EU Directive 2024/2853 on Liability for Defective Products: A Guide for Businesses

Direttiva UE 2024 2853 responsabilità danno da prodotti difettosi

Directive (EU) 2024/2853 rewrites European rules on liability for defective products, effective from the end of 2024, replacing Directive 85/374/EEC. The most significant innovation for the technology sector is the explicit inclusion of software, artificial intelligence systems, and digital services within the scope of civil liability.

This article is the general overview of our mini-guide on the directive. The linked chapters delve into specific topics: digital products and connected services, software and artificial intelligence, vulnerability assessment as a compliance tool, and penetration testing and manufacturer liability.

Why this directive also concerns technology companies

Until the 1985 directive, software was generally excluded from strict liability for defective products. The new regulation closes this gap: a SaaS application, an AI system, or firmware that causes compensable damage exposes the provider to the same rules that apply to a physical product. For companies that develop, distribute, or integrate digital products, this substantially changes the legal risk profile.

What falls within the scope: products and liable parties

The directive expands the definition of “product” to include:

  • Software and AI systems — operating systems, firmware, applications, and artificial intelligence services, regardless of the delivery method (physical device or cloud/SaaS).
  • Digital manufacturing files — for example, models for 3D printing.
  • Connected digital services — services necessary for the functioning of a physical product, such as traffic information for navigation.
  • Raw materials and electricity.

Source code, media files (such as e-books), and free and open-source software developed or distributed outside of commercial activities remain excluded. For a detailed analysis of digital products and connected services, see the dedicated chapter: EU Directive 2024/2853 and digital products.

Parties that can be held liable include the manufacturer, the importer, the authorized representative, the logistics service provider (in the absence of an EU importer), online platforms acting as distributors, and anyone who substantially modifies the product, thereby assuming the status of a new manufacturer.

Compensable damages

The directive covers three categories of damage:

  1. Death or personal injury, including medically recognized and certified psychological harm.
  2. Damage to material property for personal or mixed use, provided it is not exclusively professional.
  3. Destruction or corruption of data not used for professional purposes.

Burden of proof and cybersecurity as a mandatory requirement

The directive eases the burden of proof in favor of victims through three main mechanisms:

  • Access to evidence — courts can order the manufacturer to disclose relevant documents, with protective measures for trade secrets.
  • Presumption of defectiveness — a product is presumed defective if the operator does not cooperate in providing access to evidence, violates mandatory safety standards, or exhibits obvious malfunctions.
  • Complex technical cases — when scientific or technical complexity makes proof difficult, the judge may presume the defect or the causal link if the victim demonstrates that the damage is likely related to the defect.

The explicit reference to cybersecurity as a mandatory safety requirement is one of the most relevant elements for technology companies: unmanaged vulnerabilities in a software product or IoT system can translate into direct civil liability. The operational implications for vulnerability assessment and penetration testing are explored in the chapters Vulnerability Assessment and EU Directive 2024/2853 and Penetration Testing and manufacturer liability.

Operational deadlines for Italian companies

  • Transposition deadline: Member States must adopt national measures by December 9, 2026.
  • Application: The new rules apply to products placed on the market from December 9, 2026; for previous products, the 1985 legislation remains in force.
  • In Italy, the directive is included in the European Delegation Law 2025 (Law no. 36 of March 17, 2026), which delegates the Government to issue the implementing legislative decrees.

Frequently Asked Questions

  • What is the main difference compared to the 1985 directive?
  • The 1985 directive generally excluded software from the scope of strict liability for defective products. The new regulation explicitly includes software, AI systems, and connected digital services, closing a gap that had made compensation for damage caused by technological products difficult.
  • Does a SaaS app fall within the scope of the directive?
  • Yes. The directive explicitly includes software delivered via the cloud, including SaaS services. If an application causes compensable damage, the provider can be held liable under the new rules.
  • Does the directive apply to open-source software?
  • No, free and open-source software developed or distributed outside of commercial activities is excluded. However, commercial products that incorporate open-source components remain included.
  • What does the presumption of defectiveness related to cybersecurity mean in practice?
  • If a product violates mandatory safety standards — including those concerning cybersecurity — the judge may presume it is defective without the victim having to prove it exhaustively. For companies, this makes vulnerability management a matter of legal liability, not just technical.
  • Who is responsible if the product is sold via an online marketplace?
  • The online platform can be held liable if it acts as a distributor or leads the consumer to believe that the product comes directly from it. In the absence of an EU importer or representative, the logistics provider may also be involved.
  • Does this directive overlap with other regulatory obligations like NIS2 or the Cyber Resilience Act?
  • Yes, in part. NIS2 and the Cyber Resilience Act impose active security obligations (technical measures, notifications, updates); Directive 2024/2853 acts on the level of civil liability for damages that have already occurred. The three regulations are complementary: complying with the security requirements of NIS2 and CRA reduces the risk of incurring the presumption of defectiveness provided for by the liability directive.
  • How can a company prepare before December 2026?
  • The starting point is an assessment of the security posture of products and internal processes, with a focus on vulnerability management and documentation of adopted controls. A structured security governance path reduces exposure to legal risk before the new rules become operational.

Useful Resources

Protect your organisation with Virtual CISO.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert