

Product Liability for Medical Devices: An Overview of the New Law
The new Product Liability Act tightens product liability requirements for software used in medical devices. The more digital systems continue to learn or receive updates after they are placed on the market, the more important the question becomes: development risk or manufacturer control? It is precisely this distinction that will determine liability for medical devices in the future.
Teilen Sie diesen Beitrag:
Teilen Sie diesen Beitrag:
An Overview of the New EU Product Liability Directive
The new Product Liability Directive replaces Directive 85/374/EEC and, with it, a liability regime that essentially dates back to a time before software, cloud services, and self-learning algorithms. The basic principle remains unchanged: product liability remains strict liability. An injured party does not have to prove wrongdoing on the part of the manufacturer, but rather the defectiveness of the product, the damage, and the causal link. The framework surrounding these principles has been modernized, and this has a particularly significant impact on medical devices.
Expanded Definition of “Product”: According to Article 4 of the EU Product Liability Directive, software, digital manufacturing files, and raw materials are also expressly considered products. For medical devices, this means that standalone software, embedded software, apps, and AI systems fall directly within the scope of the directive—regardless of whether they are provided on a data carrier, as a download, or as a service.
Expanded Scope of Parties Subject to Liability: In addition to the manufacturer, Article 8 lists, among others, component manufacturers, importers, authorized representatives, fulfillment service providers, and—on a subsidiary basis—distributors and online platforms. Anyone who substantially modifies a medical device and subsequently makes it available may also be held liable as a manufacturer.
Expanded Definition of Damages: Pursuant to Article 6, the following are eligible for compensation : death and bodily injury, including medically recognized mental health impairments; property damage; and the destruction or damage of data that is not used exclusively for professional purposes. The previous deductible of 500 euros for property damage no longer applies, nor does the possibility of a national liability cap.
The New Product Liability Act: Germany’s Implementation
In Germany, the directive is being implemented through the Act on the Modernization of Product Liability Law. This is the first comprehensive reform of the Product Liability Act since 1989 and thus the most significant change to German product liability law that medical device manufacturers have experienced in the past three decades. The government’s draft bill has been available since February 2026 (BT-Drs. 21/4297); following the first reading in March 2026 and the hearing in the Legal Affairs Committee, the parliamentary process is still ongoing. It must be completed by December 9, 2026.
In practice, this means that the new Product Liability Act incorporates the provisions of the EU Product Liability Directive but, in several areas, makes use of national discretion—for example, regarding procedural matters, the protection of trade secrets in the context of disclosure, and the determination of compensation for non-pecuniary damages. Manufacturers should therefore closely monitor the final version of the Product Liability Act and not base their processes solely on the text of the directive. However, those who are already planning based on the Directive are not working in a vacuum: the substantive core—the definition of a defect, relaxed standards of proof, disclosure obligations, and time limits—is prescribed by European law and will be reflected in national law.
Medical Device Liability: MDR-Compliant, Yet Still Liable?
Those who have successfully guided their medical device through the conformity assessment process conducted by a Notified Body often believe they are in the clear. This is precisely where the most common misconception regarding medical device liability lies.
Civil courts determine independently whether a product is defective for purposes of liability law. According to Article 7 of the Directive, the criterion is whether the product provided the level of safety that the general public could reasonably expect, assessed on the basis of a number of circumstances, which expressly include relevant product safety requirements and interventions by competent authorities. MDR compliance and a positive assessment by the Notified Body thus serve as significant evidence in favor of the manufacturer in this evaluation. However, they do not have a binding effect or preclude liability.
In short, this means that a medical device may have been legally on the market for years but could still be retroactively classified as defective—for example, because the state of science and technology has advanced, because comparable products now offer a higher level of safety, or because a known risk was not consistently minimized. Conformity assessment is a regulatory snapshot in time, not a liability shield.

Liability Risks Throughout the Entire Product Life Cycle
A key shift in perspective concerns the point in time that matters. Safety is no longer viewed merely as a snapshot at the time of market release, but as an ongoing responsibility throughout the entire product life cycle.
This is made clear by the liability exemptions in Article 11. The classic defense based on development risk—that the defect was not detectable given the state of science and technology at the time the product was placed on the market—remains in effect in principle. However, it does not apply if the defect is due to a circumstance that remains under the manufacturer’s control: for example, a software update or upgrade, a related service, or an update that was necessary but not provided.
As a result, inadequate product monitoring, failure to provide safety updates, or risk mitigation measures taken too late can directly give rise to liability. Risk management, post-market surveillance, PMCF, and vigilance—already core obligations under the MDR—are thus coming even more into focus because they now indirectly influence civil liability. Anyone who collects PMS data but fails to analyze it, or identifies trends without taking appropriate action, creates not only a regulatory finding but also a documented liability risk.
Documentation Becomes a Liability Factor
Product Liability for Software and AI in Medical Devices
The situation is becoming even more challenging for software- and AI-based medical devices. Product liability for software was controversial under the old law; now it is explicitly regulated. Adaptive algorithms, continuous updates, and a high degree of dependence on data quality simultaneously create sources of error that did not exist under traditional product liability law. Article 7 explicitly lists circumstances characteristic of this product category: the effects of a product’s learning capabilities, the effects of other products on which the product reasonably depends, and relevant cybersecurity requirements.
In practical terms, this makes the following, among other things, relevant:
- inadequately validated or non-representative training data;
- algorithmic drift and performance degradation in real-world operation;
- missing or delayed security and functional updates;
- Inadequate monitoring of field behavior and model quality;
- Interfaces to third-party systems, cloud services, and data sources.
Cybersecurity as a Liability Factor
Under the new liability regime, cybersecurity is no longer purely an IT issue, but rather an element of the definition of a defect: A vulnerability that impairs the intended use or safety of a medical device may constitute a defect within the meaning of product liability. For manufacturers, this means documenting cybersecurity processes—vulnerability management, patch and update cycles, coordinated vulnerability disclosure, and monitoring—in such a way that they serve as evidence of due diligence in the event of a dispute. Anyone who fails to patch a known vulnerability thereby potentially forfeits the defense based on development risk.
In addition, several regulatory frameworks overlap when it comes to AI systems: the MDR, the AI Regulation (EU) 2024/1689, and the Product Liability Directive take different approaches but rely on the same supporting documentation. It is worthwhile to structure post-market performance monitoring, update management, and cybersecurity documentation in such a way that they can be used in all three contexts.

Deadlines, Transition Periods, and Grace Periods
The time frame is clearly defined, and it has significant economic consequences:
- The new rules apply to products placed on the market or put into service after December 9, 2026.
- For medical devices that were made available prior to that date, the existing Product Liability Act based on Directive 85/374/EEC remains applicable.
- Pursuant to Article 16, claims generally become time-barred three years after the claimant becomes aware of the damage, the defect, and the liable economic operator.
- Under Article 17, claims expire ten years after the product is placed on the market. In the case of personal injury that manifests itself only later (delayed effects), the maximum period is extended to 25 years.
For medical devices with long market cycles and implants that remain in the body for extended periods, the 25-year period means that documentation and traceability must remain available well beyond the product’s life cycle. Archiving strategies, data formats, and responsibilities should be designed with this in mind, even in the event that product lines are sold, suppliers are changed, or systems are migrated.
Conclusion
The key message of the new Product Liability Directive is this: Formal compliance alone is no longer sufficient. Manufacturers would be well advised to integrate regulatory compliance, risk management, post-market surveillance, and liability-proof documentation more closely in the future, rather than treating them as separate areas of responsibility. Specifically, it is advisable to consider the following six points:
- Gap Analysis: Which medical devices will be placed on the market for the first time or re-marketed after December 9, 2026—and will therefore be subject to the new Product Liability Act?
- Update and Lifecycle Management: Have responsibilities, deadlines, and trigger criteria for security and functional updates been defined and documented?
- PMS and Vigilance Effectiveness: Do identified trends demonstrably lead to corrective actions—and is this causal chain evident in the records?
- Quality of Documentation: Is the chain of evidence structured in such a way that it would withstand judicial disclosure—consistent, versioned, and supported by traceable rationale?
- Software and Cybersecurity: Are vulnerability management, update deployment, and post-market performance monitoring regulated for every software-based product?
- Insurance and Archiving: Do coverage limits, extended liability periods, and retention periods align with the maximum periods of 10 and 25 years, respectively?
It is no longer enough for a medical device to meet all requirements at the time of market launch; rather, its safety must be transparently monitored, evaluated, and documented throughout the entire product lifecycle. Those who establish these processes properly at an early stage are significantly better positioned in the event of an emergency—not only from a regulatory standpoint but also in terms of liability.
