Munich-based Sibylle Schumacher and Lara Bruchhausen, litigation experts at Pinsent Masons, were commenting ahead of an EU deadline to implement the revised EU product liability directive into national law.
The new EU directive extends liability to software, artificial intelligence (AI) systems and digital products, while also easing the burden of proof for injured parties and expanding the categories of compensable damage.
Member states have until 9 December to transpose the directive into national law. In Germany, the Federal Ministry of Justice (BMJ) has already initiated the legislative process, publishing a draft bill – the ‘Gesetz zur Modernisierung des Produkthaftungsrechts’ (Act on the Modernisation of Product Liability Law) – to implement the new rules.
Schumacher said: “Businesses that have not yet assessed their product liability exposure under the new rules, including their supply chain contracts and insurance arrangements, should do so ahead of the December implementation deadline.”
As well as expanding the scope of the product liability regime, the directive eases the burden of proof for injured parties and expands the definition of “damage” to include data loss and psychological harm. The range of economic operators that can be held liable for product liability failings has also been expanded to include online platforms and importers. The new framework will apply to any business that manufactures, imports, distributes or sells products into the EU market, with the update particularly relevant to companies dealing with AI-enabled products, software and connected devices, which were largely outside the scope of the previous directive.
The German draft Act on the Modernisation of Product Liability Law transposes the directive into national law. It sets out in detail how the new evidentiary regime will look like in practice. In particular, once plausibility of a claim has been established, courts may order businesses to disclose any relevant evidence in their possession, with failure to comply potentially triggering a statutory presumption of product defectiveness. Where technical or scientific complexity would otherwise make proof excessively difficult, courts may presume both defect and causation. Separate presumptions also apply where causal links are established.
“The evidentiary rules are arguably the most consequential part of the new framework, and businesses should not underestimate them,” said Bruchhausen. “A defendant that fails to comply with a court-ordered disclosure risks having defectiveness presumed against them without the claimant needing to prove it. These provisions significantly raise the stakes for manufacturers when it comes to documentation, internal record-keeping and disclosure strategy.”
Schumacher added: “The new legislation substantially increases litigation risk across the product lifecycle. It introduces a more claimant-friendly evidentiary framework and expands the categories of damage for which compensation may be sought. With Germany advancing its implementation legislation, businesses operating in or exporting to Germany are well advised to monitor the progress of the draft bill closely and to consider what adjustments may be required to their existing compliance frameworks.”
Adjustments may include a review of product portfolios to assess which products fall within the expanded scope, especially software, AI and digital services, she said, adding that firms may also review insurance coverage, supply chains and distribution agreements to allocate liability appropriately between manufacturers, importers and distributers.
Schumacher said: “In light of the new evidentiary rules, businesses may require internal processes to identify, organise and preserve relevant product documentation – including development records, safety testing reports and risk assessments – that may be subject to court-ordered disclosure under the implementing legislation. Product development, quality assurance and internal training are also important measures to consider as well as a review of product recall and incident response procedures. For businesses operating across multiple EU jurisdictions, it is also important to consider how differing national implementation choices may create varying levels of risk across different markets.”