The rule: what the directive says and from when
An AI agent acts, produces effects, causes damage. Liability for damage caused by an AI agent now has a precise European frame: Directive (EU) 2024/2853 of 23 October 2024, which repeals Directive 85/374/EEC.
Article 2(1) sets the temporal perimeter: the regime applies to products placed on the market or put into service after 9 December 2026. Article 22 requires Member States to transpose it by the same date, as set out in the official text published by the Union[1].
Two references converge on a single deadline. 9 December 2026 is at once the transposition deadline and the line dividing the old regime from the new.
The 1985 regime reasoned about physical objects. The 2024 one speaks of software, of updates, and of systems that learn. That is the regulatory delta, and it applies to every business placing a digital product on the Union market.
Software is a product: Article 4
Article 4 includes software in the definition of a product. The classification applies regardless of the medium: software embedded in a device, software distributed on its own, software delivered as a connected digital service.
The practical consequence concerns the rules on defectiveness. A model, an agent, a recommendation engine: each becomes an object to be assessed against the safety standard the public is entitled to expect.
Article 2(2) carves out an exception. Free and open-source software developed or supplied outside the course of a commercial activity remains outside the regime, and the exception is read narrowly.
Anyone who integrates an open-source library into a commercial product and places it on the market falls within the regime for the product so placed. The Dreyfus firm's analysis of the directive reconstructs this point from the perspective of software manufacturers (Dreyfus[2]).
The perimeter of compensable damage: Article 6
Here lies the point most internal presentations get wrong. Article 6, read together with recital 24, lists compensable damage as a closed set.
Three categories fall within it:
- death and personal injury, including medically recognised damage to health
- damage to property other than property used exclusively for professional purposes
- destruction or corruption of data not used for professional purposes
Purely economic loss stays outside. The directive protects the integrity of persons, of property and of private data, and leaves the rest to contractual ground.
Readers expect the opposite, and it is worth stating plainly: an agent that gets a payment wrong between two businesses falls outside this regime. A botched reconciliation, a duplicated order, a margin eroded by a badly calculated price: these are economic losses between professionals.
Who decides in those cases? The contract between the parties and the applicable national law, with its limitation clauses, service levels, warranties and rules on breach.
Continuous learning enters the defectiveness test: Article 7
Article 7(2)(c) introduces an unprecedented criterion. In assessing whether a product is defective, account is taken of the effect of the product's ability to continue to learn after it is placed on the market.
The reach is broad. A system that updates itself, retrains or adapts its own parameters stays connected to the party that placed it on the market, even after delivery.
The moment of sale thus loses its function as a boundary. Defectiveness is assessed by also looking at how the product has changed on its own.
A compliance framework calibrated on a static product is therefore undersized for an agent that learns. The framework calls for documented post-market surveillance: what changed, when, with what verification, under whose signature.
Who is liable: Article 8
Article 8 identifies the liable parties and arranges them in a chain. The manufacturer of the defective product or of the defective component comes first.
The chain continues to whoever substantially modifies a product already placed on the market, then the importer, the authorised representative, the fulfilment service provider, and finally the distributor when the preceding parties cannot be identified.
The rule rewards traceability. A European business that integrates a third-party model and distributes it under its own brand takes up a position within this chain.
The question the General Counsel has to settle has a first and last name: which internal role answers for the product's classification along the Article 8 chain, in writing, before deployment? A framework without a name produces documentation, tidy and inert.
The agent's log as evidence: Articles 9 and 10
Articles 9 and 10 shift the weight of proof. The national court orders the defendant to disclose the relevant evidence at its disposal.
Where the defendant fails to disclose, the presumption that the product is defective kicks in. The mechanism is straightforward and severe: whoever holds the logs and keeps them closed loses the evidentiary advantage.
For an AI agent the relevant evidence has a precise technical name: audit trail. Prompt, model version, tools invoked, data read, action executed, upstream human authorisation.
A chained, tamper-proof audit trail therefore becomes a defensive asset. Its absence feeds a presumption against the business. Architectures that log every call the agent makes preserve the ability to prove compliance in court.
Policies that cover AI performance
The insurance market moved before national legislators. Alongside traditional product liability cover, policies have appeared that insure the system's performance: performance-level guarantees, extensions dedicated to algorithmic error, affirmative cover for AI use.
The distinction matters for the Chief Risk Officer. The directive covers damage to persons, property and private data; performance cover operates on the ground the directive leaves uncovered, that of economic loss between businesses.
The two protections work on different planes and must be read together. An insurance programme built around the physical product covers a deciding agent badly.
The useful check is specific: does the policy include software in its notion of product? Does it cover damage to data? Does it exclude model error? Does it impose logging obligations as a condition for the cover to take effect?
Three decisions for the board
The board faces three choices, in order of urgency.
- Classify the digital portfolio: which products the business places on the market after 9 December 2026, and which of them contain software that learns.
- Appoint in writing the role answerable for post-market surveillance and for retaining the audit trail.
- Review the insurance programme and the contractual clauses with suppliers and customers, separating damage covered by the directive from economic loss.
The audit committee also has a disclosure question. A new exposure that matures on a fixed date belongs on the map of material risks, with the same standing as a tax dispute.
For the CEO the constraint is one of calendar. A product on the roadmap for the first quarter of 2027 is born inside the new regime, and the architecture chosen now determines how defensible it will be then.
Organisations that build risk classification, a named owner and an audit trail before the deadline gain months of advantage over the moment enforcement becomes real.
Regulatory horizon
Status of the rule: the directive is in force as an act of the Union, and application to products runs from 9 December 2026. National transposition is under way across the Member States.
Italy: as checked on 28 September 2026, this newsroom records the domestic transposing measure as pending. The source to consult remains the Gazzetta Ufficiale, and the check should be repeated on the date the business decides.
Jurisdiction: all Member States of the European Union, with the single deadline set by Article 22.
What a European business does before 9 December 2026: an inventory of software products, the Article 8 chain of parties set down on paper, agent logging switched on and retained, policies compared against the perimeter of Article 6. Four worksites and one date.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- official text published by the Union (publications.europa.eu)
- Dreyfus (dreyfus.fr)