Indian Journal for Research in Law and Management

Advancing Law and Management

ISSN No. : 2583-9896

Cybersecurity Liability in Autonomous Vehicles: Rethinking Product Liability in the Age of Cyber-Physical Harm

Cite this Article

Ryan Bang, & Ankit Singh & Deepika Mohnani (2026). Cybersecurity Liability in Autonomous Vehicles: Rethinking Product Liability in the Age of Cyber-Physical Harm. The Indian Journal for Research in Law and Management, Volume IV(Issue 1). Retrieved from https://ijrlm.com/journal/cybersecurity-liability-in-autonomous-vehicles-rethinking-product-liability-in-the-age-of-cyber-physical-harm/

Abstract

The transition from mechanically operated automobiles to software-defined and increasingly autonomous vehicles unsettles the conceptual foundations of product liability. A conventional product defect is ordinarily understood as a condition existing when a product leaves the manufacturer’s control; cybersecurity vulnerabilities, by contrast, may emerge after deployment, remain latent until exploited, propagate across an entire vehicle fleet, and transform a digital weakness into bodily, proprietary, or economic harm. The resulting liability problem is therefore not merely one of defective driving technology, but of allocating responsibility where software, manufacturers, suppliers, vehicle owners, regulators, and malicious third parties intersect. This paper examines whether existing liability frameworks are capable of addressing such cyber-physical harm, through a comparative analysis of the European Union, the United States, and India. It argues that the European model presently offers the most conceptually coherent architecture by combining the preventive obligations of UN Regulation No. 155 with the emerging strict-liability framework of the 2024 Product Liability Directive, including its express treatment of software, cybersecurity vulnerabilities, post-market updates, evidentiary disclosure, and third-party attacks. The United States, by contrast, continues to rely principally upon state tort law, recalls, and non-binding cybersecurity guidance, leaving significant questions of defect, foreseeability, standing, economic loss, and proof unresolved. India occupies a more consequential regulatory gap: while section 164 of the Motor Vehicles Act, 1988 provides a limited no-fault compensation floor and proposed Rules 125-T and 125-U would introduce cybersecurity and software-update requirements, its existing product-liability framework does not adequately accommodate software defects, non-consumer victims, or malicious third-party interference. The paper consequently argues for an Indian framework that connects ex ante cybersecurity compliance with ex post civil liability. It proposes recognition of cybersecurity vulnerabilities and safety-critical failures to update as actionable product defects, disclosure and evidentiary presumptions for technologically asymmetric litigation, manufacturer responsibility notwithstanding third-party attacks, expanded standing for persons injured by compromised vehicles, and a collective compensation mechanism for correlated or fleet-wide cyberattacks. The central claim is that cybersecurity liability cannot be resolved by treating the autonomous vehicle as merely another defective product: the law must account for the vehicle as a continuously evolving cyber-physical system whose safety obligations persist beyond the moment of sale.

Journal Information

The Indian Journal for Research in Law and Management
ISSN No.
2583-9896
Submit Manuscript
Licensing
All research articles published in The Indian Journal for Research in Law and Management are fully open-access. i.e. immediately freely available to read, download, and share. Articles are published under the terms of a Creative Commons license, which permits use, distribution, and reproduction in any medium, provided the original work is properly cited.
Disclaimer
The opinions expressed in this publication are those of the authors. They do not purport to reflect the opinions or views of the IJRLM or its members. The designations employed in this publication and the presentation of material therein do not imply the expression of any opinion whatsoever on the part of the IJRLM.

Article Analytics

15
Page Views
1
Downloads