, that company is liable for defects caused by it.

In addition to the manufacturer of the overall product, the manufacturer of a defective component may also be held liable, including providers of related digital services. A related service is a digital service without which one or more functions of the product could not be performed. If, for example, a navigation service integrated into an autonomous vehicle with the consent of the vehicle manufacturer fails and this causes an accident, both the vehicle manufacturer and the provider of the navigation service are liable. For providers of digital services, who have so far rarely been confronted with product liability issues, this may give rise to a new risk situation.

Where manufacturers are established outside the European Union, a number of further actors become liable so that injured persons have a tangible defendant within the internal market. These may include the importer, the manufacturer’s authorised representative established in the Union, the fulfilment service provider and, on a subsidiary basis, any distributor and, under certain conditions, the provider of an online platform. This becomes relevant in practice where, for example, a private individual purchases a device of an unknown brand from a third country via an online marketplace and that device causes damage. If there is no manufacturer or importer established in the Union, the fulfilment service provider responsible for warehousing, packaging, addressing or dispatch may be liable and, in certain circumstances, also the platform provider, provided that it creates the impression, from the perspective of an average consumer, that it is itself supplying the product. For the software sector, this means that sales and distribution structures for applications developed outside the Union must also be taken into account.

Finally, a person who substantially modifies a product already placed on the market without the consent of the original manufacturer and subsequently makes it available on the market may also be liable as a manufacturer. With regard to software, it should be noted that updates or upgrades can also constitute a substantial modification if they change the risk profile of the product. Companies that further develop or refurbish third-party products may thus find themselves in the role of manufacturer for the first time.

II. Obligations and Liability Risks

The extended scope of application entails changed obligations and increased liability risks for the companies concerned, which are likely to be felt above all in the software sector.

First, the standard of defectiveness is adapted to digital products. A product is defective if it does not provide the safety that can be expected, and additional circumstances will have to be taken into account in future. These include a product’s ability to continue learning or to acquire new features after being placed on the market, its interaction with other products, and the relevant cybersecurity requirements. For manufacturers of self-learning AI systems, this means that unexpected behaviour of the system arising only after it has been placed on the market may also become relevant for liability purposes. Cybersecurity vulnerabilities may render a product defective, for example where they can be exploited by third parties.

A significant tightening lies in the extension of liability over time. Although the relevant point in time for the assessment is, in principle, the placing on the market, the manufacturer retains control over the product if it can provide software updates or upgrades or consents to their provision by third parties. In that case, the relevant point in time shifts, and the manufacturer may also be liable for defects caused by a later update. Omissions are covered as well: anyone who fails to provide safety-relevant updates may be liable for the resulting damage for as long as they retain control over the product. Although the Directive itself does not impose an obligation to provide updates, a de facto duty (Obliegenheit) to continuously maintain digital products arises, because failing to do so can trigger liability. A product that was free of defects when placed on the market may therefore become relevant for liability purposes solely because the manufacturer subsequently fails to adapt it to new safety requirements.

These risks are reinforced by new rules on the taking of evidence. At the request of a claimant, the court may order the defendant manufacturer to disclose relevant evidence at its disposal, such as design and safety documentation or information on the software. If the manufacturer fails to comply with such an order, the product is presumed to be defective.
Whether and to what extent erroneous outputs of generative AI systems, such as incorrect information provided by a chatbot, trigger product liability has not yet been conclusively resolved. Some classify such cases as pure information liability, which falls outside the protective purpose of product liability law. Others argue in favour of liability because an AI system does not merely convey information but generates it independently. Until this has been clarified by the courts, manufacturers of AI systems should assume a potential liability risk.

III. Recommendations for Action

Several practical priorities can be derived from the extended liability risks, which companies should address even before the new rules enter into force.

First, it is advisable to take stock of one’s own role in the value chain. Since the group of potential defendants is being expanded considerably, companies should examine whether, in their specific distribution model, they qualify as a manufacturer, component or service provider, importer, fulfilment service provider or platform provider. Anyone who, for example, integrates open-source components into their own software, refurbishes third-party products or distributes applications from third countries may find themselves in a manufacturer’s position that they had not previously anticipated. This classification forms the basis for all further measures and should also include the related digital services integrated into the company’s own products.

Second, processes for providing software updates should be reviewed, and the security maintenance of digital products should be safeguarded organisationally throughout their entire life cycle. Since in future both defective updates and the failure to provide safety-relevant updates may trigger liability, it is advisable to establish a structured procedure for monitoring security vulnerabilities, assessing the need for action and providing updates promptly, and to document this procedure. For self-learning AI systems, it should also be determined how the behaviour of the system will be monitored after it has been placed on the market.

Third, documentation becomes of central importance for any later defence. Since defectiveness is presumed as soon as ordered evidence is not produced, and the burden of proof shifts to the detriment of companies, design, test and safety documentation as well as the development and release history, including training and version states in the case of AI systems, should be prepared in such a way that the absence of defects in a product can be demonstrated in the event of a dispute. In view of the period being extended to up to 25 years for latent damage, the corresponding retention periods should be extended significantly.

Finally, contractual relationships within the supply chain and insurance coverage should be adapted to the new liability situation. Since several actors are jointly and severally liable, it is advisable to review recourse and indemnification arrangements with suppliers, component and service providers and to clearly allocate responsibilities for software maintenance and security updates. At the same time, the scope of insurance coverage should be reassessed in light of the abolition of the liability cap and the increased cost of defence.

IV. Conclusion and Outlook

The modernisation of product liability law expands the group of liable actors, adapts the concept of defect to digital and self-learning products and makes it noticeably easier to enforce claims. For manufacturers and providers of software and AI systems, this results in an increased liability risk, which is further aggravated by the extension of responsibility over time, the new evidentiary relief and the abolition of the liability cap. As the act is still in the parliamentary process, amendments remain possible; however, in view of the largely fully harmonising requirements of the Directive and the transposition deadline of 9 December 2026, no fundamental deviations are to be expected. Companies are advised to initiate the preparations outlined above at an early stage in order to be ready when the new rules enter into force.

This article was created in collaboration with our student employee Emily Bernklau.

Download as PDF

Contact persons

You are currently using an outdated and no longer supported browser (Internet Explorer). To ensure the best user experience and save you from possible problems, we recommend that you use a more modern browser.