Software becomes a product in EU liability law in December. The firm that bought it is the one party the new directive does not pay.
The revised directive compensates people for injury, private property and private data, and no contract can cap what they are owed. Between businesses, the loss still lands where the indemnity clause puts it.

Draft, not yet edited. Written by Tomasz Wierzbicki, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.
Directive (EU) 2024/2853 has to be in national law by 9 December 2026. Article 4(1) lists what counts as a product: movables, electricity, digital manufacturing files, raw materials, and software. Recital 13 extends that to software reached through "cloud technologies" or supplied "through a software-as-a-service model".
That is where most summaries start. It is also the part least likely to help a firm that buys software rather than ships it. Article 1 governs damage "suffered by natural persons". A bank is not one of those.
It pays for three kinds of damage, and a firm's losses are none of them
Article 6 is a closed list. It covers death and personal injury, including medically recognised harm to psychological health; damage to property, unless the property is the defective product itself or is used exclusively for professional purposes; and the destruction or corruption of data not used for professional purposes. Recital 24 closes the obvious door. Pure economic loss, privacy infringements and discrimination do not "by themselves trigger liability".
The two professional-use tests are not the same test. Property is excluded only when its use is exclusively professional, so the personal phone that also carries work email is in. Data is excluded when it is used professionally "even if not exclusively so", which is recital 22. The phone is compensated. What was on it may not be.
| The loss | Inside the directive | Where it says so |
|---|---|---|
| Personal injury, including psychological | Yes | Article 6(1)(a) |
| A person's own property, including mixed-use | Yes | Article 6(1)(b), recital 25 |
| Property used only for work | No | Article 6(1)(b)(iii) |
| A person's private data destroyed or corrupted | Yes, though a free restore may mean no loss | Article 6(1)(c), recital 20 |
| Data used for work, even partly | No | Article 6(1)(c), recital 22 |
| Money lost, revenue lost, a missed settlement | No | Recital 24 |
| A data breach | Not under this directive | Recital 20 |
So when a supplier's platform fails next year, your payment file is late and your clients are compensated out of your own accounts, nothing here gives your firm a claim against anyone. That position was contractual before December and stays contractual; Article 2(4)(b) leaves national contract law where it was.
Your firm becomes a manufacturer more easily than it expects
The directive reaches a regulated firm from the other side. Article 4(10) counts as a manufacturer anyone who develops a product, has one made, or puts their name on it and so presents themselves as its manufacturer, and anyone who develops one "for their own use". The customer app an agency built and you shipped under your logo is a product, and your firm is its manufacturer.
Article 15 says liability to the injured person cannot be "limited or excluded by a contractual provision", and recital 56 adds national financial ceilings to the things that cannot cap it. Article 12(1) lets operators liable for the same damage be held jointly and severally. Article 14 lets whoever paid pursue the others "in accordance with national law".
The claimant faces no cap. Your route back to the agency runs through national recourse law and the contract you signed with it, which probably caps the agency at a year of fees. The directive only makes sure the party in front of the claimant is the one with the logo on the app.Article 12(2) goes further: a manufacturer can contractually waive recourse against a micro or small software supplier, and then has none. Expect the waiver in templates from suppliers who have read the directive.
The damage list then does something odd to the risk ranking. A defect that sends a customer's money to the wrong account is, on recital 24's wording, pure economic loss, and outside. The same defect wiping the photo library on the customer's phone is private data, and inside. No risk function in a bank would rank those two in that order. The directive does.
Updates are the manufacturer's until someone else is sitting on them
The summaries say manufacturers are now liable for failing to supply security updates. The text is narrower. Article 11(1)(c) lets an operator escape by showing the defect probably did not exist when the product went to market. Article 11(2) removes that defence where the defect comes from software, a related service, or "a lack of software updates or upgrades necessary to maintain safety", provided the thing was within the manufacturer's control. Recital 51 then says the directive "does not impose any obligation to provide updates".
It is the loss of a defence, not a duty to patch, and the test is safety rather than security in general. A vulnerability that only leaks personal data is data protection's problem.
Control, in Article 4(5), includes the ability to supply updates "themselves or via a third party". Recital 51 adds that liability falls away where the owner does not install an update that was supplied. The moment a vendor ships a fix, control moves to whoever's change calendar the fix is waiting in. For a firm that has put a vendor's component inside its own branded product, that is the firm. Change advisory boards are about to learn that they were a liability allocation mechanism all along, and they will learn it from the minutes.
Nobody has said where the cloud sits
Article 4(3) defines a related service as a digital service integrated into a product so that without it the product cannot perform a function. Recital 17's examples are all consumer ones, from a navigation system's traffic data to a smart fridge's thermostat. It excludes internet access and says the directive does not apply to "services as such".
Whether the infrastructure under a software product is a related service, a component or a service as such is not in the text. Depending on the court, the platform your app runs on is a jointly liable component supplier or a party whose liability is whatever its own terms say. The directive does not ask which control plane.
The date has a gap in it
Article 2(1) applies the directive to products placed on the market "after 9 December 2026". Article 21 keeps the 1985 directive for products placed "before that date". On the face of the English text, a product released on 9 December itself is covered by neither. Somebody's release train is scheduled for that Wednesday.
The larger gap is conceptual. A hosted service ships every fortnight. Article 17(1)(b) restarts the ten-year clock on a substantial modification, and Article 7(2)(e) judges defectiveness from when the product left the manufacturer's control, which for a hosted service may be never. Claims will be brought under national statutes, and we have not established how many of those exist yet.
Contracts signed this autumn will run under this regime for their whole term. The questions worth asking in writing: whether the indemnity covers product liability claims by natural persons, and whether they sit inside the cap; what "end of support" means, and who decides a patch is necessary to maintain safety; and whether the supplier is small enough for Article 12(2).
Article 19 requires appeal judgments to be published into a Commission database. Article 20 asks the Commission to report by 9 December 2030 on, among other things, "the availability of product liability insurance". The liability arrives in December. The report on whether anyone will sell cover for it arrives four years later.
Written from
Primary The document itself. Claims in this piece rest only on these.
- Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EECRead for this piece: all twenty-four articles, and the recitals cited here. Obtained as the English XHTML from the Publications Office. Source for: software as a product (Article 4(1)) and the software-as-a-service wording, which is in recital 13 and not in any article; the definitions of related service, component, manufacturer's control and manufacturer (Article 4(3), (4), (5), (10)); the natural-person scope (Articles 1 and 5); the closed list of damage and the two professional-use exclusions (Article 6, recitals 22 and 25); pure economic loss (recital 24); data breaches distinguished from data corruption (recital 20); the defence that a defect arose later and its removal for software, related services and missing safety updates within the manufacturer's control (Article 11(1)(c) and 11(2), recitals 50 and 51, including the sentence that the directive imposes no obligation to provide updates); joint and several liability and the small-supplier recourse waiver (Article 12); recourse under national law (Article 14); the bar on contractual limitation (Article 15, recital 56); the ten-year expiry and its restart on substantial modification (Article 17); the application date, repeal and transposition deadline (Articles 2(1), 21 and 22); maximum harmonisation (Article 3); the development-risk derogation and its notification date (Article 18); the judgment database (Article 19); and the 2030 evaluation (Article 20). The one-day gap between Article 2(1) and Article 21 is read from the English text only; other language versions were not compared.
- Council Directive 85/374/EEC on liability for defective productsNot opened. The body says only what the 2024 directive says about it, that it is repealed from 9 December 2026 and continues to apply to products placed on the market before that date. No comparison of the old damage thresholds or definitions is printed, because this desk has not reread them.
- National transposition measures for Directive (EU) 2024/2853Not opened, and not surveyed. We have not established which member states have adopted their implementing acts as of publication, whether any has notified a development-risk derogation under Article 18, or how any national text handles the date gap or the recourse rules. Claims will be brought under those acts, not under the directive, and the body says so.
- Commission Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprisesNot opened. Referred to only because Article 12(2) uses its definitions for the recourse waiver. No thresholds are printed in the body.