top of page

Can you disclaim your liabilities for someone else's software?

A client came to us recently with a design that's more common than most hardware businesses admit to: a physical product, software embedded in it that a third party built, and a growing worry that if the software fails, the claim lands on whoever's name is on the box, rather than the supplier who wrote the code.


Their proposed fix was a disclaimer in the software licence: something along the lines of "we are not the developer of this software and accept no liability arising from its operation." It's an understandable instinct. That instantly gave me more grey hairs.


Timing of the contracts


Anything you put in a contract will only work if the contract terms actually apply. And to apply, they have to be accessible at the time the contract is formed.


A business selling hardware with embedded software is usually running two contracts, and they're rarely formed at the same time.


The hardware sale happens at checkout, when payment is taken or the order is accepted. The software licence — the EULA, the click-through terms — is typically presented later, at first use or first download. Whatever sits in that later licence was never offered as a term before the hardware contract was made, so it can't retrospectively vary or limit it. If a disclaimer is only ever seen at software setup, it has no bearing on a claim about the hardware; which is where most of the practical exposure sits.


"We didn't build it" isn't a defence


Set the timing issue aside and assume the disclaimer is seen and accepted at the right moment. It still runs into three separate walls.


Where the end user is a consumer:


  1. Product liability - Under the Consumer Protection Act 1987, a defective product attracts strict liability — no need to prove fault. This cannot be excluded or limited by any contract term, notice, or other provision. Embedded software that forms part of an integrated product doesn't sit outside this. A hardware supplier who isn't the "producer" in the strict statutory sense can still find itself liable as supplier if it can't identify the actual producer or importer to a customer who asks.


  1. The Consumer Rights Act 2015 provides that liability for goods not being of satisfactory quality, fit for purpose, or as described can't be excluded, and neither can liability for death or personal injury from negligence. None of this bends to a licence disclaimer.


Negligence in tort. This is the one people find most counterintuitive, because it doesn't run through contract at all. Donoghue v Stevenson (the case with the snail that may or may not have been in the ginger beer bottle) established that a manufacturer owes a duty of care to the ultimate user of a product independent of any contractual relationship between them — Mrs Donoghue had no contract with the ginger beer manufacturer whatsoever. The same principle means an end user harmed by a defect in embedded software has a claim against the hardware supplier regardless of whether they ever read, saw, or accepted the software licence. A disclaimer buried in an agreement the claimant never entered into simply isn't in the room.


Where a disclaimer can do real work


For business customers, a well-drafted limitation of liability can validly exclude or cap liability for pure economic loss, as long as it is reasonable. So a software bug that costs a business customer money, without hurting anyone or damaging anything else, is a genuine candidate for contractual risk allocation.


Two conditions have to be met for that to work.

  1. The customer has to be a real business counterparty, not a consumer dressed as one.

  2. The clause has to sit in the main supply contract with that customer — the one formed at the point of sale — not in a software EULA that surfaces later and binds, at most, whoever clicks through it.


The structuring options that look cleverer than they are


Clients often ask about more elaborate fixes: a pass-through EULA that tries to put the customer into direct contract with the software owner, a third-party beneficiary clause under the Contracts (Rights of Third Parties) Act 1999, an agency arrangement, or a wholly separate licence issued by the software owner rather than the hardware supplier.


Each of these can genuinely help allocate risk between the supplier and the software owner behind the scenes, and the 1999 Act in particular is a useful tool for letting a software owner enforce its own exclusions against an end customer if the contract is drafted to name it properly. What none of them does is remove the hardware supplier's own liability. The supplier is still the party who sold an integrated product; its statutory obligations as to quality and fitness, its potential CPA exposure, and its exposure in negligence all attach to it by operation of law, and no amount of internal restructuring between supplier and software owner changes who the customer can sue.


What you can do instead


Stop trying to make the disclaimer do work it was never capable of, and put the effort where it actually counts:


Get the commercial terms with the software owner right — warranty, indemnity, and a genuine right of recourse if a defect claim lands, because that's the real risk transfer mechanism, not anything said to the end customer.


For business customers, put a properly drafted limitation of liability in the hardware sale contract itself, incorporated at checkout rather than surfacing later, so it actually attaches to the contract the customer's economic loss claim would be framed against.


For personal injury, property damage, and any consumer end users, accept that no drafting closes this gap. The answer is insurance and upstream recourse against the software owner, not a cleverer clause.


If a software EULA disclaimer is still wanted for transparency or signposting reasons, that's fine — just be honest with the business about what it's doing. It's communication, not legal protection.


 
 
 

Comments


Talking Fox Limited is incorporated and registered in England and Wales with company ‎number 13394689 whose registered office is at 1 Mill End Cottages, Little Missenden HP7 ‎‎0RG ‎

Get Updates

Thank You!

bottom of page