Responsible AI Platform
All obligations
Upcomingv1.0.0

Article 73: serious incident reporting

The duty to report serious incidents with high-risk AI, under strict deadlines.

The official source remains authoritative. This general interpretation is not legal advice.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
8 August 2026

Who this is relevant to

When this applies

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.

What the official source establishes

Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure. Deployers inform the provider without delay.

For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.

Our interpretation

The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.

What you can do now

Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.

  1. 01

    Set up an incident process with reporting routes

    Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.

What to retain

Incident register and reports

Record of incidents, analyses, reports to supervisors and corrective measures.

Control and reassessment

  • Incident drill and deadline watch

    Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.

Public tools

Conditions and exceptions

  • For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 73(1)-(11)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended Article 113 application dates

Version history

  1. v1.0.0

    27 July 2026

    Article 73: serious incident reporting

    The duty to report serious incidents with high-risk AI, under strict deadlines.

Execution

From obligation to arranged and demonstrable

Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.