The EU Product Liability Directive 2024/2853 fundamentally redefines what counts as a “product” under European strict-liability law, and software is now squarely within scope. Adopted on 23 October 2024 and published in the Official Journal on 18 November 2024, Directive (EU) 2024/2853 repeals the decades-old Council Directive 85/374/EEC and gives Member States until 9 December 2026 to transpose its provisions into national law. For Romanian technology companies, from SaaS providers and embedded-software developers to AI start-ups, this is not a distant regulatory exercise: it is an imminent operational reality that demands action now. At Olawru, we are already advising clients on how to restructure compliance programmes, renegotiate supply-chain contracts and prepare litigation-readiness frameworks before the transposition deadline arrives.
In my view, many Romanian tech businesses still underestimate how radically this Directive changes their exposure. The inclusion of software, AI systems and digital manufacturing files as products subject to strict liability, combined with new disclosure orders, evidentiary presumptions and an expanded catalogue of recoverable damages, creates a legal environment that no technology company operating in or exporting to the EU can afford to ignore.
Directive (EU) 2024/2853 was adopted by the European Parliament and the Council on 23 October 2024 under the ordinary legislative procedure (procedure reference 2022/0302(COD)). Its core objective is to modernise the EU’s strict-liability framework so that it adequately addresses risks created by digital products, artificial intelligence and circular-economy business models. The European Commission described the reform as bringing “product liability rules in line with the digital age and circular economy,” recognising that the previous framework, designed in 1985 for tangible goods, was structurally unfit to address harm caused by intangible software and autonomous systems.
The Directive explicitly classifies software as a product. This includes both integrated software (embedded in physical devices) and stand-alone software (distributed independently), as well as AI systems and digital manufacturing files such as 3D-printing blueprints. The scope covers both embodied software, code running on a physical product, and non-embodied software delivered purely as a digital service or download. Critically, free and open-source software developed or supplied outside the course of a commercial activity is excluded, but any commercially distributed open-source component falls within scope. For Romanian SaaS companies, this means that cloud-delivered applications, mobile apps and AI-driven analytics platforms are now treated as software products under EU strict-liability rules.
The legislative timeline is clear. The Directive was adopted on 23 October 2024, published in the Official Journal on 18 November 2024, and entered into force twenty days after publication. Member States have a twenty-four-month transposition window, which means national implementing legislation must be in place by 9 December 2026. Romania has not yet published its transposition act in the Monitorul Oficial as of July 2026, but the deadline is binding regardless of national legislative progress. Businesses should not wait for the Romanian implementing statute, the substantive obligations are clear from the Directive text, and any delay in preparation will compress an already tight compliance window.
The Directive applies to products placed on the market or put into service after the transposition date, meaning that product liability software Romania businesses develop or distribute from December 2026 onward must comply from day one.
Under the old Directive 85/374/EEC, defectiveness was assessed by reference to the safety a person is entitled to expect, considering presentation, reasonably foreseeable use and the time the product was put into circulation. That framework assumed a static, tangible product. Software, by contrast, evolves continuously, through updates, patches, configuration changes and, in the case of AI, autonomous learning. The new Directive retains the “entitled to expect” test but adapts it to account for the dynamic nature of digital products.
The Directive makes clear that a software product can be defective if it fails to deliver the level of cybersecurity that the public is entitled to expect, or if the manufacturer fails to provide necessary security updates after deployment. In practice, this creates several concrete categories of software defect:
A key challenge for Romanian courts, and for courts across the EU, will be determining the relevant moment at which defectiveness is assessed for a product that continuously evolves. The Directive addresses this by requiring courts to consider whether the manufacturer retained the ability to control the product after placing it on the market, including through software updates, AI model adjustments or ongoing data feeds. Where a manufacturer maintains such control, defectiveness can be assessed at the time the damage occurred, not only at the time of initial market placement.
This is a significant departure from the 1985 framework and has direct implications for lifecycle management: Romanian tech companies must document every update, patch and model retraining event to defend against future defectiveness claims.
The Directive imposes strict liability, meaning the injured party does not need to prove that the manufacturer was negligent or at fault. It is sufficient to demonstrate that the product was defective, that damage occurred, and that there is a causal link between the defect and the damage. For strict liability software EU businesses, this is a fundamental shift: product-liability exposure no longer depends on whether the company exercised reasonable care. A defective product triggers liability regardless of intent or diligence.
The Directive establishes a clear liability hierarchy to ensure that an injured party can always pursue an EU-based defendant. The primary liable actor is the manufacturer, the entity that develops, produces or presents a product under its own name or trademark. When the manufacturer is established outside the EU, liability extends in sequence to:
This hierarchy is particularly significant for Romanian companies that distribute, rebrand or integrate software components from non-EU developers. If a Romanian company imports a software module from a US or Asian developer and incorporates it into its own product, it may bear strict liability as the importer or, if it markets the combined product under its own brand, as the manufacturer.
SaaS vendors and cloud providers need to map their supply chains immediately. Where third-party libraries, APIs or AI models are incorporated, contractual liability allocation through supply-chain indemnities becomes essential, though, as I discuss below, such clauses cannot eliminate the vendor’s statutory liability toward the injured party. Online marketplaces that facilitate the distribution of software products may also face exposure under the fulfilment-service-provider route if they handle storage, packaging or dispatch of physical media or connected devices.
The Directive significantly broadens the categories of recoverable damage compared to the 1985 framework. Compensation now explicitly covers:
The inclusion of damages for psychological harm and non-professional data destruction is directly relevant to Romanian technology companies. A defective consumer app that causes data loss, a malfunctioning AI chatbot that delivers harmful medical advice, or a cybersecurity breach that exposes personal data could each trigger claims for these expanded damage categories.
From what I am seeing in practice, quantifying damages for data destruction and AI-driven harm presents genuine challenges. Unlike physical property damage, lost digital data does not have an easily ascertainable market value. Courts will need to develop methodologies for valuing irreplaceable personal photographs, corrupted financial records or destroyed creative works. For AI-related harm, such as a flawed algorithmic decision that denies a consumer access to housing or insurance, the causal chain may involve multiple intermediate steps, making both causation and quantum difficult to establish. Insurers and legal teams should begin developing valuation frameworks now, rather than waiting for the first wave of litigation to define the parameters.
One of the most practically significant innovations in the Directive is the introduction of disclosure orders and rebuttable presumptions that shift the evidentiary balance in favour of claimants. Under the new rules, a court may order the defendant to disclose relevant evidence in its control, including technical documentation, source code, update logs, model-training data and cybersecurity incident records. If a defendant refuses to comply with a disclosure order, or fails to comply adequately, the court may presume that the product was defective. Similarly, where a claimant demonstrates that a product does not comply with mandatory safety requirements, or that the damage was caused by an obvious malfunction, defectiveness may be presumed.
These provisions on disclosure orders product liability EU-wide will fundamentally alter the dynamics of product-liability litigation.
The Directive acknowledges that disclosure orders must be proportionate and may engage legitimate interests in protecting trade secrets and confidential business information. Courts are required to apply proportionality tests and may impose confidentiality orders, restrict access to disclosed materials, or use in-camera procedures. However, the existence of trade secrets does not constitute an absolute bar to disclosure, Romanian defendants should expect courts to balance transparency against commercial confidentiality on a case-by-case basis.
In my experience advising technology clients, the single most valuable step a company can take now is implementing a systematic document-preservation policy. The following records should be created, maintained and securely stored:
A critical point that many businesses overlook: the Directive’s strict-liability regime is mandatory and cannot be excluded or limited by contract. Contractual liability caps, limitation-of-liability clauses and disclaimers that purport to waive product-liability claims against the manufacturer are ineffective insofar as they conflict with the rights granted to injured parties under the Directive. This does not mean that contractual risk allocation is irrelevant, but it means that such allocation operates only between commercial parties in the supply chain, not as a shield against end-user claims.
While contractual clauses cannot eliminate statutory liability, they remain essential tools for allocating risk within the supply chain. I recommend that Romanian software businesses incorporate the following provisions into their commercial agreements:
Based on my work with Romanian technology companies, I recommend the following prioritised action items, ordered by implementation urgency:
The following table summarises the critical milestones for the EU Product Liability Directive 2024/2853. Romanian businesses should use this timeline to benchmark their own compliance preparations against the binding transposition deadline.
| Date | Event | Relevance |
|---|---|---|
| 23 October 2024 | Directive (EU) 2024/2853 adopted by the European Parliament and the Council. | Primary legal text that expands product scope to software and AI, source of all substantive obligations. |
| 18 November 2024 | Directive published in the Official Journal of the EU. | Publication triggers calculation of the entry-into-force and transposition deadlines. |
| 8 December 2024 | Directive enters into force (20 days after publication). | Formal legal effect at EU level, transposition clock begins running for Member States. |
| 9 December 2026 | Deadline for Member States to transpose the Directive into national law. | Binding deadline, Romanian businesses must be fully compliant by this date regardless of national legislative progress. |
The EU Product Liability Directive 2024/2853 represents the most significant expansion of European product-liability law in four decades, and its treatment of software as a product subject to strict liability will reshape the legal landscape for Romanian technology businesses. The 9 December 2026 transposition deadline is not a distant prospect, it is an operational imperative. In my professional view, the companies that act now to audit their product portfolios, restructure their supply-chain contracts, implement document-retention protocols and review their insurance coverage will be materially better positioned than those that wait for the Romanian implementing act to appear in the Monitorul Oficial.
The Directive’s text is clear, its obligations are specific, and its enforcement mechanisms, from disclosure orders to presumptions of defectiveness, are designed to give claimants real teeth. Preparation is not optional; it is the cost of doing business in the EU’s digital economy.
Last reviewed: 27 July 2026. This article will be updated when Romania publishes its transposition act.
For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.
posted 20 minutes ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 8 hours ago
posted 12 hours ago
posted 13 hours ago
posted 13 hours ago
posted 14 hours ago
posted 14 hours ago
posted 14 hours ago
posted 14 hours ago
No results available
Find the right Advisory Expert for your business
Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message