9 ms·
All software in EU under product liability from 2026
- hggigg 2y agoI hope the EU are liable for software that they make defective by their own security legislation.
- cynicalsecurity 2y agoI wonder if CrowdStrike's fiasco played a role in this.
- Muromec 2y agoYou greatly overestimate the speed at which bureacracy moves
- phkamp 2y agoI've talked to various people over the last couple of years, and it seems Colonial Pipeline was the big eye-opener for politicians in USA: Nobody could be sued, even though they were aware of the problems. In EU I've heard more about ransomware in general and the behavior of Microsoft and Oracle in license negotiations and "audits" in particular. But the overall tenor is that politicians have had it up to here with the IT industry's "What me worry?" attitude to quality, responsibility and liability.
- bubblesnort 2y agoYou have no idea how slow governments are.
- phkamp 2y agoEU countries have 2 years to legislate the national implementations. FOSS exemption but only for "outside commercial activity" - whatever that will mean. I guess that guy in Nebraska is safe, but not so sure about my own one-man company.
- hfifuvthdj 2y ago[dead]
- deleted 2y ago[deleted]
- ashildr 2y agoYour one man company definitely is not safe, you’ll be responsible for all damages done by the full stack you’re providing. Each library / OS / whatever software is part of your product. Yes, this is bad.
- xvector 2y agoThe EU really needs to be isolated from the world technology market. They are only creating hostility and rent-seeking from people that build things and contribute actual value. The EU regulatory bureaucracy on tech, like all bureaucracies, does nothing but serve its own cancerous expansion.
- mikece 2y agoSo this means it will be easier/possible to sue developers/companies for defective software? How is this anything other than a cash grab by lawyers?
- phkamp 2y agoThere's something called "The American Rule" which sets USA apart from pretty much the rest of the world. In USA, win or loose, each party pays their own lawyer. This is why USA has lawyers often work on "contingency" where they nominally work for free, but receive a large fraction of any settlement or award if the case is won. In the rest of the world, and specifically in EU where this applies, the looser pays the winner's (reasonable) legal fees. Not saying that lawyers are not greedy in EU, but not in the way USAnians are used to think about lawyers. So no: This is genuine consumer protection.
- yread 2y agoWho will be liable for "defective" directives and regulations? I would like to sue someone for all the wasted time and effort around cookie popups.
- master-lincoln 2y agoIt's easy: if you as a website owner transfer personally identifiable information to a third party and it's not strictly necessary to provide your service, then you need consent from the user. If you would refrain sharing that info, you wouldn't need to ask for consent. There is no law that asks for cookie popups
- someplaceguy 2y agoEven the EU's own official web portal [1] has a cookie pop-up that covers half the screen of my mobile phone when I visit it. [1] https://europa.eu/ https://europa.eu/
- KingOfCoders 2y agoProbably built by a web gency who added tracking, perhaps even GA, so there was need for a cookie pop up banner. Why that website would need tracking and profiling is beyond me.
- tensor 2y agoI think every website should understand how and by who their website is used. I don't consider this "spying." If you walk into a brick and mortar store the shopkeeper has every right to count that you came in, and watch where you go in the store to optimize it. The web should be no different. Fortunately there are in fact cookieless analytics systems that people can use to get this information why not being required to have the stupid cookie popup.
- KingOfCoders 2y ago"I think every website should understand how and by who their website is used" 1. You don't need cookies or profiling for that - use Simple Analytics et. al. 2. You can ask for my consent, but you can't profile me against my will 3. A brick and mortar store does not profile me without my consent.
- jmclnx 2y agoI wonder if this will speed up the push to "renting" software as opposed to buying it. By that I mean, in order to use any software product, you will need to phone home and what you do is logged on a server. This way, the vendor may be able to find a way to blame you for a violation.
- rwmj 2y agoWhy would renting software be any different? If you rent a defective car, the company that rents it to you is still liable.
- jmclnx 2y agoNow (or at one time), you could buy Microsoft Office and use it without an internet connection. With this, maybe that option will be gone, companies can blame the EU for requiring a internet connection and the user is stuck being logged/spied on agreeing to this via an EUL.
- rwmj 2y agoIn your imagination maybe.
- phkamp 2y agoA company cannot exempt itself from product liability with an EULA. Cloud services are also explicitly mentioned as covered.
- csdreamer7 2y agoThis is an absolutely terrible argument. So much shrinkwrapped software phones home these days well before this law. MS Office has required it for years! Look up MS Office XP (2001).
- phkamp 2y agoI hate to admit it, but the EUrocrats who drafted this are smarter than that: All software is covered, sold, licensed, embedded, rented. Even the cloud services tied to products are covered.
- smackay 2y agoInteresting to see from the press release that Right to Repair is being cracked down upon: When a product is repaired and upgraded outside the original manufacturer’s control, the company or person that modified the product should be held liable. Will we see companies sue repair shops or compatible component manufacturers in order to prevent potential injury to their customers. Interesting times.
- gbanfalvi 2y agoWhy would companies do that? They won't be held liable once it's modified.
- kroolik 2y agoSo they have the monopoly on repairs
- black_puppydog 2y agonot true. if you make a repair, you're liable for it. if you do your job well, there's no reason that would mean more of a business risk than the OEM takes. If, on the other hand, you do a rush job, then yes you're very much on the hook. If anything, this makes repairs/reuse of devices more interesting to the consumer, since you know that some basic level of responsibility (read: liability) is taken care of.
- phkamp 2y agoEU has been pretty vocal about "Circular Economy" and also the right to repair for ages, so I do not expect a bona-fide repair job brings anybody in legal trouble. But conversely: Should the original manufacturer be responsible if somebody installs hacked-up "performance" software in a car ? Of course not!
- Muromec 2y agoSo I can't just blame my bullshit on "the computer" or say that AI ate my homework and have to own it? Terroble times. Next thing, evil bureacrats will then make me actually care and owm broken accessibility.
- beretguy 2y agoWill this prevent shut downs of games that rely on central server, like what happened to The Crew?
- phkamp 2y agoIf you look at page 51 it says: 2. […]an economic operator shall not be exempted from liability where the defectiveness of a product is due to any of the following, provided that it is within the manufacturer’s control: (a)a related service; (b)software, including software updates or upgrades; (c)a lack of software updates or upgrades necessary to maintain safety; (d)a substantial modification of the product. Not sure if (a) or (d) would be more applicable, but I think it would be covered ?
- beretguy 2y agoYeah, looks like D would apply but I afraid it would have to be tested in court. Game companies won't go without a fight.
- devnull3 2y agoWho decides the definition of "what was suppose to work" in the context of a given software product? There are times when a feature is used in a way which was not intended by the developers. Now do the developers have to publish their test scenarios? What if the bug is in 3rd party library? Add to it the complexity of open-source code.
- phkamp 2y agoIn the end, a court of justice (in EU, not in USA!) does. It's not a bad first approximation to expect courts in EU to very sensible and fair.
- gwbas1c 2y ago> What if the bug is in 3rd party library? It will probably be similar to when a physical product is defective because of a faulty 3rd party component. More importantly, as a professional software developer, the testing of my product should find problems in 3rd party components. If I chose poorly and the 3rd party component doesn't do what it's supposed to do, that's my responsibility. I can't just slough it off onto someone else.
- devnull3 2y ago> my product should find problems in 3rd party components. Does that mean that say a security vulnerability in openssl is a responsibility of all software which uses them? I think its unreasonable to expect software projects/products to find things like heartbleed. What about bugs in kernel/OS? How many user-mode software can find bugs in kernel/OS?
- gwbas1c 2y agoThe OS is not a 3rd party library. You're confusing two different topics here. BTW: Software vendors find bugs in the OS all the time.
- gwbas1c 2y ago> There are times when a feature is used in a way which was not intended by the developers. Now do the developers have to publish their test scenarios? I think the vendor will need to be a lot more clear about what the supported use case is; and what use cases aren't supported.
- mrtksn 2y agoThis seems to be about liability for injury, not liability in general. It's probably about software that manages critical processes or hardware which might cause physical harm if malfunction. CMIIW, but this appears to be an attempt to clarify who is at fault when a device malfunctions due to software issue and allow a manufacturer in Czechia to use software from Poland without dealing with differences on Czech and Polish laws and regulations over software.
- phkamp 2y agoThat's the entire point of EU directives: The differences should be so small that it will not matter to anybody.
- mrtksn 2y agoExactly. That's why the red tape and paperwork increased in UK once they left the EU. The gist is, there are about ~30 countries that have their own laws and regulations(the exact number differs because it's not just the EU-only thing) and EU swoops in, makes up a regulation and tells all the members states and associated countries to align their laws and regulations with the EU stuff and you end up with 30 or so countries that have about the same laws and regulations instead of 30 very different laws and regulations. As a result, you don't have to deal with the laws of 30 countries - at least that's the idea but AFAIK EU is not unified enough to make this as smooth as desired - yet.
- rob_c 2y agoThe only problem is where should this end? I'm all for improving trade, improving general cooperation, recycling rules/laws. The EU here did get a little too big with the curvature of a banana being mentioned. However, I think a _LOT_ of people start to take issue when you say, "OK we're standardizing the way you vote now", "We're standardizing the way rights are structured in your country", "We now place the EU as a supreme directive with a foreign court on certain issues". I can see the appeal, but this has a concerning dark side when it's brought in not through voting, but through treaty and trade in the real-world. Notice how I'm avoiding saying crony-capitalizm or a alike. I wish the EC was more successful in lasting by itself or the EU more flexible and less like a bag of hammers on certain issues which required a soft-touch. I'm not a fan of red tape, but less of a fan of 'Brussels' (I'm not being lyteral) dictating law over a multi-layered legal system with various existing rights and paths to appeal. Hence why I personally voted for Brexit. Yes I'm now working with those new laws and red-tape day to day (boy you think industy had it bad look into academia at times), but most of the issues I see come from foreign entities being in denial of Brexit happening and now drafting in draconian laws that look like they're punishing britain, even if it's just a case of the EU never thought to harmonize EU<->UK relations into 1 concrete set of agreements after the fact. (Yes, Boris and alike did NOT help by sitting across the table acting like spolit childrean at a birthday party. No to mention the whole NI thing dominating discussions because the US has some dealings here historically (I'm being polite!) and for some reason dragged them in whenever there was a 'threat to the peace accords'...) In summary, I like the idea, I just wish people didn't power-grab under the guise of standardization. (Huh, isn't that Intel with USB3, x86, ... or Apple with lightning, wifi, ...)
- graemep 2y agoIs the exemption for open source adequate? There are clear exemptions for non-profits and source distribution, but what about things such as FOSS distributed as binaries in commercial Linux distro repos?
- phkamp 2y agoDoesn't the word "Commercial" in "Commercial Linux distro" answers that?
- ApolloFortyNine 2y ago> In order not to hamper innovation or research, this Directive should not apply to free and open-source software developed or supplied outside the course of a commercial activity, since products so developed or supplied are by definition not placed on the market. Developing or contributing to such software should not be understood as making it available on the market. Providing such software on open repositories should not be considered as making it available on the market, unless that occurs in the course of a commercial activity Can't this wording easily be interpreted that commercial entities publishing open source software counts as a commercial activity? Wouldn't that kill corporate sponsored open source overnight? You could even argue Redhat (IBM) would be responsible for every user of any of their linux kernel patches/services no? If not, what does this wording actually apply to?
- phkamp 2y agoThat guy in Nebraska from the XKCD comic is probably safe. I'm not convinced that my one-man company is, since I derive most of my income from FOSS software. But that seems quite fair to me.
- ApolloFortyNine 2y agoOnly now every user of the software in Europe has recourse to sue you if you make a mistake, instead of just your paying customers. Your total liability went to infinity overnight (in 2026 anyways). >I'm not convinced that my one-man company is, since I derive most of my income from FOSS software. It's a bit of a problem that it's hard to even tell as well.
- TeMPOraL 2y ago> Only now every user of the software in Europe has recourse to sue you if you make a mistake, instead of just your paying customers. Only if they somehow directly got it from GP, through some kind of commercial thing. I doubt downloading stuff from Github for personal use qualifies. The way I read it, this directive wants to ensure that for any digital product sold on the EU market, there exist some entity that can be sued in EU jurisdiction; within the Union, that would be the vendor; outside - a vendor representative, or an importer. Which is a perfectly reasonable expectation to have, and it's how it mostly works with physical goods and services (aliexpress notwithstanding).
- aaronheid 2y ago[dead]
- gwbas1c 2y agoHonestly, it's about time. I've paid for so many things that fail because of defective software, and had limited or no recourse. As a result, software companies are incentivized to make software full of hardly-used features with limited testing; because there are no consequences when software doesn't do what the claim is.
- EasyMark 2y agoSo if you only market/sell your software outside of the EU then this wouldn’t apply, correct? If someone bought it in the USA and then moved capital equipment to the EU with said software I would think the law isn’t enforceable in that or similar situations?
- PhilStunell 2y agoThe product liability directive holds all producers jointly liable for any harm caused by unsafe or defective products - including software. So, people who supply 'software as component' or software service may be held responsible for the safety of the products that incorporate or use the software. But people can also claim for the loss, corruption or destruction of 'personal data' caused by product defects.