EU Trends and Developments Contributed by: Hans-Patrick Schroeder, Kristina Weiler, Laura Knoke, Anita Bell and Rixa Kuhmann, Freshfields
This creates a significant tension for businesses as disclosure orders may require the production of com - petitively sensitive material. The disclosure obligation is given teeth by the PLD’s system of rebuttable presumptions under Article 10. A failure to comply with a disclosure order triggers a rebuttable presumption of defect. In practice, defend - ants faced with such an order will have little choice but to comply or risk losing the case. Beyond this link to disclosure, the presumptions oper - ate independently. Perhaps most consequential: in cases of “scientific and technical complexity,” courts may presume both defect and causation where the claimant shows that each is merely likely (Article 10 (3) (a) PLD). AI systems, with their opaque decision-mak - ing processes and complex architectures, are prime candidates for this provision. This significantly lowers the evidentiary hurdles: the claimant needs only to demonstrate a likelihood of a defect and causation and the burden effectively shifts to the manufacturer to disprove both. Recent Updates in Product Compliance Laws to Target Modern Safety Risks The GPSR, the Machinery Regulation, the CRA and the AI Act sit at the heart of this interlocked architec - ture. Each framework imposes its own set of compli - ance obligations, but together, they set the benchmark against which courts will assess whether a product is defective. Reflecting the additional factors for assess - ing the defectiveness of digital products in Article 7 (2) PLD, these new and updated product safety regula - tions also address evolving risks arising from techno - logical progress, particularly for interconnected and AI-driven products. The GPSR: a modernised safety baseline for consumer products The GPSR, applicable since 13 December 2024, replaces the former General Product Safety Directive and establishes the baseline safety framework for consumer products. Its core requirement is straight - forward: economic operators may only place safe products on the market (Article 5 GPSR). What has changed is what safety now requires.
The GPSR broadens the criteria that manufacturers must take into account when assessing whether a product is safe (Article 6 GPSR), now including: • cybersecurity – products must incorporate appro - priate protection against external influences, including malicious third parties, that could affect safety (a cybersecurity vulnerability can now directly constitute a product defect); • interconnection – the effect a product has on other products and that other products might have on it must be considered; in other words, how it inter - acts with other hardware or software; and • AI functionalities – the safety implications of evolv - ing, learning and predictive capabilities must now be expressly considered. Compliance with revised product safety require - ments is not only a regulatory imperative; it is also the frontline defence in any subsequent liability claim for economic operators under the GPSR. For the first time, product safety obligations also extend to online marketplaces. The CRA: lifecycle cybersecurity for connected products Even more specific, the CRA introduces horizontal cybersecurity requirements for all products with digital elements throughout their entire lifecycle – covering any hardware or software that is directly or indirectly connected to another device or network. Under Article 6 in conjunction with Annex I CRA, rather than treat - ing cybersecurity as an abstract goal, it translates the concept into concrete, verifiable design and process requirements. Products must: • ship with secure-by-default configurations; • protect data confidentiality and integrity through encryption; • limit attack surfaces; and • be capable of receiving secure updates. The CRA imposes a tiered set of pre- and post-market obligations across the entire supply chain – manufac - turers bear the most comprehensive duties, including vulnerability reporting and long-term security updates, while importers must verify manufacturer compliance before placing products on the market and distribu -
107 CHAMBERS.COM
Powered by FlippingBook