Author:Zhou Xuefeng (Professor at the Law School of Beihang University, PhD in Law)
Source:: “Comparative Law Studies”, Issue 6, 2025
Table of Contents
1.Introduction
2.Characteristics of IoT Products and the Importance of Civil Remedies
3.Defining the Scope of IoT Products (Goods) under Warranty Liability
4.Defining the Scope of IoT Products under Product Liability
5.Conclusion
Abstract:The typical characteristic of IoT products lies in their integration of hardware, software, and services. As the intelligent functions of products enhance and the value of software and services increases within IoT products, their importance becomes increasingly prominent. The traditional legal systems of warranty liability and product liability are designed with tangible objects as the typical applicable subjects, failing to consider the characteristics of IoT products. In the current context of digitization, networking, and intelligence, to fully protect the rights and interests of IoT users and consumers, it is necessary to expand the conceptual scope of “goods” and “products” to include the software and services essential for the functionality of IoT products, applying warranty liability and product liability to them as a whole with hardware. With the inclusion of software and service factors, significant impacts will arise on the identification of defects in warranty liability, the seller’s after-sales obligations, as well as the identification of product defects, the scope of damage compensation, and defenses in product liability.
Keywords:IoT; Warranty Liability; Product Liability; Product Scope
01
Introduction
With the development of modern information technology, especially the advancement of IoT and artificial intelligence technologies, the manufacturing industry is undergoing digital transformation, with new products and business models emerging continuously. IoT products characterized by digitization, networking, and intelligence are entering households. For example, smart refrigerators can automatically identify food placed inside and adjust temperature and expiration reminders, allowing users to remotely view and control them via mobile applications; smart wristbands can collect, analyze, and monitor users’ health data such as heart rate and blood pressure in real-time, providing health reminders; designers abroad have even created smart candles that users can light remotely through a mobile app; smart salt shakers allow users to control the amount of salt dispensed via mobile apps or voice assistants; even sports shoes can be made smart, allowing wearers to control the tightness of shoelaces through a mobile app, and some IoT products with artificial intelligence attributes can even automatically reorder supplies online when they run out without human intervention.
At the same time, the safety of IoT products is increasingly attracting attention from all sectors of society. For instance, many smart home devices contain cameras, which can be hacked if there are network security vulnerabilities, leading to breaches of users’ home environments and privacy information; smart microwaves may cause fires, endangering users’ personal and property safety; smart connected cars may be hijacked and controlled by system intruders due to network security flaws, jeopardizing the safety of vehicles and passengers, and may also lead to traffic accidents due to defects in autonomous driving software that fail to accurately identify obstacles or respond in a timely manner.
Two types of civil liability closely related to defects in IoT products are warranty liability under contract law and product liability under tort law. However, both types of civil liability systems are designed with physical goods as the applicable subjects, reflecting the product safety concepts of the industrial era. In today’s digital age, how to define the scope of goods or products for IoT products, which integrate hardware, software, and services, has become a contentious issue in judicial practice. Continuing to adhere to the traditional concepts of products or goods would make it difficult for many victims to obtain adequate remedies. In this context, how to construct a warranty liability and product liability system that aligns with the digital age, how to reconsider the distinction between products and services, how to define the nature of software, and how to redefine the scope of products are urgent issues that need to be addressed.
Currently, the European Union has responded to these issues by formulating and revising the “Digital Content and Digital Services Contract Directive” (DCD), the “Sales of Goods Directive” (SGD), and amending the “Product Liability Directive”; in the United States, many scholars have extensively discussed the implied warranty system and product liability system for goods in the digital age concerning the “Uniform Commercial Code”. Although the “Civil Code of the People’s Republic of China” (hereinafter referred to as “Civil Code”) was promulgated in 2020, its provisions on warranty liability and product liability do not adequately reflect the needs of today’s digital age, and many theoretical issues need clarification. This article will conduct an in-depth analysis of this issue based on the introduction of relevant cases, theories, and legislation from the United States and the European Union, in conjunction with China’s current legal provisions, with the aim of contributing to the improvement of China’s relevant legal system.
It should be noted that in Anglo-American law and some directives of the European Union, as well as documents such as the “United Nations Convention on Contracts for the International Sale of Goods”, the term “goods” is typically used in the field of warranty liability for commercial transactions, which can be translated into Chinese as “货物” or “商品”; while in the field of product liability under tort law, the term “product” is usually used, which is typically translated as “产品” in Chinese. Strictly speaking, the meanings of “goods” and “products” are not entirely the same; for example, primary agricultural products are goods but do not fall under the definition of products in product liability law. However, for the IoT products studied in this article, the scope of “goods” and “products” is basically consistent, and this article will not make a strict distinction, sometimes using them interchangeably. However, out of respect for legal traditions and the rigor of expression, the term “goods” will still be used in some places when discussing certain legal rules of warranty liability, while the term “product” will mainly be used when discussing product liability.
02
Characteristics of IoT Products and the Importance of Civil Remedies
The “IoT products” referred to in this article are information physical systems that can collect information about users and their surrounding environments through various sensors and information sensing devices, transmit data through information communication networks, analyze and process data using data processing platforms, and achieve hardware control through software systems such as industrial control software. Some scholars refer to IoT products as “connected objects”; however, the author believes that the term “connected objects” may mislead people into thinking they belong to the traditional sense of “objects”. In reality, they exceed the category of objects, as they include not only hardware with “object” properties but also non-object attributes such as software and services. Therefore, this article adopts the term “IoT products”.
The most significant feature of IoT products is their integration of hardware, software, and services, where the functionality of the hardware is driven by software programs, and the combination of software and hardware can take various forms. One approach is to integrate software programs into hardware products, becoming firmware within the product. Users of such products typically cannot replace, delete, or upgrade the firmware program themselves and must rely on the manufacturer to do so. Another approach is for manufacturers to provide external software separately from the hardware, or for users to download software programs from the internet and install them, then connect the software program to control the hardware. A third approach is for manufacturers to provide software services to users through a cloud platform in a Software as a Service (SaaS) model, allowing users to access software services from cloud servers without downloading the software onto the hardware. Manufacturers of IoT products also provide users with data storage, data analysis, remote upgrades, maintenance, and various services related to hardware functionality and consumer needs, some of which are offered on a subscription basis, charging users periodically. With the development and application of artificial intelligence technology, IoT products are becoming increasingly intelligent, and their functionality increasingly relies on software and services.
Although the safety defects of IoT products are often related to the defects of the software and services embedded or used in conjunction with them, they differ from pure software or services. Defects in IoT products due to software or service issues can lead to hardware malfunctions, resulting in physical damage and causing personal and property harm to users and consumers. Additionally, some IoT products have interactive functions with the environment, and when product safety incidents occur, they may cause harm to surrounding people, objects, and the environment, thus threatening public safety. Unlike traditional industrial products, IoT products have network connectivity and remote control capabilities, enabling intelligent identification, positioning, tracking, monitoring, and management of objects through IoT technology. This brings many conveniences to users but also adds vulnerabilities in network security, making them susceptible to data breaches, algorithm flaws, illegal intrusions, and remote unauthorized control—safety defects and catastrophic incidents that traditional industrial products typically do not experience.
IoT products are the result of the development of modern information technology to a certain stage, and their technical and business models are still evolving. Therefore, both the establishment of technical standards and the formulation of product safety regulatory rules inevitably exhibit certain lag. In this context, relying on prior regulation to eliminate safety defects in IoT products is unrealistic. From a market perspective, producers of IoT products often lack sufficient motivation to enhance the safety of their products. This is mainly because improving product safety incurs certain costs, which producers often find difficult to recoup, leading them to feel it is not worth the investment. This is primarily due to the following two factors.
First, as new products in the digital, networked, and intelligent era, IoT products also apply the laws of network effects and economies of scale. The value of an IoT product often increases with the number of users. Once a product dominates the market, it becomes challenging for other competitors to enter, creating a “winner-takes-all” situation. In this context, many developers and producers of IoT products may rush to market with products that have not undergone sufficient safety testing to be the first to capture the market and achieve user scale.
Second, the safety of IoT products largely depends on the security of their software systems. Unlike hardware, the security of software is difficult for ordinary people to perceive, assess, or verify; it cannot be displayed externally like product functionality for consumers to intuitively feel. Due to the existence of information asymmetry, IoT products with high security levels may not necessarily compete effectively against those with lower security levels, leading to adverse selection and causing manufacturers to be reluctant to invest in product safety, resulting in a market flooded with IoT products that have safety defects.
If neither prior regulation nor market constraints can ensure the safety of IoT products, then it is necessary to rely on post-facto civil remedy mechanisms to urge manufacturers to improve product safety. Therefore, exploring the warranty liability and product liability of IoT products is of great significance. Although warranty liability and product liability have similar institutional functions and share certain common issues, there are still differences in their rule constructions. Thus, this article will discuss these two systems separately.
03
Defining the Scope of IoT Products (Goods) under Warranty Liability
Warranty liability under contract law mainly includes two types: warranty of title and warranty of quality. The warranty liability related to product defects causing harm to others, which this article studies, refers to warranty of quality. The traditional warranty liability under contract law typically applies to physical objects, referring to goods or products in commercial transactions. In civil law countries represented by German law, warranty of quality is also known as warranty of defects in goods. This raises a question: for IoT products, how to define the scope of warranty liability applicable to them? In other words, if a quality issue arises from their software or related services, can it be considered part of the goods or products to apply warranty liability? The root of this question lies in whether the principle of distinguishing between goods and services in traditional legal systems can continue to apply to IoT products.
(1) Distinction between Goods and Services in Traditional Warranty Liability Systems
In both Anglo-American and civil law countries, traditional contract law limits the scope of warranty liability, which serves to impose different responsibilities on sellers of goods and providers of services.
In the contract law of Anglo-American countries, the warranty system, which has a strict liability nature, applies only to the sale of goods, excluding services. For example, the “Uniform Commercial Code” of the United States stipulates the warranty system in Chapter 2, “Sales”, and explicitly limits its scope to transactions involving “goods”, which are referred to as tangible personal property. In American law, warranties are divided into express warranties and implied warranties. Compared to express warranties, implied warranties are statutory and are closer in function to product liability in tort law. If a buyer pays a substantial value for a product, they have a reasonable expectation that the product is defect-free. Generally, defects are relative to merchantability, and the existence of defects often implies a lack of merchantability. In American law, for service providers, even professional service providers, they typically do not “warrant” that their services or skills are “merchantable” or “fit for a particular purpose”; they can only guarantee that they can achieve the skill level and degree of care that a reasonable professional would typically exercise. In other words, they will only be liable for negligence. Therefore, service contracts differ from sales contracts and do not apply the strict liability nature of implied warranties.
In civil law countries represented by Germany, the civil code has a strict definition of “goods”, but there is no strict legal definition for “services”. In recent years, as the service industry has become increasingly important in economic life, some countries’ civil legislation has begun to categorize service contracts as a type of contract, such as the “Dutch Civil Code” and the “Draft European Model Civil Code”. However, their definitions of the scope of service contracts are inconsistent. Overall, the German civil code’s institutional framework is based on the distinction between objects and actions. Warranty liability is based on objects and applies to sales contracts for goods and contracts for the provision of certain works. For example, in a sales contract, when a buyer claims warranty liability from the seller, they only need to prove that the quality of the delivered object does not meet the contractual or legal quality standards, without needing to prove the seller’s fault. Therefore, warranty liability has a strict liability nature. In contrast, for contracts aimed at providing certain labor or service actions rather than works, such as commission contracts and labor contracts, the debtor obligated to provide labor or services typically only bears liability for fault and does not apply the strict liability nature of warranty liability.
In the Civil Code of China, provisions regarding quality warranty liability appear in sales contracts, gift contracts, and lease contracts, all referring to warranty liability for “goods”, with the warranty provisions for quality defects in sales contracts being the most typical. According to Articles 615 and 616 of the Civil Code, sellers in sales contracts must deliver the goods according to the agreed quality requirements; if the parties have not agreed on or have ambiguously agreed on the quality requirements for the goods, the performance standards shall be determined according to Article 510 of the Civil Code. For goods without national or industry standards, performance must meet the usual standards or specific standards that meet the purpose of the contract. The so-called usual standards mean that if the goods belong to products in the sense of the Product Quality Law, they must comply with the requirements of Articles 26 and 27 of the Product Quality Law, which means that the products must not pose unreasonable dangers to personal and property safety. At the same time, Article 646 of the Civil Code states: “Where the law provides for other paid contracts, it shall be implemented according to its provisions; where there are no provisions, the relevant provisions of sales contracts shall apply by analogy.” This raises a question: in contracts aimed at providing certain services, can the quality defects of services apply the warranty liability provisions in sales contracts? Article 599 of the Japanese Civil Code is similar to Article 646 of the Civil Code, but it contains an exclusion clause stating, “unless it is not permitted by the nature of the paid contract.” Japanese judicial practice and theory tend to believe that the judgment of service defects should not apply the relevant norms of sales contracts, and there is a theoretical and practical dispute regarding whether service providers should bear strict liability for service defects or fault liability for non-performance of obligations. From the perspective of the Civil Code of China, although it generally adopts a strict liability principle for contractual liability, it still adopts a fault liability principle for some well-known contracts with service contract characteristics, such as commission contracts, custody contracts, and storage contracts, while for other types of service contracts, some scholars in China believe that it is advisable to leave room for the application of the fault liability principle through legal interpretation.
(2) Disputes over the Nature of Software Transactions
The rules of warranty liability in traditional contract law, whether in the civil code of civil law countries or the “Uniform Commercial Code” of the United States, were formed before the advent of computer software, and they were designed primarily for the sale of tangible goods. At that time, legislators could not foresee the emergence of software, let alone the emergence of IoT products that integrate hardware, software, and services. The essence of IoT products lies in their software, and the difficulty (or key issue of contention) in applying warranty liability rules to IoT products is how to view the legal nature of software transactions, whether they belong to the category of goods transactions or other types of transactions.
One of the important reasons for the dispute over the nature of software transactions is that software itself is protected by intellectual property rights, and many manufacturers adopt licensing rather than ownership transfer for software transactions. In China, according to Article 600 of the Civil Code (Article 137 of the 1999 Contract Law), software can become the subject of a sales contract, and the “Interpretation of the Supreme People’s Court on Issues Concerning the Application of Law in the Trial of Sales Contract Dispute Cases” stipulates the delivery of electronic information products in Article 2. However, not all software transactions fall under the category of sales contracts; it is still necessary to distinguish between software copyright licensing contracts and software sales contracts. Therefore, under the legal context of China, the dispute over software transactions is not whether software can be the subject of a sales contract, but how to determine whether a software transaction is a sales contract or another type of contract, such as a copyright licensing contract or a technology development contract.
In the United States, some courts believe that the characteristic of a sales contract lies in the transfer of ownership of the subject matter, and under the software licensing transaction model, there is no transfer of software ownership, thus it does not fall under the sales contract and does not apply the legal provisions regarding sales contracts. However, some American courts argue that the fact that software is protected by intellectual property rights does not exclude the applicability of the provisions of Chapter 2 of the “Uniform Commercial Code” regarding sales contracts, because the “Uniform Commercial Code” defines “sales” as the “transaction” of goods, which can take various forms and does not necessarily require the transfer of ownership. Moreover, even if software transactions adopt a licensing model, it does not automatically exclude the applicability of Chapter 2 of the “Uniform Commercial Code”; courts should judge the nature of the transaction based on its substance rather than its form.
Careful examination of American court cases reveals that they distinguish between software intellectual property transactions and software copy transactions, with the latter more likely to be recognized as product sales. Early software transactions were conducted through the sale of physical media such as CDs or independent packaging, and some American courts have held that such software product transactions should apply the provisions of the “Uniform Commercial Code” regarding sales contracts. For instance, in a case involving Adobe software, the court held that if a buyer pays the full licensing fee in a software licensing transaction and receives a copy of the software along with an indefinite license, then the transaction is essentially a sale of a software copy, and the buyer can obtain ownership and usage rights over that software copy, thus the provisions of Chapter 2 of the “Uniform Commercial Code” regarding sales of goods apply. In another case involving Adobe software, the court determined that the software transaction between the parties was a licensing transaction rather than a sales transaction based on factors such as the parties’ intentions, transaction practices, and contract language, thus not applying the principle of exhaustion of rights. Additionally, some courts have held that if the seller sells mass-produced, standardized software to the buyer, that transaction can be regarded as a sale of goods, while custom-developed, personalized software for users should be recognized as a service provision.
With the widespread application of the internet, some manufacturers provide software through online downloads and require users to sign intellectual property licensing agreements. In this transaction model, although there is no delivery of physical media like CDs, some American courts still consider it to be recognized as “goods” and apply the provisions of the “Uniform Commercial Code” regarding warranty liability in sales contracts. However, with the advent of cloud computing, especially when some companies provide software to users as “Software as a Service” without requiring users to download the software, there is significant controversy over whether the software transactions between the parties should be recognized as sales transactions or service transactions.
In summary, it is challenging to provide a universally applicable answer regarding the nature of software transactions; it can only be judged based on the specific circumstances of each case. In the face of contentious issues in the legal applicability of software transactions, the American legal community has attempted to resolve these issues through legislation, but without success. For example, the American Law Institute (ALI) and the Uniform Law Commission attempted to amend Section 2 of the “Uniform Commercial Code” by adding a 2B clause to clarify the nature of software transactions, but ultimately failed due to significant controversy. Subsequently, the Uniform Law Commission drafted the “Uniform Computer Information Transactions Act”, which involves software transactions and stipulates warranty rules for software licensors, but this model law has only been adopted by a few states in the United States, indicating that there are still significant disagreements in the American legal community on this issue.
(3) Determining the Nature of IoT Product Transactions and the Scope of Warranty Liability
If there is controversy over the nature of pure software transactions, then the determination of the nature of transactions involving IoT products that integrate hardware, software, and related services is even more contentious. Theoretically, there are three possible approaches to defining the nature of IoT product transactions and determining the applicable scope of warranty liability.
The first approach is the separate application approach, where different laws apply to the hardware, software, and related services within IoT products. For example, some manufacturers often enter into separate contracts with users for the sale of hardware products, software licensing, and service subscriptions, intending to apply the legal rules of sales contracts, intellectual property law, and service contract law separately. If there is a hardware defect, the warranty liability rules in the sales contract apply; if it is a service defect, the relevant service contract rules apply; if it is a software defect, it needs to be classified on a case-by-case basis as either a goods defect or a service defect to determine the applicable law.
The advantage of the separate application approach is that it provides clearer and more certain legal guidance for the parties involved. However, its drawbacks are also very apparent: IoT products are not simply a mixture of hardware, software, and services, but an organic system that integrates hardware, software, and services into a whole, blurring the boundaries between goods and services, and between software and services. For example, a personal computer purchased by consumers typically includes hardware, software, and related software upgrade services and security services. Generally, consumers can freely add, delete, or modify various software and security services on their computers. However, for IoT products, their hardware, software, and services are often bundled together, and manufacturers can use technical protection measures and contractual agreements to fix this bundling, making it difficult for consumers to replace or remove them. Therefore, compared to traditional electronic products, IoT products exhibit a more integrated characteristic of hardware, software, and services. For traditional industrial product manufacturers, the sale of a product realizes its value, and after-sales service is merely ancillary, provided to promote product sales. In contrast, many manufacturers of IoT products continue to provide related paid services after selling the product, which are not ancillary but essential for the functionality of the product. In the long run, the revenue from providing services will exceed the revenue from selling hardware products, and some manufacturers have even stopped selling hardware products altogether, instead providing paid services through subscription or leasing models, thus obtaining stable cash flow over the long term. At the same time, with the development and application of internet and cloud computing technologies, the distinction between software and services is becoming increasingly blurred. For example, some software manufacturers do not sell software in a one-time sale model but provide software to customers through periodic subscriptions, and some manufacturers offer software services through cloud services in a “Software as a Service” model. Applying different laws to the hardware, software, and services that make up IoT products effectively separates the organic whole of IoT products into artificial legal divisions, severing their inherent connections, which contradicts the nature of IoT products and may lead to outcomes that deviate from the parties’ transaction purposes. Therefore, this article does not recommend adopting this approach.
The second approach is to borrow the “predominant purpose test” from American law, which analyzes the parties’ contract language, the nature of the industry in which the parties operate, the transaction structure, the parties’ intentions, and the composition of the price to determine whether the primary purpose of the transaction is to obtain goods or services, thus deciding the nature of the transaction and determining whether to apply warranty liability under contract law. Before the advent of computer technology, there were traditional mixed transactions involving goods and services in the market, such as contracts that included both the sale of building materials and construction services. After the advent of computer technology, mixed transactions involving hardware and software also emerged. In American judicial practice, courts have adopted the “predominant purpose test” when dealing with such mixed transaction cases. For example, in a case where the parties agreed to collaborate on the research, testing, and mass production of a charging device, the court found that the primary consideration during negotiations was the knowledge, ability, and skills of the entrusted party rather than the hardware device, thus determining that the transaction was a service transaction rather than a sale of goods, and the warranty liability rules for goods did not apply. Conversely, if the value of the hardware product dominates the total transaction price while the value of the related software and services is minimal, then the transaction is likely to be recognized as a sale of goods and subject to warranty liability rules.
Under the guidance of the predominant purpose test, courts judge the primary purpose of the parties in signing contracts based on the specific circumstances of each case. However, in such cases that heavily rely on individual judgment, different courts often reach different conclusions regarding similar cases. In the context of IoT, determining the predominant purpose will become even more contentious and uncertain. Many products before the emergence of IoT were primarily hardware, with software or services being ancillary or value-added. For IoT products, hardware is merely a shell, while software and related services are the soul. Without software to drive and control, pure hardware is as useless as a “brick”. More importantly, the value of software and services is continuously increasing, even surpassing that of hardware, becoming the most attractive selling point for consumers. For instance, the previously mentioned smart candle costs $100, while a regular candle costs only $10. Consumers purchase the smart candle not merely to obtain a candle but to experience the joy of lighting it through a mobile app. However, we must also recognize that in IoT products, software and services do not exist independently but are bound together with hardware. All information technology means ultimately act on hardware, achieving transaction purposes through the functionality of hardware. If hardware is missing, the IoT product ceases to exist. In this context, how to determine the primary purpose of the parties in IoT product transactions will become a matter of subjective interpretation. Many issues have already been exposed in American judicial practice, so this article does not advocate adopting the predominant purpose test for IoT product transactions.
The third approach is the single concept expansion application approach, which expands the concepts of goods or services to encompass hardware, software, and services, thus treating them as a whole within the scope of goods or services. Adopting the single concept expansion application approach can avoid the artificial severance issues arising from the separate application approach and the subjective arbitrariness and uncertainty issues arising from the predominant purpose test. If the single concept expansion approach is to be adopted, the subsequent question is whether to expand the concept of goods or the concept of services. From the perspective of protecting user and consumer rights, it is advisable to expand the concept of goods to include the relevant software and services under the concept of goods, thereby applying warranty liability rules to better protect consumers. Given that there are currently no specific provisions regarding service defect liability in China’s existing laws, it is not advisable to resolve the liability issues of IoT products by expanding the concept of services.
The next question is how to expand the concept of goods. Is there a boundary to this expansion? With the development and widespread application of the internet, cloud computing, and artificial intelligence technologies, the software and services connected to IoT products will continue to increase. Therefore, if all software and services are indiscriminately included in the concept of products and uniformly subject to warranty liability, it would clearly be unreasonable, not only increasing the liability of relevant manufacturers but also conflicting with the transaction purposes and reasonable expectations of the parties. Thus, the boundaries of the product must be defined. In this regard, some American scholars represented by Elvy and the legislators of the EU “Sales of Goods Directive” have chosen a functionalist testing method, which includes the software and related services necessary for the normal functioning of the product within the scope of the product, uniformly applying warranty liability. This method is commendable.
The EU legislators have adopted a distinctive “dichotomy” approach to software and digital service transactions, separately formulating the “Sales of Goods Directive” and the “Digital Content and Digital Services Contract Directive”. For digital content and digital services that are integrated into or connected with goods, if they are necessary for the functionality of the goods, then such digital content and digital services will be included within the scope of “goods” and thus subject to the “Sales of Goods Directive”; while transactions involving digital content and digital services that do not fall within the scope of the “Sales of Goods Directive” should be subject to the “Digital Content and Digital Services Contract Directive”. Notably, according to the aforementioned directives, if there is any doubt about whether a digital content or digital service falls within the scope of the sales contract, it should be presumed to fall within the scope of the sales contract, thus applying the “Sales of Goods Directive” rather than the “Digital Content and Digital Services Contract Directive”. This indicates that EU legislators have chosen a relatively strict legal regulation path for IoT products.
Under the current legal framework in China, it is possible to expand the interpretation of the relevant provisions on warranty liability for goods in the Civil Code to include the software and services necessary for the functionality of IoT products within the scope of goods. Additionally, for IoT users and consumers, based on the purpose of consumer rights protection, it can be clarified through the interpretation of Articles 23 and 24 of the Consumer Rights Protection Law that the quality assurance obligations of operators for IoT products fall within the scope of warranty liability with a strict liability nature, and that the hardware, software, and services in IoT products should be treated as components of goods uniformly subject to warranty liability systems.
Using a functionalist definition method, it is first necessary to clarify what the function of the goods is. This should refer to the relevant agreements in the contract and consider the functions that similar goods should typically possess and the reasonable expectations of consumers regarding the functionality of the goods. For example, IoT terminal products should typically be equipped with an operating system; otherwise, they cannot operate normally. Therefore, the operating system can generally be included within the scope of the sales contract for goods. However, if the parties explicitly agree that the product does not include the operating system at the time of sale, and the consumer subsequently downloads the operating system from a third party, then that operating system does not fall within the scope of the sales contract for IoT goods. The software or services included within the scope of goods can be provided by the product manufacturer or by third parties, and can be directly provided to consumers by the product manufacturer, downloaded by consumers via the internet, or provided through a “Software as a Service” cloud service model, all of which do not affect the recognition of such software and services as components of the goods.
(4) The Impact of Including Software and Services within the Scope of IoT Products on Warranty Liability
Including software and services within the legal definition of goods for IoT products will have significant impacts on the warranty liability system.
First, the rules of warranty liability in traditional contract law are primarily designed based on defects in physical objects, and the standards for determining defects are usually targeted at objects. The differences between software, services, and objects are significant, making it difficult to simply apply the standards for determining defects in objects. Determining whether an IoT product has defects differs from assessing whether traditional goods have defects, with different focal points and methods of determination. For example, IoT products typically have the functionality of collecting and processing data, and the operation of this functionality is essential for the normal functioning of the product as a whole. Therefore, IoT products are at risk of hacking, data and personal privacy breaches, and illegal control, which are closely related to network security, data security, and artificial intelligence security—issues that do not exist in traditional goods. Moreover, the focus of concern regarding these risks and security issues is usually not on the hardware part of IoT products but on the software or network service part.
Second, traditional contract law typically uses the time of delivery of the subject matter as the point of judgment for whether defects exist. However, when software and services are included within the scope of goods, this rule should change. In some scenarios, the seller may deliver the hardware, software, and services all at once, making the delivery time easy to determine. In other scenarios, the seller may first deliver the hardware of the IoT product to the buyer and then inform the buyer to download the software via the internet, and after the buyer installs the software, provide related services. In this case, the last time point, i.e., when the service is provided, should be used to determine whether the IoT product has defects, because without software driving and supporting the services, the hardware cannot demonstrate its functionality, making it impossible to assess whether it has defects. Additionally, there may be a scenario where the seller agrees in the contract to continuously provide related services for a period after delivering the hardware, or even if the contract does not specify this, based on the design or functional attributes of the product, if it requires the seller to provide ongoing services to function normally, then the seller will have the obligation to provide such services and will bear corresponding warranty liability during the entire period of service provision. The most common situation is when the seller provides software support services for the hardware of smart products in a “Software as a Service” cloud service model.
In cases where the seller has an obligation to provide ongoing services, a question that needs to be discussed is how to determine the duration of the seller’s service provision. If the contract has clear provisions on this, it can be determined according to the contract. However, the tricky part is how to handle it if the contract does not specify this. IoT products consist of hardware, software, and related services, where the hardware often has a lifespan or term, while the software can theoretically be indefinite. However, as the network environment and technology evolve, software must be continuously updated to maintain its security. Additionally, as products are continuously updated, some software upgrades may require higher hardware configurations, rendering the original hardware products incompatible. Disputes arising from the seller’s discontinuation of services have occurred in both domestic and international practices. For example, Amazon stopped operating the Kindle eBook store in China in June 2023, after which users could not purchase new eBooks and by June 2024, cloud download services were discontinued, preventing Kindle users in China from accessing new eBooks, effectively limiting the functionality of the Kindles in users’ hands, and Amazon only promised a compensation of 50 yuan to old users, leading to litigation, but related refund requests were not supported by the court. In the United States, after the smart home device manufacturer Revolv was acquired by Nest, Nest unilaterally announced that it would no longer provide cloud services for the smart home devices already sold, preventing users from using those devices. Later, Nest was forced to refund users in full due to enforcement investigations by the Federal Trade Commission. These cases reflect the issue that some IoT products require manufacturers to provide ongoing services based on their functional design. However, requiring manufacturers to provide indefinite cloud services or software upgrade services would impose a heavy burden on them, which also seems unreasonable. Therefore, future legislation needs to balance consumer rights protection and manufacturer interests, starting from consumers’ reasonable expectations, and clearly defining the minimum duration for which manufacturers of IoT products must provide related services.
04
Defining the Scope of IoT Products under Product Liability
(1) Defining the Scope of Products in Traditional Product Liability Legal Systems
The product liability system in tort law is a product of the industrial era. Before the industrial era, manufacturers of handmade products typically only bore liability for negligence and were protected by the relativity of contracts. Product liability, as a form of strict liability, applies the principle of no-fault liability and breaks through the relativity of contracts; however, its scope of application is limited, generally applying only to products. The term “product” refers to items that have been processed, manufactured, and are intended for sale. In the context of traditional product liability systems, services are usually excluded from the definition of products. For example, the “Restatement of Torts” (Third) in the United States explicitly states: “Services, even if commercially provided, are not products.” This limitation on the scope of application is related to the legitimacy of product liability. The justification for imposing product liability on producers lies not in their fault or merely in the risk of product damage they create, but in their ability to disperse liability risks through pricing and liability insurance mechanisms. The homogeneity and mass production characteristics of industrial products make it possible to disperse liability risks. However, services are typically one-to-one and personalized, making large-scale homogeneous sales difficult, and they cannot circulate in the market like industrial products, generating numerous remote consumers. Therefore, service providers cannot disperse their liability risks like product manufacturers and only bear liability for fault. Additionally, victims of service defects typically do not need to trace defects back to the original service provider through a long commercial chain. The Idaho Supreme Court in the United States stated in a case: “Neither this court nor any other court has ever applied strict liability to personal services, nor has there ever been an exception.”
In China, the Product Quality Law limits the application of product liability to products, while Article 48 of the Consumer Rights Protection Law uses the expression “goods or services that have defects” and also stipulates that “unless otherwise provided in this law, civil liability shall be borne in accordance with other relevant laws and regulations,” making the provisions regarding civil liability for service defects ambiguous. In this regard, some scholars in China believe that the application of no-fault liability principles or fault presumption principles should be distinguished based on the type of service, and in special circumstances, fault liability principles should be applied.
(2) The Scope of Product Liability Applicable to IoT Products
Typical IoT products usually consist of hardware, software, and related services, where the hardware part does not fundamentally differ from products in the sense of traditional product liability law, and its applicability to product liability is unquestionable. The contentious issue is whether software and related services can be considered products or components of products subject to product liability, with the software issue being the most critical.
Before the emergence of IoT products, there has been ongoing debate regarding whether software alone is subject to product liability in domestic and international practices. In American law, it is generally believed that standardized, homogeneous software sold in large quantities by manufacturers can be considered products in the sense of product liability law; however, software specifically tailored to meet customer needs is regarded as a service and thus not subject to product liability. However, as some scholars have pointed out, despite the academic community advocating for the application of product liability to software for over twenty years, there have been no cases in American judicial practice where software vendors have been held strictly liable for software products. Unlike standalone software, with the integration of modern information technology and industrial development, more and more software is embedded in hardware, existing as firmware, thus forming a complete product together with the hardware, such as software programs in automotive brake systems or automated washing machines. Such software can be considered components of products subject to product liability, and there have been many judicial cases in the United States, especially in the automotive sector. IoT products differ from both pure software and traditional embedded industrial products in that their hardware and software integration methods are more diverse, and their software upgrade methods also vary. Therefore, whether the relevant software is subject to product liability cannot be generalized.
Before the emergence of IoT products, there were also issues regarding how to define the scope of product liability when products and services were mixed in transactions. Common scenarios include manufacturers providing installation, maintenance, and other services when selling products, or service institutions in medical and other fields providing services while also selling some products. Courts often either separate the two, applying product liability and fault liability to products and services respectively, or make an overall determination based on the dominant nature of the transaction. However, the combination of products and services in IoT products, both from a technical model perspective and a business model perspective, differs from traditional models, making it difficult to continue using previous handling methods.
In recent years, the EU has attempted to address the issues of software defects and service defects in digital products by expanding the scope of products under the product liability directive during the revision process. It proposed three schemes and conducted impact assessments: Scheme 1 is to include software and services necessary for the functionality of the product within the scope of product liability; Scheme 2 expands the scope of software subject to product liability to include all software that may cause damage, including standalone pure software (such as medical software) and various software provided by third parties that can be used in conjunction with the product; Scheme 3 further expands the scope of software subject to product liability to include software related to basic human rights. The EU ultimately chose Scheme 2.
The author believes that in the context of digitization, networking, and intelligence, it is reasonable to appropriately expand the definition of products to include some software and services, thus extending the applicability of product liability for the following reasons:
First, for IoT products, their hardware is driven and controlled by software, and many complex software programs may contain millions of lines of code. Even if programmers write carefully and conduct thorough checks, it is difficult to avoid various errors or vulnerabilities in software programs. If software has defects, it will significantly impact the functionality of the hardware, leading to overall product defects. In this case, if legislators want product liability to exert its intended deterrent effect, it is necessary to include software defects within the scope of product liability.
Second, with the development of modern digital technology, especially the breakthrough development of artificial intelligence technology, software functionality is increasing, and software design is becoming more complex. In this context, embedding large software into hardware is becoming more challenging. Meanwhile, with the reduction of network communication costs and the development of cloud computing, some manufacturers are beginning to provide software support services for products through cloud platforms, offering software upgrade services online. In this case, it is also essential to include related services within the scope of product liability. The necessary software for the operation of product functions should not have differing liability based on its storage location or provision method.
Third, with the continuous emergence of new technologies and business models, many product functionalities are expanded and changed through related digital services provided by manufacturers or their partners. In this case, defects in related services can lead to a lack of safety in products, threatening the personal and property safety of product users. Therefore, including related services within the scope of product liability is crucial for enhancing overall product safety and protecting consumer rights.
Fourth, the design of IoT products is becoming increasingly complex, with diverse combinations of hardware, software, and digital services, exhibiting characteristics of deep integration. When safety failures occur in IoT products, it is often challenging to determine whether they are caused by hardware defects, software defects, or defects in related digital services. In such cases, applying product liability rules can alleviate the burden of proof on victims, facilitating the protection of users’ legitimate rights and interests.
Fifth, as integrators of hardware, software, and services, IoT product manufacturers control the risks associated with product safety. Holding them accountable for the overall product helps them design software and provide related services more cautiously or choose higher-quality software or service providers, thereby reducing the likelihood of product defects. Additionally, from the perspective of dispersing damage risks, manufacturers have a greater capacity to disperse risks compared to users and consumers. They can transmit liability risks or insurance costs through pricing mechanisms to the market, thus dispersing them to the public.
Sixth, for product users, especially consumers, it is unreasonable that if they can receive protection under product liability when purchasing traditional industrial products, they cannot enjoy the same protection when purchasing products with IoT elements solely because the defects arise from software or related services. Technological development should adhere to a human-centered principle, and the purpose of new technologies and products should be to enhance and secure human life, not to diminish people’s sense of safety.
At the same time, we must recognize that the expansion of product definitions must be moderate. This is mainly because one prominent feature of IoT products is their extensive connectivity and functional extensibility. They can connect with other products used by users through information networks and can also connect with various software and applications through various hardware and software interfaces, while also leaving room and possibilities for manufacturers to provide various value-added services. However, if all software and services that are paired or connected with hardware are indiscriminately included in the scope of products and manufacturers are held liable for their defects, it will lead to excessive liability for manufacturers and create significant uncertainty. Under these conditions, manufacturers may strictly limit the connectivity of their products with other software and services in order to control their liability risks, or even choose a closed design for their products, ultimately affecting the development of IoT products and diminishing consumer welfare. Therefore, the author believes that when revising laws such as the Product Quality Law in China to expand the scope of product liability from hardware to software and services, two limiting conditions should be added: (1) The software or services included within the scope of products must be necessary for the functionality of the product, while excluding non-functionally necessary software or services. This means that China should make a different choice from the EU. The author believes that the approach chosen by the EU in the “Product Liability Directive” will lead to an overly broad definition of product scope and should not be emulated. Additionally, the inclusion of the functional necessity limitation can align the scope of products in tort law with the scope of goods in warranty liability, facilitating future rule integration. (2) The integration of software or services into IoT products or their connection with hardware should be completed by the product manufacturer or authorized third parties. At the same time, China can learn from the EU “Product Liability Directive” to clarify that manufacturers should not be deemed to have consented to integration or connection merely because they provided the technical possibility for integration or connection or did not prohibit potential related services. By implementing these limiting conditions, manufacturers can control their liability risks while not excessively restricting the connectivity or extensibility of products.
05
Conclusion
Although IoT products are currently considered a new type of product arising from the application of modern information technology, in the long run, the future society will undoubtedly be a digital, networked, and intelligent society, where everything will be interconnected. The IoT products we discuss today will no longer be regarded as a special type of product but will become the norm for many products, and the legal issues related to IoT products will also become general legal issues in future society. Therefore, in-depth exploration of this issue is not only helpful for addressing current problems but also of great significance for preparing for the challenges of future society.
The greatest difference between IoT products and traditional industrial products lies in their integration of hardware, software, and related services into a whole. It is precisely the integration of software and service elements that presents many challenges when applying traditional warranty liability and product liability systems to IoT products. In the context of the continuous emergence of new technologies and products, we need to update traditional legal systems, appropriately expand the concepts of “goods” in warranty liability and “products” in product liability to include the software and services necessary for the functionality of goods or products, while also addressing issues such as defect identification, after-sales obligations, and data loss to fully protect the legitimate rights and interests of users and consumers of IoT products.
Previous Recommendations:
“Comparative Law Studies”, Issue 5, 2025
Wang Xixin: Public Regulation of Private Surveillance
Xu Duo: International Games of Stablecoin Regulation and China’s Countermeasures
Yuan Kang: Debates and Choices in Unified Legislation on Artificial Intelligence
Yin Jiguo: Regulation of Platform Abuse Behavior under Unfair Competition Law
Li Yan: Normative Construction of Directors’ Duties in Companies on the Brink of Bankruptcy from a Business Perspective
Zhao Jingchen: Clarifying and Normative Expression of Directors’ Obligations to Creditors from a Comparative Law Perspective
Guo Zhiyuan: International Standards for Effective Legal Defense and Paths to Localization
Mo Jihong | On the Judgment Criteria of “Constitutional Issues” in Constitutional Review: Theory, Practice, and Balance
Zhao Shanshan: Research on the Construction of an Independent Knowledge System of Chinese Supervision Law
Tang Anran: Reconstruction of the Principle of Due Process in Automated Administration
Zhou Guangquan: The Judicial Application Status and Improvement of Reward-Based Sentencing Circumstances
Wang Liming and Bao Ding Yurei: On the Analogous Application of the “Notice” Rule in Infringement of Generative AI Works
Wang Ye: Systemic Impacts of the Delayed Retirement Policy and Its Legal Responses
Sun Jin: Outline of the Construction of an Independent Knowledge System of Chinese Competition Law
Guo Hua: Theoretical Reflection and Improvement Path of the Norms on the Connection between Administrative and Criminal Penalties
Yang Xianbin: On the Compensation for Mental Damages in Personality Rights Infringement
Yu Wenwen: On the Legal Positioning of Data Property Rights
Li Fenfei: On the Governance of “Decriminalization” of Minor Offenses
Zhu Guangxin: The Doctrinal Structure and Realization Path of Punitive Damages
Huang Zhongshun: Reflection on the Expansion of Enforcement Power
Liu Yinliang: The Evolution and Choice of Punitive Damages
Huang Yuxiao: The Subjective and Objective Disputes in Administrative Law Studies and Their Reflection
Zhang Tao | Regulating Artificial Intelligence through Technical Standards: A Jurisprudential Approach Based on Cooperative Regulation
Xu Yan: The Challenge and Response of Tariff Hegemony to the Construction of China’s Unified Market Tax System
Hosted by China University of Political Science and LawEdited by the Institute of Comparative LawLong press to identify and scanNote