WHAT THE ARTICLE IS ABOUT
Mandatory incident notification with tight deadlines
Article 73 requires providers of high-risk AI systems to report serious incidents to market surveillance authorities promptly after discovering them. A serious incident is defined in Article 3 as an incident leading to death, serious harm to health, significant disruption of critical infrastructure, or violation of fundamental rights obligations. The reporting obligation is not discretionary — where the threshold is met, reporting is mandatory.
WHAT IT SAYS
15 days normally, 2 days for severe incidents, 10 days for fatalities
- Providers must report serious incidents to the market surveillance authority of the member state where the incident occurred
- Reporting must happen immediately after the provider establishes a causal link — or reasonable likelihood of one — between the AI system and the incident
- The general deadline is 15 days from when the provider or deployer becomes aware of the incident
- Where the incident is severe — posing an immediate threat to the safety of persons or the functioning of critical infrastructure — reporting must happen within 2 days
- Where a death has occurred, the deadline is 10 days
- Providers may submit an initial incomplete report where the full information is not yet available — but must follow up promptly with a complete report
- Following the report, providers must investigate without delay and cooperate with authorities — they must not alter the AI system in ways that could affect the investigation without informing authorities first
- Deployers who become aware of a serious incident must also notify the provider without undue delay, triggering the provider’s reporting obligation
WHO IS AFFECTED
All providers of high-risk AI systems and deployers who discover incidents
- Providers of high-risk AI systems — primary reporting obligation
- Deployers who discover serious incidents — must notify the provider promptly
- Market surveillance authorities who receive and act on reports
- Providers and deployers of GPAI models where serious incidents involve those models — additional reporting to the AI Office
WHAT IT MEANS FOR SMES
Prepare your incident response process before you need it
- The two-day deadline for severe incidents is extremely tight — you cannot build an incident response process after an incident occurs; it must exist in advance
- Define in advance what constitutes a serious incident for your specific AI system — map the Article 3 definition to your use case so that when something happens, your team knows immediately whether the reporting threshold is met
- Establish clear internal escalation paths: who in your organisation decides whether an incident is reportable? Who drafts the report? Who is the contact point for the authority?
- Your deployer agreements should include an obligation for deployers to notify you of incidents promptly — their delay in notifying you does not extend your reporting deadline
- An initial incomplete report is better than a late complete one — if you are unsure whether you have all the information, submit what you have within the deadline and follow up
- Document your monitoring processes and incident logs carefully — authorities will request these during investigations and they form part of your compliance evidence
Related Articles
- Article 3 — Definitions (defines ‘serious incident’ — the threshold that triggers this obligation)
- Article 72 — Post-market monitoring (the monitoring system that will typically detect serious incidents)
- Article 20 — Corrective actions (must be taken alongside or following incident reporting)
- Article 74 — Market surveillance (the authority that receives and acts on incident reports)
