The EU Product Liability Directive will take effect Dec 2026. Software, firmware, applications, AI systems, and will now be subject to the same strict liability regime as traditional physical goods. Cybersecurity vulnerabilities will be considered product defects. Analysis by Reed Smith LLP: https://www.lexology.com/library/detail.aspx?g=bbef1939-2af0-465a-8b8f-c1ff3ebe9118

@Weld I'm curious how "Companies cannot contractually exclude or limit their liability under the PLD, and disclaimers for software defects or security vulnerabilities are not valid." works with FOSS. Am I now exposed even if I leave a copy of my software in a repo somewhere; or is it only if I actually sell it to you?

If the former that seems apocalyptic; if the latter it seems like all software will either be free or eleventy-billion euros.