ISHIGHRISK AI
Analysis

How serious incident reporting works under Article 73

Article 73 makes providers of high-risk AI systems report serious incidents. The four limbs of the definition, the 15, 10 and two-day clocks, and who files.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 73 of Regulation (EU) 2024/1689 puts the reporting duty on the provider of a high-risk AI system, addressed to the market surveillance authorities of every member state where the incident occurred. A serious incident is defined in Article 3(49) as an incident or malfunctioning that directly or indirectly leads to death or serious harm to health, a serious and irreversible disruption of critical infrastructure, an infringement of Union law protecting fundamental rights, or serious harm to property or the environment. Every day count runs from awareness, not from establishing the causal link: 15 days generally, two days for critical infrastructure or a widespread infringement, and 10 days where a person has died. Deployers do not report under Article 73, they inform first the provider and then the importer or distributor and the market surveillance authorities under Article 26(5), which applies from 2 December 2027 for Annex III systems.

What counts as a serious incident

A serious incident is reportable by the provider of a high-risk AI system to the market surveillance authorities of every member state where it occurred, under Article 73(1) of Regulation (EU) 2024/1689. It is due immediately once a causal link is established, or on awareness alone where limb (b) or a widespread infringement is engaged, with an outer limit of 15, 10 or two days from awareness.

The definition is in Article 3, point (49): an incident or malfunctioning of an AI system that directly or indirectly leads to one of four outcomes. A malfunctioning counts on its own, and indirect causation counts, so a chain running through a human decision does not break the link. The Digital Omnibus, Regulation (EU) 2026/1744, amended neither Article 3(49) nor Article 73 nor Article 26, though it did insert an express derogation from Article 73 in the new Article 75(1a).

Article 3(49) limb What it covers Outer limit from awareness
(a) Death of a person, or serious harm to a person's health 10 days on death, otherwise 15
(b) Serious and irreversible disruption of the management or operation of critical infrastructure Two days
(c) Infringement of obligations under Union law intended to protect fundamental rights 15 days
(d) Serious harm to property or the environment 15 days

Limb (b) is narrower than it reads: both "serious" and "irreversible" must hold, and it covers disruption of the management or operation of critical infrastructure, not damage to the asset. Article 3(62) takes the term from Article 2, point (4) of Directive (EU) 2022/2557.

Limb (c) carries no qualifier where (b) and (d) require seriousness, and no de minimis appears anywhere in the Regulation. That omission reads as deliberate, so treat any infringement of fundamental-rights protective Union law as engaging the limb rather than filter on gravity. Limb (c) alone survives the narrowing rules in Article 73(9) and (10), and it triggers the Article 73(7) referral to the bodies listed under Article 77(1).

Who reports, and to whom

Article 73(1) binds providers, and its addressee is plural: the market surveillance authorities of the member states where the incident occurred. That need not be the provider's home state, and one incident spanning several markets produces several reports, to the bodies set out in the national authorities guide.

Two rules redirect the filing. Article 73(10) sends reports about medical devices under Regulation (EU) 2017/745 or (EU) 2017/746 to the national competent authority chosen by the state where the incident occurred. Article 75(1a), inserted by the Omnibus and in force since 27 July 2026, sends the report to the AI Office instead where the system falls under its exclusive competence under the widened Article 75(1), with Article 73(2) to (9) applying mutatis mutandis.

Deployers do not report under Article 73, and the summary that they simply inform the provider is half the duty. Article 26(5) requires a deployer that has identified a serious incident to immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities. Where it cannot reach the provider, Article 73 applies mutatis mutandis and the deployer inherits the provider's clocks. The Regulation does not say what counts as unable to reach, which puts that escalation route in the contract rather than the statute, and into vendor due diligence.

A lower trigger sits in the same paragraph: a deployer with reason to consider that use in accordance with the instructions may result in the system presenting a risk within Article 79(1) must inform the provider or distributor and the market surveillance authority without undue delay, and suspend use. No harm need have materialised, and the serious-incident limb requires no suspension. Which duty lands on which party turns on role, so settle provider or deployer status first.

The three clocks

No day count runs from establishing the causal link. The link triggers the word "immediately"; every outer limit runs from awareness of the incident by the provider or, where applicable, the deployer.

Regime Immediate report triggered by Outer limit from awareness
General, Article 73(2) A causal link between system and incident, or the reasonable likelihood of one 15 days
Widespread infringement, Article 3(61), or critical infrastructure, Article 3(49)(b), Article 73(3) No causal-link condition: immediate on awareness Two days
Death of a person, Article 73(4) The provider or deployer having established, or as soon as it suspects, a causal relationship 10 days

Three points get reversed in practice. The death case has the longer backstop, 10 days against two, but the lower immediacy trigger, since suspicion is enough. The two-day regime has no causal-link limb, so it cannot be deferred while the investigation runs. And 15 days is a ceiling, not an entitlement: the second subparagraph of Article 73(2) requires the period to take account of severity. Article 73(5) then makes the deadlines absolute, permitting an incomplete initial report followed by a complete one, so an unfinished investigation never excuses a missed clock.

The Regulation never says when a corporate provider becomes aware, or whose knowledge counts. Since Article 73(2) names the deployer's awareness alongside the provider's, a provider cannot postpone its own backstop by pointing to a slow deployer escalation. Nor is Article 3(61) listed in Article 3(49), so a widespread infringement is reportable only where it also engages limb (c), which it ordinarily will.

Where other Union law takes over

Two provisions narrow the duty to the same limb. Under Article 73(9), where an Annex III high-risk system comes from a provider subject to Union legislative instruments laying down equivalent reporting obligations, notification shrinks to Article 3(49)(c) incidents only. Article 73(10) shrinks the medical device case to the same limb and changes the recipient. Paragraph 9 covers Annex III systems, and Annex I embedded products get no equivalent relief beyond the medical device rule. The Regulation names no instrument as equivalent and nobody to decide equivalence, and as an exception to a reporting duty the burden sits with the provider invoking it, so record which instrument is relied on and map it against all four limbs.

General-purpose AI is a separate regime. Article 55(1)(c) binds providers of general-purpose AI models with systemic risk only, and requires them to report serious incidents and possible corrective measures, without undue delay, to the AI Office and as appropriate to national competent authorities. There is no day count, so the 15, 10 and two-day clocks do not apply, and Article 55(2) allows reliance on a code of practice under Article 56 until a harmonised standard is published. Where one organisation is both model provider and high-risk system provider, nothing says one filing discharges both, and the standards differ, so file both. The addressee will often be the same body, because Article 75(1), point (a) puts a high-risk system built on that provider's own general-purpose AI model under the AI Office's exclusive competence, and Article 75(1a) then routes the Article 73 report to the AI Office as well, unless one of the carve-outs in that point applies. The model-level picture is in the GPAI obligations guide.

What the process has to capture

Each item below is there because a provision turns on it.

  • First awareness, timed, in the organisation and at any deployer: every day count runs from it under Article 73(2), (3) and (4).
  • Which Article 3(49) limb is engaged, because it selects the clock and decides whether Article 73(9) or (10) shrinks the duty, and whether Article 3(61) also applies.
  • When a causal link was established, its likelihood formed, or in a death case suspected, because that starts the immediacy duty, plus the Article 73(6) risk assessment and corrective action.
  • Every member state where the incident occurred, because Article 73(1) owes a report to the authorities of each, and whether Article 75(1a) redirects it to the AI Office.

The feedstock is Article 72, whose post-market monitoring system must actively and systematically collect, document and analyse performance data across the system's lifetime, including data from deployers. The Omnibus replaced Article 72(3): the plan stays mandatory and part of the Annex IV technical documentation, but the binding implementing-act template is gone, and non-binding Commission guidance and a template are due by 2 September 2027.

Article 73(6) can make a hotfix unlawful. No investigation may alter the system in a way which may affect a later evaluation of the causes before the competent authorities are told, yet Article 20(1) requires corrective action immediately. The two reconcile: withdrawing, disabling or recalling is corrective action, not investigation, but overwriting the failing weights, configuration or logs is what paragraph 6 catches.

Dates, and what a failure costs

Article 73 sits in Chapter IX, Section 2, not Chapter III. The Omnibus amended the third paragraph of Article 113, and its new point (c) defers Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), to 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those classified under Article 6(1) and Annex I. Chapter IX is in no carve-out, so on the face of the text Article 73 has applied since the general date of 2 August 2026. What is deferred is the deployer duty, because Article 26 is in Chapter III, Section 3.

2 Dec 2027 Chapter III Sections 1 to 3 apply to Annex III systems, so the Article 26(5) deployer duty starts to bite. 2 August 2028 for Annex I.

The Regulation does not resolve the tension that leaves: Article 73 is textually live while the Chapter III classification rules and provider obligations it depends on are not, so it has little to bite on until the high-risk requirements apply. Article 111(2) also excludes systems placed on the market before that date unless significantly changed in design, with a 2 August 2030 backstop for public authorities. The guidance that would settle the mechanics is overdue: Article 73(7) required it by 2 August 2025, and the draft published on 26 September 2025 is still a draft as at 6 August 2026.

The exposure is asymmetric, and the usual 3% line is only half right. A deployer in breach of Article 26(5) is inside Article 99(4)(e): up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. A provider that fails to report is not. Article 99(4) is a closed list whose provider hooks are Article 16 and, since the Omnibus inserted point (da), Article 25(2) and (4), and neither reaches Article 73, so the failure falls to Article 99(1), amended by the Omnibus to reach "any infringement of this Regulation", and the ceiling is national law, not a figure in the Regulation. Two things pull it back up: Article 16(j) covers the Article 20 corrective-action duties, which the same facts usually trigger, and under the new Article 75c(4) an infringement of any provision "including those not listed in Article 99(4)" sits in the 3% tier for systems under AI Office competence. Article 99(7) treats cooperation and self-notification, at points (f) and (h), as mitigating factors, as the penalties guide sets out.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What counts as a serious incident under the EU AI Act?

Article 3(49) defines it as an incident or malfunctioning of an AI system that directly or indirectly leads to any of four outcomes: the death of a person or serious harm to a person's health, a serious and irreversible disruption of the management or operation of critical infrastructure, the infringement of obligations under Union law intended to protect fundamental rights, or serious harm to property or the environment. Two features of the chapeau matter. A malfunctioning counts on its own, with no external event required, and indirect causation counts, so a chain running through a human decision still qualifies.

How long do you have to report a serious incident under the AI Act?

Three outer limits, all measured from awareness of the incident rather than from establishing its cause. Article 73(2) sets the general backstop at 15 days and requires the report immediately once the provider has established a causal link or the reasonable likelihood of one. Article 73(3) cuts that to two days for a widespread infringement or a critical infrastructure incident under Article 3(49)(b), with no causal-link condition at all. Article 73(4) allows 10 days where a person has died, but the immediacy trigger is mere suspicion of a causal relationship.

Do deployers have to report serious incidents to the authorities?

Not under Article 73, which binds providers. Article 26(5) requires a deployer that has identified a serious incident to immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities. The sequence is prescribed and the authority is in it. If the deployer cannot reach the provider, Article 73 applies mutatis mutandis, so the deployer inherits the provider's clocks. Sensitive operational data of law enforcement deployers is excluded. The duty applies from 2 December 2027 for Annex III systems.

Who do you report an AI Act serious incident to?

Article 73(1) names the market surveillance authorities of the member states where the incident occurred, which may be several and need not include the provider's home state. Two rules redirect that. Article 73(10) sends reports about medical devices under Regulation (EU) 2017/745 or (EU) 2017/746 to the national competent authority chosen for that purpose by the state where the incident occurred. Article 75(1a), inserted by Regulation (EU) 2026/1744 and in force since 27 July 2026, sends reports to the AI Office where the system falls under its exclusive competence.

Is there an official AI Act serious incident reporting template?

Not a final one for high-risk systems. Article 73(7) required the Commission to issue dedicated guidance on the Article 73(1) obligation by 2 August 2025. A draft guidance and reporting template was published for consultation on 26 September 2025, the consultation closed on 7 November 2025, and the Commission consultation page still carries only the draft as at 6 August 2026. A separate final template exists for general-purpose AI models with systemic risk, published 4 November 2025 under Article 55(1)(c).

What is the penalty for failing to report a serious incident?

It depends on who is in breach. A deployer that fails the Article 26(5) duty is inside Article 99(4)(e), so up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. A provider that fails Article 73 is not: Article 73 appears neither in the closed Article 99(4) list nor in the Article 16 provider obligations, so the exposure falls to national law under Article 99(1). For systems under AI Office competence, Article 75c(4) puts unlisted infringements back in the 3% tier.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.