skipToContent
ArkeonTech Logo
Back to all posts

Who Is Liable When AI Makes a Mistake? New Product Liability from December 2026

September 19, 2026
Label: content created with AI assistance This article was created with AI assistance

The text and images in this article were generated with the help of AI systems. Labelled in accordance with Art. 50(4) of the EU AI Act. Responsible for publication: ArkeonTech.

AI Liability Product Liability AI Adoption SMB Compliance
Legal document with a paragraph seal, glowing agent node and a three-tier responsibility chain with a highlighted name-badge card

The phone assistant promises a customer a delivery date that production cannot keep. The chatbot quotes a price that does not exist on the price list. The AI-assisted vision system lets defective parts through. In all three cases the same question hangs in the room: who pays?

The short answer today: usually you, not the provider. And the long answer changes on 9 December 2026, when the new European Product Liability Directive must be transposed into national law. For the first time it expressly counts software and AI systems as products - with strict manufacturer liability. What it actually means for a mid-sized company, however, is not the headline "manufacturers are now liable", but two points most summaries skip: operational damage remains uncovered, and anyone who uses AI under their own name or modifies it can become the manufacturer themselves.

Key takeaway: A mid-sized company using AI is liable to its own customers for the system's mistakes - the model providers' terms largely exclude liability for outputs and consequential damage. From 9 December 2026 the new Product Liability Directive (EU) 2024/2853 applies: software and AI systems become products whose manufacturers are strictly liable. But the protection covers personal injury and private property, not the damaged machine in your own plant. The real novelty sits elsewhere: anyone who offers a product under their own name or brand, has it made or substantially modifies it counts as the manufacturer - and is strictly liable with no cap.

Who is liable today when AI makes a mistake?

Toward your customer, you are. The customer has a contract with you, not with the model provider; whether an answer came from a human or an agent changes nothing in the contract. Toward the AI provider, only what the contract gives applies - and the terms of the major providers regularly exclude liability for the correctness of outputs and for consequential damage, with low liability caps.

On top sits the layer that has nothing to do with the model: if the error harms third parties - an AI agent autonomously placing a wrong order, a statement being spread - the company running the process remains liable in tort. And internally, managing-director liability under section 43 of the German GmbH Act threatens when the deployment lacked a documented organisation behind it. What exactly a prudent manager must be able to evidence is set out in the article on AI adoption for managing directors.

What does the new Product Liability Directive change on 9 December 2026?

Directive (EU) 2024/2853 replaces the 1985 Product Liability Directive and must be transposed into national law by 9 December 2026. It applies to products placed on the market or put into service after that date (Article 2). The German implementing draft exists as Bundestag printed paper 21/4297 but has not been passed - statements about the final statute remain at draft stage.

Four changes matter for mid-sized businesses:

  1. Software and AI systems are expressly products (Article 4). The manufacturer is strictly liable - it is enough that the product was defective, regardless of fault.
  2. Evidence relief for claimants: the manufacturer must disclose evidence on request (Article 9), defectiveness is presumed in defined circumstances, and where technical or scientific complexity makes proof excessively difficult, a likelihood standard suffices (Article 10). With an AI system whose internals nobody fully documents, that is a tangible shift.
  3. Old limits fall: the 500-euro deductible for property damage and the 85-million-euro cap on personal injury are gone.
  4. Free software stays outside - but only where it is not provided commercially (Article 4). Anyone embedding open source into a product does not buy the exemption along with it.

Why does the new liability barely protect your business?

Because the directive protects consumers, not companies. Covered are death, personal injury and damage to goods used privately; for data, cover applies only to the destruction or corruption of data not used professionally. A faulty AI module that damages your production line or corrupts your inventory system falls outside its scope - while the same module injuring an employee is covered.

The honest takeaway for procurement: for operational damage, the contract with the provider remains the only lever. Liability clauses, usage limits and recourse rules belong in the contract, not in the hope that a directive will settle it. That holds doubly because the model providers' terms exclude exactly these damages.

When do you become the manufacturer yourself?

That is the directive's actual message, and it affects more mid-sized companies than it appears. Under Article 4 number 10, a manufacturer is anyone who develops or produces a product, who has it designed or made - and anyone who puts their name, trademark or other distinguishing mark on it. Under Article 8 paragraph 2, anyone who substantially modifies a product outside the original manufacturer's control and re-supplies or commissions it also counts as the manufacturer.

Three constellations from the Mittelstand hit this directly:

  • White label and own branding: you have an AI agent built and offer it to your customers under your own name - as part of your software or as "company X's AI service". Whenever your name is on it, you are liable like the producer, even if a third party supplied the technology.
  • AI as a component: you build an AI module into your own product - vision inspection inside the machine, control logic inside the device. For defects, you as product manufacturer and potentially the component manufacturer are liable side by side (Article 8).
  • Substantial modification: anyone who adapts an existing model so far that the change lies outside the original manufacturer's control legally produces a new product - including manufacturer liability.

The directive also matters from the other direction: where the manufacturer sits outside the Union, its authorised representative, the importer and potentially the supplier or fulfilment provider are liable too (Article 8 paragraph 1). For AI software from the US there will be, from December 2026, a liable addressee inside the EU for the first time.

Who carries what in a real claim?

ScenarioWho is liable to the injured partyYour recourse
Your chatbot quotes a customer wrong pricesYou - under the contract with the customerContractual only, and provider terms exclude a lot
Your AI agent triggers a wrong orderYou - toward the supplier and internallyContractual only
An AI-controlled machine injures an employeeThe manufacturer - product liability, personal injuryAgainst the manufacturer, stricter for new products from 9 Dec 2026
Your product with an embedded AI module harms a private customerYou as manufacturer, beside you possibly the component makerContractual recourse against the model provider
A self-adapted open-weight model causes damageYou yourself - substantial modification or own productionNone

Two points sit beside the table that no table carries: insurance and documentation. Whether business or cyber liability covers AI-related damage is decided solely by the policy wording - it belongs on the checklist before a claim, not after. And whoever records the system selection, its usage limits and the approvals in writing stands better in every liability question; the same documentation is what the company AI policy requires anyway.

What became of the planned AI Liability Directive?

It never arrived. In 2022 the Commission proposed a dedicated regime for AI damage - with presumption rules and relief for claimants beyond product liability. In October 2025 it formally withdrew the proposal, arguing that the core concerns - software and AI defects - are now covered by the reformed product liability.

For users the sober conclusion is: there is no dedicated AI liability regime and none is coming. What remains is the new product liability for private-side damage on one hand and ordinary contract and tort law on the other. The middle ground - the operational damage that matters in practice - is still filled by the contract. Anyone tracking AI Act duties should note that fines and roles are a second topic, separate from liability; the assignment of provider and operator roles is covered in the EU AI Act overview.

What should you check before 9 December?

Five points, all feasible without a lawyer - and all worth putting in writing:

  1. The liability clauses of running AI contracts: what does the provider exclude, what does it assume, and is there a cap? Whoever sees a cap knows the real protection.
  2. The name and brand question: does your name or brand sit on a product with an AI component - including one sold as "powered by" a third party? From December 2026 you count as the manufacturer.
  3. The list of substantial modifications: which third-party systems have you adapted, and does the change still sit under the original provider's control? Without a written record you cannot draw that line in a dispute.
  4. The placing on the market of your own products: the new liability only bites for products supplied after the deadline. Anyone shipping an AI feature inside an existing product should know from when they count as the manufacturer of its new state.
  5. The insurance policies: ask explicitly whether software- and AI-related damage is covered. A written confirmation beats a verbal assurance.

Does this also apply in Austria and Switzerland?

In Austria, yes: as an EU member it must transpose by 9 December 2026 too - manufacturer definition, strict liability and evidence relief are the same. Switzerland is not an EU member and has its own product liability act, which does not automatically adopt the directive. Two cases still matter: Swiss providers shipping into the EU are caught via importer liability; and a German company selling into Switzerland keeps clarifying liability there by contract.

Frequently asked questions

Can I hold OpenAI or Anthropic directly responsible when their model outputs an error? Hardly via contract: the terms of the major model providers largely exclude liability for the correctness of outputs and for consequential damage. The new product liability regime from December 2026 helps injured private individuals, not your business - for operational damage the contract with your provider remains the only lever.

Am I personally liable as a managing director for AI errors? Internal liability toward your own company looms under section 43 of the German GmbH Act when adoption ran without documented selection, rules and oversight - the machine's mistake is rarely the ground for liability, the missing organisation behind it is. Externally, the company is liable, not the person.

What applies if we adapt and run an open-source model ourselves? Open-source software not provided commercially is exempt from product liability - that protects the developer community, not you. Anyone who substantially modifies an open-weight model, builds it into their own product or ships it under their own name counts as the manufacturer under Articles 4 and 8 of the directive and is strictly liable.

Does the new product liability cover damage our AI causes at a customer's site? Only when the customer is harmed as a private individual: the directive protects natural persons, property damage only to privately used goods and data loss only for non-professionally used data. A business customer whose plant is idled by your AI module is left to contract and tort - and will take that route against you.

Our AI provider is based in the US. Does that change anything? Yes, from December 2026. When the manufacturer is based outside the Union, its authorised representative, the importer and potentially the supplier or fulfilment provider are also liable under Article 8. For the first time there is a liable addressee inside the EU without any US contract being involved.

Will our business liability insurance pay for AI-related damage? Not categorically. Whether AI-related damage is included depends on the terms of the individual policy; business and cyber liability policies differ considerably here. The right step is a written coverage enquiry to the insurer, not the assumption that existing cover includes software defects.


For a concrete project - for example an agent that autonomously places orders or answers enquiries - usage limits and documentation duties are settled most cleanly before launch; what a first process with a legal framework and technical documentation looks like is on the AI automation for companies page. This is not legal advice; for interpretation in a specific case, a specialist lawyer remains the right address.

Sources

Matching ArkeonTech service

AI process automation with a legal framework

One bounded process first, with a data processing agreement, EU hosting and the technical documentation the works council and the data protection officer want to see.