Who Pays When AI Causes Harm? The New Product Liability Directive Lands 9 December 2026 - and the AI Act Will Not Help You
Compliance teams across the EU have spent two years building AI Act programmes: risk classifications, technical documentation, conformity assessments, post-market monitoring. Almost none of that work answers the question a claimant's lawyer will ask first. Who pays?
Here is the fact that should reframe your AI liability planning. In the entire text of Regulation (EU) 2024/1689, the AI Act, the word "compensation" appears exactly once, in a recital, and only to confirm that rights and remedies under other Union law, including compensation under Council Directive 85/374/EEC, remain unaffected and fully applicable. The AI Act points at a different instrument and walks away.
That instrument is the new Product Liability Directive. And the question of who is liable when AI causes harm is now governed almost entirely by it, with a transposition deadline that is under three months away.
The AI Act fines you. It does not compensate anyone. Those are separate machines, and only one of them writes cheques to claimants.
Why the AI Liability Directive is not coming back
Many compliance programmes were built on the assumption that a dedicated AI liability directive would eventually arrive to handle fault-based claims against AI providers and deployers. It will not.
The AI Liability Directive, COM(2022) 496 final, procedure 2022/0303(COD), was proposed on 28 September 2022. It was listed for withdrawal in the Commission Work Programme 2025, COM(2025) 45, announced on 11 February 2025, and formally withdrawn by notice in the Official Journal, C/2025/5423, of 6 October 2025.
On 20 May 2025 the IMCO committee adopted an opinion calling the AILD "premature and unnecessary" and asking JURI to propose rejection. On 3 December 2025 the JURI committee rejected a proposal to legally challenge the Commission's withdrawal. Nothing has replaced it.
Nor did the recent AI Act amendments fill the gap. Regulation (EU) 2026/1744, the Digital Omnibus on AI of 8 July 2026, in force 27 July 2026, deferred high-risk AI Act obligations to 2 December 2027 and 2 August 2028, but contains nothing on civil liability.
This also explains why AI harm claims in Europe are currently brought under whatever regime is available. noyb's Norwegian complaint against OpenAI in March 2025, over ChatGPT falsely stating that a man had murdered his children, was brought under GDPR accuracy rights rather than any liability instrument. There was no liability instrument to use.
What actually governs: the product liability directive and AI
Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products repeals Council Directive 85/374/EEC and entered into force on 8 December 2024. Article 22(1) requires member states to bring the implementing laws into force by 9 December 2026.
That is the date on which product liability directive AI exposure becomes real, and it is now roughly eleven weeks out.
Two structural points matter more than most compliance summaries suggest.
First, the cut-off. Article 2(1) applies the new directive only to products placed on the market or put into service after 9 December 2026. Article 21 repeals 85/374/EEC with effect from that date, but the old regime continues to govern products placed on the market before it.
The practical consequence is that you will run two liability regimes in parallel for a decade. An AI system you shipped in October 2026 sits under the 1985 framework, with no software-as-product clarity, no disclosure mechanism and no complexity presumption. The same system, shipped in January 2027, sits under a regime built to catch it. Your product inventory is now a liability map.
Second, Article 3 makes the directive a maximum-harmonisation instrument: member states may not maintain or introduce provisions that are more or less stringent. The 1985 directive was minimum harmonisation. That is meant to close the divergence problem. As we will see, the transposition drafts are not fully cooperating.
Software is now a product
Article 4(1) defines "product" as all movables and expressly includes electricity, digital manufacturing files, raw materials and software.
Recital 13 names "operating systems, firmware, computer programs, applications or AI systems" as software. It confirms that liability applies whether software sits on a device, is accessed over a network or cloud, or is supplied as software-as-a-service. It states that a developer or producer of software, including AI system providers within the meaning of Regulation (EU) 2024/1689, should be treated as a manufacturer.
Read that last clause slowly. Your AI Act role as a provider is being imported directly into product liability law as manufacturer status.
The carve-outs are narrower than people hope. Recital 13 excludes information as such: digital file content, media files, e-books and "the mere source code of software" are not products. Article 2(2) excludes free and open-source software developed or supplied outside a commercial activity. If you monetise it, support it commercially or bundle it into a paid offering, that exclusion does not help you.
Integrations matter too. Article 4(3) defines a "related service" as a digital service whose absence would prevent the product performing a function, and Article 4(4) makes related services and intangible items "components". A model API that a device depends on is a component of that device.
The three provisions that change AI cases
Article 7(1), the regulatory limb. A product is defective where it does not provide the safety a person is entitled to expect "or that is required under Union or national law". That second limb is new, and it is the hinge. It links defectiveness directly to regulatory non-compliance. An AI Act breach is not just a supervisory matter any more: it becomes an argument that the product was defective as a matter of civil law. The AI Act does not create damages. It now supplies the evidence for them.
Article 7(2)(c), continued learning. In assessing defectiveness, courts must weigh "the effect on the product of any ability to continue to learn or acquire new features after it is placed on the market". Article 7(2)(f) adds safety-relevant cybersecurity requirements. Model behaviour drift is now an express defectiveness factor.
Article 4(5), the control window. The definition of "manufacturer's control" expressly covers software updates, upgrades and modifications. Wherever you retain the ability to push an update, your liability window has not closed. For most SaaS and most deployed models, it never closes.
Evidence and presumptions: the single biggest change for AI defendants
If you read only one section, read this one.
Article 9 is a disclosure-of-evidence mechanism: a claimant who "has presented facts and evidence sufficient to support the plausibility of the claim" can require the defendant to disclose relevant evidence, subject to necessity, proportionality and trade-secret protection. Article 9(2) is reciprocal.
Article 10(1) keeps the claimant's burden of proof. But Article 10(2) presumes defectiveness where the defendant fails to disclose under Article 9(1), or the product breaches mandatory safety requirements, or the damage was caused by "an obvious malfunction... during reasonably foreseeable use". Article 10(3) presumes causality where the product is defective and the damage is "of a kind typically consistent with the defect".
Then the provision written for machine learning. Article 10(4) requires a court to presume defectiveness, or causality, or both, where despite disclosure the claimant "faces excessive difficulties, in particular due to technical or scientific complexity" and shows it is likely that the product is defective or causally linked. Article 10(5) preserves the defendant's right to rebut.
The recital explaining Article 10(4) names machine learning as an example of technical complexity, and says a claimant "should... neither be required to explain the AI system's specific characteristics nor how those characteristics make it harder to establish the causal link."
In plain terms: opacity used to be the defendant's best friend. A claimant who could not explain how a model reached an output usually could not prove the case. That asymmetry is now reversed by design. The claimant does not have to explain your model. You have to disclose, and then you have to rebut.
Who is on the hook
Article 8(1) makes liable the manufacturer, the component manufacturer, and for non-EU manufacturers the importer, the authorised representative, and where neither exists the fulfilment service provider. Article 8(3) makes distributors liable if they fail within one month to identify an EU economic operator. Article 8(4) extends this to providers of online platforms meeting the DSA Article 6(3) conditions.
If you resell or distribute a third-party model or AI-enabled product in the EU, a one-month clock is the only thing standing between you and manufacturer-equivalent exposure.
Article 8(2) treats anyone who substantially modifies a product outside the manufacturer's control and then makes it available as its manufacturer. Article 4(18) defines substantial modification as a change to performance, purpose or type that was not foreseen in the initial risk assessment and that changes the hazard or increases the level of risk.
This is the PLD mirror of the AI Act's own role-flipping logic. Fine-tune a model, repurpose it, ship it: you may have become the manufacturer of a new product, with a fresh liability clock.
What is recoverable now
Article 6(1) covers death or personal injury "including medically recognised damage to psychological health"; property damage other than the product itself and property used for professional purposes; and "destruction or corruption of data that are not used for professional purposes". Article 6(2) extends to non-material loss where national law allows.
Data corruption as recoverable damage is new and directly relevant to AI tooling that writes to user systems.
The EUR 500 lower threshold from the 1985 directive is gone, and the optional national cap on total liability is gone. Article 15 bars exclusion or limitation of liability by contract or by national law. Your limitation of liability clause does not apply here.
Article 16(1) sets a three-year limitation period from knowledge. Article 17(1)(b) sets a ten-year long-stop from placing on the market, restarting from the date of a substantial modification. Article 17(2) extends this to twenty-five years for latent personal injury. Every substantial modification restarts the ten-year clock.
AI Act versus PLD, side by side
| Question | EU AI Act | Product Liability Directive (EU) 2024/2853 |
|---|---|---|
| What it does | Sets duties: classification, documentation, conformity, monitoring | Allocates liability for harm caused by defective products |
| Who can act | Market surveillance authorities; individuals may complain or seek an explanation | Any injured person, in national civil courts |
| What a breach costs | Administrative fines paid to the state | Compensation paid to the claimant |
| Burden of proof | Regulatory, on the provider to demonstrate compliance | On the claimant, subject to the Article 10(2), 10(3) and 10(4) presumptions |
| Applies from | Staged, with high-risk obligations deferred to 2 December 2027 and 2 August 2028 | Products placed on the market after 9 December 2026 |
The AI Act's Chapter IX Section 4 is titled "Remedies" and contains only two articles: Article 85, the right to lodge a complaint with a market surveillance authority, and Article 86, the right to obtain an explanation of individual decision-making from the deployer. Neither is a private right of action for damages.
Fragmentation is already visible
Maximum harmonisation is the theory. The drafting is the practice.
As of an update on 17 August 2026, Hungary, Croatia and Lithuania have adopted transposing laws. Bills have been published in Croatia, Cyprus, Germany, the Netherlands, Denmark, Finland, Czechia, Slovakia and Sweden.
Divergences are already apparent: Finland's draft drops the development-risk defence entirely while Germany and Sweden retain it; the Dutch draft omits the "medically recognised" qualifier on psychological harm; Denmark adds a fault-based distributor liability with a reversed burden of proof; Germany and Slovakia omit Article 12(2) on recourse limits for micro and small software-component makers.
No infringement proceedings are possible yet, because the deadline has not passed. There is no enforcement activity to point to, and nobody should suggest otherwise.
For a multi-market defendant, the consequence is forum sensitivity. Whether the development-risk defence is available to you, and whether psychological harm needs a medical qualifier, may depend on where the claim is filed.
Insurance is tightening at exactly the wrong moment
Article 20 requires the Commission's future review to consider "the availability of product liability insurance". That clause was drafted with some foresight.
On AI liability insurance, the signals are not encouraging. According to press reporting, AIG, Great American and W.R. Berkley have filed with US regulators to exclude AI-related claims, with W.R. Berkley's proposed exclusion covering any claim arising from AI "in any form", and AIG telling Illinois regulators that such claims are likely to increase. This is reported filing activity, not confirmed policy language in force, and it is a US market signal rather than an EU one. It is still the direction of travel your broker is watching.
The litigation backdrop is not theoretical either. In Moffatt v. Air Canada, British Columbia Civil Resolution Tribunal, 14 February 2024, the airline was held liable in negligent misrepresentation for its chatbot's bereavement-fare advice, with damages of CAD 650.88, the tribunal holding that the chatbot was part of the airline's website and the airline responsible for it. Small damages, large principle: the organisation deploying the system owned its output.
What to do before 9 December 2026
Map which products you place on the market or put into service after the cut-off. Everything on the later side of 9 December 2026 falls under the new regime. Everything before stays under 85/374/EEC. You need that line drawn in your product register, not in someone's head.
Treat your AI Act technical documentation as litigation evidence. Article 9 disclosure will reach it. Write it knowing a claimant's counsel may read it, and check that what it says about testing, known limitations and risk assessment is defensible.
Check whether your update and fine-tuning practices keep you inside "manufacturer's control". Article 4(5) means a live update channel keeps your liability window open. Decide whether that is a deliberate choice or an accident of architecture.
Review your contractual limitation and exclusion clauses against Article 15. Clauses excluding or limiting liability for covered damage will not survive contact with the directive. Know which of your agreements currently rely on them.
Check whether your role in the Article 8 chain has changed. Importer, authorised representative, fulfilment service provider, distributor with a one-month identification duty, platform under DSA Article 6(3). Also test your fine-tuning and repurposing against Article 4(18) substantial modification.
Ask your broker, in writing, what your current policy says about AI. Specifically whether any AI exclusion is present, proposed or being contemplated at renewal, and how the policy treats software supplied as a service.
Track transposition in every market you sell into. Maximum harmonisation does not mean identical texts, and the divergences above are already material.
This is general information about the regime, not legal advice on your situation.
The date
9 December 2026 is the transposition deadline. It is also the line that decides, for every product you ship, which of two liability regimes applies for the next decade. Products shipped after it carry software-as-product status, a disclosure obligation that reaches your technical file, and a complexity presumption written with machine learning in mind.
There are under three months left to know which side of that line your AI estate sits on.
If you would like help mapping your products, roles and update practices against Directive (EU) 2024/2853 before the deadline, get in touch.
Related reading

The AI Governance Operating Model: Who Owns What, Who Signs, and How to Build the Machine
Most AI governance frameworks fail not because the policy is wrong but because nobody owns anything. Here's how to build the operating model that actually works - roles, RACI, forums, inventory, and a first-90-days plan.
The Cyber Resilience Act and the EU AI Act: Reporting Went Live on 11 September 2026 - What AI Product Makers Must Do Now
Since 11 September 2026, makers of software and connected products, including most AI products, must report actively exploited vulnerabilities within 24 hours under the Cyber Resilience Act. Here is how CRA reporting works, how CRA Article 12 links to AI Act Article 15, and how to build one incident playbook for both.
EU AI Act News: What the First 60 Days of Enforcement Actually Produced (August-September 2026)
2 August 2026 was supposed to be the day the EU AI Act got teeth. Sixty days later, here is what actually happened: the AI Office's first information requests to GPAI providers, a transparency Code of Practice with 200+ signatories, a new complaints tool, and a string of GDPR decisions that show where AI enforcement is really coming from.