Law & Contract Management

Product Liability for Software and Digital Products Under the Revised EU Directive

Understand how Directive (EU) 2024/2853 extends product liability to software, AI systems and firmware updates, and adapt contracts and evidence practice accordingly.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Directive (EU) 2024/2853 brings standalone software, firmware, AI systems and digital manufacturing files inside the scope of strict product liability for the first time, and it changes how defectiveness, causation and evidence work for every claim brought after transposition. A missing security patch, a flawed machine-learning model or a defective over-the-air update can now found a claim in a way the 1985 directive never anticipated. This course walks legal, engineering and quality teams through the revised text clause by clause: the extended definition of a product, the new disclosure of evidence procedure that shifts information asymmetry back towards claimants, the rebuttable presumption of defectiveness in technically complex cases, and the recoverable damage categories that now include the loss or corruption of data. Sessions translate each change into contract and process work: warranty and liability clauses in software supply agreements, update and patching obligations that reduce defect exposure, incident evidence preservation protocols, and coordination with CE marking and cybersecurity conformity assessments. Participants finish able to assess a digital product's exposure under the revised regime and to redraft supply terms before national transposition deadlines close.

Expected Learning Outcomes

01

Determine whether standalone software, an AI system or a digital file falls within the revised product definition.

02

Apply the defectiveness test to a software product, accounting for cybersecurity vulnerabilities as a defect category.

03

Assess how the reversed and presumed burden of proof provisions change litigation strategy in technically complex claims.

04

Draft disclosure of evidence responses that meet the directive's new pre-trial information obligations.

05

Identify recoverable damage categories, including data loss and corruption, under the revised directive.

06

Allocate liability across manufacturers, importers, authorised representatives and fulfilment service providers.

07

Redraft software supply and update agreements to manage post-market monitoring and patching obligations.

Who Should Attend

01

Product liability and technology dispute lawyers advising software and hardware manufacturers.

02

In-house counsel for connected device, AI and enterprise software businesses.

03

Quality, safety and regulatory affairs managers responsible for post-market surveillance.

04

Insurance underwriters and claims handlers pricing digital product liability risk.

05

Contract managers drafting software supply, licensing and maintenance agreements.

06

Compliance officers coordinating product safety, cybersecurity and liability regimes.

Course Modules

Select any module to see its sessions and points.

01

Scope of the Revised Directive and the Extended Product Definition

2 sessions · 8 points

Session 1Software, AI Systems and Digital Files as Products

  • Apply the revised directive's inclusion of standalone software and digital manufacturing files within the product definition.
  • Classify an AI system component as a product or as a service to determine which liability regime applies.
  • Assess when a free or open source software component falls inside the directive's commercial activity threshold.
  • Distinguish a product update or upgrade that creates fresh liability exposure from routine maintenance activity.

Session 2Economic Operators and Allocation of Liability Along the Supply Chain

  • Map liability across manufacturers, importers, authorised representatives and fulfilment service providers under the directive.
  • Assess when a substantial modification to a product transfers manufacturer-level liability to the modifying party.
  • Draft supply chain indemnity clauses that reflect each party's exposure under the revised liability allocation.
  • Identify non-EU manufacturer scenarios requiring an EU-based responsible economic operator to be named.
02

Defectiveness, Causation and the Cybersecurity Dimension

2 sessions · 8 points

Session 1Applying the Defectiveness Test to Software and Connected Products

  • Apply the safety expectations test to software features, updates and AI-driven decision outputs.
  • Treat an unpatched cybersecurity vulnerability as a defect where it falls below reasonably expected safety standards.
  • Assess how self-learning system behaviour after deployment affects the defectiveness assessment at the time of claim.
  • Document post-market surveillance evidence that supports or rebuts a defectiveness allegation.

Session 2Reversed Burden of Proof and Disclosure of Evidence

  • Identify the conditions triggering the rebuttable presumption of defectiveness in technically complex cases.
  • Prepare a disclosure of evidence response that meets the directive's proportionality and confidentiality safeguards.
  • Build an internal evidence preservation protocol for incident logs, model training records and update histories.
  • Advise on trade secret protection strategies when disclosure obligations require releasing sensitive technical data.
03

Damages, Limitation Periods and Claims Handling

2 sessions · 8 points

Session 1Recoverable Damage Categories Including Data Loss

  • Assess claims for data loss or corruption now recoverable as damage under the revised directive.
  • Distinguish recoverable personal injury and property damage from excluded pure economic loss categories.
  • Calculate quantum for a data loss claim, including recovery, remediation and reconstitution costs.
  • Coordinate a software product liability claim with parallel GDPR breach notification and compensation exposure.

Session 2Limitation Periods, Long-Stop Rules and Cross-Border Claims Handling

  • Apply the standard and extended long-stop limitation periods introduced for latent and slow-developing harm.
  • Coordinate a multi-jurisdiction claim where a digital product is deployed across several member states simultaneously.
  • Draft insurance notification protocols triggered by the revised directive's expanded liability exposure.
  • Prepare a litigation readiness file combining technical evidence, contract terms and regulatory correspondence.
04

Contract Redrafting and Compliance Coordination

2 sessions · 8 points

Session 1Redrafting Software Supply and Update Agreements

  • Draft liability and indemnity clauses in software supply contracts calibrated to the revised strict liability regime.
  • Set patching and update service level commitments that reduce exposure to unpatched vulnerability defect claims.
  • Negotiate limitation of liability clauses that remain enforceable against mandatory product liability provisions.
  • Draft warranty terms distinguishing manufacturer liability from third-party component and integration liability.

Session 2Coordinating Product Liability with Cybersecurity and CE Marking Regimes

  • Align product liability compliance with Cyber Resilience Act conformity assessment and vulnerability handling duties.
  • Coordinate CE marking documentation with product liability defect evidence to avoid contradictory technical files.
  • Build a cross-functional compliance calendar tracking national transposition deadlines across target markets.
  • Train product and engineering teams to flag design decisions that create defect exposure before release.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course