
Software Is Now a Product in the EU
From 9 December 2026 the EU treats software as a product under strict liability. What it means for Monaco companies selling apps and connected devices.
A quiet deadline with loud consequences
By 9 December 2026, every EU member state must have the revised Product Liability Directive — Directive (EU) 2024/2853 — written into national law. It replaces a 1985 regime built for toasters and car parts, and it does one thing that should make anyone who ships code pay attention.
Software is now a product.
Not software embedded in a machine. Software. Standalone applications, firmware, mobile apps, AI systems, digital manufacturing files, and software delivered as a service. If it is placed on the EU market or put into service after 9 December 2026, it falls under a strict liability regime — meaning an injured person does not have to prove you were careless. They have to prove the product was defective, that they suffered damage, and that one caused the other.
This is a different animal from the compliance deadlines that usually fill this space. The Cyber Resilience Act, NIS2 and the AI Act are regulatory — a public authority enforces them. Product liability is private. It arrives as a claim, from a customer, in a national court.
Why "we're not in the EU" doesn't settle it
Monaco is not an EU member state, and EU directives do not apply in the Principality of their own force. Monaco's position inside the French VAT territory is a separate matter entirely and does not change the analysis here — a distinction worth keeping clear, because the two get conflated constantly.
What matters is the same test the Cyber Resilience Act uses: where the product is placed on the market, not where the company is registered.
The Directive is built so that an injured consumer in the EU always has someone within the Union to sue. Where the manufacturer sits outside the EU, liability moves down a cascade:
- the importer who places the product on the EU market;
- the manufacturer's authorised representative in the Union;
- a fulfilment service provider, where no manufacturer, importer or representative can be identified in the EU;
- a distributor, if asked to identify the responsible operator and unable to do so within a month;
- an online platform, in defined circumstances where it presents the product as its own or fails to disclose the supplier.
For a Monaco software company, the practical reading is this: the claim may not land on you directly, but it lands on someone you have a contract with — and that contract almost certainly pushes it back. Agreements written before this Directive rarely allocate that risk explicitly, which is why the useful work here is often contractual rather than technical.
What makes software "defective"
The Directive lists factors courts weigh, and several are aimed squarely at digital products:
- The effect of updates and upgrades on the product, including ones you supply after launch.
- Failure to supply security updates or upgrades where doing so remains within your control.
- Non-compliance with product safety or cybersecurity requirements — so a Cyber Resilience Act failing can be used as evidence of defectiveness in a liability claim.
- The ability to continue to learn after deployment, which is the drafters' way of accommodating machine learning.
Two consequences follow. First, "it was fine when we shipped it" is no longer a complete answer — if you retain the ability to patch and you don't, that inaction is part of the assessment. Second, anyone who substantially modifies a product after it is on the market can be treated as its manufacturer for defects arising from that modification. Ongoing website maintenance and support stops being a nice-to-have line item and becomes part of your liability posture.
Free and open-source software developed and supplied outside a commercial activity is excluded. That exclusion is narrower than it sounds: monetise it, or supply it in exchange for personal data beyond what is needed for security and compatibility, and it can come back into scope.
What can actually be claimed
The compensable heads of damage have been widened:
- death and personal injury, including medically recognised damage to psychological health;
- damage to property, other than the defective product itself and property used exclusively for professional purposes;
- destruction or corruption of data that is not used for professional purposes.
That third one is new and directly relevant to anyone running consumer-facing software. Pure economic loss, privacy infringement as such, and discrimination remain outside the Directive.
The old €500 minimum threshold for property damage is gone, and there are no financial caps. Claimants also get help proving their case: national courts can order disclosure of relevant evidence, and where technical or scientific complexity makes proof excessively difficult, courts may apply rebuttable presumptions of defectiveness or causation. Claims run three years from knowledge, with a ten-year long-stop from placing on the market — extended to twenty-five years for latent personal injury.
Who in Monaco should care, and who shouldn't
Most Monaco businesses are not in the frame. A restaurant booking page, a corporate site, a portfolio for a wealth manager — ordinary web development work does not become a strictly liable product because it exists on the internet.
The ones that should look properly:
- anyone publishing a mobile or desktop app to EU users;
- anyone selling connected hardware with companion software — well represented in Monaco around yachting, building technology and access control;
- anyone shipping a product with AI features to EU customers, where AI automation has moved from internal tooling to something in the customer's hands;
- anyone selling physical goods into the EU through their own e-commerce channel, since the Directive covers conventional products too.
What to do before December
Four things, none of them expensive:
- Write down what you place on the EU market. Products, form, and countries. For most Monaco firms this ends in a documented "nothing" — worth having on file.
- Find your EU operator and read the contract. Identify your importer, authorised representative or platform, and check who carries product liability risk. Renegotiate now rather than after a claim.
- Check your insurance. Product liability cover written against the 1985 regime may not contemplate software, data loss, or a twenty-five-year tail. Ask your broker the question in writing.
- Make patching a documented commitment. Define your support period, your update cadence and your vulnerability response, and record that you follow them. It is your best evidence of non-defectiveness — and it belongs in your product plan rather than an operations ticket.
One honest caveat. This is a directive, not a regulation, so the detail that binds you depends on each member state's transposition law, and those will differ. Monegasque law governs your own contracts and its own liability rules independently. Where the answer affects your product roadmap, your insurance or your ability to sell into Europe, verify it with a qualified lawyer. Nothing here is legal advice.
If you build software or connected products in Monaco and sell them to European customers, this is the year to find out where you stand — before someone else works it out for you. Get in touch and we will map it with you.
Related services