1. 10. 2026

When Software Causes Damage

Europe’s New Product Liability Regime

Software is becoming an integral part of almost every product, from cars and production machinery to household appliances and medical devices. Yet Europe’s product liability rules were written in 1985, when products were predominantly physical and rarely changed after leaving the factory. A new EU directive now brings these rules into the digital age.

Software Becomes a Product

Under the new regime, software is expressly treated as a product. This includes operating systems, applications, firmware and artificial intelligence systems, whether installed in a physical device or supplied separately. Digital manufacturing files, such as files used by 3D printers, are also covered.

The consequences are significant. A software developer may be held liable if defective software causes personal injury, property damage or the destruction or corruption of data used for private purposes. Liability does not depend on proving negligence. The injured person must generally establish that the product was defective, damage occurred and the defect caused that damage.

A product may also become defective after being placed on the market. This may occur where the manufacturer fails to provide necessary security updates, issues a defective upgrade or continues to control an AI system that develops unsafe behaviour through machine learning. Cybersecurity vulnerabilities are therefore no longer only a regulatory concern. They may also create direct liability for resulting damage.

A Wider Circle of Potential Defendants

The manufacturer remains the primary liable party, but the new rules reflect the realities of global supply chains. If a manufacturer is based outside the EU, claims may be brought against its EU importer or authorized representative. In certain cases, fulfilment service providers, distributors and online platforms may also face liability.

Businesses that substantially modify a product may themselves be treated as manufacturers. This is particularly relevant for companies refurbishing machinery, integrating new software into existing equipment or adapting third-party products for a new commercial purpose.

Easier Access to Evidence

Digital products are often technically complex, making it difficult for an injured person to identify exactly what went wrong. The new directive allows courts to order businesses to disclose relevant evidence. It also introduces presumptions that may make it easier to establish defectiveness or causation where technical complexity makes direct proof excessively difficult.

This increases the importance of reliable technical documentation. Product development records, testing results, cybersecurity reviews, software updates and incident-response decisions may become central evidence in future disputes.

What Businesses Should Do Now

EU Member States must transpose the directive into national law by 9 December 2026, but so far no Czech transposition measures have been published.

Manufacturers and software providers should nevertheless start preparing. Product portfolios should be reviewed to identify software and connected services falling within the new regime. Contracts with developers, component suppliers, importers and distributors should allocate liability and provide effective rights of recourse. Product documentation, cybersecurity processes and insurance coverage should also be reassessed.

The central message is clear: software defects are becoming product defects. For businesses, product safety will increasingly extend beyond physical design to code, data, updates and cybersecurity throughout the product’s lifecycle.

By Mgr. Radek Werich LL.M.

Download

G&P Newsletter 3/2026 (PDF)

Author

Mgr. Radek Werich LL.M.

Mgr. Radek Werich LL.M.

Neuigkeiten & Publikationen

From Ankara to Brno: Why the Constitutional Court Intervened Before Deciding the NATO Dispute

From Ankara to Brno: Why the Constitutional Court Intervened Before Deciding the NATO Dispute

The Czech Constitutional Court’s interim measure secured the President’s participation in the NATO summit but left the underlying constitutional dispute unresolved. The case highlights the role of established constitutional practice when the written Constitution provides no clear answer and raises broader questions about the balance of power between the President and the Government.

Who Will Inherit Your Digital Life? Digital Estate Part One

Who Will Inherit Your Digital Life? Digital Estate Part One

What happens to online accounts, cloud-stored data and cryptocurrency after death? This introduction to the digital estate explains which assets may pass to heirs, why legal inheritance does not always mean practical access and what the German Facebook case reveals about digital inheritance.

Czech Cadastral Reform – Faster Registration, Shorter Safety Net?

Czech Cadastral Reform – Faster Registration, Shorter Safety Net?

The proposed Czech Cadastral Reform may substantially shorten the built-in 20-day protection period in the Czech Real Estate Register and reshape the way real estate transactions are documented. This article examines the planned acceleration of selected registrations, the debate over reduced procedural safeguards, and the potential consequences for investors, lenders and businesses active in the Czech property market.