In the European Union, software and AI systems are now defined as products, and from 9 December 2026 they are subject to strict liability. In the United States, courts are hearing claims against chatbot companies as product liability cases and deciding the question case by case. In Israel, the 1980 statute does not mention software, and whether it applies has not been decided.
LEGISLATIVE UPDATE
Directive (EU) 2024/2853 on liability for defective products was published in the Official Journal of the European Union on 18 November 2024 and replaces the 1985 directive. Member States must transpose it by 9 December 2026, and it applies to products placed on the market or put into service after that date. Products placed on the market earlier remain subject to the old directive.
CONTENTS
- Why it matters whether an AI system is a product or a service
- The two leading cases in the United States
- The European directive: software is a product, even when supplied as a service
- The link to the AI Act
- Israeli law
- Software inside a physical product
- What this means for manufacturers and providers of AI systems
1. Why it matters whether an AI system is a product or a service
Liability for a defective product is strict liability. The injured person must prove that the product was defective and that the defect caused the harm, but need not prove that the manufacturer was negligent. A person who provides a service is subject to the law of negligence, under which the injured person must prove that the provider failed to take the precautions a reasonable provider would have taken. The difference has practical consequences. A negligence claim against an AI company requires proof of what the company knew about the risk, what testing it carried out and what design alternatives were available to it, and all of that information is held by the company. In a product liability claim the inquiry turns to the product itself: whether its design is reasonably safe, and whether adequate warnings were given.
In the United States the question carries a further consequence. Technology companies defend claims about content with two main arguments: that the content is speech protected by the First Amendment, and that a company operating a platform is not liable as the publisher of content created by others, under Section 230 of the Communications Decency Act. A plaintiff who frames the claim as one of defective design, pointing for example to memory of earlier conversations, a character that imitates a person, the absence of age verification or the absence of a mechanism that stops a dangerous conversation, moves the inquiry from the text the system produced to the way it was built. Both of the cases described below were pleaded in this way.
The distinction works the same way in Israel. The Defective Products Liability Law, 5740-1980, imposes strict liability on the manufacturer of a product, and a person harmed by a service must sue in negligence under the Civil Wrongs Ordinance.
2. The two leading cases in the United States
Garcia v. Character Technologies
Character.AI is a platform on which users converse with virtual characters that behave like people. Sewell Setzer, a 14-year-old from Florida, talked with characters on the platform for months. According to the complaint, his relationship with one character became emotional and sexual, and when he wrote to it about suicidal thoughts the system did not activate any meaningful safeguards. He took his own life in February 2024. In October 2024 his mother, Megan Garcia, sued Character Technologies, its two founders and Google in the federal court for the Middle District of Florida, pleading product liability for design defect and failure to warn, negligence and wrongful death. She alleged that the system was designed to create emotional dependency and was operated without safeguards for minors and without any warning to parents.
The company moved to dismiss on two main grounds: that the chatbot’s output is speech which users have a First Amendment right to receive, and that the chatbot is a service to which product liability law does not apply. On 21 May 2025 Judge Anne Conway denied most of the motion. She declined to hold at that stage that the output of a language model is protected speech, and held that the app could be treated as a product for the purposes of the claim, because the allegations were directed at specific design features. She also allowed the claim against Google to proceed on an aiding and abetting theory. The ruling was made at the pleadings stage, where the court assumes the facts alleged in the complaint to be true, so it did not hold that a chatbot is a product as a matter of law. In January 2026 the court was told of a settlement in principle, on confidential terms, covering this case and four similar ones, so the question was never decided.
Raine v. OpenAI
Adam Raine, a 16-year-old from California, started using ChatGPT in September 2024 for help with schoolwork. According to the complaint, the conversations gradually became personal, and over the following months he confided his suicidal thoughts to the chatbot. His parents allege that the chatbot validated those thoughts instead of directing him to help, discouraged him from confiding in his family, and kept engaging as his distress deepened. He took his own life in April 2025. On 26 August 2025 his parents, Matthew and Maria Raine, sued OpenAI and its chief executive, Sam Altman, in the San Francisco County Superior Court, pleading strict liability for design defect and failure to warn, negligence and wrongful death. The amended complaint further alleges that shortly before launching the GPT-4o model in May 2024 OpenAI relaxed the instruction requiring the chatbot to refuse conversations about self-harm, and that the model’s safety testing was carried out on single questions, while the teenager’s conversation with it ran for months.
In its answer filed in November 2025 OpenAI denied liability. It argued that the teenager had risk factors that predated his use of the chatbot, that he circumvented the safeguards by presenting his questions as being for a story or for research, that ChatGPT directed him to crisis resources and trusted people more than 100 times, and that the terms of use prohibit using the service for self-harm. Seven further claims on similar grounds were filed against OpenAI that same month. The case is now in discovery, within a coordinated proceeding in California that brings together the product liability claims against the company, and in that proceeding OpenAI describes ChatGPT as a software-based service. That is the question described in the previous section: if ChatGPT is a service, the plaintiffs will have to prove negligence.
Both cases show that in the United States the question whether a chatbot is a product or a service is being decided case by case, on the basis of the design features alleged. In the European Union the question has been settled by legislation, as the next section explains.
3. The European directive: software is a product, even when supplied as a service
The new directive keeps the principle of strict liability and expands the definition of “product” to cover software expressly, including operating systems, firmware, applications and AI systems. A developer or producer of software, including the provider of an AI system, is treated as a manufacturer. The recitals state that software is a product irrespective of how it is supplied: whether it is stored on a device, accessed through a communication network or cloud technologies, or supplied through a software-as-a-service model. For product liability purposes, the directive therefore removes the distinction between delivering a copy of software and giving access to it. The Court of Justice of the European Union took a similar direction in 2021, when it held in Software Incubator that software supplied by download is “goods” for the purposes of the Commercial Agents Directive. Information is not a product, so the directive does not apply to the content of digital files, such as media files or e-books, or to source code as such. Free and open-source software is excluded only where it is developed or supplied outside the course of a commercial activity; a commercial product built on open-source libraries is fully covered.
The directive also widens the heads of recoverable damage to include medically recognised psychological harm and the loss or corruption of data, and it widens the circle of liable operators to component manufacturers, importers, authorised representatives and fulfilment service providers. A manufacturer established outside the Union falls within its scope when it places the product on the Union market. Liability continues after the sale for defects that emerge while the product remains within the manufacturer’s control, for example through updates.
| Question | Directive (EU) 2024/2853 | Israel’s Defective Products Liability Law, 1980 |
|---|---|---|
| Is software a product | Yes, expressly, including AI systems and software as a service | The definition does not mention software; the question is undecided |
| Recoverable damage | Personal injury, including medically recognised psychological harm, property damage and data loss | Bodily injury only, including mental or intellectual impairment. Property damage is not covered |
| Fault | Not required | Not required |
| Easing the burden of proof | Presumptions of defect in defined situations, and power to order disclosure of technical documentation | Presumption of defect where the circumstances are more consistent with that conclusion |
| Contractual exclusion | Not permitted | A term excluding liability under the Law is void |
4. The link to the AI Act
One of the situations in which the directive presumes a product to be defective is non-compliance with mandatory safety requirements laid down in Union law, and those include the Artificial Intelligence Act, Regulation (EU) 2024/1689. A breach of an AI Act obligation therefore exposes a company to a fine from the supervisory authority and may also be relied on by an injured person in a civil claim. Courts may also order the manufacturer to disclose the technical documentation it holds, so the documentation a company prepares for AI Act compliance may become evidence in a claim against it.
The connection is most visible in the prohibition added to Article 5 of the AI Act, effective 2 December 2026, on systems that generate intimate imagery of an identifiable person without consent. A provider that has not implemented reasonable safeguards will be exposed to a fine under the prohibition and, where the system was placed on the market after 9 December 2026, to a civil claim by anyone harmed by it. We discussed the prohibition in The New Prohibition on AI-Generated Intimate Imagery.
5. Israeli law
The Defective Products Liability Law makes a manufacturer liable to compensate anyone who suffers bodily injury caused by a defect in a product, regardless of fault. “Product” is defined as “including a component and packaging of a product, a product attached to land, and a building”. The definition is inclusive rather than exhaustive, but it does not mention software, and we are not aware of any judgment deciding whether software or an AI system is a “product” for the purposes of the Law.
The narrow and the broad reading of “product”
The closest discussion of the question is in LCA 10011/17 Mi-Tal Engineering and Services Ltd v. Salman (19 August 2019). The case concerned a building contractor that refused to sell an apartment to an Arab couple, and the question was whether an apartment is a “product” under the Prohibition of Discrimination in Products, Services and Entry into Places of Entertainment and Public Places Law. It is relevant here because the justices had to interpret the word “product” in Israeli legislation, and one of them relied expressly on the Defective Products Liability Law. Justice Stein held that in ordinary usage a product is a movable object, relying on the legislative history of the Defective Products Liability Law: in the Knesset Constitution, Law and Justice Committee it was said that “the intention was that a product is movable property”, and the examples given were air-conditioning systems, electricity meters and heating systems. Justice Mazuz gave the term a broad meaning, citing among other things the Encouragement of Research, Development and Technological Innovation in Industry Law, 1984, which defines a product as “a tangible or intangible asset” including computer software. Justice Hendel left the question open. There is therefore no binding holding, but the judgment contains two opposing views from Supreme Court justices, and both bear on software.
What tax law can teach
A similar question has been considered in Israel in a different context, the taxation of payments to foreign software suppliers, where it decides between a royalty, which is subject to withholding tax, and business profits, which absent a permanent establishment in Israel are not. Income Tax Circular 13/2001 distinguishes between an outright sale of copyright, the sale of a copy of software, including by download, and the grant of a right to use software, and expressly excludes the provision of services. In Taxing SaaS Payments we proposed, among other tests for a cloud transaction, asking who controls the software: a supplier that keeps the servers and the software, updates the software and operates it on a continuing basis is providing a service. In Israel’s Tax Treaties and Payments for Software and Cloud we reviewed how royalties and software are defined in Israel’s tax treaties with different countries.
A chatbot meets that test clearly: the model and the code remain on the company’s servers, the company updates them constantly, and the user receives answers only. If an Israeli court were to ask, as tax law does, what exactly was supplied to the user, the answer would bring the chatbot closer to a service and send the injured person to the tort of negligence. On Justice Stein’s narrow reading that outcome is more likely. On Justice Mazuz’s broad reading, software can be a product irrespective of how it is supplied, which is also the approach the European legislature adopted. The question has not yet been considered by the courts in a product liability context.
If the Law applies
If a court holds that the Law applies to an AI system, three of its provisions will be central. First, bodily injury is defined to include mental impairment, which is the kind of harm at issue in most of the US chatbot cases. Second, a term excluding liability under the Law is void, so terms of use disclaiming liability will not operate as a contractual defence to a claim under the Law. Third, the manufacturer has a defence if, given the state of scientific and technological knowledge when the product left its control, it could not have known that the product did not meet a reasonable standard of safety. The more publicly documented the risks of language models and image generators become, the harder that defence is to invoke.
Proceedings brought in Israel
While the question of application remains open, a person harmed by a stand-alone AI system, such as a chatbot, will turn to the tort of negligence and must prove that the manufacturer fell below the standard of care expected of a reasonable software developer. The proceedings brought in Israel so far rest on other causes of action. In March 2026 the content creator Shir Shachaf sued X.AI Corp in the Tel Aviv Magistrates’ Court after Grok, the company’s chatbot, produced edited images of her in revealing clothing at the request of anonymous users. The claim relies on the Prevention of Sexual Harassment Law and the Protection of Privacy Law. In January 2026 a motion to certify a class action was filed in the Tel Aviv District Court against X and xAI on behalf of all women and girls who use X, whose images are accessible, and who experienced fear, anxiety or a loss of control because Grok could generate a sexualised depiction of them. The class is defined by the risk the system created, even where no image was actually generated, which comes close in substance to a design defect claim. Both proceedings are pending, according to media reports.
6. Software inside a physical product
The Israeli definition expressly includes a “component” of a product, and the Law provides that where the damage is caused by a defective component, both the manufacturer of the product and the manufacturer of the component are liable. Where an AI system is embedded in a physical product, such as a driver-assistance system in a car or software in a medical device, the physical product is plainly a “product”, and its manufacturer is liable for a defect in it whichever part failed. Whether the software developer is also liable as a component manufacturer depends on the same open question, whether software counts as a component. The distinction between a stand-alone system, which the Israeli Law may not reach, and a system integrated into a physical product currently determines the extent of exposure in Israel. Under the European directive it does not arise, because both are covered.
7. What this means for manufacturers and providers of AI systems
A manufacturer or provider that places an AI system on the Union market after 9 December 2026 is exposed to strict liability in every Member State for personal injury, recognised psychological harm, property damage and data loss, even if it supplies the system as a cloud service and wherever it is established. Terms of use excluding liability will not help it, and the documentation it prepared for the AI Act may be produced in court. A product placed on the market before that date stays under the old directive, so the date on which a product or a new version is placed on the market determines which law applies. The importer or authorised representative in the Union may be the first defendant, which makes the indemnity provisions in contracts with them, and appropriate insurance cover, important.
Outside the Union the question is open. In the United States exposure depends on whether a court treats the system as a product, and plaintiffs meanwhile plead their claims as design defects. In Israel the exposure is narrower while the question remains open, but it exists: a physical product with an integrated AI component is subject to the Law, and a stand-alone system is exposed to negligence claims, to claims under the sexual harassment and privacy statutes, and to class action motions. A party that uses an AI system without having developed it is also responsible for its output: in AAA 63194-08-25 Cohen v. Ramat Gan Municipality (23 March 2026) the Supreme Court stressed the need for human oversight and held that responsibility for the final output is not removed because a technological tool was used.
SOURCES
- Directive (EU) 2024/2853 of the European Parliament and of the Council on liability for defective products, Official Journal of the European Union, 18 November 2024, including recital 13
- Regulation (EU) 2024/1689, the Artificial Intelligence Act
- Judgment of the Court of Justice of the European Union in The Software Incubator Ltd v. Computer Associates (UK) Ltd, 16 September 2021
- Defective Products Liability Law, 5740-1980, sections 1, 2, 3, 4 and 7
- LCA 10011/17 Mi-Tal Engineering and Services Ltd v. Salman (19 August 2019)
- Income Tax Circular 13/2001, Classification of income from international transactions involving software
- AAA 63194-08-25 Cohen v. Ramat Gan Municipality (23 March 2026)
- Garcia v. Character Technologies, Inc., No. 6:24-cv-01903 (M.D. Fla.), order of 21 May 2025
- Raine v. OpenAI, No. CGC-25-628528 (Cal. Super. Ct., San Francisco), and the answer filed in November 2025
- Media reports on Shir Shachaf’s claim (March 2026) and on the class action motion against X and xAI (January 2026)
Questions and answers
What is the practical difference between a claim about a product and a claim about a service?
In a claim for a defective product the injured person must prove that the product was defective and that the defect caused the harm, without proving fault. In a claim about a service the injured person must prove that the provider was negligent, that is, failed to take the precautions a reasonable provider would have taken.
We are established outside the EU and supply an AI system from the cloud to customers in Europe. Does the directive apply to us?
Yes, for products placed on the Union market after 9 December 2026. The directive applies to software irrespective of how it is supplied, including software as a service. A manufacturer outside the Union falls within it when it places the product on the Union market, and the importer, authorised representative and fulfilment service provider may also be liable.
We use open-source libraries. Does that exempt us?
No. The exclusion covers only free and open-source software developed or supplied outside the course of a commercial activity. A commercial product built on such libraries is fully covered.
Our terms of use exclude liability. Is that enough?
Not for product liability. The European directive does not allow liability to be limited or excluded by contract, and under the Israeli Law a term excluding liability under the Law is void.
Can the maker of a chatbot be sued in Israel under the Defective Products Liability Law?
The question has not been decided. The statutory definition does not mention software, and in Mi-Tal Supreme Court justices expressed opposing views on the scope of the term “product”. While the question remains open, the route available to an injured person is negligence, which requires proof of fault.
