Skip to main content
50 days

Super Intelligence definition proposal due (60 days) · Nov 28, 2026 · See what changes

News

UK Law Commission: Software and AI as Products (Oct 2026)

The Law Commission wants software and AI systems treated as products under the Consumer Protection Act 1987. What changes, and a readiness checklist.

9 min readBy Johnie T YoungLast reviewed
UK Law Commission: Software and AI as Products (Oct 2026)

Image: Unsplash.

TL;DR: On October 8, 2026, the Law Commission of England and Wales opened a consultation proposing that software and AI systems be treated as "products" under Part 1 of the Consumer Protection Act 1987. That would put them inside a strict liability regime, where an injured consumer does not have to prove fault. Free software supplied in the course of business would count, there is no specific open-source exemption, and a faulty or missing update could make a product defective after it ships. Nothing has changed in law yet: responses close on 14 January 2027 and final recommendations are expected in late 2027.

Event date: October 8, 2026 (consultation opened, press release published). First reported: late on October 7, 2026 (Solicitors Journal), then October 8 (Legal IT Insider, Law Society Gazette, Solicitor News).

What the Law Commission published

The Law Commission published Consultation Paper 279 on product liability and a separate summary on October 8, 2026. The consultation runs from 8 October 2026 to 14 January 2027. Its terms of reference were published on 8 December 2025.

The law under review is Part 1 of the Consumer Protection Act 1987 (the CPA), which implements the 1985 European Product Liability Directive. It is a strict liability regime: consumers can claim for injury or certain property damage "caused by defective products without having to prove fault on the part of the defendant." The Commission's press release says that law "was introduced almost 40 years ago, before smartphones, apps, social media and artificial intelligence."

Professor Solène Rowan, Commissioner for Commercial and Common Law, said in the release: "As technology evolves, the law must evolve with it." Legal IT Insider reported the launch the same day as a consultation "to bring product liability law up to date", and Solicitor News described it as a framework update for "digital products, artificial intelligence, online marketplaces".

Law Commission press release of October 8, 2026 announcing a major overhaul of product liability law for the digital age

Screenshot: Law Commission press release, October 8, 2026 (lawcom.gov.uk). Open Government Licence v3.0.

Geography matters. The summary says the recommendations "only apply to England and Wales", but the CPA itself applies in England, Wales and Scotland, and the same regime applies in Northern Ireland under separate legislation. If you sell software to UK consumers, assume the debate covers you even if your company sits elsewhere.

Current law vs the proposals, side by side

This table is built only from the Commission's summary and press release. "Proposed" means a provisional proposal in a consultation, not a rule anyone must follow today.

Topic Current CPA position Provisional proposal
Software and AI systems Uncertain whether the definition extends to them; it was designed primarily with tangible goods in mind Products in their own right, whether embedded in a device, downloaded or accessed remotely
Social media features Same tangible-goods definition Design components and features in scope, including recommendation systems such as algorithms
Free products Same tangible-goods definition Supplied even with no payment, if made available in the course of business or with a view to profit
Open-source software No specific rule; supply outside the course of business and without a view to profit is not liable No specific exemption for non-commercial open source; the business or profit test decides
Updates A defect that arises after supply can fall outside liability A faulty update, or a missing update needed for safety, can make a product defective after supply
Who can be sued Producers, own-branders, importers, some suppliers Adds fulfilment service providers, "core participants" (including online marketplaces) and UK authorised representatives
Proving defect Claimant proves defect, with significant evidential hurdles in complex cases Rebuttable presumption of defect where evidence is exceptionally hard to get, with a risk-sharing mechanism
Data Not expressly addressed in the CPA Destruction and corruption of data compensable, unless the data is used exclusively for professional purposes
Property damage threshold No award unless the loss exceeds £275 £275 threshold removed
Mixed-use property Only property mainly in private use Mixed-use property covered, award reduced for the professional share
Psychiatric harm Within personal injury, but when it is compensable is uncertain New framework, including people who witness harm to a loved one
Time limits Three-year limitation, 10-year long-stop from supply Long-stop resets after a substantial modification by the producer; 25 years for latent personal injury
Development risks defence Available Retained and applied to all products and industries

What this means for software and AI suppliers

"Free" is not a safe harbour

The proposed supply rule covers products "made available without the user giving any monetary or other consideration for their use, provided they are made available in the course of business and/or with a view to profit." The summary gives the example of software made available free of charge "while generating revenue through associated support, maintenance or other services." A freemium AI app, or an open-source library with a paid support tier, sits inside that description.

On open source, the Commission says it is aware of concerns that strict liability could discourage collaborative development. It still does not propose a specific exemption, because "the critical question under the CPA is not whether software is open-source, but whether it is supplied in the course of business and/or with a view to profit." A hobbyist releasing code with no commercial angle stays outside under the existing rule for supply outside the course of business. A company shipping the same code as part of a paid offering may not.

Updates become a liability event

Today, a defendant can rely on the fact that a defect did not exist when the product was supplied. The summary says a producer "may cause a product to become defective after it has been supplied, for example by introducing a faulty software update or by failing to provide an update necessary to address a safety risk", and calls the current outcome unsatisfactory. Under the proposals, the state of scientific and technical knowledge would be assessed "at the time the product became defective, rather than at the time of supply."

Two related points for AI teams:

  • If a product is substantially modified within the original producer's control, the original producer "should remain liable for the damage caused by the modified product."
  • The Commission does not think an AI system's "ordinary self-learning" counts as a substantial modification. Routine learning after deployment would not, by itself, count as a modification.

Laptop showing code on a white desk next to a plant and a yellow mug, representing software that could be treated as a product under UK law

Image: Unsplash.

How the Commission would spot an "AI system"

Instead of a fixed definition, the summary lists features associated with AI systems: "machine operation, the generation of outputs from inputs, autonomy in the production of those outputs, the use of relevant development techniques, and the possibility of self-learning after deployment." It asks consultees whether these features are a helpful basis. It also asks whether information products, such as code meant for users to compile or "the sale of training data for large language models", should fall within scope. That question is open, not a proposal.

Marketplaces and distributors

The new "core participant" category would catch a person who "played a significant role in bringing a product to the UK market", "benefited financially from doing so" and had "direct or indirect control or decisive influence" over manufacturing or distribution. Fulfilment service providers would be liable only where no UK producer, own-brander, importer or UK authorised representative can be identified. The Law Society Gazette summarised the effect as: "Online marketplaces such as Amazon would be liable for harm caused by defects in products from businesses without a UK presence." App stores and AI model marketplaces will want to read the core participant test closely.

The evidence problem

The summary notes that in AI cases the developer typically has exclusive insight into "the system's design, training and operation." Where a claimant faces exceptional difficulty getting evidence, a presumption of defect would apply. In the press release's words, defendants "could seek to rebut the presumption or accept it, in which case the court would award partial compensation under a new risk-sharing mechanism." Your design, testing and update records become the material you would use to rebut it.

Law Commission summary of Consultation Paper 279, page 6: at a glance, the key provisional proposals

Screenshot: "At a glance" page of the Law Commission's summary of Consultation Paper 279, October 2026. Open Government Licence v3.0.

Readiness checklist: copy this for your team

None of this is law yet, so treat this as a list of records to start keeping now, not compliance steps. Each line maps to a proposal in the table above.

UK PRODUCT LIABILITY READINESS (Law Commission CP 279, consultation open to 14 Jan 2027)
Product / feature: ____________   Owner: ____________   Reviewed on: ____________

1. SCOPE
[ ] Is the software or AI feature available to UK consumers? (England, Wales, Scotland, NI)
[ ] Is it supplied in the course of business or with a view to profit,
    including free tiers funded by subscriptions, ads, support or services?
[ ] Is any open-source component shipped as part of a paid offering?

2. UPDATES
[ ] Log of every release: date, change, safety review sign-off
[ ] Named owner for safety-related patches and the time to ship them
[ ] Record of known safety risks and whether an update addressed each one
[ ] End-of-support dates published for each version

3. MODIFICATION AND AI BEHAVIOUR
[ ] List of who can substantially modify the product (us, partners, customers)
[ ] For AI features: what the model can learn after deployment, and how we monitor it

4. EVIDENCE FILE (to rebut a presumption of defect)
[ ] Design rationale and safety requirements for each AI feature
[ ] Training and evaluation records kept for the life of the product
[ ] Incident log linking each user harm report to the version in use

5. DATA AND DAMAGE
[ ] Can a defect destroy or corrupt user data? Which backups or restore paths exist?
[ ] Which users are consumers, which are professional, which are mixed?

6. SUPPLY CHAIN
[ ] Marketplaces, app stores and fulfilment partners we sell through
[ ] UK authorised representative named (if we have no UK entity)
[ ] Contract terms with upstream model or component providers on defects and updates

7. CONSULTATION
[ ] Decide whether to respond; owner and draft date before 14 Jan 2027
[ ] Questions from the full paper we want to answer (62 in total)

How to respond

The press release says people can respond "using the online form at https://lawcom.gov.uk/project/product-liability/ or by emailing [email protected]". The full paper contains the 62 consultation questions; the project page notes that the summary does not. The Commission says it wants to hear from consumers, businesses of all sizes, legal academics and practitioners, and that it will meet stakeholders during the consultation period.

Compare this with the EU, where the new Product Liability Directive "shall apply to products placed on the market or put into service after 9 December 2026." We cover that regime in our EU Product Liability Directive guide. A company selling into both markets will face the EU rules first, with the UK still deciding.

Our take

For small software and AI teams, the update rule matters more than the headline about AI being a "product". Under the proposals, shipping a faulty patch, or failing to ship a needed safety patch, could make you liable for a defect that did not exist on day one. A commit log shows what changed; it does not show why a known safety risk was or was not fixed. That record is cheap to start now and hard to rebuild later.

The open-source position is also sharper than many developers will expect. The Commission looked at the concern about discouraging collaboration and still chose the business-or-profit test over an exemption. If your company ships an open-source project with a paid support plan, the summary's own example describes you.

These are provisional proposals with 62 open questions, and the final report is not expected until late 2027. Anyone who disagrees with the update rule or the open-source position has until 14 January 2027 to say so, and after that the Commission's recommendations still need legislation.

Community reaction

We looked for a public discussion of this consultation on Reddit and Hacker News on October 9, 2026 and found none, so there is no community quote here yet. We will add one if a substantive thread appears.

Embedded media

The Law Commission did not publish a video or webcast for the launch, and a YouTube search for the consultation returned only law-firm webinars on product liability in general, none about this consultation, so there is no embed in this article.

How we checked this

We read the Law Commission's press release and project page, the summary of Consultation Paper 279 and the full paper (both PDFs, read with pdftotext), the EU directive on EUR-Lex, and reports from Legal IT Insider, the Law Society Gazette and Solicitor News: 8 sources, checked on October 9, 2026. Every number and date in this article maps to a row with a verbatim quote in our source log. Last reviewed: October 9, 2026.

Legal disclaimer

This article is published for informational and educational purposes only. It does not constitute legal, regulatory, or professional compliance advice and should not be relied upon as such. AI governance requirements vary by jurisdiction, industry, and organizational context. Always consult a qualified legal or compliance professional before implementing policies or making decisions with regulatory implications.

About the author

Johnie T Young

AI expert and governance practitioner helping small teams implement responsible AI policies. Specialises in regulatory compliance and practical frameworks that work without a dedicated compliance function.

  • AI governance practitioner
  • EU AI Act and GDPR specialist
  • AI risk management expert
  • Compliance frameworks for small teams