Open source liability is coming
EU plans to update product liability and cybersecurity rules so that software makers can be held responsible when their products cause harm, extending strict liability to software in a similar way to physical goods. Commenters largely agree that commercial vendors should be on the hook for vulnerabilities in the open source components they choose to ship, but worry about vague definitions of “commercial activity,” the impact on small businesses, and whether donation‑funded or hobby open source could be exposed to lawsuits. Several point out that current drafts explicitly exempt non‑commercial open source, see the article raising alarm as exaggerated or misleading, and expect the main practical effects to be more due diligence, more insurance, and potential new business models around “certified” open source.
Scope and Intent of the EU Rules
- Many commenters say the article is misleading or FUD: the proposed EU Product Liability Directive / Cyber Resilience Act target commercial activity, not most non-commercial FOSS.
- Multiple links to EU documents note: free and open‑source software developed or supplied outside commercial activity, and source code itself, are excluded.
- When software is supplied for a price or via monetization of personal data (beyond security/compatibility), normal product liability applies.
Who Is Liable for What
- Consensus: the entity that “puts the product on the market” (sells software, device, or service, or monetizes via ads/tracking) is liable to consumers for defects, including those originating in OSS dependencies.
- Licenses like MIT/Apache cannot waive state‑imposed strict liability for commercial vendors.
- For direct, free use of OSS with no commercial relationship or monetization, several commenters assert there is no liability under the drafts.
- Still unclear edge case: what exactly counts as “commercial activity” (paid support, telemetry sold as “insights,” ad‑funded downloads, sponsorships, Patreon, tip jars).
Impact on Open Source Developers
- Many fear a chilling effect:
- Risk that ambiguity around “commercial” makes maintainers with small income streams (support contracts, minor sponsorships) afraid to publish or keep code public.
- Concern about being dragged into lawsuits even if they ultimately win; legal costs and stress alone deter contribution.
- Worry that making a living from OSS in the EU becomes harder if liability attaches as soon as any money flows.
- Others argue non‑commercial OSS authors remain safe and this mainly affects companies selling products or services.
Impact on Companies and Ecosystem
- Supportive views:
- Forces vendors to audit dependencies, patch known OSS vulns, and stop blaming hobby projects for harms to their customers.
- Aligns software with other industries where sold products carry liability.
- Critical views:
- Big firms can absorb paperwork, audits, and insurance; small vendors and solo devs may be priced out.
- May push companies to:
- Avoid OSS, rewrite components in‑house, or buy “certified” commercial forks/warrantied packages.
- Shift to SaaS (often carved out) rather than distributed software.
Unresolved Questions and Hypotheticals
- Liability when consumers directly use OSS apps (e.g., free Android app, screen reader, tools with installers) remains a key concern; some think exempt, others see risk.
- Ambiguity around liability for open core, dual‑licensed, or commercially supported OSS, and for code contributions from unpaid contributors to a commercially monetized project.
- Several note that final legal impact will depend on how courts interpret “commercial activity” and causation, which is currently uncertain.