Software as a defective product as of 9 December 2026
Why limitation of liability clauses in terms and conditions will not protect you
A software supplier has a carefully set liability cap in their terms and conditions, relying on it to protect them from heavy damages. As of December 9, 2026, under a European directive that the Czech Republic must implement by then, new rules will apply to new products, including software, which exclude contractual limitations of liability towards an injured person. Lawyers from the Prague-based ARROWS law firm will structure your contracts to withstand these changes.

Executive Summary
What changes on 9 December 2026 and who is affected
Directive (EU) 2024/2853 replaces the previous Directive 85/374/EEC from 1985 and member states must transpose it by 9 December 2026 (Directive (EU) 2024/2853). It will apply to products placed on the market or put into service after this date; the original regulation continues to apply to older products (Articles 2, 21 and 22).
The main change is that software is now explicitly considered a product. The term includes applications, firmware, and artificial intelligence systems, whether they are part of a device or supplied separately, via the cloud, or as a service (recital 13); mere source code is not a product. Conversely, the current rule under Czech legislation refers to a movable thing intended to be placed on the market (Section 2939 of the Czech Civil Code), so for purely digital products, it is uncertain whether today's regulation applies to them.
It is important to note who holds the claim. The Directive only protects natural persons and covers death or personal injury, including medically recognized psychological harm, damage to property, and loss or destruction of data not used for professional purposes; damage to the defective product itself and to property used exclusively for professional purposes is excluded (Articles 5 and 6). Therefore, a company that purchased software for manufacturing operations will generally not be able to invoke the new product liability, but claims can be made by individuals without a contract with the supplier, such as a consumer or an employee of another company.
This is precisely why the topic also concerns suppliers who sell exclusively to businesses. The injured party can turn to both the manufacturer of the product and the manufacturer of the defective software component, and they are jointly and severally liable (Article 8(1)(b) and Article 12(1)). A B2B software supplier may thus face a claim directly, or recourse from the device manufacturer, even if they have never dealt with the injured party.
Custom software can fall under the new regime just like software sold en masse. The Directive explicitly exempts only free and open-source software developed or supplied outside the course of a commercial activity (Article 2(2)); the fact that the software was created for a single customer does not change this. The decisive factor is whether it was supplied in the course of a commercial activity, placed on the market or put into service, and whether a natural person suffered damage.
The Czech amendment has not yet been adopted. The Government submitted a proposal to the Chamber of Deputies that rewrites Sections 2939 to 2943 of the Czech Civil Code on 3 September 2026 as Chamber Press 295; according to the Chamber's overview as of 7 October 2026, the first reading has not yet taken place and the discussion is proposed for the session starting 13 October (history of Press 295). The proposed effective date is 9 December 2026, and the new regulation would apply to products placed on the market or put into service from the effective date of the act.
Today's regulation under Czech legislation contains, for example, a rule that damage to property is only compensated in an amount exceeding EUR 500 converted at the exchange rate of the Czech National Bank (Section 2939(3)). The Directive does not recognize such a threshold and the government proposal repeals this rule; however, until the amendment is effective, today's wording applies. Companies should therefore not build their business model on one wording or the other, but on a risk allocation that will stand up under both regulations.
Why limitations in terms and conditions do not protect against the injured party
According to the Directive, the liability of the economic operator towards the injured party may not be limited or excluded by a contractual provision or by national law (Article 15). A classic clause according to which the supplier is liable up to the price of the contract does not work against a person who suffered damage, even if it was properly negotiated between businesses and signed by both parties.
Furthermore, terms and conditions were never intended to bind a third party. Part of the content of a contract can be determined by reference to terms and conditions that the proposer attaches to the offer or that are known to the parties (Section 1751(1) of the Czech Civil Code), but a contract binds its parties. The injured person did not enter into such a contract and therefore cannot be limited by its cap.
Moreover, the prohibition on limiting liability already exists today for intentional harm and gross negligence: no regard is paid to an agreement that excludes or limits in advance the obligation to compensate for harm caused intentionally or through gross negligence, or harm to a person's natural rights (Section 2898 of the Czech Civil Code). The Directive goes further for products because the prohibition applies to liability for product defects as such, i.e., even without intent and gross negligence.
This does not mean that limitations will lose their meaning entirely. Between the supplier and its business customer, the cap remains valid within the limits of the law. The Directive leaves recourse between economic operators to national law (Article 14) and, in the case of small software manufacturers, explicitly allows for a contractual waiver of recourse (Article 12(2)). However, this must not affect the claim of the injured party, and therefore the cap must be read as a tool for the relationship between businesses, not as protection against a lawsuit by an individual.
The practical risk lies in the fact that companies already count on the limitation clause when calculating the price. If the cap means that the maximum loss will not exceed the price of the contract, and in reality it does not apply to the injured person, the supplier is underestimating its risk. The contract price, insurance coverage, and reserves should therefore be calculated according to the liability towards the injured party, not according to the cap that only applies in relation to the business customer.
Imagine a supplier of control software for manufacturing equipment. An employee of the end customer suffers an injury due to an error caused by the software. They can assert a claim against both the equipment manufacturer and the supplier of the software component, provided it was integrated into the equipment or interconnected with it under the manufacturer's control and caused its defectiveness. If the equipment manufacturer pays, they will turn to the supplier for recourse. The cap in their terms and conditions will at most regulate this recourse between the businesses, not the claim of the injured person.
Software, updates and components: who is liable for whom
According to the Directive, the manufacturer of a defective software component can be held directly liable, jointly and severally with the manufacturer of the product (Article 8(1)(b) and Article 12(1)). The condition is that the component was integrated into the product or interconnected with it under the control of its manufacturer and caused its defectiveness. A component also includes a related digital service without which the product could not perform one of its functions. The circle of liable persons is wider and includes, for example, importers, so that there is always a person in the EU against whom a claim can be made.
Whoever compensates the injured party has a right of recourse against the other liable entities under national law (Article 14). Furthermore, the component supplier is exempt from liability if they prove that the defect in the product is attributable to the design of the product or to the instructions given by the manufacturer of the product to the component supplier (Article 11(1)(f)). Therefore, it makes sense to keep the customer's specifications and instructions.
For small software companies, an important exception applies: a manufacturer who has integrated software from a micro-enterprise or small enterprise into their product does not have a right of recourse against its manufacturer if they have contractually waived it (Article 12(2)). The Czech draft bill does not adopt this provision because, according to the explanatory memorandum, Czech legislation already allows for a contractual waiver of recourse. Liability towards the injured person is not limited by this.
Updates are not excluded from liability. A manufacturer cannot defend themselves by claiming that the defect arose after the product was placed on the market if it was caused by software, including an update or a lack of an update necessary to maintain safety, and it was under their control (Article 11(2)). At the same time, the Directive does not impose an obligation to provide updates, and liability does not apply to cases where the delivery or installation is outside the manufacturer's control, for example, when the owner does not install the supplied update (recital 51).
The practical impact is twofold. The supplier must monitor how their software behaves after being placed on the market, because for software under their control, liability does not end with the delivery of the product. At the same time, they need information from the customer on how the software is deployed, because without it they cannot assess whether the damage was caused by their error or by incorrect use.
The new regulation will also be reflected in transactions. During due diligence, the buyer of a software company will want to know how the company contractually allocates the risk of liability for damage, whether it keeps records of versions and components, and what its insurance coverage is. A company with a clear process can sell under better conditions because the buyer does not have to factor into the price an uncertainty they would otherwise be unable to value.
In relation to the customer, if a debtor performs with the help of another person, they are liable as if they performed themselves (Section 1935 of the Czech Civil Code). In the case of liability for damage, it must be assessed separately whether the third party acts as an assistant within the meaning of Section 2914, or as someone who undertook to perform the activity independently; for the latter, one is only liable in the event of careless selection or insufficient supervision. How this applies to a third-party library integrated into a product depends on the specific relationship, and recourse against the subcontractor should therefore be included in the contract with them.
This is where the value of component tracking, which companies often postpone until an incident occurs, becomes apparent. A company that knows what third-party code is running in the product, in what version, and from whom, can quickly identify the source of the error and seek recourse. A company without an overview of its own product risks bearing the entire damage because it cannot document where the defect originates.
How to adjust terms and conditions and contracts before December
The first step is to separate two levels that are often mixed up in terms. One is the supplier's relationship with the business customer, where the liability cap can remain, and the other is the liability towards an individual, which the cap will not limit. If the terms speak generally of excluding "all liability for damage," it is advisable to rewrite them so that they apply only to the relationship between the contracting parties.
The second step is to adjust the recourse between businesses. The contract with the customer should determine who will bear the damage compensated to the injured person and to what extent it can be further transferred to the supplier. Without such an agreement, recourse is governed by general rules under Czech legislation, and the extent will only be decided by a dispute, where the evidentiary situation often turns out worse for the party that has no records.
The third step is to record what version of the product was placed on the market and when. The new rules are linked to the moment of placing on the market or putting into service, and the right to compensation expires ten years from that moment, or in the case of a substantially modified product, from its new placing on the market (Article 17). A supplier who cannot document this moment cannot reasonably argue that the original regulation applies to their older version or that the limitation period has expired. Version tracking is therefore one of the cheapest protections.
The fourth step is to address updates and support. The contract should specify how long and to what extent security patches are provided, who is responsible for their installation at the end-user level, and what happens after support ends. A similar logic of contractual service quality assurance is also discussed in the text on contractual assurance of availability and quality of cloud services.
The fifth step is to consider how the new risk will be reflected in insurance coverage. The scope of coverage and its limits need to be compared with the fact that liability towards injured individuals cannot be contractually limited; related issues are discussed in the text on cyber risk insurance. The agreed insurance limit should correspond to what the company actually risks, not what it would like to risk.
The sixth step is to arrange cooperation in investigating damage. The customer should notify the supplier without undue delay that damage or a defect has appeared, and provide logs, versions, and deployment circumstances. Without such cooperation, the supplier from whom recourse is sought has no way to defend themselves, and disputes over the cause are conducted without evidence. The parties can also agree on a joint approach towards the injured party or their insurer.
It can be expected that large customers will start requiring explicit assumption of recourse and documentation of version tracking in their purchasing terms. A supplier who has thought through these issues in advance negotiates from a position of a partner, not a petitioner. A ready-made draft of a recourse clause and obligations during damage investigation can then shorten contract negotiations by weeks.
A comprehensive view of what an IT contract must contain is offered in the text on ordering custom software or SaaS. It is wise to incorporate the new product liability into such a contract now, because changing the contract after damage occurs will no longer solve anything, and the negotiating position generally deteriorates after an incident.
What to do by December
The practical schedule is simple. By the end of October, it is advisable to review all contract templates and terms and conditions and mark provisions that limit liability for damage, and by the end of November, split them into a part for the relationship with the customer and a part that must also stand up against the injured party. The last weeks before December then belong to version and component tracking.
It is suitable to prepare the adjustment so that after the amendment is approved, it can be supplemented without having to rewrite entire contracts. It is practical to separate the general provision on recourse and tracking from provisions that refer to specific sections, because it is the references that will change after the act is adopted. The company can then implement the templates immediately and, after the act is promulgated, adjust only a short reference article instead of opening the contracts a second time.
The order of adjustments should be guided by risk. First come products that reach consumers or households, and products whose failure can endanger health, because that is where the probability of a claim by a natural person is highest. Purely industrial tools with no link to human health and property can wait, but even for them, it is reasonable to unify the contract template.
The company should also designate a person responsible for tracking products and updates. Without them, gaps arise in practice where the technical team knows what has been deployed, but the legal department does not, and it is this gap that delays recourse. It is equally important to monitor the status of the Czech amendment, because its final wording will determine a number of details, such as the exact circle of liable persons or transitional rules.
How exactly to adjust contract templates and tracking for a specific product depends on whether the company only develops software or also integrates it into hardware, and on who they sell it to – which is why the Czech legal team at ARROWS law firm always assesses this based on the specific product and supply chain, not according to a universal template of terms.
Risks of liability limitation for software after 9 December 2026
Risk in the company | How ARROWS will review and secure it |
Terms and conditions limit "all liability for damage" in one sentence. Such a clause does not work against the injured person, and the company is unaware of this. | We will split the clause into the relationship with the customer and liability towards the injured party. We will prepare and review the contractual documentation. |
The contract with the customer does not address recourse. The company compensates the injured party and is unclear about what it can transfer further. | We will negotiate the scope and conditions of recourse between businesses. We will negotiate the conditions directly with the counterparty. |
There is no version and component tracking. The company cannot document when the version was placed on the market and where the defect originates. | We will set up version and component tracking and contractual obligations of suppliers. We will provide an expert legal opinion on setting up the process. |
Updates and support periods are not agreed. Depending on the circumstances, liability for damage from an unpatched error can last even after the cooperation ends. | We will incorporate security patches, support periods, and installation liability into contracts. We will verify the enforceability of clauses before signing. |
Final summary
From 9 December 2026, a new regulation of product liability under the European Directive is to apply in the Czech Republic, which explicitly includes software and does not allow limiting liability towards the injured party by contractual provisions. The Czech amendment has not yet been adopted, and therefore its status must be monitored. The article showed that terms and conditions with a liability cap protect the supplier only in relation to the customer, that the claim primarily concerns natural persons, and that version, component, and recourse tracking is decisive.
For the management of a software company, this implies a clear task: rewrite contract templates to separate the relationship with the customer from liability towards the injured party, and implement version and support tracking by December. A change after damage occurs will no longer help, because the new rules are linked to the moment the product is placed on the market.
The Prague-based legal team at ARROWS law firm adjusts terms and conditions and IT contracts for the new product liability regime, sets up recourse between businesses and version tracking, and helps negotiate changes with customers. Write to us at consultation@arws.cz or review our contracts and negotiation practice.
About the author
Disclaimer:
The information contained in this article is for general informative purposes only and serves as a basic guide to the issue under the legal status as of 2026 under Czech legislation. Although we ensure maximum accuracy of the content, legal regulations and their interpretation evolve over time. We are ARROWS advokátní kancelář, a Prague-based law firm registered with the Czech Bar Association (our supervisory authority), and for the maximum security of our clients, we hold professional indemnity insurance with a limit of CZK 350,000,000. To verify the current wording of the regulations and their application to your specific situation, it is necessary to contact our Czech legal team at ARROWS advokátní kancelář directly (consultation@arws.cz). We accept no liability for any damages arising from the independent use of the information in this article without prior individual legal consultation.

