Regulatory

9 December 2026. That's when the rebuttable presumption applies.

The EU Product Liability Directive puts the burden on you to prove the decision was sound. Here's what it means in plain English, the three scenarios where it hits hardest, and what evidence actually closes the gap.

The burden shifts

Fail to disclose the decision evidence and the court can presume your agent caused the harm, rather than requiring the claimant to prove it. The rebuttable presumption applies to any agent decision in scope.

AI is now explicitly in scope

Software and AI systems fall squarely within the revised Directive as "products," a category expansion from the previous regime that mostly aimed at physical goods.

The gap closes with evidence

An independent, tamper-evident evidence trail for every consequential decision, produced before a dispute exists. Not reconstructed after litigation starts, not audited by consultants, not signed off by compliance. Verifiable at the moment the decision lands.

What this means in practice

The rebuttable presumption hits hardest in three moments. Each one requires evidence that someone can produce right now, not reconstruct after the fact.

Customer sues

Your customer claims the agent made a consequential decision that harmed them. They ask the court to compel you to disclose the decision trace, context, and reasoning. If you don't produce it, the court presumes the decision was defective and your liability follows.

Regulator asks

A financial regulator, data protection authority, or sector supervisor requests the decision evidence for a specific trace as part of a formal investigation. You have days to respond. If you can't produce a verifiable, contemporaneous record, the regulator can treat absence of evidence as evidence of defect.

Board asks

Internal audit or your board's risk committee requests a random sample of consequential decisions with full evidence. You need to demonstrate that decisions were made systematically, against defined criteria, with independent audit. Logs reconstructed from application databases don't satisfy the requirement; contemporaneous, signed records do.

The evidence question: dashboard, report, or logs?

The Directive doesn't mandate a specific format, but it does require evidence that a court can scrutinize. Three formats show up in practice. Only one withstands cross-examination.

Dashboard screenshot

A screen capture of your monitoring platform showing the decision was logged. Problem: anyone can fake a screenshot after the fact. A court will treat it as unverifiable, especially if the underlying data changed or the dashboard was reconfigured.

Signed report

A contemporaneous, tamper-evident record issued by an independent evaluator at the moment of decision. Includes the decision, the criteria evaluated, the reasoning, and the seal. This is what Jiminy produces: a tamper-evident evidence trail showing the decision was evaluated systematically when it mattered, not reconstructed later.

Application logs

Database records of what your application did and when. Weak evidence under the Directive because logs can be modified, contexts are often implicit, and the reasoning behind a decision isn't captured. Logs alone do not show the decision was evaluated by an independent judge.

The court's job is to assess whether you acted reasonably to ensure the decision was sound. A signed, independent audit record answers that. A screenshot or a log entry does not.

Evidence that no longer exists when a claim is brought answers nothing. Jiminy's standard retention is 6 months; evidence for the Independent Audit tier and for domain profiles we classify as high-risk is retained 10 years automatically (see pricing for the current list and security for the full policy). If your deployment doesn't fall into one of those categories, the 6-month default is a cost/scope tradeoff, not a claim that every plausible claim window closes within 6 months — a rebuttable-presumption claim under the Directive can in some circumstances be brought well after a decision was made. This isn't legal advice about your specific exposure; it's a plain statement of what the default configuration does and doesn't cover, so the gap isn't silent.

Supporting frameworks outside the EU

The PLD is the lead anchor, but two other frameworks reinforce the same underlying expectation: that someone can explain an AI decision after the fact.

SR 26-2 (United States)
The Fed / OCC / FDIC's replacement for SR 11-7 explicitly places agentic AI outside its scope, leaving a gap Jiminy fills rather than duplicates.
UK SM&CR
No deadline, always live. Frames the buyer as an individually accountable risk owner, a Senior Manager with personal regulatory accountability, not a general "AI governance" function.

How Jiminy evidence works

The evidence your regulator or court actually needs: an independent verdict on every consequential decision, signed and timestamped at the moment of decision, verifiable against your actual trace data.

See how we evidence agent decisions →

Full legal detail and citations

What the product itself maps against

EU AI Act (Arts. 5, 9, 12, 13, 14, 15, 26, 50, 72), UK GDPR (Arts. 5, 22, 25), FCA Consumer Duty (PRIN 12, PROD 2.1), SRA Code of Conduct and Bar Council AI Guidance, Equality Act 2010 (ss. 13, 19, 20), and the ICO AI Auditing Framework.

Not legal advice, deliberately

Jiminy does not perform conformity assessments and does not provide legal advice. The regulatory mapping this page and the product describe is observational: it identifies which obligations a decision touches, so your compliance team can reach its own determination. Output vocabulary is deliberately constrained to evidenced / partially_evidenced / not_evidenced, never compliant / non-compliant.

Jiminy audits the log, not the agent

Every verdict evaluates the decision trace as submitted. Attestation (see reliability) proves that trace wasn't altered after it was emitted; it does not, and structurally cannot, prove the trace is a complete account of what the agent did. A step withheld from the submitted log is invisible to the judge, the same way a fact withheld from a witness statement is invisible to a court. This is a limitation of evaluating a submitted record rather than the agent itself, not a gap Jiminy is trying to close quietly — see docs/KNOWN_LIMITATIONS.md for the test built to demonstrate it directly.

Directive reference

Directive (EU) 2024/2853 on liability for defective products, repealing Directive 85/374/EEC. Member states must bring implementing measures into force by the transposition deadline; the rebuttable presumption of defectiveness applies where a defendant fails to disclose relevant evidence despite a court or competent authority's request.

Explore the EU AI Act articles referenced above →