AUSTRIA Trends and Developments Contributed by: Andreas Eustacchio, EUSTACCHIO
From a practical perspective, companies will be responding in several ways. • Development contracts increasingly specify detailed responsibilities for safety concepts, hazard analyses and safety validation, often aligned with automotive standards such as ISO 26262 or ISO 21448. • Supply/distribution agreements between OEMs, Tier 1 suppliers and software developers contain more nuanced provisions on data access, co-oper - ation in incident investigations and responsibilities in recalls or field actions. • Cross-border teams, involving both technical and legal experts, prepare scenario-based assess - ments of potential accidents and claims in different jurisdictions, including Austria. These developments show that autonomous driving does not simply add more technology. It fundamental - ly changes how risk and responsibility are structured. For clients, the challenge is to ensure that technical reality and legal allocation of risk are aligned, so that no important gap remains uncovered and no party bears disproportionate liability exposure. Updates, Connectivity and Cybersecurity: Safety as a Moving Target A core characteristic of modern automated and con - nected products is that they are never truly “finished”. Vehicles and other devices receive software updates throughout their lifetime, sometimes adding new func - tions, sometimes fixing bugs, sometimes addressing security vulnerabilities. Each update can, in effect, create a new version of the product. From a product liability perspective, this dynamic raises two key issues. • The assessment of whether a product is defec - tive must consider the state of the product at the relevant time, including any updates installed or deliberately withheld. If a company knows of a safety issue that can be addressed by an update, failing to act may be treated similarly to failing to recall a dangerous product. For clients, this means that update policies must be carefully designed: (a) when to push mandatory updates;
(b) how to handle user refusal; and (c) how to document decisions.
Second, cybersecurity is now recognised as an inte - gral part of product safety. A vulnerability that allows an attacker to manipulate steering, braking or sensor data is not only an IT risk. It may directly endanger life and health. Consequently, cybersecurity measures, including secure development practices, penetration testing, key management and incident response, are increasingly scrutinised in liability disputes. Companies active in Austria therefore need integrated concepts that cover: • safe design and coding practices for embedded and backend software; • structured vulnerability management and clear escalation paths; • communication strategies towards customers when vulnerabilities are discovered; and • co-ordination with regulators and authorities in the event of serious incidents. These structures are particularly critical for automat - ed and connected vehicles, where large fleets may require co-ordinated updates and communication across several countries. Market Practice and Client Expectations in Austria In the Austrian market, these trends are reflected in the type of mandates and questions that companies bring to legal advisers. Manufacturers and suppliers of automotive and technical products no longer ask only whether a particular design choice complies with a standard. They also want to understand how courts might view a complex chain of software-driven events and what kind of documentation will be helpful in defending a claim. In practice, specialised product liability counsel are increasingly asked to: • review product safety concepts for automated functions, including warning strategies and user interaction;
44 CHAMBERS.COM
Powered by FlippingBook