Ten days before Christmas 2024, a second-hand e-bike stood charging on the first floor of a family house in Catford, south-east London. It had started life as an ordinary pedal cycle; someone had fitted a lithium battery pack and sold it on through an online marketplace. The charger was generic. When the battery let go, one person escaped through the front door; two others found the stairs already burning and had to be rescued from the loft. The house did not survive.
Go deeper — impact analysis
The London Fire Brigade’s report on that fire reads like dozens of others it now writes every year. In 2025 the Brigade attended 206 e-bike and e-scooter fires — a record, one every other day, up from five in all of 2018. Two people died last year; five have died in London since 2023, and none of the five owned the bike that killed them. The Brigade has spent three years calling these fires one of the city’s fastest-growing risks — and the same machines are on every European street.
This article is about a quieter question underneath those fires, one that decides who pays for them: which part failed? The cell chemistry, the charger — or the piece of software whose entire job was to say stop? From December 2026, the EU’s new Product Liability Directive makes that question, and the frequent impossibility of answering it, the manufacturer’s problem rather than the victim’s. E-bikes are simply the clearest place to watch it happen — the case study for every product that is secretly a computer.
The computer hiding in the bicycle
An e-bike looks like hardware with a battery bolted on. It is closer to a small network of computers wearing a bicycle. The battery pack carries a battery-management system — firmware that decides how fast the cells may charge, keeps them balanced, and cuts the current when temperature or voltage drift out of range. The motor has its own controller deciding how much power to deliver and when to stop assisting. Many models add a companion app that talks to both, unlocks speed modes, and receives updates over the air. Even the charger often has logic of its own.
Notice what the battery-management system is: it is the component whose specific purpose is to prevent the fire. A cell can be manufactured imperfectly, a charger can be counterfeit — the BMS exists to catch exactly those conditions before they become thermal runaway. When a parked bike ignites, the story is rarely one component’s alone; it is a failure of a chain in which at least one link was software. And each link, under the new law, has its own author — and its own liability.
A 1985 law meets a 2026 machine
Until now, Europe’s product liability law — Directive 85/374/EEC, living in Romania as Legea 240/2004 — was written for the world of kettles and gearboxes. It worked on a simple bargain: no need to prove the manufacturer was careless, but the victim had to prove the product was defective, prove the damage, and prove the causal line between them. For a burned-out bicycle whose battery pack is now slag, that proof was often impossible. Whether software even counted as a “product” was a forty-year argument the text never settled.
Directive (EU) 2024/2853 settles it. Software is a product — embedded, downloaded or served from the cloud; firmware and applications by name. A software update, or the failure to supply one the product needed, can itself make a product defective, because defectiveness is now judged for as long as the manufacturer keeps control through updates. The damage that counts has widened to include medically recognised psychological harm and destroyed personal data, and the old €500 floor is gone. And none of it can be contracted away against the injured person — no terms of service, no liability cap, touches a product-liability claim. The full mechanics are in The Product You Didn’t Know You Shipped; here it is enough to watch what they do to one battery fire.
Romania sits inside this story on the standard clock. The directive must be transposed by 9 December 2026 and applies to products placed on the market from that date; the government has listed the directive for transposition in 2026, with the draft still to come. Until then, Legea 240/2004 governs — which means everything sold in the next months will be judged under the old rules, and everything sold after the switch under the new ones. Two bikes in the same shop window, months apart, two different legal universes.
The unknown becomes the manufacturer’s problem
Here is the uncomfortable fact buried in the fire statistics: nobody can reliably say, across the fleet of incidents, which layer fails. The UK’s product-safety regulator, one of the few in Europe publishing systematic data, received notice of 211 e-bike and e-scooter fires in 2024, with eight deaths. Of the e-bike fires, 45% were post-market conversions; for another third, investigators could not even establish how the bike was built. Fire reports name “battery failure, conversion kits and chargers” as the usual suspects — but whether a given fire began in cell chemistry, in a counterfeit charger, or in a battery-management system that never cut the current, the wreckage rarely says.
Under the old regime, that uncertainty quietly decided cases: a victim who cannot name the defect cannot carry the burden, so the loss stayed where it fell — on the family in Catford, on the neighbours of the five Londoners who died owning no e-bike at all. The new directive reverses the flow. A bike that ignites while parked in a hallway is the paradigm of an obvious malfunction, so the defect is presumed. The claimant can ask the court to order disclosure of the technical evidence — firmware versions, BMS logs, test records — and a manufacturer who cannot or will not produce it hands the claimant a presumption instead. The absence of attribution data stops being the victim’s dead end and becomes the manufacturer’s exposure. What you cannot document, you now effectively own.
If you build, import or convert
For the companies that write the firmware and assemble the machines, the practical consequence is an evidence discipline, not a drafting exercise. The record that shows how the BMS was designed, what its thermal thresholds were, when each firmware version shipped and why, which updates were pushed and to whom — that record is the only thing standing between an obvious-malfunction presumption and a rebuttal. Products that phone home already generate most of it; the question is whether it is kept, versioned, and producible in a form a court can read. Build the file before the fire.
For brands and importers, the directive is a supply-chain question. Whoever brings the product into the Union inherits the front of the liability cascade, and recalls are already reaching named Western brands — the US regulator’s 2026 warning on Rad Power Bikes batteries shows this is no longer a no-name-import story. An importer who has never seen the supplier’s firmware documentation is signing for a black box with its own name on the customs form. And the insurance question bites here too: policies written for mechanical defects may say nothing useful about software as a product.
For the conversion economy — kit sellers, workshops, fleet rebuilders, the gig-economy operators whose riders’ modified bikes appear disproportionately in the fire data — the directive has one short sentence: substantially modify a product and you become its manufacturer. The workshop that fits a battery pack to a pedal cycle is no longer a bystander to what that pack’s firmware does at 3 a.m. in a hallway. That is not a reason to abandon conversion; it is a reason to choose components whose makers can show their documentation — because their file is now your defence too.
The move
Three questions, answered plainly
- Does the new EU Product Liability Directive apply to e-bikes and e-scooters?
- Yes. Directive (EU) 2024/2853 applies to e-bikes and e-scooters placed on the EU market from 9 December 2026 — and, for the first time, expressly to the software inside them: battery-management firmware, motor controllers and companion apps are products in their own right, carrying strict liability without proof of fault.
- Is firmware or a companion app a 'product' under Directive 2024/2853?
- Yes. The directive treats software as a product however it is supplied — embedded in a device, downloaded, or accessed as a service. Firmware such as a battery-management system, a motor controller, and a companion app each count, and the maker of a defective software component can be liable alongside the manufacturer of the finished product.
- Who is liable in the EU when an e-bike from a non-EU manufacturer catches fire?
- The directive builds a cascade so an EU claimant always has an EU defendant: first the EU importer, then the manufacturer's authorised representative, then the fulfilment service provider. A distributor that cannot name an operator upstream answers itself, and anyone who substantially modifies the product — a conversion kit, a new battery — becomes its manufacturer.
General information on Directive (EU) 2024/2853 and its forthcoming transposition in Romania, where Legea 240/2004 currently governs product liability, not legal advice, and no lawyer–client relationship is created. UK fire statistics are cited as published by the London Fire Brigade and the Office for Product Safety and Standards for illustration; references to English or UK matters are comparative observations by a solicitor (non-practising), not English-law advice. The directive applies to products placed on the market from 9 December 2026 and carries defences and conditions not covered here; any specific situation needs advice on its own facts.
Making, importing or converting products with software inside? Map every firmware layer to its liability answer before December 2026.
Free brochure
The firmware liability checklist
A one-page brief on this topic, sent straight to your inbox.
Facing this on a live document?
Book a 30-minute clinic
A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.
Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.