The EU AI Act's Serious-Incident Reporting Duty (Article 73)

Article 73 of the EU AI Act requires providers of 'high-risk' AI systems to report incidents causing death, serious health harm, critical-infrastructure disruption, or fundamental-rights violations to national regulators within 15 days (or as few as 2, for the most severe cases) — but the duty applies only to systems formally classified as high-risk, leaving general-purpose AI assistants and agents in a gray zone.

Created 2026-09-08 Last reviewed 2026-09-08

What it is

Article 73 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) creates a legal duty for providers of “high-risk” AI systems to tell national regulators when something has gone seriously wrong. A “serious incident” is defined in Article 3(49) as an event where an AI system, directly or indirectly, causes death or serious harm to a person’s health, causes serious and irreversible disruption to the management of critical infrastructure, infringes obligations under EU law meant to protect fundamental rights, or causes serious harm to property or the environment.

The timelines are tiered by severity. The general rule is that a provider must notify the market surveillance authority of the Member State where the incident occurred immediately after establishing a causal link between the AI system and the harm, and in any case no later than 15 days after becoming aware of it. If someone has died, the deadline tightens to 10 days. If the incident involves widespread infringement or serious disruption to critical infrastructure, the deadline is just 2 days. Regulators are then expected to act on a report within 7 days. Providers cannot wait for a complete picture before reporting — the rule explicitly allows an incomplete initial report, followed later by a full one, precisely so companies don’t sit on bad news while investigating.

Critically, the duty only attaches to systems that are formally classified as “high-risk” under Annex III of the Act — categories like employment screening, credit scoring, law enforcement, and critical infrastructure management. A general-purpose AI chatbot or autonomous agent is not automatically high-risk; it becomes subject to Article 73 only if it is deployed in one of those enumerated high-risk contexts, or otherwise meets the Act’s high-risk classification criteria under Article 6.

Why it matters for AI governance and narratives

Article 73 sits at the center of a recurring framing contest: is AI harm something companies self-report in good faith, or something regulators must independently detect and enforce? The provision is the EU’s answer — a mandatory, deadline-driven disclosure regime backed by fines of up to €15 million or 3% of global annual turnover — and it makes the absence of a filing itself a piece of evidence, not just silence. When a correspondent asks whether a company has filed a serious-incident report, they are implicitly testing whether the company accepts that its system falls under high-risk classification at all, or is quietly relying on the ambiguity of general-purpose systems to avoid the reporting trigger. That ambiguity is not incidental; the European Commission’s own draft guidance (published 26 September 2025) acknowledges the scope questions around general-purpose AI models with systemic risk under the separate Article 55(1)(c) regime, and states plainly that it does not yet resolve how the two reporting tracks interact. An agent episode — an AI system autonomously taking a consequential action, such as editing a public reference source — sits exactly in this unresolved space: is it a high-risk deployment triggering Article 73, a systemic-risk GPAI event under Article 55, or neither? The narrative question of “did they report it” cannot be settled until the prior legal question of “were they obligated to” is.

Key facts and dates

The AI Act entered into force in August 2024, with obligations phased in over several years; the high-risk system provisions, including Article 73’s reporting duty, became applicable from 2 August 2026 — meaning the duty is now live. The European Commission published draft implementing guidance on serious-incident reporting on 26 September 2025, opening a public consultation that closed 7 November 2025, aimed at clarifying ambiguous cases (the guidance’s own examples include a medical AI system whose flawed output causes harm only after a clinician’s subsequent decision, and a wrongful loan denial based on a flawed automated assessment — both illustrating a broad, indirect-causation reading of “serious incident”). Enforcement runs through national market surveillance authorities in each Member State, coordinated with the Commission via the EU’s existing market surveillance framework (Regulation (EU) 2019/1020).

Where to learn more

Sources

Primary-source mirror of the official Article 73 text with structured explanation of scope, deadlines, and recipients
Independent primary-text reference confirming Article 73 applies only to providers of high-risk AI systems, not general-purpose AI models
Law firm client alert summarizing the Commission's 26 September 2025 draft implementing guidance, consultation timeline, and open scope questions on GPAI
Corroborating law-firm analysis of the same Commission guidance and consultation process
Referenced in: Editorial No. 307