1Tool

Blog · 08 October 2026

New product liability from 9 December 2026: what SMEs need to know now

New product liability from 9 December 2026: what SMEs need to know now

On 9 December 2026, product liability in the EU changes fundamentally. The new Product Liability Directive (EU) 2024/2853 replaces rules dating back to 1985 – a time when a "product" was still something you could hold in your hand.

The headlines sound dramatic: software is liable, AI is liable, no more caps. In this article we explain, without scaremongering, what really changes, who is affected and what your company can sensibly prepare now.


What is product liability in the first place?

Product liability means that whoever places a defective product on the market is liable for the damage it causes – even without fault. The injured party does not have to prove that the manufacturer was careless, only that the product was defective and caused the damage.

In Austria this is currently governed by the Product Liability Act (PHG), in Germany by the Product Liability Act (ProdHaftG). Both countries must align their laws with the new directive by 9 December 2026.

The five most important changes

1. Software and AI are now products

Until now it was disputed whether software fell under product liability at all. Now it is clear: software is a product – whether it is installed on a device, runs as an app or is used as a cloud solution (software as a service). This explicitly includes:

  • AI systems
  • updates and upgrades
  • digital services integrated into a product (such as the app without which a smart device does not work)
  • digital manufacturing files, for example files for 3D printing

Free and open-source software is exempt as long as it is not supplied in the course of a commercial activity.

2. More companies can be held liable

So far the focus was mainly on the manufacturer. In future, depending on the situation, the injured party can also turn to others:

  • importers and authorised representatives of manufacturers outside the EU
  • fulfilment service providers that store, pack and ship goods
  • distributors – if, on request, they cannot say within one month who supplied them with the product
  • online platforms, if they act like a distributor
  • anyone who substantially modifies a product – for example converts or retrofits it – is considered the manufacturer for that modification

The point about distributors matters to many SMEs: if you cannot prove where an item came from, you may end up liable yourself.

3. No more threshold and no more cap

Until now, property damage was only compensated above 500 euros. This threshold disappears. Germany also had a ceiling of 85 million euros for personal injury – this goes as well.

Also new: the loss or corruption of data can be compensable damage – but only for data that is not used for professional purposes (more on that shortly). And recognised psychological health damage explicitly counts as personal injury.

4. Evidence becomes easier – for the injured party

Many claims used to fail simply because the injured party could not prove a defect in a complex product. That changes:

  • Courts can order companies to disclose evidence – for example technical documentation or logs.
  • If a company fails to do so, the product is presumed to be defective.
  • Where technical complexity is high – typical of software and AI – the court can presume the defect or the causal link to the damage if the injured party has shown it to be likely.

In plain terms: if you cannot prove what you delivered, checked or updated and when, you are in a weak position when it matters.

5. Updates and security vulnerabilities count too

With software, responsibility does not end at the point of sale. A manufacturer is also liable for defects caused by an update and for failing to fix a known security vulnerability, as long as the product remains under its control.

When does this apply – and to which products?

The new rules apply to products placed on the market from 9 December 2026. For products sold before that date, the old law continues to apply.

With software, however, the line is less clear than it sounds: a cloud solution or app that is updated continuously is never really "finished and delivered". You should assume that software which continues to be developed after the cut-off date falls under the new rules.

Claims become time-barred three years after the injured party learned of the damage and of the liable party. They expire at the latest ten years after the product was placed on the market – or after 25 years for health damage that only becomes apparent later.


The good news for B2B companies

Amid all the excitement, one point is often overlooked: product liability protects private individuals. Only natural persons receive compensation, namely for:

  • death and bodily injury (including psychological health damage)
  • damage to property used privately
  • loss or corruption of data used privately

Product liability does not cover:

  • damage to property used exclusively for professional purposes
  • loss of data used professionally
  • pure economic loss – such as lost revenue or an incorrectly calculated invoice

An example: if faulty software causes customer data to be lost in your company, that is not a product liability case. As before, your contract with the provider applies, together with warranty and damages.

Still, B2B companies should not sit back entirely. As soon as consumers are at the end of the chain – your customers, their end customers or people who also use a device privately – product liability applies again. And towards these injured parties it cannot be excluded by contract.

Who should take a closer look now

  • Retailers and online shops: can you name the supplier of every product you sold within one month? If not, you are liable yourself.
  • Trades, installation, service: anyone who converts or retrofits devices or replaces components may be considered the manufacturer for that modification. Complete installation and inspection records become even more important.
  • Manufacturers with software in their products: controllers, apps, firmware – everything counts. That includes a clear process for updates and security vulnerabilities.
  • Companies building their own apps or AI solutions for customers: anyone who supplies software to consumers – even an app built quickly with AI – is a manufacturer within the meaning of the directive. Read here why a solid foundation matters.

Documentation is the best protection

The new directive noticeably shifts the burden of proof towards companies. The best protected are those who can show at any time what they sourced, delivered, checked and changed, when and from whom.

This is exactly where central business software like 1Tool helps:

  • Trace suppliers and goods receipts: in merchandise management, purchasing, goods receipt, sales and invoicing are linked. Even months later you can still say where a product came from – the one-month deadline for distributors becomes a formality.
  • Document complaints properly: with the ticket system, every customer report is recorded with its history, replies and solution.
  • Prove inspections and on-site work: with checklists and inspection reports in the app, your field staff record inspections, photos and signatures directly at the customer's site.
  • Store documents centrally: data sheets, certificates, installation instructions and delivery notes are kept in document management with the relevant customer, project or order – not scattered across email inboxes.

Important: with 1Tool, this data is held by an Austrian provider in an Austrian data centre.


Checklist: are you prepared?

✅ Do you know whether your products or services (also) end up with private individuals?

✅ Can you name the supplier of every product you sold within one month?

✅ Are inspections, installations and modifications to products documented – with date and person responsible?

✅ Are complaints recorded centrally rather than just handled by phone or email?

✅ If you offer software or apps: is there a fixed process for security updates?

✅ Have you clarified with your insurer whether your business liability insurance covers the new product liability – including for software?

✅ Have your supplier contracts been adapted so that you can take recourse in the event of a claim?


Conclusion

The new product liability rules finally bring software, AI and online retail into liability law. For pure B2B business less changes than the headlines suggest – but anyone who deals with consumers or sells, installs or modifies products should use the time until December.

The most important step is not a legal one but an organisational one: document everything, without gaps. If you can prove where a product came from, how it was checked and what happened to it, you hold the best cards when it matters.

👉 Would you like to see how to bring purchasing, complaints and inspection reports together in one solution? Book a demo now.

Note: this article provides a general overview and does not replace legal advice. The details depend on how the directive is transposed into Austrian and German law.


You might also be interested in

Vibe coding with 1Tool: the platform beneath your AI appEU Packaging Regulation (PPWR): do I have to shut down my online shop now?Software tool for checklist & inspection