Article 73: serious incident reporting
The duty to report serious incidents with high-risk AI, under strict deadlines.
The official source remains authoritative. This general interpretation is not legal advice.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 8 August 2026
Who this is relevant to
When this applies
Deployer
An organisation using an AI system under its authority, excluding personal non-professional use.
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.
What the official source establishes
Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure. Deployers inform the provider without delay.
For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.
Our interpretation
The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.
What you can do now
Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.
- 01
Set up an incident process with reporting routes
Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
What to retain
Incident register and reports
Record of incidents, analyses, reports to supervisors and corrective measures.
Control and reassessment
Incident drill and deadline watch
Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.
Public tools
Full text of Article 73
The full legal text in the public AI Act Explorer.
Conditions and exceptions
- For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 73(1)-(11)
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Amended Article 113 application dates
Version history
v1.0.0
27 July 2026
Article 73: serious incident reporting
The duty to report serious incidents with high-risk AI, under strict deadlines.
Execution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.