AI Liability Directive Withdrawn: the Rule That Matters Lands on 9 December 2026
5 min read
In 2025 the European Commission withdrew its proposed AI Liability Directive. The most common reading was: “Europe is giving up on regulating who answers when AI causes harm.” That reading is wrong — and dangerous for anyone who takes it literally. Because a different rule, far less talked about, already brings software and artificial intelligence systems within the general regime of liability for defective products. And it carries a precise deadline, already on the calendar: 9 December 2026.
The withdrawal that made headlines — and what it left behind
The AI Liability Directive was born in 2022, designed to sit alongside the AI Act with rules dedicated to anyone harmed by an artificial intelligence system. In February 2025 the Commission listed it among the proposals to be abandoned in its annual work programme, citing the lack of agreement between Parliament and Council; the formal withdrawal followed in autumn. Twelve industry organisations had specifically asked for this, fearing a double layer of rules. The result: no bespoke AI liability law. But the gap is only apparent.
The directive that actually matters: product liability, rewritten
While attention was fixed on the AI Liability Directive, Directive (EU) 2024/2853 quietly entered into force, replacing forty-year-old legislation (Directive 85/374/EEC) on liability for damage caused by defective products. The change that matters for anyone operating with AI lies in the very definition of “product”: it now explicitly includes software and artificial intelligence systems, regardless of the channel — local installation, cloud, SaaS, or embedded in physical machinery. A computer-vision system on a production line, a model that steers clinical decisions, an agent that updates a price or routes an order: all of these now fall within the scope of a manufacturer who can be called to answer.
The directive applies to products placed on the market from 9 December 2026; member states must have transposed the new rules by the same date. In Italy, the delegation to government has already been granted: the 2025 European Delegation Law (Law No. 36 of 17 March 2026) includes Directive 2024/2853 among the directives to be implemented. The detailed implementing decree has not yet been published — but the deadline stands, and it is not moving.
The three levers that shift the burden of proof
The most consequential practical change is not the definition of “product”: it is how harm is proven in court. The directive introduces three mechanisms designed precisely for complex systems:
- Duty of disclosure. A claimant seeking compensation need only show the plausibility of the harm suffered: at that point a judge can order the manufacturer to disclose the product’s technical documentation. Anyone who fails to produce it, or produces it incomplete, risks triggering the presumption that follows directly.
- Presumption of defectiveness. This applies when the manufacturer has failed to meet applicable safety requirements, or when the harm is consistent with an obvious malfunction under normal conditions of use. It is no longer necessary to show how the product is defective: it is enough that it appears to be so.
- Presumption on the causal link in cases of technical or scientific complexity. This is the part written with AI’s “black box” explicitly in mind: if it is excessively difficult for the claimant to prove the link between defect and harm because of the system’s complexity, the link is presumed — and it falls to the manufacturer to dismantle that presumption.
In other words: anyone placing an AI system on the market, or integrating one, can no longer rely on the model’s opacity as a defence. Opacity, if anything, now counts against whoever created it.
What changes for those who let an AI agent execute actions
The delicate point concerns agents that genuinely touch corporate systems: a modified order, an updated price, a routed case file are actions with direct consequences. If that agent embeds a third party’s model inside a product or service of its own, whoever integrates it can be treated as a “manufacturer” for the purposes of the directive — not only whoever trained the original model. It is the same principle of cascading liability along the supply chain that the European AI Act calendar is already entrenching on another front: compliance can no longer simply be passed downstream without consequence.
Under a regime like this, the defence is built before any litigation begins: traceability of decisions, documented human oversight of critical actions, an architecture that can demonstrate what the system decided and why. That is why, in our approach, the human operator remains within the perimeter of decisions that matter: it is not merely operational caution, it is the evidence needed in court when the statutory presumption is working against you.
What to do now
- Map out where your software or AI agents are, in fact, a “product”: including anything you integrate from third-party suppliers into a service carrying your own brand.
- Strengthen technical documentation and decision logs: this is the first line of defence against a presumption of defectiveness for non-disclosure.
- Review contracts with model and platform suppliers: who provides evidence in the event of litigation, and on what timeline.
- Check insurance coverage against the new, wider perimeter of compensable harm.
- Do not wait for the Italian decree: the European perimeter is already written, and the deadline — 9 December 2026 — does not depend on Rome’s timetable.
This applies in particular to manufacturers of machinery and connected production lines — the systems that combine mechanics and software in manufacturing processes fall within the broadened definition just as much as a cloud application does.
Sources
- Directive (EU) 2024/2853 — EUR-Lex
- Law No. 36 of 17 March 2026 — 2025 European Delegation Law, Official Gazette No. 70
- AI Liability Directive — Legislative Train Schedule, European Parliament
The perimeter of liability is being rewritten before the Italian decree has even been published. If you want to understand where your AI architecture exposes you — and where it protects you instead — let’s talk in an operational session.