EU AI Act Art. 73 — Reporting of serious incidents
Article 73 puts strict clocks on serious-incident reporting: providers report to market surveillance authorities as soon as a causal link is established — within 15 days generally, 10 days when someone has died, and 2 days for widespread infringements.
At a glance
What this article requires
- Providers must report serious incidents to market surveillance authorities as soon as a causal link is established or reasonably suspected.
- General deadline: 15 days from becoming aware.
- Death of a person: 10 days.
- Widespread infringement or serious incidents affecting many people: 2 days.
- An incomplete initial report is allowed, followed by a complete report.
Scope
Who this applies to
Providers of high-risk AI bear the reporting duty; deployers must inform providers and can trigger the report themselves where relevant.
Obligations
What you must actually do
Build the incident process before you need it
Have the triage, causality, and notification workflow rehearsed, with an on-call owner.
Know your clocks
15 days general, 10 days on death, 2 days on widespread infringement — and start the clock on awareness, not confirmation.
Report even when unsure
A reasonable likelihood of a causal link is enough to trigger reporting; you can file an incomplete initial report and follow up.
Action plan
Practical first steps
- 1
Define 'serious incident' for your systems per Art. 3(49) and rehearse classification.
- 2
Stand up a 24/7 contact and a template report to the market surveillance authority.
- 3
Log every incident and your reporting decision — the paper trail is your defence.
Penalty exposure
Failing to report serious incidents sits in the general tier: up to €15 million or 3% of global annual turnover — and incident-reporting failures are exactly the kind regulators pursue aggressively.
FAQ
Questions about Art. 73
What counts as a 'serious incident'?
Art. 3(49): an incident that directly or indirectly leads to death or serious harm to health, property, or the environment, a serious and irreversible disruption of critical infrastructure, or a serious violation of fundamental rights.
Do deployers report directly?
Deployers must inform the provider; where the provider is unknown or the situation demands it, deployers can and should escalate to authorities too. Make the reporting handoff explicit in contracts.
Sources
Citations & further reading
Related
More article explainers
Wondering which articles apply to your AI?
Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.
Check my use casePreliminary EU AI Act clarity summary. Not legal advice.