In short
  • Article 9(1) of Directive (EU) 2024/2853 requires a defendant to disclose relevant evidence at its disposal when a claimant has presented facts and evidence sufficient to support the plausibility of a compensation claim. Disclosure is limited to what is necessary and proportionate, and courts must be able to protect trade secrets.
  • Article 10(2)(a) presumes the product defective where the defendant fails to disclose. Evidence that does not exist, cannot be retrieved or cannot be understood is, in effect, a presumption against the manufacturer.
  • Article 10(4) lets a court presume defectiveness, causation or both where technical or scientific complexity makes proof excessively difficult and the claimant shows the defect or the causal link is likely. Recital 48 names machine learning and the inner workings of an AI system as examples. Every presumption is rebuttable under Article 10(5), and rebuttal is done with evidence.
  • There is a retention gap. The AI Act sets a minimum of six months for automatically generated logs (Articles 19 and 26(6)) and ten years for provider technical documentation (Article 18). The Directive's expiry period is ten years from placing on the market, restarting on substantial modification. Logs kept to the minimum will be gone long before a claim can arrive.
  • This framework therefore assesses evidence for five properties: it exists, it is retained for the exposure period, it can be retrieved for a specific product version and date, it can be presented intelligibly, and trade secrets in it can be separated from the rest.

What Article 9 allows a court to order

Article 9(1) has two conditions and one consequence. The person claiming compensation must be in proceedings before a national court, and must have presented facts and evidence sufficient to support the plausibility of the claim. The consequence is that the defendant is required to disclose relevant evidence that is at its disposal. The threshold is plausibility. It is lower than proof, and it is meant to be: recital 42 records that claimants are often at a significant disadvantage in access to, and understanding of, information on how a product was produced and how it operates, in particular in cases involving technical or scientific complexity.

Three limits follow. Disclosure is limited to what is necessary and proportionate (Article 9(3)). In deciding that, the court considers the legitimate interests of all parties, including third parties, in particular the protection of confidential information and trade secrets (Article 9(4)). And where a trade secret has to be disclosed, the court must be empowered to take specific measures to preserve its confidentiality during and after the proceedings (Article 9(5)). Recital 45 gives examples of such measures, including restricting access to documents and hearings and allowing access only to redacted versions.

Two further provisions matter for how evidence is kept. Under Article 9(6) the court can require evidence to be presented in an easily accessible and easily understandable manner, where it considers that proportionate in terms of cost and effort. And recital 42 states that the evidence to be disclosed includes documents that have to be created ex novo by the defendant by compiling or classifying the available evidence. A manufacturer can therefore be asked to assemble and explain, and not only to hand over what happens to be lying in a repository.

The mechanism runs both ways. Under Article 9(2) a defendant that shows it needs evidence to counter the claim can ask for disclosure from the claimant. And it has edges the Directive leaves to national law: recital 43 lists pre-trial procedures, how specific a request must be, third parties, declaratory actions and sanctions for non-compliance as matters the Directive does not regulate.

The four presumptions in Article 10

Article 10(1) keeps the starting point of the 1985 regime: the claimant proves defectiveness, damage and the causal link. Paragraphs 2 to 4 then set out the situations in which part of that burden is lifted.

Failure to disclose. Defectiveness is presumed where the defendant fails to disclose relevant evidence pursuant to Article 9(1). Recital 46 describes this as an incentive to comply with the obligation to disclose.

Non-compliance with mandatory product safety requirements. Defectiveness is presumed where the claimant demonstrates that the product does not comply with mandatory product safety requirements laid down in Union or national law that are intended to protect against the risk of the damage suffered. Recital 46 adds that this includes cases in which a product is not equipped with the means to log information about the operation of the product as required under Union or national law.

Obvious malfunction. Defectiveness is presumed where the claimant demonstrates that the damage was caused by an obvious malfunction during reasonably foreseeable use or under ordinary circumstances.

Excessive difficulty. Under Article 10(4), a court presumes defectiveness, the causal link, or both, where despite disclosure the claimant faces excessive difficulties, in particular due to technical or scientific complexity, and demonstrates that it is likely that the product is defective or that there is a causal link. Recital 48 lists the factors: the complex nature of the product, the complex nature of the technology used, "such as machine learning", the complexity of the information and data to be analysed, and the complexity of the causal link, including one that would require the claimant "to explain the inner workings of an AI system". The same recital states that a claimant in a case concerning an AI system should not be required to explain the system's specific characteristics, nor how those characteristics make the causal link harder to establish, in order for the court to find that excessive difficulties exist.

Separately, Article 10(3) presumes the causal link where the product has been established to be defective and the damage is of a kind typically consistent with the defect.

Article 10(5) gives the defendant the right to rebut any of these presumptions. The recital is careful to describe the design as alleviating the burden of proof while avoiding a reversal of it. The fourth presumption is the one most visibly written with AI products in mind, and where it applies the question that decides the outcome is whether the manufacturer has the evidence to rebut it.

What a manufacturer would need to show

The Directive does not list the evidence a manufacturer should hold. It does list, in Article 7(2), the circumstances a court takes into account when assessing defectiveness, and that list reads as an index of what rebuttal evidence has to address.

  • Presentation and instructions (point a): the labelling, design, technical features and the instructions for installation, use and maintenance. For an AI system this is the stated intended purpose, the stated limits, and what the user was told.
  • Reasonably foreseeable use (point b). Recital 46 describes this as covering intended use, ordinary use as determined by design, and use that can be reasonably foreseen from lawful and readily predictable human behaviour.
  • The effect of any ability to continue to learn or acquire new features after placing on the market (point c).
  • The effect of other products that can be expected to be used together with it, including by inter-connection (point d). For agents, that is the tools, plugins and data sources they call.
  • The moment in time the product was placed on the market or, where the manufacturer retains control, the moment it left that control (point e).
  • Product safety requirements, including safety-relevant cybersecurity requirements (point f).
  • Any recall or other safety intervention by an authority or an economic operator (point g).
  • The specific needs of the group of users for whose use the product is intended (point h).

Each point corresponds to artefacts this framework already looks for: the intended purpose statement and user-facing disclosures under trust and transparency, test results and drift monitoring under performance and reliability, the tool and dependency map under integration, release history under change control, and adversarial testing under security and resilience. What the Directive changes is the standard those artefacts are held to. An artefact that satisfies a checklist may not survive being read by an opposing expert.

Five properties of disclosable evidence

Reading Articles 9 and 10 together, evidence protects a manufacturer only if it has five properties. They are this framework's reading of what the two articles require in practice. The Directive does not enumerate them.

It exists. The first presumption attaches to a failure to disclose. A manufacturer that never recorded its pre-release testing cannot disclose it, and the absence is treated in the same way as a refusal would be. Reconstruction after the event is possible, since recital 42 contemplates documents created ex novo, but only by compiling evidence that is actually available.

It is retained for the exposure period. This is where most files will fail, and the next section deals with it.

It can be retrieved for a version and a date. A claim concerns a specific product as it stood when it caused damage. The evidence has to answer what the system was on that date: which model version, which system prompt or configuration, which retrieval corpus, which tools. A file that describes only the current state of a system describes a different product from the one in the claim.

It can be presented intelligibly. Article 9(6) allows a court to require evidence in an easily accessible and easily understandable manner. Raw logs in a proprietary format, without a schema or an explanation of fields, meet the letter of disclosure and lose the argument. A short explanatory layer, kept current, is part of the evidence.

Trade secrets can be separated from the rest. Articles 9(4) and 9(5) protect confidential information through measures the court orders, and those measures work document by document. A file in which model weights, training data details, customer data and test results are mixed together makes every request a confidentiality dispute. A file structured so that the sensitive layer is identifiable makes proportionate disclosure possible.

The retention gap: six months against ten years

The AI Act sets retention periods for high-risk systems, and they are not aligned with the Directive's exposure period.

For providers, Article 18(1) of the AI Act requires the technical documentation, the quality management system documentation and the declaration of conformity, among other documents, to be kept for ten years after the system has been placed on the market or put into service. That matches the length of the Directive's expiry period.

For logs it does not. Article 19(1) requires providers to keep automatically generated logs, to the extent they are under their control, for a period appropriate to the intended purpose of the system, "of at least six months", unless Union or national law provides otherwise. Article 26(6) sets the same minimum for deployers. Six months is a floor and the operative test is appropriateness, but a retention schedule written to the floor satisfies the words of the AI Act.

Against that, Article 16 of the Directive gives an injured person three years from awareness of the damage, the defectiveness and the identity of the operator, and Article 17 ends the right to compensation ten years after the product was placed on the market or put into service, or twenty five years where a personal injury was latent. Under Article 17(1)(b) the ten years restart when a product is substantially modified, which recital 40 says can happen through a software update or the continuous learning of an AI system. The temporal analysis is at agentliability.eu, on which regime applies to AI already on the market.

The logs are the evidence most likely to show what a system actually did on the day of the damage. A manufacturer that deletes them at six months will, in a claim brought in year three, be able to disclose its documentation and unable to disclose the operational record. Whether that amounts to a failure to disclose under Article 10(2)(a) is for a court. It is not a position to choose by default. A retention decision for logs should be taken deliberately, with the limitation and expiry periods and data protection law in view, and the reasoning recorded. Note also that these AI Act provisions are high-risk obligations, which after Regulation (EU) 2026/1744 apply from 2 December 2027 for Annex III systems, while the Directive applies to every AI product placed on the market after 9 December 2026, whether high-risk or not. For systems outside the high-risk category, no AI Act retention rule applies at all and the Directive's periods are the only guide.

How this framework assesses it

For AI products supplied to natural persons in the Union, or capable of causing the kinds of damage in Article 6 of the Directive, the assessment now includes a disclosure test. The assessor picks a past date and a product version and asks the organisation to produce, within a fixed time, the intended purpose statement in force on that date, the configuration and model version, the test evidence that supported release, the change record since the previous version, and a sample of operational logs with an explanation a non-specialist could follow. The test is scored on what is produced and not on the existence of a policy that says it could be.

The test is designed to surface three weaknesses that a document review does not. Evidence that exists but is tied to people and not to versions, so that it cannot be retrieved once those people have moved on. Logs kept for whatever period a vendor's default sets, which nobody in the organisation chose. And a missing explanatory layer, so that the organisation's own staff cannot read its older records. Each is inexpensive to fix before a claim and difficult to fix after one.

The starting point for an organisation that has not done this is the inventory. An evidence file is kept per product and per version, and that presupposes a list of what the products and versions are: see the AI asset inventory as the first evidence artefact. How the same evidence is read by an underwriter is covered at agentinsured.eu, on the documentation and insurance evidence chain.

A certificate is not a defence under the Directive, and this framework does not present one as such. The Directive contains no safe harbour for certified products. Article 11 lists the exemptions from liability, and certification is not among them. What certification can do is narrower and still worth having: it forces the evidence to exist, to be retained, and to be tested for retrievability by somebody other than its author, before the first time it matters.

Questions

When can a court order an AI manufacturer to disclose evidence under the Product Liability Directive?

Under Article 9(1) of Directive (EU) 2024/2853, when a person claiming compensation in proceedings before a national court has presented facts and evidence sufficient to support the plausibility of the claim. The defendant is then required to disclose relevant evidence at its disposal. Disclosure is limited to what is necessary and proportionate, and the court must consider the protection of confidential information and trade secrets. The Directive applies to products placed on the market or put into service after 9 December 2026.

What happens if the manufacturer does not disclose?

Article 10(2)(a) provides that the defectiveness of the product shall be presumed where the defendant fails to disclose relevant evidence pursuant to Article 9(1). The presumption can be rebutted under Article 10(5), but a manufacturer that lacks the evidence to disclose will generally also lack the evidence to rebut.

Does the Directive make it easier to prove that an AI system was defective?

Yes, in defined circumstances. Article 10(4) requires a court to presume defectiveness, the causal link or both where, despite disclosure, the claimant faces excessive difficulties due in particular to technical or scientific complexity and shows that the defect or causal link is likely. Recital 48 gives machine learning and the need to explain the inner workings of an AI system as examples, and says a claimant should not have to explain the AI system's specific characteristics for the court to find excessive difficulty.

How long should AI logs be kept in light of the Directive?

The Directive sets no retention period. The AI Act sets a minimum of six months for automatically generated logs of high-risk systems, for providers in Article 19(1) and deployers in Article 26(6), subject to a period appropriate to the intended purpose. The Directive's limitation period is three years from awareness and its expiry period is ten years from placing on the market, restarting on substantial modification. Logs kept only to the six month minimum will not be available for most claims. The retention decision should be deliberate, recorded, and consistent with data protection law.

Can trade secrets be protected when evidence is disclosed?

Yes. Article 9(4) requires courts to consider the protection of confidential information and trade secrets when deciding whether disclosure is necessary and proportionate, and Article 9(5) requires that courts be empowered to take specific measures to preserve confidentiality during and after proceedings. Recital 45 mentions restricting access to documents and hearings and allowing access only to redacted documents. Evidence that is structured so the confidential layer can be identified makes those measures workable.

Is a certified AI product protected from product liability claims?

No. The Directive contains no safe harbour for certified products, and the exemptions from liability are listed in Article 11. Certification is relevant as a discipline: it causes the evidence to exist, to be retained and to be tested for retrievability before a claim, which is what a manufacturer needs in order to meet a disclosure order and rebut a presumption.

Sources and basis

Sources

  • Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products. Articles 2(1), 6, 7(2), 9, 10, 11, 16 and 17, and recitals 40, 42, 43, 45, 46 and 48, read in the Official Journal text served by the Publications Office of the European Union at publications.europa.eu on 18 September 2026. Quotations are verbatim from that text.
  • Regulation (EU) 2024/1689 (EU AI Act), Article 18(1) (documentation keeping, ten years), Article 19(1) (provider logs, at least six months) and Article 26(6) (deployer logs, at least six months), read at the European Commission AI Act Service Desk: Article 18, Article 19, Article 26, on 18 September 2026.
  • Regulation (EU) 2026/1744 (the AI Omnibus), under which Annex III high-risk obligations apply from 2 December 2027, as published by the European Commission at digital-strategy.ec.europa.eu.
  • The five properties of disclosable evidence, the disclosure test and the three weaknesses it is designed to surface are this framework's own methodology. They are not requirements stated in the Directive and are not attributed to any court, authority or insurer.
  • No national transposition measure has been read for this article. Procedural rules on disclosure, including sanctions for non-compliance, are left by recital 43 to national law and are not described here.