EU AI Act
Article 73 — Reporting of serious incidents
Article 73 puts a provider on three clocks. Fifteen days from awareness is the general outer limit for reporting a serious incident to market surveillance authorities; two days where the incident is a widespread infringement or a serious and irreversible disruption of critical infrastructure; ten days where a person has died. Each runs from awareness, not from certainty.
§ 1 — When it applies
Three clocks, and when each starts
2 August 2026
General application. Article 73 sits in Chapter IX, which Article 113 does not except, and the Digital Omnibus deferred only Chapter III Sections 1 to 3.
2 December 2027
When Annex III standalone systems become subject to the Chapter III requirements, and therefore when the population whose incidents this article reaches begins to exist in volume.
2 August 2028
The same for Annex I embedded systems, under Article 113 third paragraph point (c) as replaced by Regulation (EU) 2026/1744.
§ 2 — In practice
Why the trigger matters more than the deadline
The outer limits are backstops and reading them as deadlines is the first mistake. Paragraph 2 requires the report to be made immediately once the provider has established a causal link between the AI system and the incident, or the reasonable likelihood of such a link, and in any event not later than fifteen days after awareness. Two consequences follow. Waiting for a confirmed root cause forfeits the "immediately" limb, because reasonable likelihood is a lower bar than proof. And the same paragraph adds that the reporting period is to take account of severity, so the fifteen days is not a flat allowance to be spent. Paragraph 5 removes the usual excuse for spending it: where necessary to ensure timely reporting, an incomplete initial report may be filed and completed afterwards.
What counts is settled by Article 3(49), which is unchanged by the Digital Omnibus and has four limbs: the death of a person or serious harm to health; a serious and irreversible disruption of the management or operation of critical infrastructure; the infringement of obligations under Union law intended to protect fundamental rights; and serious harm to property or the environment. The third limb is the one engineering-led incident processes miss entirely, because nothing about it looks like an outage. A discriminatory pattern in an automated decision is a serious incident under (c) on the same footing as a physical injury under (a), and it will not be caught by a severity matrix calibrated on availability. The judgement that limb (c) is engaged is a legal one, and it has to be made by someone competent to make it within the same clock as the rest.
The two short clocks are not symmetrical, and the asymmetry is instructive. Paragraph 3 gives two days for a widespread infringement — defined in Article 3(61) by harm to collective interests across Member States — or for an incident under Article 3(49)(b), critical infrastructure. Paragraph 4 gives ten days where a person has died, but changes the trigger: the report is due immediately once the provider or deployer has established, or as soon as it suspects, a causal relationship. Suspicion, not likelihood. The provision with the longest short deadline therefore has the earliest starting gun, which is the opposite of the way most escalation policies are drafted.
The clock can start on somebody else’s knowledge. Paragraphs 2 and 4 both run from the point at which the provider "or, where applicable, the deployer" becomes aware, and Article 73(1) puts the reporting duty on the provider alone. A provider whose customer learns of a fatality on Monday and raises a support ticket on Friday has lost most of its window without knowing it existed. That makes the notification clause in the deployment contract a reporting control rather than a commercial term, and it is the reason this article cannot be operated purely from the provider’s own telemetry — the deployer-side duty to escalate lives at Article 26, and the two have to be wired to each other.
What follows the report is where the article bites hardest and is least often implemented. Paragraph 6 requires the provider, without delay, to investigate, to perform a risk assessment of the incident and to take corrective action, and — the sentence to put in the runbook — not to perform any investigation involving alteration of the AI system in a way that may affect a subsequent evaluation of the causes, before informing the competent authorities of that action. Rolling back a model to stop the bleeding is exactly such an alteration. Two narrowing paragraphs also matter: under 9 and 10, Annex III providers already subject to equivalent Union reporting obligations, and providers of systems in devices under Regulations (EU) 2017/745 and (EU) 2017/746, report only incidents under Article 3(49)(c). And the Digital Omnibus inserted Article 75(1a), under which providers subject to the AI Office’s exclusive competence report to the AI Office instead, with paragraphs 2 to 9 applying mutatis mutandis. The monitoring that surfaces most of this is a separate duty at Article 72.
§ 3 — Who it binds
Whose duty this is, and who reports less
Providers of high-risk AI systems on the Union market, for any serious incident as defined in Article 3(49), reported to the market surveillance authorities of the Member State where it occurred. Two populations report less — Annex III providers subject to equivalent Union reporting obligations, and providers of systems that are or sit inside devices under Regulations (EU) 2017/745 and (EU) 2017/746 — both confined to Article 3(49)(c).
§ 4 — What discharges it
What the incident file must show
The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.
01
An awareness timestamp per incident, naming the person
The clocks run from when someone knew, which is rarely when a ticket was opened. The record shows who first held the information and at what hour, on the provider side and on the customer side.
02
The Article 3(49) classification note, limb by limb
Which of the four limbs is engaged and on what reasoning, including an explicit answer on limb (c). A severity rating produced by an operations matrix does not address the fundamental-rights question at all.
03
The customer notification clause, with an hour figure in it
Because the deadline can run from the deployer’s knowledge, the contractual escalation window is a reporting control. An obligation to notify "promptly" leaves the provider unable to show its own clock ever started on time.
04
A filed initial report that was later completed
Paragraph 5 exists to stop timeliness being traded for completeness. A file where every submission was final and several were late shows a process that has never used the provision it needed.
05
The preservation record for the system as it stood
Version, weights, configuration and inputs held unchanged, with the date the authorities were told of any alteration. Paragraph 6 bars changes that could affect a later evaluation of causes until that notification has been made.
06
The post-report investigation, with its risk assessment and corrective action
Paragraph 6 names three outputs, not one. An investigation closing on a fix, with no reassessment of the risk picture and no cooperation record with the authority or notified body, has delivered a third of what is required.
§ 5 — Worked example
Worked example — a death, a ticket, and a rollback
A provider of a clinical triage system learns on 3 March, from a hospital customer’s incident report, that a patient prioritised as low acuity on 24 February deteriorated and died on 27 February. The customer had opened an internal review on 25 February. The provider’s process assigns a severity, opens an engineering investigation, and schedules a reporting decision for the point at which root cause is confirmed. On 6 March an engineer rolls the model back two versions to remove the suspected behaviour.
When was the report due, and what has the rollback cost?
The report was late before the provider heard about it. Paragraph 4 applies because a person has died, and it runs from the point at which the provider or, where applicable, the deployer establishes or suspects a causal relationship — the hospital’s review on 25 February is the candidate date, and the ten-day outer limit measured from the deployer’s awareness had close to expired by 3 March. The duty is the provider’s under paragraph 1 even though the knowledge was the deployer’s, which is why the contract needed a notification clause with hours in it. Waiting for confirmed root cause is not available: paragraph 4 is triggered by suspicion, and paragraph 5 permits an incomplete initial report precisely so that timeliness is not traded against completeness. The rollback is the more serious error. Paragraph 6 forbids an investigation that alters the system in a way which may affect any subsequent evaluation of the causes before the competent authorities have been informed of that action, and reverting the deployed version does exactly that. The fix would have been to inform first, then revert, and to preserve the version under which the incident occurred.
§ 6 — What a weak answer looks like
An outage process pointed at the wrong event
A security incident process retimed to the wrong event. Severity is assigned, an investigation opens, and the decision to notify waits on a confirmed cause — which is how a fifteen-day outer limit becomes six weeks. Article 73 never asks for certainty: paragraph 2 runs on reasonable likelihood, and where someone has died paragraph 4 runs on suspicion. The second half of the failure is jurisdictional. Nothing in the runbook captures when the customer knew, so the organisation cannot demonstrate whether its window had already been running for a week when its own ticket opened.
§ 7 — Exposure
Exposure — national, with one Union exception
No Union ceiling for the general population; national penalties under Article 99(1)
Article 73 is not enumerated in Article 99(4), and it sits in Chapter IX rather than Chapter III Section 2, so the Article 16(a) bridge that carries most provider duties does not reach it either. Direct exposure is therefore under Article 99(1), the penalties each Member State lays down, which must be effective, proportionate and dissuasive but vary by jurisdiction. One population is different: for operators subject to the AI Office under Article 75(1), the new Article 75c(4), inserted by the Digital Omnibus, makes infringement of any applicable provision — expressly including provisions not listed in Article 99(4) — subject to fines as referred to in Article 99(4). Market surveillance measures under Regulation (EU) 2019/1020, which the authority must consider within seven days of notification, are frequently the more consequential outcome.
§ 8 — Elsewhere
What this connects to either side
Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.
The monitoring system a provider runs under Article 72 is what surfaces most reportable events. This article governs what happens once one is surfaced, and on what clock.
ISO/IEC 42001
Clause 10.2 covers reacting to a nonconformity, evaluating the need for action to eliminate its causes, and retaining evidence of the results. It is the management-system home for the investigation this article requires after reporting.
A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.
§ 9 — provenance
The provision itself
This page sets out what the instrument requires and what discharges it. The official text is the authority — these go straight to it.
- Article 73, with the definitions in Article 3(49) and Article 3(61)
- Article 113 second paragraph — Chapter IX is not among the exceptions in the third paragraph
- Regulation (EU) 2026/1744, Article 1 point (32), inserting Article 75c(4) of Regulation (EU) 2024/1689; Article 99(1) of that Regulation for national penalties
- Regulation (EU) 2026/1744, Article 1 point (31), inserting Article 75(1a) — the derogation routing reports to the AI Office
§ 10 — Also read
Also read
Article 26 — obligations of deployers
Article 12 — record-keeping and logs
Certification
Assessed on the same standard of evidence
Every Council credential is examined on applied judgement against a published anchor, set out the way the obligations on this page are. The free AI Literacy Certificate is open to any adult today, and the register lists what is open for enrolment.