Art.73
EU AI Act Guide › Chapter IX — Post-Market Monitoring › Article 73

Article 73 – Reporting of Serious Incidents

High-Risk Systems SME Relevant ~3 min read · 538 words

Article 73 establishes the obligation to report serious incidents involving high-risk AI systems to national market surveillance authorities. It defines what counts as a serious incident, sets strict reporting timelines — as short as two days for the most severe cases — and specifies what the report must contain. This is the AI Act’s equivalent of mandatory breach notification: time-critical, legally binding, and requiring advance preparation.

! High compliance impact for SMEs

WHAT THE ARTICLE IS ABOUT

Mandatory incident notification with tight deadlines

Article 73 requires providers of high-risk AI systems to report serious incidents to market surveillance authorities promptly after discovering them. A serious incident is defined in Article 3 as an incident leading to death, serious harm to health, significant disruption of critical infrastructure, or violation of fundamental rights obligations. The reporting obligation is not discretionary — where the threshold is met, reporting is mandatory.

WHAT IT SAYS

15 days normally, 2 days for severe incidents, 10 days for fatalities

  • Providers must report serious incidents to the market surveillance authority of the member state where the incident occurred
  • Reporting must happen immediately after the provider establishes a causal link — or reasonable likelihood of one — between the AI system and the incident
  • The general deadline is 15 days from when the provider or deployer becomes aware of the incident
  • Where the incident is severe — posing an immediate threat to the safety of persons or the functioning of critical infrastructure — reporting must happen within 2 days
  • Where a death has occurred, the deadline is 10 days
  • Providers may submit an initial incomplete report where the full information is not yet available — but must follow up promptly with a complete report
  • Following the report, providers must investigate without delay and cooperate with authorities — they must not alter the AI system in ways that could affect the investigation without informing authorities first
  • Deployers who become aware of a serious incident must also notify the provider without undue delay, triggering the provider’s reporting obligation

WHO IS AFFECTED

All providers of high-risk AI systems and deployers who discover incidents

  • Providers of high-risk AI systems — primary reporting obligation
  • Deployers who discover serious incidents — must notify the provider promptly
  • Market surveillance authorities who receive and act on reports
  • Providers and deployers of GPAI models where serious incidents involve those models — additional reporting to the AI Office

WHAT IT MEANS FOR SMES

Prepare your incident response process before you need it

  • The two-day deadline for severe incidents is extremely tight — you cannot build an incident response process after an incident occurs; it must exist in advance
  • Define in advance what constitutes a serious incident for your specific AI system — map the Article 3 definition to your use case so that when something happens, your team knows immediately whether the reporting threshold is met
  • Establish clear internal escalation paths: who in your organisation decides whether an incident is reportable? Who drafts the report? Who is the contact point for the authority?
  • Your deployer agreements should include an obligation for deployers to notify you of incidents promptly — their delay in notifying you does not extend your reporting deadline
  • An initial incomplete report is better than a late complete one — if you are unsure whether you have all the information, submit what you have within the deadline and follow up
  • Document your monitoring processes and incident logs carefully — authorities will request these during investigations and they form part of your compliance evidence

Related Articles

← Previous Art. 72 — Post-Market Monitoring by Providers and Post-Market Monitoring Plan for High-Risk AI Systems Next → Art. 74 — Market Surveillance and Control of AI Systems in the Union Market