LinkedInInstagramXTikTok

Software becomes a product under the new liability rules from 9 December 2026

Why the new product liability rules affect more businesses than many think

On 13 August 2026 the Swedish government referred a bill for a new Product Liability Act to the Council on Legislation, taking forward the proposals in SOU 2025:103. The new act is proposed to enter into force on 9 December 2026, the same day the transposition deadline in Directive (EU) 2024/2853 falls due, and the Product Liability Act (1992:18) will then cease to apply.

The common misconception is that product liability is a matter for manufacturers of physical goods. That has been broadly true in Sweden since 1992. It stops being true in December. Under the new regime software counts as a product in its own right, which means a company that has never manufactured anything can be strictly liable for what its code does.

What actually changes?

The framework itself is familiar. Liability remains strict, so an injured person need not prove negligence, only that the product was defective, that damage occurred and that the two are connected. What changes is almost everything around that core: what counts as a product, who can be sued, what damage is compensable and how hard it is to prove a case.

Which products are covered?

Article 4 of Directive (EU) 2024/2853 defines a product to include software, whether embedded in a physical item or supplied on its own, together with digital manufacturing files and electricity. AI systems fall within this because they are software. A related digital service, such as the cloud back end a connected device depends on, is treated as a component of the product rather than as a product in itself. Free and open source software developed or supplied outside the course of a commercial activity is excluded, but incorporating such software into a commercial offering does not carry that exclusion across.

A product can also become defective after it leaves the factory. A missing or inadequate security update, or an update that introduces a fault, can render a product defective even years after sale where the matter lay within the manufacturer’s control. Anyone who substantially modifies a product already on the market outside the manufacturer’s control, and then makes it available again, is treated as its manufacturer for that modification.

Who can be held liable?

The circle of liable operators is considerably wider than under the 1992 act. Alongside the manufacturer and the maker of a defective component, it reaches importers, an authorised representative established in the Union, and fulfilment service providers where no manufacturer, importer or representative in the Union can be identified. A distributor who fails to identify the relevant operator within one month of a request becomes liable itself, and an online platform can be liable where it presents a product so that an average consumer believes the platform supplies it. Liability is joint and several.

What damage is compensable?

Personal injury now expressly includes medically recognised harm to psychological health. On property, the test has widened. The 1992 act covers property of a kind ordinarily intended for private use, whereas the new regime covers any property except the defective product itself and property used exclusively for professional purposes, which deliberately brings mixed use items such as a laptop or a car within reach. New in the digital chapter is compensation for destruction or corruption of data not used for professional purposes. Pure economic loss, privacy infringements and discrimination remain outside the regime and must be pursued on other grounds.

Two thresholds disappear. The directive carries over no equivalent of the EUR 500 floor in the 1985 regime, and the Swedish proposal removes the deduction of 3,500 kronor that section 9 of the 1992 act applies today. Small claims that were not worth bringing become worth bringing, particularly as collective redress under Directive (EU) 2020/1828 continues to develop.

How much harder is it to defend a claim?

This is where the practical shift is sharpest. A Swedish court will be able to order a defendant to disclose relevant evidence in its possession where the claimant has presented facts and evidence sufficient to support the plausibility of the claim, subject to safeguards for trade secrets. Swedish civil procedure has offered nothing of this breadth in product cases before.

The directive also introduces rebuttable presumptions. Defectiveness is presumed where the defendant fails to comply with a disclosure order, where the product breaches mandatory safety requirements intended to protect against the risk that materialised, or where the damage was caused by an obvious malfunction during reasonably foreseeable use. Both defectiveness and causation may be presumed where the claimant faces excessive difficulties in proving them because of technical or scientific complexity, provided the claim is at least probable. For an AI system whose reasoning cannot readily be reconstructed, that condition is often met.

Finally, the long stop moves. Claims generally expire ten years after the product is placed on the market, but where a personal injury is latent the period runs to twenty five years.

A practical example

A Swedish company sells a smart heating controller to consumers, consisting of a device and an app with a machine learning model that predicts demand. Eighteen months after launch a model update misreads sensor data in a small number of installations and causes water damage in several homes, along with the loss of household photographs stored in the associated cloud account.

Under the 1992 act the supplier would have argued, with reasonable prospects, that no product had caused the damage and that the data loss was not compensable at all. From 9 December 2026 the app is a product, the update is within the manufacturer’s control, the water damage to private property is compensable without deduction, and the destroyed personal files are a separate head of loss. If nobody can explain why the model behaved as it did, the complexity presumption is likely to help the claimants rather than the company.

Common mistakes

The most frequent error is treating this as an insurance question to be looked at in the autumn. Product liability cover written on 1992 assumptions may not respond to data loss or to psychological harm, and renewal conversations take time.

A second is assuming the old rules govern existing products. They do for products placed on the market before 9 December 2026, but a substantial modification or an update after that date can bring a legacy product within the new regime.

A third is waiting for a separate AI liability instrument. The proposed AI Liability Directive was withdrawn by the Commission in February 2025, which makes Directive (EU) 2024/2853 the operative framework for damage caused by AI.

A fourth is documenting to satisfy an auditor rather than a court. Under a disclosure order, thin or scattered records are not neutral, because failure to comply triggers a presumption of defectiveness.

Recommended actions

Start by identifying which of your offerings will be a product from December, including standalone software, embedded code, AI components and digital services built into a physical item, and note in each case whether you are manufacturer, importer or distributor. Map the supply chain behind each one so that a one month identification request can actually be answered. Review your update and security policies, because a decision not to patch is now a liability decision rather than a commercial one. Bring technical documentation, risk assessments, testing records and model documentation into a state where they could be produced to a court at short notice, held centrally rather than in individual engineers’ folders. Then review contracts with suppliers, integrators and platform partners for allocation of responsibility, indemnities and recourse, and take the whole picture to your insurance broker well before December.

Frequently asked questions

Does this apply to business-to-business software?

The regime protects natural persons, and property used exclusively for professional purposes is excluded. Software sold to businesses is not outside the rules, because a defect in it can injure an individual or damage mixed use property, but a customer company’s commercial losses fall outside.

Can we exclude this liability in our terms?

No. Liability under the directive cannot be limited or excluded in relation to the injured person by contract or by national law. Contractual allocation between commercial parties remains possible and matters for recourse, but it does not affect the claimant’s position.

Are we liable if the defect was undiscoverable?

The development risk defence survives, so an operator can escape liability by proving that scientific and technical knowledge did not allow the defect to be discovered. It has narrowed, because the state of the art is now assessed across the whole period the product remained within the manufacturer’s control, not only at launch.

Conclusion

Directive (EU) 2024/2853 moves software from the edge of product liability to its centre, and 9 December 2026 is the day that happens in Sweden as well as across the internal market. Strict liability, disclosure, presumptions tailored to opaque technology and a twenty five year tail add up to a materially different risk profile for anyone who writes or ships code. At Lawgent, we help companies work out which of their products fall under the new act, review update and documentation practices against the disclosure and presumption rules, and reallocate risk through contracts and insurance. Get in touch and we will go through what the new product liability regime means for your business.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop