
NEW PRODUCT LIABILITY BILL EXPANDS RULES TO COVER SOFTWARE AND AI AS DEADLINE LOOMS - in-cyprus 20/9
By Kyriacos Angelides*
The House Parliamentary Committee on Energy, Commerce, Industry and Tourism is set to begin examining the Product Liability Law of 2026. The bill transposes a new European framework into national law, broadening and modernizing liability rules for economic operators regarding damages caused by defective products.
The most significant change adapts the definition of a “product” to the digital age. Software, applications, and artificial intelligence systems now fall under the new framework, alongside products dependent on software for their operation and safety.
Adapting to Digital Realities and Software Updates
The legislation does not classify every technical issue as an automatic defect. Evaluations will consider factors critical to modern digital products, including product interconnectivity, cybersecurity requirements, post-market modifications, and the degree of control retained by the manufacturer after sale.
For technology companies and manufacturers of smart devices, software updates and upgrades carry distinct legal weight. Economic operators remain responsible when product defects link directly to software or updates under their control. Consequently, the post-sale period gains heightened legal importance for items dependent on software, updates, or cybersecurity services.
Broadened Supply Chain Liability
The bill expands the chain of economic operators subject to compensation claims. Beyond the primary manufacturer, liability may extend to makers of defective components. When manufacturers operate outside the European Union, importers, authorized representatives, or fulfilment service providers may incur responsibility. Distributors can also face liability in specific circumstances.
Additionally, any natural or legal person carrying out a substantial product modification outside the original manufacturer’s control before placing it back on the market may be deemed a manufacturer under the law.
Compliance and Industry Response
While plaintiffs must still prove damage, defect, and causality, the framework introduces mechanisms to ease proof burdens in technically complex cases. The scope impacts manufacturers and importers of electronics, smart devices, machinery, and software-driven vehicles.
Businesses must move beyond physical product safety at the point of sale. Effective compliance requires managing software updates, cybersecurity, technical documentation, evidence retention, and clear contractual risk allocation among suppliers and developers.
With the EU transposition deadline expiring on December 9, 2026, the Cyprus Employers and Industrialists Federation (OEB) is monitoring the legislative process and urging affected businesses to review the framework and submit observations.
*Business Association Coordinator (OEB)