Just after three in the morning on October 31, 2025, on the eastbound Loop 202 near the Dobson Road exit in Mesa, Arizona, a Tesla Model 3 is sitting still in a travel lane. Not on the shoulder, not in the breakdown lane. In the lane, in the dark, at the speed of whatever is coming up behind it. A Ford F-350 hits it square in the back. The Tesla’s driver dies at the scene. The Red Mountain Freeway stays closed for a couple of hours and reopens around a quarter to six, in time for the Friday morning commute.
Local news does its job, which at half past four in the morning is not much. Arizona’s Family writes that details are limited, that a Department of Public Safety spokesperson says two vehicles were involved and offers nothing on injuries. 12News, later, adds that the sedan was a Tesla, that the pickup was a Ford F-350 and that the driver is dead. Neither mentions a driver-assistance system. Not because they are hiding it. Because they don’t know. At three in the morning, a car stopped on a freeway is a car stopped on a freeway.
Then there is a second document, one nobody reads on October 31 and one that exists because of a federal obligation. Since 2021 NHTSA, the American road safety agency, has held manufacturers to a Standing General Order: any crash in which a Level 2 driver-assistance system was engaged within the thirty seconds before impact must be reported, and if someone died, within five days. Tesla reports. The vehicle is a 2020 Model 3. The field describing the system’s status reads Verified Engaged. The pre-crash movement reads Stopped. The speed reads 0 mph. Clear weather, no unusual road conditions. The car was struck across its entire rear by the front of the pickup. Tesla also states that it holds the event data recorder, the telematics and the video.
And then three black fields. The crash narrative, which would explain why the car was stopped. The software version, which would say whether Autopilot or Full Self-Driving was running. The field indicating whether that stretch of road fell inside the system’s approved operating domain. All three carry the same label, worth quoting in full because it is the real subject of this essay: REDACTED, MAY CONTAIN CONFIDENTIAL BUSINESS INFORMATION. Confidential business information. Blacked out.
Nobody connected the report to the crash for ten months. Electrek did, on August 31, 2026, by cross-referencing the few fields NHTSA leaves readable, city, vehicle, month and an incident time logged in UTC, against the local coverage. Converted to Arizona time, the report’s timestamp lands just after three in the morning on October 31, on the same freeway, with the same outcome and the same 2020 Model 3. The link between a man’s death and the fact that his driving system was engaged was made by a reporter with a spreadsheet and a time-zone conversion. Not by the transparency mechanism that had been designed for exactly that purpose. Electrek then filed a public-records request with the Arizona DPS and contacted the agency to ask whether the manufacturer had ever told it what it had told NHTSA, namely that the system was on.
And it is the second case with the same signature. On October 6, 2025, around 9:25 p.m., on I-4 in Florida near Lake Mary Boulevard in Seminole County, another 2020 Model 3 is stopped in the centre eastbound lane. A semi tries to avoid it, clips it, hits the guardrail and overturns. The Tesla is pushed into a second semi. The driver, a 43-year-old man from Deltona, dies at the scene. The Florida Highway Patrol says it does not know why the car was stopped in the middle of the interstate. Tesla’s report to NHTSA says, here too, Verified Engaged, Stopped, 0 mph. Here too the narrative, the software version and the operating-domain field are black.
Twenty-five days separate Florida from Arizona.
The discomfort I want to leave with the reader is not about blame. It is about a simpler question, and a harder one to shake off. Why can’t anyone know.
Two hypotheses, both uncomfortable
The first hypothesis is the one anybody who has followed Tesla over the past few years arrives at on their own. Phantom braking, the sudden brake application with nothing in the way, is a documented problem. NHTSA opened a preliminary evaluation in February 2022 on the strength of 354 complaints about 2021 and 2022 Model 3 and Model Y vehicles, a number that had climbed to 758 by May of that year. A class action has been pending in the federal court for the Northern District of Illinois since 2023. But the file has to be read to the end, because it contains a detail that complicates the picture rather than simplifying it. The investigation was closed on June 29, 2026 without any manufacturer action, and the closing resume describes a typical event: a speed reduction of ten to twenty miles per hour over one to three seconds, which the driver overrides by pressing the accelerator. No collisions identified, no vehicle brought to a complete stop. A car stopped dead in a lane resembles the phantom braking NHTSA catalogued, and nobody outside Tesla has seen the phenomenon closely enough to say whether it is the same thing.
The second hypothesis is more prosaic, and it is the one a highway patrol officer considers first at three in the morning. A medical event. The driver falls asleep. The driver stops responding, the system realises it no longer has anyone to talk to and does what it was designed to do: it slows to a stop and holds the car where it is. This is not a remote hypothesis. At three in the morning it may well be the most likely one.
Here one has to resist the temptation to treat it as an acquittal. A Level 2 system that, having lost its driver, leaves the vehicle stopped in a live freeway lane, in the dark, without moving to the shoulder and without signalling itself so that someone arriving at sixty miles an hour can see it, has a degradation design problem. What the standards call the minimal risk condition, the place a system brings the vehicle to when it can no longer continue, is not even defined for Level 2, because in theory the driver is always responsible. In practice, when the driver is gone, what the car does is decided by the manufacturer, and decided for every customer at once. If that decision is to stop where you are, the medical-event hypothesis does not close the question. It moves it from the software that drives to the software that decides what to do when driving ends.
The two hypotheses can be told apart in exactly one way. The log. The video. The telematics. The sequence of driver inputs in the last thirty seconds, the moment the system decided to brake and why, the software version that made that decision. All of it exists, Tesla states in the report itself that it holds it, and all of it is what the report does not contain.
Something needs saying about Electrek before going further. The outlet has an openly hostile editorial line on Tesla, and the Mesa article is part of a running investigation, complete with a tracking hub, that aims to reconstruct one by one the fatal crashes the manufacturer reported to NHTSA with the narrative blacked out. I flag it because the reader is entitled to know, and because it changes nothing. The black fields are in NHTSA’s document, not in the article. Anyone can download the file and count them. Electrek did, and found that Tesla redacts the narrative on 99.9% of its reports, that its reports make up roughly 85% of the whole industry’s, nearly four thousand crashes, and that General Motors, Ford, Honda and Toyota redact essentially nothing. The point about the omissions holds regardless of who raises it.
Something else needs saying, because it is the most awkward fact for this essay’s argument. The three fields Tesla blacks out are exactly the three the Standing General Order allows to be blacked out. NHTSA’s order lists three exceptions for which a manufacturer may claim confidential treatment: the name of the automation system’s version, whether the vehicle was within its operational design domain, and the narrative. Everything else is public by definition. Tesla has not broken the rule. It has used the rule to the hilt, every single time. The transparency mechanism has the hole at its centre, and it was written that way. NHTSA did open, in August 2025, an audit query into how promptly Tesla files these reports, after finding reports that arrived several months after the events. That is an investigation into when you report. It does not touch what you redact.
The same report before an Italian judge
The case is American. European law does not apply to it and will not. I say so at once because everything that follows is a counterfactual experiment, and I want it declared as one. The question is what would happen to the same defensive strategy, I have the data but it is confidential business information, if the product had been placed on the European market after December 9, 2026, and the case were before an Italian court.
December 9, 2026 is the day Directive (EU) 2024/2853 on liability for defective products starts to apply. It replaces the 1985 directive, and Italy is transposing it by rewriting Articles 114 to 127 of the Codice del consumo, the consumer code. The draft legislative decree, Atto del Governo n. 434, was transmitted to Parliament on August 7 and is before the committees for their opinion as I write. I come back to it at the end, because the window in which anything can still be said is shorter than people think.
The directive has a reputation, and the reputation is that it is a compensation tool. It extends the notion of product to software, lengthens the time limits, removes the deductible, adds destruction and corruption of data to the heads of recoverable damage. Its critics say, with some reason, that it is a round trip between insurers, that compensation always arrives afterwards and that afterwards it helps nobody. Its defenders list the injured parties who will finally be paid. Both are looking at the moment the cheque is written.
The mechanism that matters is a different one, and it sits in two articles that have to be read together. Article 9 provides that, at the request of a claimant who has presented facts and evidence sufficient to support the plausibility of the claim, the defendant is required to disclose the relevant evidence at its disposal, limited to what is necessary and proportionate, with specific measures to protect trade secrets. Article 10, paragraph 2, point (a), provides that if the defendant fails to disclose that evidence, the product’s defectiveness is presumed. In the Italian draft these are Articles 119 and 120 of the new consumer code, and the wording is almost identical.
Now reread NHTSA’s report with those two articles beside it. The driver’s family brings the manufacturer’s own document into court: system verified engaged, car stopped at zero in a live lane, clear weather, manufacturer states it holds the recorder, the telematics and the video. Facts and evidence sufficient to make the claim plausible; hard to argue otherwise. The judge orders disclosure. At this point the phrase “confidential business information” changes nature. Before NHTSA it is a box you tick that nobody adjudicates. Before an Italian judge after December 9 it is a request for confidentiality measures, which Article 9 provides for and grants, and not a reason to withhold. And if the manufacturer still decides to withhold, the product is defective by presumption, and it falls to the manufacturer to prove otherwise without the data it chose to keep in the drawer.
The trade secret, in this scheme, stops being a defence. At most, it becomes a mode of delivery.
Punishing what you knew, or what you cannot say
Anyone who has worked in civil liability long enough smiles when told that a liability rule makes products safer. They have good reasons. Forty years of literature on medical malpractice say that fear of the lawsuit produces defensive medicine more often than it produces safe medicine. In a survey published in JAMA in 2005, 93% of high-risk specialists surveyed in Pennsylvania reported practising defensive medicine, and 43% reported ordering imaging in clinically unnecessary circumstances. Kessler and McClellan, in 1996, had shown that reforms reducing liability pressure on doctors cut spending by 5 to 9% with no appreciable effect on mortality or complications. In Italy a parliamentary commission of inquiry estimated in 2013 that defensive medicine accounted for 10.5% of health spending, over ten billion euros a year. The argument is serious, the reader knows it, and it should not be waved away.
It is worth isolating why, though. Classic liability punishes what you knew. The doctor is liable for missing a symptom that was in front of them, the manufacturer for ignoring a defect it was aware of. Hence the perverse incentive, which is the true root of defensive medicine and defensive engineering alike: don’t look. Don’t run the test you might fail. Don’t keep the log that might end up in evidence. Don’t write the post-mortem in a form opposing counsel could quote. Every engineer who has worked in a company with an active legal department has heard, at least once, the advice not to put a certain thing in writing. Inside that rule, the advice is rational.
The presumption in Article 10 does something different, and I think it is the most important thing written in the directive. It punishes being unable to say. The manufacturer that does not produce the data is not sanctioned for what the data would have revealed. It is put in the position of having already lost the first round, whatever was in the data. The sign of the incentive flips. Not looking stops being a defensive posture and becomes an admission. The log you didn’t keep stops being the log that can’t hurt you and becomes the log that convicts you by its absence. The legal department’s advice, inside this rule, points the other way: keep everything, and keep it in a form we can hand over.
Add to this the fourth paragraph of the same article, which is worth reading for what it says about software. Where the claimant faces excessive difficulties in proving the defect or the causal link, in particular because of the technical or scientific complexity of the product, and shows that it is likely that the product was defective, the court presumes the defect. Recital 48 adds that, in the case of an AI system, the claimant cannot be required to explain the system’s inner workings. Complexity, which for thirty years has been the most effective shield available to anyone who makes software, stops working as one. The judge does not become an engineer. The difficulty of understanding the product simply lands back on the party that built it and understands it.
Then there is time, and time is the point that holds up everything else. The presumption operates before the judgment on the merits. Not at the end of the case, after the expert reports and the adjournments. At the beginning, at the moment the court decides who must prove what. This changes the producer’s calculus in a concrete way: putting the data on the table in the weeks after the event, when explaining is still possible, costs less than defending its absence for years. And weeks are the unit of measurement that matters here. The first death cannot be undone by compensation. The second can be avoided, if the data from the first become legible in time. Twenty-five days passed between I-4 and Loop 202. Nobody outside the manufacturer had, in those twenty-five days, the elements to ask whether the second case resembled the first. The manufacturer had them.
This is the point that neither the directive’s critics nor its defenders put at the centre. It is not a law about sanctions. It is a law about legibility.
What serious engineering already does
Now the translation, because an essay that stops at the principle is an essay nobody forwards to their colleagues.
The sentence I would like to carry out of this section is simple. The directive makes mandatory what serious engineering already does. Whoever complains about the burden is complaining, in substance, about being asked to know what their own software does. That said, it is worth spelling out what this means in practice, with the article that makes each item enforceable beside it.
Observability becomes a legal artefact. Until now logs, traces and metrics were an operations convenience, something you configured to debug and rotated after thirty days to save space. Article 9 turns them into evidence at the defendant’s disposal, and recital 42 adds that the evidence to be disclosed includes documents that have to be created from scratch by compiling and classifying what already exists. The quality bar moves. Being able to debug is no longer enough. You have to be able to explain it to a court-appointed expert six years from now. Which means logs that survive rotation, over a horizon that covers at least the ten years of the expiry period, reliable timestamps in a declared time zone (Electrek’s investigation was made possible by a UTC timestamp and would have been impossible without it), and a trail of the system’s decisions that stays intelligible to someone who did not write it. Article 9, paragraph 6, lets the court require that evidence be presented in an easily accessible and easily understandable manner. A three-terabyte dump of schema-less binary events amounts to not handing anything over.
Versioning and provenance become a question with a duty to answer. Which build was running at that moment, with which dependencies, which configuration, which model. In NHTSA’s report the software version is one of the three black fields, and it is the field that would say whether the active system was Autopilot or Full Self-Driving, two products with different capabilities and different operating domains. The directive’s expiry period is ten years from placing on the market, and in cases of personal injury that surfaces after a long latency it stretches to twenty-five. Anyone working with a Software Bill of Materials for the Cyber Resilience Act already has half the infrastructure: component manifests, reproducible builds, immutable artefacts. The other half is retention, and retention is a budget decision almost nobody takes at a ten-year horizon today. I have argued elsewhere that European compliance fails for lack of inventory more than for lack of rules. The directive adds one thing to that argument: the inventory has to carry a date, and the date has to be defensible.
The AI part is where the directive is more explicit than one expects from a text on product liability. Article 7, paragraph 2, lists among the circumstances for assessing defectiveness the effect on the product of any ability to continue to learn or acquire new features after it is placed on the market, and the moment the product left the manufacturer’s control where the manufacturer retains control after sale. Recital 32 puts it without circumlocution: a manufacturer that designs a product with the ability to develop unexpected behaviour remains liable for behaviour that causes harm. Article 11, paragraph 2, closes the classic escape route, the defect that arose later: the exemption does not apply where the defect is due to software, to updates or to their absence, as long as the product is within the manufacturer’s control. And recital 19 clarifies that a product remains within the manufacturer’s control as long as the manufacturer retains the ability to supply updates. A drifting model is a product that changes after it has left your hands, and the directive does not release you while you hold the key. In operational terms: evaluation snapshots at every release, versioned model cards, drift monitoring with documented thresholds and, above all, the ability to reconstruct what that model would have answered, on that input, on that date. None of this is exotic: every team doing serious fine-tuning already does it for itself, the day a customer asks why the system changed its mind between Tuesday and Thursday.
Then the convergence, which is why this essay sits on a blog about compliance as architecture. The Cyber Resilience Act and NIS2 impose active obligations before the damage: vulnerability handling, security updates for the support period, incident notification within twenty-four hours. The Product Liability Directive steps in afterwards, on damage already done, and the failure to supply the updates necessary to maintain safety is, in Article 11, precisely one of the things you cannot exempt yourself from. Article 7 adds safety-relevant cybersecurity requirements to the defectiveness criteria. The three instruments hold each other up. Complying with the first two is the best defence against the third’s presumption, because it produces, as a by-product, the documentation Article 9 asks you to disclose. Whoever built the SBOM for the CRA already has the answer to what was inside the product on that date. Whoever keeps the incident register for NIS2 already has the answer to when they knew. For those who took the first two seriously, the marginal cost of the third is low.
The other side of the coin has to be stated, otherwise the next section loses its credibility before it starts. All of this has a real cost. Keeping structured logs for ten years costs storage and encryption. Making a build reproducible costs pipeline time and discipline. Versioning a model with its evaluations costs hours of people who would rather be training the next one. Writing technical documentation that stands up before a court expert, and not only before the colleague who wrote it with you, costs a skill the market does not price today and almost nobody teaches. In a ten-person software house, the one I work in, these costs are not spread over an in-house legal department. They are subtracted from the same hours in which the product gets written. There is no way to sweeten that, and I am not going to try.
The objections that deserve an answer
Without this section the essay would be a pamphlet. The objections below are not straw men. They are the things I have actually been told, in order of strength.
The first is that civil liability has never saved anyone. It is the strongest objection and I addressed it above, so here I add only the part I left out. It is true of liability that punishes what you knew. I have no evidence that it is true of liability that punishes what you cannot say, because that rule has never been applied at scale to software, and from 2027 we will see whether it produces what its structure gives reason to hope. I am prepared to be wrong. I am not prepared to treat the malpractice literature as if it were about a rule that is not the same rule.
The second is that the long time limits and software-as-product crush small companies. It has to be conceded, because it is true. The burden falls asymmetrically. The giant absorbs it with a legal department and a retention budget nobody notices on the balance sheet. The ten-person software house does not. A twenty-five-year term, even limited to personal injury with long latency, and therefore in practice to medical software and little else, is a horizon no small Italian company has ever had to plan for. I would add that the government’s explanatory report on the draft decree records that associations of pharmaceutical victims argued that even the three- and ten-year terms are inadequate, which says something about the direction the pressure comes from. The answer is not that everything is fine. The answer is that the remedy lies in the proportionality of the procedural rules, in the sense that Article 9 already speaks of necessary and proportionate, and not in repealing the substantive rule. I say this from inside a ten-person company, and I suspect it carries a different weight than the same argument made by an academic. Asking a small company to know what its software does is not a disproportionate burden. Asking it to defend itself with the same procedural tools as a global manufacturer is, and the Italian decree could do something about that. For now it does not.
The third is doctrinal, and I take it seriously because I raised it myself a few months ago. Software is not a product, and a system that learns and changes its own behaviour does not reduce to the category of the defective movable good. True. The category is imperfect, forced, and holds up badly on distributed systems where nobody controls everything. But the alternative the critics proposed was a directive dedicated to liability for AI systems, and it has been withdrawn. I will get there in a moment. In the void the withdrawal left, the imperfect category beats the absence of any category.
The fourth is that the result will be defensive engineering, not safe engineering. Overcautious systems, frozen releases, features switched off in Europe, withdrawal from the market. The risk is real and I do not deny it. Part of the industry will react that way, and for a while some things will arrive in Europe later or not at all. The reply lies in the incentive structure I have described. Classic defensive engineering consists of not looking, and that is precisely the conduct the presumption punishes. The producer that wants to defend itself against the presumption has to produce the data, and to produce it has to have collected it, and to have collected it has to have looked. It is possible to build an overcautious, well-documented system, certainly. It is not possible to build a defensible, undocumented one, and that is the point.
The fifth is the scenario objection: yet another European regulatory weight while everyone else runs. Here the Mesa case serves this purpose too. It shows concretely what the alternative model produces, the one where the trade secret holds. A family that does not know why. A highway patrol investigating without knowing the system was engaged. A regulator that receives the report with three black fields and files it. A public that finds out ten months later, from a journalist with a spreadsheet, that there were two identical cases twenty-five days apart. The others run. Running without a legible black box is a choice, and its price is paid by people other than the runner.
The only instrument left
There is an irony in this whole story that deserves its own space.
On September 28, 2022, the European Commission proposed a directive on civil liability for artificial intelligence, the AI Liability Directive. It did two things, and it did them with a specific focus on high-risk systems: it gave courts the power to order disclosure of the technical evidence held by the provider, and it introduced a rebuttable presumption of a causal link between the defendant’s fault and the system’s output. It was, for AI, the dedicated version of what Articles 9 and 10 of the product directive do in general.
On February 11, 2025, the Commission adopted its work programme for 2025, presented to the European Parliament in Strasbourg the following day. Annex IV lists thirty-seven proposals to be withdrawn. Row 32 is the AI Liability Directive, with a reason worth quoting: no foreseeable agreement, the Commission will assess whether another proposal should be tabled or another type of approach chosen. The formal withdrawal was published in the Official Journal on October 6, 2025. On December 3 the Parliament’s legal affairs committee rejected, by twenty-two votes to one, a proposal to challenge it. The file is closed.
The consequence has to be stated precisely, because it is easy to overstate. The AI Act contains no rules on compensation: its recital 9 explicitly refers to the product directive for the compensation of damage. With the AILD withdrawn, Directive 2024/2853 is today the only European instrument that harmonises civil liability for damage caused by AI systems, and it does so within the limits of product liability. Everything else, and the rest is a great deal, stays with twenty-seven national laws of non-contractual liability.
And here is the reversal. Whoever applauded the AILD’s withdrawal as a victory for simplification should today be the first to defend the product directive, because without it what remains is not less regulation: it is twenty-seven regulations. For a company selling software in five European countries, twenty-seven different regimes of non-contractual liability, each with its own presumptions, its own time limits, its own rules on access to evidence, are a worse scenario than one harmonised rule, even a strict one. Axel Voss said so in the days of the withdrawal. He was the Parliament’s rapporteur on the AILD and sits with the European People’s Party, so hardly a voice of the regulatory left: he called the withdrawal a strategic mistake and predicted that AI liability would be dictated by a fragmented patchwork of twenty-seven national legal systems, suffocating European AI startups and SMEs. He was right, and the product directive is what we have left to prevent it.
Twelve days, then ninety-six
Back to the decree, because it is the part that can still be touched.
The delegation sits in the 2025 European delegation law, Law no. 36 of March 17, 2026, Annex A, item 4. The Council of Ministers gave the draft its preliminary approval on August 4. The text reached Parliament on August 7 as Atto del Governo n. 434. In the Chamber of Deputies, the Justice and EU Policies committees have until September 16 to deliver their opinion. In the Senate, the second committee has forty days from referral, so the same deadline. From today that is twelve days. Then the government adopts the final text, and on December 9, ninety-six days from today, the directive starts applying to products placed on the market from that day on. Products already on the market stay under the 1985 regime.
The draft transposes the directive almost word for word, and there is little to say about that: the explanatory report itself observes that, this being full harmonisation, the national legislator’s margins are narrow. Disclosure of evidence is at Article 119, the presumptions at Article 120, the software carve-out at Article 118, paragraph 2. Everything in its place.
There is one point to watch, though, and it is the only one on which the State had a real choice. Article 18 of the directive allows Member States to derogate from the development risk defence, the exemption by which the producer escapes liability by proving that the objective state of scientific and technical knowledge at the time the product was placed on the market did not allow the defect to be discovered. The derogation can be introduced only for specific categories of products, for public interest objectives, proportionately, and after notifying the Commission. The government chose not to exercise it. The impact assessment gives this reason: keeping the exemption, already provided for in the current text, ensures continuity of the national framework and uniform conditions of liability exposure across the internal market, while introducing a derogating regime is not, at present, supported by evidence demonstrating its necessity.
I am not sure that is the wrong choice. The development risk defence is reasonable for most products, and a blanket derogation would have been a mistake. But “at present” and “evidence” are words that, in the specific case of systems that keep learning after sale, deserve a question in committee. Can a manufacturer that designs a product capable of unexpected behaviour, and that keeps control over its updates, really claim that the state of knowledge did not allow the defect to be discovered, when it is the manufacturer that decides what the product records about itself? The directive already confines this defence to the period in which the product was within the manufacturer’s control. If the parliamentary opinion wants to say one useful thing in the twelve days that remain, it could ask the government to explain why it did not think it worth looking at least at that category, and what evidence it will be seeking in the coming years in order to reconsider. A modest request, a request for legibility, which is after all the subject of everything else here.
At three in the morning on Loop 202, a Model 3 sits in a live lane with its lights on in the dark. The system holding it there knows why. It wrote it to its recorder, sent it to the manufacturer, the manufacturer declared it to the regulator and then covered it with three black rectangles the regulator itself allowed it to use. Ten months later a journalist reconstructed what little could be reconstructed from outside. The family, the highway patrol and everyone who drives a 2020 Model 3 still know nothing.
Europe’s Product Liability Directive would not have saved that driver. No law would have. But it would have made the manufacturer incapable of answering with a black rectangle, and twenty-five days after the first death, that might have counted.
Not knowing is no longer free. It is the most useful thing a liability law could say to software.
Key takeaways
Classic liability punishes what you knew, which produces the incentive not to look. Article 10 of Directive 2024/2853 presumes the product defective when the producer fails to disclose the evidence it holds: it punishes being unable to say. Opacity stops being a defence and becomes an admission, and the producer’s interest shifts to putting the data on the table in weeks rather than years.
The directive makes mandatory what serious engineering already does: logs that survive rotation, timestamps in a declared time zone, reproducible builds, an SBOM with a defensible date, versioned model evaluations. Compliance with the CRA and NIS2 produces, as a by-product, the very documentation Article 9 requires you to disclose. All of it costs, and in a ten-person software house the cost comes out of the hours spent writing the product.
With the AI Liability Directive withdrawn, the Product Liability Directive is the only EU instrument that harmonises civil liability for damage caused by AI systems. Italy’s draft decree (Atto del Governo 434) transposes it almost verbatim and chooses not to derogate from the development risk defence. The parliamentary opinion is due September 16, 2026: the moment to ask why.
Sources
- A second Tesla driver died stopped on a freeway with Autopilot/Self-Driving on, Electrek, 31 August 2026
- Tesla driver who died when his car stopped on highway was using FSD/Autopilot, Electrek, 31 August 2026
- Tracking the fatal Tesla Autopilot and FSD crashes hidden in its data, Electrek, 1 September 2026
- Loop 202 reopens in Mesa after serious crash, Arizona's Family (KPHO/KTVK), 31 October 2025
- Driver killed in early morning crash on Loop 202, 12News (KPNX), 31 October 2025
- Standing General Order 2021-01 on Crash Reporting (Third Amended), NHTSA, 24 April 2025
- Audit Query AQ25-002: Compliance with Standing General Order 2021-01 Reporting Requirements (Tesla), NHTSA Office of Defects Investigation, 19 August 2025
- Preliminary Evaluation PE22-002, Unexpected Brake Activation (2021-2022 Tesla Model 3 and Y): closing resume, NHTSA Office of Defects Investigation, 29 June 2026
- Directive (EU) 2024/2853 of the European Parliament and of the Council of 23 October 2024 on liability for defective products, Official Journal of the European Union, 18 November 2024
- Atto del Governo n. 434: schema di decreto legislativo recante attuazione della direttiva (UE) 2024/2853, Camera dei deputati, 7 August 2026
- Atto del Governo n. 434: relazione illustrativa, analisi tecnico-normativa, analisi di impatto della regolamentazione e tavola di concordanza, Camera dei deputati, 7 August 2026
- Legge 17 marzo 2026, n. 36, Legge di delegazione europea 2025, Gazzetta Ufficiale della Repubblica Italiana, 25 March 2026
- Comunicato stampa del Consiglio dei Ministri n. 185, Presidenza del Consiglio dei Ministri, 4 August 2026
- Proposal for a Directive on adapting non-contractual civil liability rules to artificial intelligence (AI Liability Directive), COM(2022) 496 final, European Commission, 28 September 2022
- Commission work programme 2025, Annexes 1 to 5, COM(2025) 45 final, European Commission, 11 February 2025
- Withdrawal of Commission proposals, C/2025/5423, Official Journal of the European Union, 6 October 2025
- Don't drop AI liability mechanism, lead lawmaker warns Commission, Euronews, 12 February 2025
- Regulation (EU) 2024/1689 (AI Act), recital 9, Official Journal of the European Union, 12 July 2024
- Defensive Medicine Among High-Risk Specialist Physicians in a Volatile Malpractice Environment, JAMA, 293(21), June 2005
- Do Doctors Practice Defensive Medicine?, The Quarterly Journal of Economics, 111(2), May 1996
- Relazione conclusiva della Commissione parlamentare di inchiesta sugli errori in campo sanitario e sulle cause dei disavanzi sanitari regionali (Doc. XXII-bis, n. 10), Camera dei deputati, XVI legislatura, 22 January 2013