Ransomware: Should you pay?
David Reed on why the ransomware question rarely has a universal answer, and why the strongest position is having options before the attack happens.
Article
The European Union has modernized its product liability framework through Directive (EU) 2024/2853.
The Directive replaces the original 1985 Product Liability Directive and reflects the realities of modern digital and connected product ecosystems.
The revised framework expands the legal definition of products to include software, artificial intelligence systems, digital manufacturing files and digital services that are integral to a product’s operation.
For businesses operating within the EU market, these changes significantly increase liability exposure. Manufacturers, technology providers, and importers must reassess product safety governance, supply chain transparency, and insurance coverage.
This paper examines the Directive’s regulatory changes, emerging risk exposures, insurance implications, and strategic actions organisations should take before the implementation deadline in December 2026.
Over the past four decades, the nature of products has changed dramatically. Modern products increasingly combine physical components with software systems, artificial intelligence, and cloud‑based services. Connected vehicles, smart home devices, robotics, industrial automation platforms and medical devices all rely on complex digital ecosystems.
Traditional product liability frameworks were not designed to address the risks associated with software defects, algorithmic errors, cybersecurity vulnerabilities or remote updates. The EU’s revised Product Liability Directive aims to close these gaps by expanding liability rules to reflect the realities of the digital economy.
The Directive introduces several structural reforms that affect how liability is assigned.
Expanded Product Definition Software, AI systems and digital manufacturing files are now legally recognised as products.
These provisions significantly increase potential exposure for organisations involved in technologically enabled products.
The Directive introduces new categories of risk that organisations must address:
The insurance sector is expected to adapt to increased product liability risk driven by the Directive. Historically, product liability insurance focused primarily on manufacturing defects. The inclusion of software as a product introduces a hybrid exposure combining technology risk and product risk.
Insurers are expected to evaluate several factors when underwriting technology-enabled products:
Associated insurance costs may reflect increased uncertainty around emerging technologies such as AI.
Risk managers should review current product liability insurance policies to ensure that coverage adequately reflects modern digital exposures.
Areas requiring careful review include:
To address emerging risks, organisations may consider a layered insurance strategy.
Insurance should complement — not replace — operational risk management.
Best practice frameworks include:
The Directive will be implemented through national legislation across EU member states.
Key milestones include:
Organisations should begin preparation well before national legislation enters force.
To prepare effectively, organisations should adopt a structured readiness strategy.
| Risk category | Example exposure | Potential mitigation |
| Software defects | Firmware bug causing device malfunction | Robust QA testing and patch governance |
| Cybersecurity breach | Remote hacking leading to product failure | Security-by-design engineering |
| AI algorithm error | Autonomous decision causing unsafe behaviour | AI risk assessment frameworks |
| Supplier software failure | Third-party component introducing defect | Supplier contractual liability controls |
The Directive represents one of the most significant reforms of European product liability law in decades.
By recognising software and digital services as products, the Directive reflects the realities
of modern technology ecosystems while strengthening consumer protection.
Organisations that proactively strengthen governance frameworks, risk management processes and insurance programmes will be best positioned to manage the expanded liability landscape.
We are Sompo, a global provider of commercial and consumer property, casualty, and specialty insurance and reinsurance. Building on the 138 years of innovation of our parent company, Sompo Holdings, Inc., Sompo employs approximately 10,000 people around the world who use their in-depth knowledge and expertise to help simplify and resolve your complex challenges. Because when you choose Sompo, you choose The Ease of Expertise™.
“Sompo” refers to the brand under which Sompo International Holdings Ltd., a Bermuda-based holding company, together with its consolidated subsidiaries, operates its global property and casualty (re)insurance businesses. Sompo International Holdings Ltd. is an indirect wholly-owned subsidiary of Sompo Holdings, Inc., one of the leading property and casualty groups in the world with excellent financial strength as evidenced by ratings of A+ (Superior) from A.M. Best (XV size category) and A+ (Strong) from Standard & Poor’s. Shares of Sompo Holdings, Inc. are listed on the Tokyo Stock Exchange.
To learn more please follow us on LinkedIn.