What it is
Article 73 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) creates a legal duty for providers of “high-risk” AI systems to tell national regulators when something has gone seriously wrong. A “serious incident” is defined in Article 3(49) as an event where an AI system, directly or indirectly, causes death or serious harm to a person’s health, causes serious and irreversible disruption to the management of critical infrastructure, infringes obligations under EU law meant to protect fundamental rights, or causes serious harm to property or the environment.
The timelines are tiered by severity. The general rule is that a provider must notify the market surveillance authority of the Member State where the incident occurred immediately after establishing a causal link between the AI system and the harm, and in any case no later than 15 days after becoming aware of it. If someone has died, the deadline tightens to 10 days. If the incident involves widespread infringement or serious disruption to critical infrastructure, the deadline is just 2 days. Regulators are then expected to act on a report within 7 days. Providers cannot wait for a complete picture before reporting — the rule explicitly allows an incomplete initial report, followed later by a full one, precisely so companies don’t sit on bad news while investigating.
Critically, the duty only attaches to systems that are formally classified as “high-risk” under Annex III of the Act — categories like employment screening, credit scoring, law enforcement, and critical infrastructure management. A general-purpose AI chatbot or autonomous agent is not automatically high-risk; it becomes subject to Article 73 only if it is deployed in one of those enumerated high-risk contexts, or otherwise meets the Act’s high-risk classification criteria under Article 6.
Why it matters for AI governance and narratives
Article 73 sits at the center of a recurring framing contest: is AI harm something companies self-report in good faith, or something regulators must independently detect and enforce? The provision is the EU’s answer — a mandatory, deadline-driven disclosure regime backed by fines of up to €15 million or 3% of global annual turnover — and it makes the absence of a filing itself a piece of evidence, not just silence. When a correspondent asks whether a company has filed a serious-incident report, they are implicitly testing whether the company accepts that its system falls under high-risk classification at all, or is quietly relying on the ambiguity of general-purpose systems to avoid the reporting trigger. That ambiguity is not incidental; the European Commission’s own draft guidance (published 26 September 2025) acknowledges the scope questions around general-purpose AI models with systemic risk under the separate Article 55(1)(c) regime, and states plainly that it does not yet resolve how the two reporting tracks interact. An agent episode — an AI system autonomously taking a consequential action, such as editing a public reference source — sits exactly in this unresolved space: is it a high-risk deployment triggering Article 73, a systemic-risk GPAI event under Article 55, or neither? The narrative question of “did they report it” cannot be settled until the prior legal question of “were they obligated to” is.
Key facts and dates
The AI Act entered into force in August 2024, with obligations phased in over several years; the high-risk system provisions, including Article 73’s reporting duty, became applicable from 2 August 2026 — meaning the duty is now live. The European Commission published draft implementing guidance on serious-incident reporting on 26 September 2025, opening a public consultation that closed 7 November 2025, aimed at clarifying ambiguous cases (the guidance’s own examples include a medical AI system whose flawed output causes harm only after a clinician’s subsequent decision, and a wrongful loan denial based on a flawed automated assessment — both illustrating a broad, indirect-causation reading of “serious incident”). Enforcement runs through national market surveillance authorities in each Member State, coordinated with the Commission via the EU’s existing market surveillance framework (Regulation (EU) 2019/1020).
Where to learn more
- Article 73: Reporting of Serious Incidents — official text and explanation
- Art. 73 Reporting of Serious Incidents — EU AI Act text mirror with scope notes
- Latham & Watkins: European Commission Publishes Draft Guidance on Reporting Serious AI Incidents (28 October 2025)
- Freshfields: EU AI Act unpacked #30 — Commission launches consultation on serious AI incident reporting rules