Directive (EU) 2024/2853, published in the Official Journal on November 18, 2024, updates the regulatory framework on liability for damages from defective products, adapting it to developments related to new technologies.
The new legislation – which will replace the previous Directive 85/374/CEE from December 9, 2026 – will be applicable to all movable property, including software and artificial intelligence systems.
Software Included in the Notion of “Product”
For the purposes of applying the new rules on strict liability for damages from defective products, software is expressly included in the definition of “product,” regardless of how it is provided or used, and therefore, whether the software is integrated in a device, used in the cloud, or provided with SaaS (software-as-a-service) models.
In this regard, the Directive clarifies that, in the digital age market, software has acquired primary importance, especially if one considers the possible implications in terms of safety that may arise from the use of operating systems, firmware, applications, or AI systems.
Therefore, since software can be placed on the market as a product in its own right or as a component of other products, the Directive recognizes that software itself may cause damage due to its operation.
The Person Responsible for the Damage
The Directive extends the range of liable parties, including any party involved in the production process. In particular, the Directive defines as a manufacturer – therefore as a party called to answer for any damages – not only those who actually produce or develop the defective product or component, but also those who present themselves as manufacturers by affixing or authorizing a third party to affix their name, trademark, or other distinctive sign on the product.
It also provides for the possibility, for the injured party, to be able to claim compensation for the damage from both the manufacturer of the product and the manufacturer of the component, in the event that a manufacturer incorporates into a product a defective component provided by another manufacturer.
With particular regard to software, the Directive also considers the software developer and the provider of artificial intelligence systems as manufacturers. It is also specified that, once placed on the market, a product continues to remain under the control of the manufacturer if the latter maintains the ability to provide updates or improvements. With respect to software, this means that the product is considered to be under the control of the manufacturer even if the updates concern only the software integrated as a component of another product and even if such updates are provided by third parties.
This is the case, for example, of the manufacturer of a smart appliance who agrees to the provision by third parties of updates to the software integrated in the appliance manufactured by him.
Evaluation of Software Safety
The new legislation provides that the defective nature of a product must be determined on the basis of the lack of safety “which a person can legitimately expect” in relation to that product. Thus, for products that generate high safety expectations due to the high risk of causing harm to people (such as life support equipment), judicial bodies are allowed to consider a product defective even without ascertaining its actual defective nature, provided that that product belongs to the same series as another product already declared defective.
With respect to AI systems, the effect that the latter’s ability to learn or acquire new characteristics after being placed on the market has on the safety of the product is taken into account. Consequently, “a manufacturer who designs a product capable of developing unexpected behavior should remain liable for behaviors that cause damage.”
Open Source Software
In order not to hinder research and innovation, the applicability of the Directive to open source software is excluded, but only on condition that such software is developed or provided in the course of a non-commercial activity. The Directive remains applicable when the software is provided in the course of a commercial activity and, by commercial activity, is meant both the provision of the software in exchange for a price, and the provision of personal data used for purposes other than those necessary to improve the safety, compatibility, or interoperability of the software.
The Directive also remains fully applicable if the open source software is subsequently integrated as a component in another product in the course of a commercial activity. In this case, only the manufacturer who placed the product on the market is considered liable for any damages, but not the developer of the software, since the latter would not satisfy the condition of “having placed on the market a product or a component.”
Ilaria Feriti