Abstract
The transition from mechanically operated automobiles to software-defined and increasingly autonomous vehicles unsettles the conceptual foundations of product liability. A conventional product defect is ordinarily understood as a condition existing when a product leaves the manufacturer’s control; cybersecurity vulnerabilities, by contrast, may emerge after deployment, remain latent until exploited, propagate across an entire vehicle fleet, and transform a digital weakness into bodily, proprietary, or economic harm. The resulting liability problem is therefore not merely one of defective driving technology, but of allocating responsibility where software, manufacturers, suppliers, vehicle owners, regulators, and malicious third parties intersect.
This paper examines whether existing liability frameworks are capable of addressing such cyber-physical harm, through a comparative analysis of the European Union, the United States, and India. It argues that the European model presently offers the most conceptually coherent architecture by combining the preventive obligations of UN Regulation No. 155 with the emerging strict-liability framework of the 2024 Product Liability Directive, including its express treatment of software, cybersecurity vulnerabilities, post-market updates, evidentiary disclosure, and third-party attacks. The United States, by contrast, continues to rely principally upon state tort law, recalls, and non-binding cybersecurity guidance, leaving significant questions of defect, foreseeability, standing, economic loss, and proof unresolved. India occupies a more consequential regulatory gap: while section 164 of the Motor Vehicles Act, 1988 provides a limited no-fault compensation floor and proposed Rules 125-T and 125-U would introduce cybersecurity and software-update requirements, its existing product-liability framework does not adequately accommodate software defects, non-consumer victims, or malicious third-party interference.
The paper consequently argues for an Indian framework that connects ex ante cybersecurity compliance with ex post civil liability. It proposes recognition of cybersecurity vulnerabilities and safety-critical failures to update as actionable product defects, disclosure and evidentiary presumptions for technologically asymmetric litigation, manufacturer responsibility notwithstanding third-party attacks, expanded standing for persons injured by compromised vehicles, and a collective compensation mechanism for correlated or fleet-wide cyberattacks. The central claim is that cybersecurity liability cannot be resolved by treating the autonomous vehicle as merely another defective product: the law must account for the vehicle as a continuously evolving cyber-physical system whose safety obligations persist beyond the moment of sale.