AI Act, Article 73 (reporting of serious incidents)
Regulation (EU) 2024/1689, Article 73
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 47 days, effective 2 August 2026.
An AI risk obligations rule binding public and private bodies.
As of 18 September 2026.
What it requires
- If your high-risk AI system is placed on the EU market and you are its provider, report any serious incident to the market surveillance authority of the Member State where the incident occurred.
- Report a serious incident not later than 15 days after you become aware of it, or immediately once you establish a causal link between your AI system and the incident, or the reasonable likelihood of one, whichever is sooner.
- Report immediately, and not later than 2 days after becoming aware of it, a widespread infringement or a serious incident causing a serious and irreversible disruption to the management or operation of critical infrastructure.
- Report a serious incident involving the death of a person not later than 10 days after becoming aware of it, and immediately once you establish, or suspect, a causal link between your AI system and the incident.
- Where necessary for timely reporting, you may submit an initial report that is incomplete, followed by a complete report.
- If you are a deployer of a high-risk AI system and identify a serious incident, immediately inform first the provider, then the importer or distributor, and the relevant market surveillance authority; if you cannot reach the provider, report the incident yourself under the same rules that bind a provider.
- After reporting a serious incident, without delay investigate it, including a risk assessment and corrective action, and cooperate with the competent authorities; do not alter the AI system in a way that could affect the investigation before telling the authorities.
- If your high-risk AI system is, or is a safety component of, a device covered by Regulation (EU) 2017/745 or (EU) 2017/746, report only an incident that infringes obligations under Union law intended to protect fundamental rights, and report it to the national competent authority the Member State chose for that purpose rather than to its market surveillance authority.
- If your high-risk AI system is one the AI Office supervises directly, such as a system built on your own general-purpose AI model or one integrated into a very large online platform or search engine, report the serious incident to the AI Office instead, on the same schedule.
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Providers of high-risk AI systems placed on the EU market must report a serious incident to the market surveillance authority of the Member State where it occurred. The report is due immediately after the provider establishes a causal link between the AI system and the incident, or the reasonable likelihood of one, and in any event not later than 15 days after becoming aware of it.
For a widespread infringement or a serious incident causing a serious and irreversible disruption to critical infrastructure, the report is due immediately and not later than 2 days after becoming aware of it. Where the incident caused a person's death, the report is due immediately after the provider or deployer establishes, or suspects, a causal relationship, but not later than 10 days after becoming aware of it.
Where necessary for timely reporting, the provider, or deployer where applicable, may file an initial report that is incomplete, followed by a complete report. A deployer who identifies a serious incident must immediately inform the provider first, then the importer or distributor and the market surveillance authority, and reports directly under the same rules if the provider cannot be reached.
After reporting, the provider must without delay carry out the necessary investigations, including a risk assessment of the incident and corrective action, must cooperate with the competent authorities, and must not run any investigation that alters the AI system in a way that could affect a later evaluation of the causes before telling those authorities.
Where the provider of an Annex III high-risk system is already subject to Union instruments laying down equivalent reporting obligations, notification is limited to incidents that infringe obligations under Union law intended to protect fundamental rights.
Where the high-risk AI system is, or is a safety component of, a device covered by Regulation (EU) 2017/745 or (EU) 2017/746, notification is limited to that same class of incident and goes to the national competent authority the Member State where the incident occurred chose for that purpose, rather than to its market surveillance authority.
The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) inserted a new Article 75(1a) requiring a narrow set of providers under the AI Office's own exclusive supervisory competence, meaning a general-purpose AI model integrated into the provider's own system or a system built into a Commission-designated very large online platform or search engine, to report a serious incident to the AI Office instead, with Article 73(2) to (9) applying in the same way.
The Digital Omnibus deferred a separate block, the obligations in Sections 1, 2 and 3 of Chapter III, to 2 December 2027 and 2 August 2028, which does not include Article 73's own Chapter IX reporting duty.
When LexLint raises it
high_risk_decisionsprocesses_biometrics