Every provision of Directive (EU) 2024/2853 and of Directive 85/374/EEC described below was read in the Official Journal text served by the Publications Office of the European Union on 18 September 2026. Article and recital numbers are those of the published text. Where the text does not answer a question, this article says so and does not supply an answer of its own. It does not describe any national transposition measure, none of which has been read by this desk, and it is not legal advice.

In short
  • Directive (EU) 2024/2853 applies to products placed on the market or put into service after 9 December 2026 (Article 2(1)). Directive 85/374/EEC is repealed from that date but continues to apply to products placed on the market or put into service before it (Article 21). The two regimes will therefore run side by side, product by product, for years.
  • Placing on the market is the first making available of a product on the Union market. Putting into service is the first use of a product in the Union in the course of a commercial activity where it has not been placed on the market before (Article 4(8) and 4(9)). Both are single moments.
  • A substantially modified product is considered a new product. Recital 40 states that where a substantial modification is made through a software update or upgrade, or due to the continuous learning of an AI system, the product should be considered to be made available or put into service at the time the modification is actually made.
  • A substantial modification restarts the ten year expiry period, which then runs from the date the modified product was made available or put into service (Article 17(1)(b)). If the modification was made outside the original manufacturer's control, the person who made it is treated as the manufacturer (Article 8(2)).
  • The text does not say when a continuously supplied software service is placed on the market for each customer, and it sets no AI-specific threshold for what makes an update substantial. Operators should record the dates and the reasoning now, because those records will decide which regime a future claim falls under.

The rule in two articles

Article 2(1) of Directive (EU) 2024/2853 reads: "This Directive shall apply to products placed on the market or put into service after 9 December 2026." Article 21 is its counterpart. Directive 85/374/EEC is repealed with effect from 9 December 2026, and then: "However, it shall continue to apply with regard to products placed on the market or put into service before that date."

Two consequences follow directly. First, the test is attached to the product and not to the damage or the claim. An injury in 2029 caused by a product placed on the market in 2025 is governed by the national law that implemented the 1985 directive. Secondly, neither regime displaces the other in time. With a ten year expiry period in both texts, claims under the 1985 rules remain possible into the middle of the next decade, alongside claims under the new rules.

A third point is about the instrument. A directive binds Member States as to the result, and Article 22(1) gives them until 9 December 2026 to bring national provisions into force. What a claimant will plead is the national measure. This desk has not read the national measures and says nothing about where any Member State stands. The analysis below is of the Union text that those measures must implement, and Article 3 of the Directive does not allow Member States to diverge from it, in either direction, unless the Directive itself provides otherwise.

Two moments, and both are single moments

The Directive defines its temporal triggers in Article 4. Making available on the market is any supply of a product for distribution, consumption or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. Placing on the market is the first making available. Putting into service is the first use of a product in the Union in the course of a commercial activity, in circumstances in which the product has not been placed on the market prior to its first use.

Each is a single event. For a machine with a serial number that is uncontroversial. For software the Directive settles one thing and leaves another. It settles that the mode of supply is irrelevant to whether software is a product: recital 13 says software is a product for the purposes of no-fault liability whether it is stored on a device, accessed through a communication network or cloud technologies, or supplied through a software-as-a-service model. It does not say, for a service that is supplied continuously to many customers from a single codebase, whether there is one placing on the market for the product or a separate one each time it is first supplied to a new customer. The 1985 directive, for what it is worth, speaks in Article 11 of the date on which the producer put into circulation "the actual product which caused the damage".

This desk does not resolve that question and is not aware of anything in the text that does. It is flagged because it determines the regime for every customer onboarded after the date onto a system that went live before it, and because the prudent assumption for a provider is the unfavourable one.

The hinge between the regimes: substantial modification

The Directive contains one mechanism that moves an existing product forward in time. Recital 39 states that when a product is substantially modified and is thereafter made available on the market or put into service, it is considered to be a new product. Recital 40 extends the principle to software in terms: the same principles apply to modifications made by way of a software update or upgrade as to modifications made in other ways, and "where a substantial modification is made through a software update or upgrade, or due to the continuous learning of an AI system, the substantially modified product should be considered to be made available on the market or put into service at the time that modification is actually made."

Read with Article 2(1), the effect is that an AI system placed on the market before 9 December 2026 and substantially modified after it becomes, from the modification, a product to which the new Directive applies. That is this desk's reading of the two provisions together; the Directive does not state the conclusion in a single sentence.

What counts as substantial is defined in Article 4(18), in two limbs. The first defers to product safety law: a modification is substantial if it is considered substantial under relevant Union or national rules on product safety. The second applies where those rules lay down no threshold. Then a modification is substantial if it changes the product's original performance, purpose or type without that change having been foreseen in the manufacturer's initial risk assessment, and it changes the nature of the hazard, creates a new hazard or increases the level of risk. Both conditions of the second limb must be met.

The phrase that does the work for AI is "foreseen in the manufacturer's initial risk assessment". A system designed to keep learning, whose provider assessed that learning in advance and bounded it, is in a different position from one whose behaviour drifted somewhere nobody documented. The AI Act uses a parallel idea for high-risk systems, where Article 43(4) provides that, for systems that continue to learn, changes pre-determined by the provider at the moment of the initial conformity assessment and recorded in the technical documentation shall not constitute a substantial modification. That parallel is an observation and not a rule of the Directive, which does not cross-refer to the AI Act on this point. The AI Act side is covered in the conformity assessment guide and Article 25 on value chain responsibilities.

Who made the change decides who answers for it

The Directive separates modifications by whether they were within the manufacturer's control. Article 4(5) defines that control as the manufacturer performing, authorising or consenting to the integration, inter-connection or supply of a component, including software updates or upgrades, or the modification of the product; or the manufacturer having the ability to supply software updates or upgrades, itself or through a third party.

Within that control, the original manufacturer stays liable, and it loses the defence it would otherwise have. Article 11(1)(c) exempts an operator that proves the defect probably did not exist when the product was placed on the market. Article 11(2) disapplies that exemption where the defectiveness is due to a related service, to software including updates or upgrades, to a lack of software updates or upgrades necessary to maintain safety, or to a substantial modification, provided it is within the manufacturer's control. Recital 39 states the policy: a manufacturer should not be able to avoid liability by arguing that the defectiveness came into being after it placed the product on the market.

Outside that control, Article 8(2) applies. Any natural or legal person that substantially modifies a product outside the manufacturer's control, and thereafter makes it available on the market or puts it into service, is considered a manufacturer. Putting into service includes first use in the course of a commercial activity, so a deployer that substantially modifies a system for its own commercial use is within the words. Its defence is Article 11(1)(g): it is not liable if it proves that the defectiveness is related to a part of the product not affected by the modification. Recital 39 adds that operators carrying out repairs or other operations that do not involve substantial modification should not be subject to liability under the Directive.

For a deployer the practical line is therefore between operating a system within its instructions and changing what it is. The deployer obligations that sit on the first side of that line are in the Article 26 complete guide. The earlier analysis of the Directive as a whole is in the revised Product Liability Directive and AI software exposure.

The clocks restart

Both directives carry a three year limitation period and a ten year expiry period. Under Article 16 of the new Directive the three years run from the day the injured person became aware, or should reasonably have become aware, of the damage, the defectiveness and the identity of the relevant economic operator. Under Article 17(1) the right to compensation ends ten years from the date the defective product was placed on the market or put into service, unless proceedings have been initiated in the meantime. Article 17(2) extends the ten years to twenty five where the injured person could not initiate proceedings in time because of the latency of a personal injury. The 1985 directive has no equivalent of that extension in the text this desk read.

Article 17(1)(b) is the provision that matters for software. In the case of a substantially modified product, the ten years run from the date on which that product was made available on the market or put into service following its substantial modification. A system that is substantially modified every eighteen months never reaches the end of its expiry period. For the manufacturer of a long-lived AI product, the ten year long stop is a rolling one, and the retention period for technical evidence has to be set accordingly. The insurance consequence is set out at agentinsured.eu, on the ten year expiry period and claims-made cover.

What changes when a product crosses the line

The difference between the regimes is the reason the date matters. Comparing the two texts as read, five differences bear on AI.

The product. The 1985 definition is all movables, and it adds that product includes electricity. It does not mention software. The new Article 4(1) includes software in terms, and recital 3 records that the meaning of the term product was one of the inconsistencies that led to the revision.

The damage. The 1985 text covers death and personal injury, and damage to property intended and mainly used for private use or consumption, above a lower threshold of 500 ECU. The new Article 6 adds medically recognised damage to psychological health and the destruction or corruption of data that are not used for professional purposes. It sets no lower threshold, and its property test excludes only property used exclusively for professional purposes.

The evidence. Under Article 4 of the 1985 directive the injured person proves the damage, the defect and the causal relationship, and the text contains nothing further. The new Directive keeps that burden in Article 10(1) and then adds court-ordered disclosure in Article 9 and rebuttable presumptions in Article 10(2) to (4), including a presumption where the claimant faces excessive difficulties due to technical or scientific complexity. Recital 48 gives as an example a causal link that would require the claimant to explain the inner workings of an AI system. The evidential side is treated at agentcertified.eu, on disclosure, presumptions and the evidence file.

The later-defect defence. Article 7(b) of the 1985 directive exempts a producer who proves the defect probably did not exist when the product was put into circulation, without qualification. The new Article 11(2) removes that exemption for software, updates, missing safety updates and related services within the manufacturer's control.

The defendants. The 1985 directive reaches the producer, the own-brander, the importer and, where the producer cannot be identified, the supplier. The new Article 8 adds the authorised representative, the fulfilment service provider, the person who substantially modifies, and in defined circumstances the provider of an online platform.

How this sits against the AI Act calendar

The Directive applies from 9 December 2026. Following Regulation (EU) 2026/1744, the AI Act's stand-alone Annex III high-risk obligations apply from 2 December 2027 and those for Annex I products from 2 August 2028. For almost a year, therefore, an AI system can be a product under a no-fault liability regime before the AI Act's high-risk requirements apply to it.

That sequence matters for one of the presumptions. Article 10(2)(b) presumes defectiveness where the claimant demonstrates that the product does not comply with mandatory product safety requirements laid down in Union or national law that are intended to protect against the risk of the damage suffered. Recital 46 adds that this includes cases in which a product is not equipped with the means to log information about its operation as required under Union or national law. The Directive does not name the AI Act in that article, and this desk does not assert that any particular AI Act requirement is a mandatory product safety requirement for this purpose. What can be said is narrower: until an obligation applies it cannot be breached, so that presumption cannot rest on an AI Act high-risk requirement before that requirement's own application date. The presumptions in Article 10(2)(a), (2)(c) and (4) do not depend on any other instrument and are available from the start. The dates are tracked in what lands on 2 December 2026.

The records to hold on the date

Which regime governs a future claim will be decided on evidence of dates and changes. Four records are worth having in order before 9 December 2026.

A placing register. For each AI product or system: the date it was first made available on the Union market or first used in the Union in the course of a commercial activity, and the evidence for that date. For continuously supplied services, record first supply per customer as well, because the text leaves open which moment counts.

The initial risk assessment, with its foreseen changes. The second limb of Article 4(18) asks whether a change was foreseen in the manufacturer's initial risk assessment. A provider that documents in advance the range within which the system is expected to learn or be updated has something to point to. A provider that did not has nothing.

A modification log with a reasoned classification. For every update, retraining or reconfiguration after the date: what changed, who made or authorised it, and a short reasoned entry on whether it changes performance, purpose or type and whether it changes the hazard or the level of risk. The classification may later be disputed. An absent one cannot be defended at all.

For deployers, the instructions for use and the record of staying within them. The deployer's protection against Article 8(2) is that it operated the system and did not change what it is. The provider's instructions define the difference. Where a deployment involves fine-tuning, retrieval over the deployer's own data or a purpose the provider did not describe, obtain the provider's written position on whether that is within the intended purpose. Smaller operators will find the plain-language version at insureyouragent.com, on whether the new product liability law applies to a small business using AI.

Questions

Does the revised Product Liability Directive apply to AI systems already on the market on 9 December 2026?

Not by reason of the date alone. Article 2(1) of Directive (EU) 2024/2853 applies it to products placed on the market or put into service after 9 December 2026, and Article 21 provides that Directive 85/374/EEC continues to apply to products placed on the market or put into service before that date. An AI system already on the market stays under the national law implementing the 1985 directive unless and until it is substantially modified.

Can a software update move an AI product from the old regime to the new one?

Yes, if the update is a substantial modification. Recital 39 states that a substantially modified product that is thereafter made available or put into service is considered a new product, and recital 40 states that where a substantial modification is made through a software update or upgrade, or due to the continuous learning of an AI system, the product should be considered to be made available or put into service at the time the modification is actually made. If that time is after 9 December 2026, Article 2(1) brings the modified product within the new Directive.

What is a substantial modification under Directive 2024/2853?

Article 4(18) defines it in two limbs. A modification is substantial if it is considered substantial under relevant Union or national product safety rules. Where those rules lay down no threshold, it is substantial if it changes the product's original performance, purpose or type without that change having been foreseen in the manufacturer's initial risk assessment, and it changes the nature of the hazard, creates a new hazard or increases the level of risk.

Does a substantial modification restart the ten year expiry period?

Yes. Under Article 17(1)(b), in the case of a substantially modified product the ten year expiry period runs from the date on which that product was made available on the market or put into service following its substantial modification. Where the injured person could not initiate proceedings in time due to the latency of a personal injury, Article 17(2) extends the period to twenty five years.

Can a deployer become a manufacturer under the Directive?

Yes, in one defined situation. Under Article 8(2), any natural or legal person that substantially modifies a product outside the manufacturer's control and thereafter makes it available on the market or puts it into service is considered a manufacturer of that product. Putting into service includes first use in the Union in the course of a commercial activity. The modifier is exempt under Article 11(1)(g) if it proves that the defectiveness is related to a part of the product not affected by the modification.

When is a software-as-a-service AI product placed on the market for a customer who joins after the date?

The text does not say. Placing on the market is defined as the first making available of a product on the Union market, and recital 13 confirms that software supplied as a service is a product, but the Directive does not state whether a continuously supplied service has one placing on the market or a separate one for each customer. The point will be settled by national measures and courts. Providers should record both the original launch date and the date of first supply to each customer.

Sources

  1. Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products and repealing Council Directive 85/374/EEC. Articles 2, 3, 4(5), 4(7) to 4(9), 4(18), 6, 8, 9, 10, 11, 16, 17, 21 and 22, and recitals 3, 13, 39, 40, 46 and 48, read in the Official Journal text served by the Publications Office of the European Union at publications.europa.eu on 18 September 2026. Quotations are verbatim from that text.
  2. Council Directive 85/374/EEC of 25 July 1985 on liability for defective products, Articles 2, 3, 4, 7(b), 9, 10 and 11, read in the text as originally published, served by the Publications Office at publications.europa.eu on 18 September 2026. The consolidated version incorporating later amendment was not read; the provisions cited here are described as they appear in the original text.
  3. Regulation (EU) 2024/1689 (EU AI Act) as amended by Regulation (EU) 2026/1744. The application dates of 2 December 2027 for Annex III and 2 August 2028 for Annex I are as published by the European Commission at digital-strategy.ec.europa.eu.
  4. Regulation (EU) 2024/1689, Article 43(4), read at the European Commission AI Act Service Desk, ai-act-service-desk.ec.europa.eu, on 18 September 2026.
  5. The reading in section 3 that a post-date substantial modification brings a product within the new Directive, the observation on the parallel with the AI Act's treatment of pre-determined changes, and the narrower statement in section 7 about the Article 10(2)(b) presumption are this desk's own analysis and are not attributed to any institution.
  6. No national transposition measure has been read for this article, and nothing in it describes the law of any Member State.
  7. No relationship exists between Future Proof Intelligence and any institution named in this article.