Time to prepare: Europe’s product liability changes and what they mean for Australian manufacturers

Will Atfield, Isabella Stubbs and Geneva Forster
28 Sep 2026
6 minutes

Manufacturers supplying products into Europe are about to face a substantially different product liability regime. The new Product Liability Directive (EU) 2024/2853, which EU Member States must transpose by 9 December 2026, overhauls a framework that has been in place since 1985 for a world in which products increasingly depend on software, connected services and artificial intelligence.

The new Directive applies to products placed on the EU market or put into service after 8 December 2026. It retains the existing principle of strict liability, meaning manufacturers can be held liable for damage caused by defective products without the claimant having to prove negligence, but the new Directive significantly changes how that liability can arise and be established.

The new regime addresses the modern reality that many products continue to change after they are first supplied through software updates, connected services and adaptive functionality. For manufacturers accustomed to assessing product liability risk at the time of supply, this represents a fundamentally different framework.

Liability follows the product

Perhaps the most significant change in the new Directive concerns when product safety is assessed. Under the existing framework, the central question was whether a product was defective at the time it was placed on the market. Under the new regime, that assessment extends beyond initial supply.

Assessing whether a product is defective can now require consideration of matters arising after it first enters the market. Relevant circumstances include a product's ability to learn or acquire new features after deployment, the foreseeable effect of other products used with it, and relevant product safety and cybersecurity requirements.

Central to this shift is the concept of manufacturer's control. A product can remain within a manufacturer's control where the manufacturer performs, authorises or consents to the integration, interconnection or supply of a component, including software updates or upgrades. Where a manufacturer continues to provide software updates, cybersecurity support or connected services, that continuing involvement can have product liability consequences.

The expansion of the product definition reinforces this shift. Software and digital manufacturing files are expressly included as "products" under the new Directive, and a "component" can include software and related digital services integrated into or interconnected with a product. For a connected product, it may therefore be increasingly difficult to separate the physical product from the software and digital functionality on which it depends.

A manufacturer will generally have a defence where the defect did not exist when the product was placed on the market or put into service. However, that defence may not apply where the defect is attributable to software or related services, a failure to provide safety-related software updates or upgrades, or a substantial modification within the manufacturer's control.

This does not make manufacturers responsible indefinitely for every post-sale change. But where a manufacturer retains control over software, updates or connected functionality, product liability risk can extend to how a product operates and changes after it leaves the factory.

Both Australia and Europe face the underlying question of how product liability law should apply where a product continues to change after supply, but they approach it differently. Europe has expressly built the concept of manufacturer's control into its new regime. Australia has not adopted the same model.

The Australian Consumer Law (ACL) does not contain an equivalent concept of manufacturer's control. While computer software is included within the definition of "goods", and the regime has considerable capacity to apply to new technologies, it does not expressly address adaptive functionality, cybersecurity or post-market software updates in the same way as the new Directive, nor does it contain equivalent evidentiary presumptions for technically complex products. The focus under the ACL has traditionally been on the product's condition at the time of supply.

However, the Federal Government's review of AI and the ACL concluded that the ACL is generally capable of applying to AI-enabled goods and services, while identifying areas of uncertainty requiring further consideration. These included the classification of AI offerings as goods or services, who may qualify as a manufacturer in complex AI supply chains, and the significance of post-supply control through software updates.

Proving defect and causation: a lower bar for claimants?

Claimants must still establish defectiveness, damage and causation under the new Directive. However, the new regime introduces disclosure obligations and rebuttable presumptions that can alter how those matters are proved.

The disclosure provisions are particularly significant in a European context, where broad pre-trial discovery of the kind familiar in Australian litigation is generally not available. In that context, the provisions work to address the information imbalance that can arise where evidence relevant to establishing whether a product is defective is held by the manufacturer. For businesses operating across multiple jurisdictions, disclosure of material in European proceedings may also have implications for claims to privilege or confidentiality over the same material in proceedings elsewhere.

The new Directive goes further in technically or scientifically complex cases. Where a claimant faces excessive difficulties in proving defectiveness, causation or both because of technical or scientific complexity, the court must apply the relevant presumption if the claimant establishes the likelihood required by the new Directive. This is particularly relevant to products whose operation is difficult to interrogate. An AI-enabled medical device, for example, may involve complex models, data and software that make conventional proof of precisely how an adverse output was generated difficult.

Key changes under the new Directive include:

  1. Disclosure: Defendants may be required to disclose relevant evidence where a claimant has presented sufficient facts and evidence to support the plausibility of the claim and disclosure is necessary and proportionate. Protections for confidential information and trade secrets apply.

  2. Defectiveness: A product is presumed defective in specified circumstances, including where a defendant fails to comply with a disclosure obligation, the product does not comply with relevant mandatory safety requirements, or damage was caused by an obvious malfunction during reasonably foreseeable use or under ordinary circumstances.

  3. Causation: Where the defective nature of the product has been established and the damage caused is of a kind typically consistent with the defect in question, the causal link between the defect and the damage is presumed.

Recoverable damage under the new Directive also expressly includes medically recognised damage to psychological health and the destruction or corruption of data not used for professional purposes.

Existing defences remain, but the context is changing

The new Directive retains the development risk defence. A manufacturer can generally avoid liability by establishing that the objective state of scientific and technical knowledge when the product was placed on the market, put into service or during the period in which it was within the manufacturer's control was insufficient to enable the defect to be discovered. However, Member States have the option of excluding this defence when transposing the new Directive, meaning that in some EU jurisdictions it may not be available.

For software and AI-enabled products, this may extend the period over which developments in scientific and technical knowledge are relevant. A manufacturer that continues to update or modify a product may therefore need to consider developments after initial supply.

The new Directive also retains a ten-year expiry period, but deals expressly with substantial modifications. Where a product is substantially modified within the manufacturer's control and then made available on the market or put into service, the applicable period runs from that later point. A 25-year period applies in specified personal injury cases where the injured person has been unable to initiate proceedings within the ordinary period because of the latency of the injury.

For products with long operating lives or significant post-sale modifications, these provisions can extend the period during which claims may arise.

What should Australian manufacturers do now?

Manufacturing outside Europe does not place a product beyond the new Directive. The regime establishes a chain of potentially liable economic operators. Depending on how a product reaches the European market, that can include an importer, authorised representative or, in specified circumstances, fulfilment service provider. Distributors and certain online platforms can also face exposure where the relevant economic operator cannot be identified. The manufacturer itself may remain liable notwithstanding that it is established outside the EU. For Australian manufacturers, the structure through which products reach Europe is therefore also a product liability consideration.

With the transposition deadline of 9 December 2026 approaching, and the new Directive applying to products placed on the market or put into service after 8 December 2026, the time for preparation is now. Businesses supplying products into Europe should consider five areas:

  1. Review the European supply chain: Identify products that will be placed on the EU market or put into service after 8 December 2026 and the key economic operators involved.

  2. Review software and connected functionality: Product safety reviews should consider software, cybersecurity, updates and related services alongside the physical product, including which aspects remain within the manufacturer's control after supply.

  3. Assess post-market responsibilities: Review processes for identifying and responding to safety issues after sale, particularly where products receive software or security updates or rely on connected services.

  4. Revisit contracts and insurance: Review agreements with component suppliers, software providers, importers and distributors for liability allocation, indemnities, insurance and access to technical information. While liability under the new Directive cannot be limited or excluded by contract in relation to an injured person, contractual allocation of risk between businesses remains an important consideration.

  5. Strengthen product-lifecycle records: Relevant material may include design and risk assessments, testing records, software change logs, cybersecurity assessments, safety-update decisions and post-market monitoring. For AI-enabled products, testing and validation records may also be important.

For manufacturers operating across both markets, the time of supply may no longer tell the whole story. Where a business retains control over software, updates or connected functionality, managing global product liability risk increasingly requires attention not only to how a product leaves the factory, but to how it operates and evolves while that control continues.

Be the first to know

Legal updates and articles on the topics that matter to you, sent as they happen.

Subscribe

Get in touch

Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.