AI Liability Directive
A bellwether of the EU's simplification turn — and a live gap: the revised Product Liability Directive covers software and AI as 'products', so AI harm claims will be channeled there from December 2026, with discovery and burden-shift tools claimants didn't previously have.
What it is
The Commission withdrew its proposed AI Liability Directive in February 2025, citing no foreseeable agreement. Civil liability for AI harms now runs through the revised Product Liability Directive (in force Dec 2024, applying from Dec 2026) and national tort law.
Who is affected
Manufacturers and providers placing AI-enabled products on the EU market
Key obligations
- Watch: revised Product Liability Directive (EU) 2024/2853 applies to products placed on the market from 9 Dec 2026, explicitly covering AI systems
Compliance dates
EU revised Product Liability Directive applies to AI products
Directive (EU) 2024/2853 applies to products placed on the market from this date — explicitly covering software and AI systems, with disclosure-of-evidence tools and eased burden of proof for claimants.
Recent signals
Commission designates ChatGPT a very large online search engine under the DSA
ChatGPT becomes the first generative AI service brought inside the Digital Services Act's strictest tier, alongside Reddit and Roblox as very large online platforms. Systemic-risk assessment, mitigation, audit and data-access duties follow four months after notification.
EU AI Act transparency obligations become applicable
Chatbot disclosure, machine-readable AI-content marking and deepfake labeling duties now apply EU-wide; the GPAI Code of Practice enforcement grace period ends the same day.
Digital Omnibus on AI enters into force, delaying high-risk deadlines
Regulation (EU) 2026/1744 pushes high-risk AI Act obligations to Dec 2027 (Annex III) and Aug 2028 (Annex I) and simplifies documentation duties — the EU's first formal AI Act correction.
EU AI Act GPAI model obligations become applicable
General-purpose model providers must maintain technical documentation, publish training-content summaries and comply with EU copyright law; systemic-risk models face safety duties.
Related instruments
- EUEU AI ActThe world's first comprehensive, risk-based AI law. It bans a set of unacceptable practices (social scoring, manipulative AI, most…
- EUEU Digital OmnibusThe first formal simplification of the AI Act. Adopted July 2026, it delays high-risk obligations to December 2027 (standalone Ann…
- EUGPAI Code of PracticeA voluntary code operationalizing the AI Act's GPAI chapter across transparency, copyright and safety/security. Major model provid…
- EUGDPR × AIThe EU's data-protection regime remains a primary AI constraint: legal bases for training data, automated-decision rights (Art. 22…
- ITItaly AI LawItaly became the first EU member state with a national AI law, layering sector rules (healthcare, work, justice, public administra…
Related reading
- Issue 17Denmark met the deadline. Sweden is late. Norway is outside the regime.A model classified Critical for cyber capability shipped this month and no Nordic AI authority has issued operational guidance in response. What policymakers, businesses and citizens should do — and what the region is getting right.
- Issue 08The clause is the policyThe world's largest buyer of AI cannot show that its own contracts carry the provisions its own policy requires. That is not an audit failure. It is a diagnosis.
- Issue 05The sovereign-AI trilemmaEvery state pursuing AI sovereignty in 2026 is making the same trade-off — usually without admitting it.