In short
- Article 73 runs three deadlines, not one: 15 days as standard, 10 days where a death may be involved, and 2 days for widespread infringement or serious disruption of critical infrastructure.
- The clock starts when the provider becomes aware of the incident, not when the cause is proven. Article 73(5) expressly allows an incomplete first report.
- The duty sits on the provider of a high-risk system. A deployer that puts its own name on a system, or substantially modifies one, can become the provider under Article 25.
- Substantive high-risk obligations now begin on 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, after the amendments approved on 16 June 2026.
- Article 73 is rarely the first duty to fire. GDPR gives 72 hours and NIS2 an early warning inside 24 hours, so the AI Act report is often the third notification, not the first.
What do AI assistants say about your organisation?
Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.
A serious incident under the AI Act does not start one clock. It starts one of three, and the difference between them is thirteen days.
Which clock runs is decided by what the incident did, not by how serious it felt inside the company.
01What does the AI Act count as a serious incident?
Article 3(49) defines it, and the definition is narrower than most internal incident taxonomies.
A serious incident is an incident or malfunctioning of an AI system that directly or indirectly leads to one of four outcomes: the death of a person or serious harm to a person’s health, a serious and irreversible disruption of the management or operation of critical infrastructure, an infringement of obligations under Union law intended to protect fundamental rights, or serious harm to property or the environment.
Two words in that definition do most of the work. “Indirectly” pulls in chains of causation that an engineering post-mortem would treat as someone else’s problem. “Malfunctioning” means the system does not have to be attacked or misused; it is enough that it did not behave as intended.
An outage is not automatically a serious incident. A model that quietly denied a benefit to a protected group for six weeks probably is.
02Which of the three clocks applies to you?
| Trigger | Deadline | Provision |
|---|---|---|
| Widespread infringement, or serious and irreversible disruption of critical infrastructure | 2 days | Article 73(3) |
| Incident where the death of a person may be involved | 10 days | Article 73(4) |
| All other serious incidents | 15 days | Article 73(2) |
| Completion of an initial report filed incomplete | Without undue delay | Article 73(5) |
The practical consequence is that the two day case has to be recognised by whoever takes the call at 19:00 on a Friday. Fifteen days survives a bad handover. Two days does not.
That argues for a triage question in the runbook rather than a severity matrix: does this touch critical infrastructure, and is the disruption irreversible? If either answer is uncertain, the safe assumption is the shorter clock.
03Who files, and can a deployer ever be on the hook?
The duty in Article 73 sits on the provider of the high-risk system.
Most organisations reading this are deployers, and conclude that the reporting duty belongs to their vendor. That conclusion is correct until Article 25 applies. An organisation that places a high-risk system on the market under its own name or trademark becomes the provider. So does one that makes a substantial modification to a high-risk system, or that changes the intended purpose of a system so that it becomes high risk.
Fine tuning a vendor model on internal data, and shipping the result to customers under your own brand, is the ordinary way a deployer becomes a provider without deciding to.
The contract does not settle this. Article 25 allocates the obligation by conduct, and a clause saying the vendor handles regulatory reporting does not move a statutory duty off the party the statute names.
04What goes in the first report when the cause is unknown?
Less than teams expect, and this is deliberate.
Article 73(2) requires the report immediately after the provider establishes a causal link, or a reasonable likelihood of one, between the AI system and the incident. Reasonable likelihood is a low bar and it is meant to be. Article 73(5) then allows an incomplete initial report, to be completed once the investigation progresses.
The failure mode is the opposite of the one teams fear. Nobody is penalised for a thin first report inside the deadline. The exposure is in waiting for root cause analysis to finish, which routinely takes longer than fifteen days, and reporting late with a complete story.
Article 73(6) is the part that outlasts the deadline: the provider must perform the necessary investigations, carry out a risk assessment of the incident, and take corrective action, while cooperating with the authority. Filing on time and doing nothing afterwards is not compliance, and the investigation depends on what the logs actually recorded.
05Which other reporting duty will reach the regulator first?
Almost always one of the others.
| Regime | First deadline | What starts it |
|---|---|---|
| NIS2, Article 23 | 24 hours | Awareness of a significant incident, early warning |
| GDPR, Article 33 | 72 hours | Awareness of a personal data breach |
| NIS2, Article 23, full notification | 72 hours | Follow up to the early warning |
| AI Act, Article 73 | 2 to 15 days | Reasonable likelihood of a causal link |
An AI system that leaks personal data during an incident engages GDPR first, by a wide margin, and since 11 September 2026 a fourth regime has been live, which we set out in four regimes, four clocks. An essential entity under NIS2 owes an early warning inside 24 hours. The AI Act report arrives days later and goes to a different authority, the market surveillance authority of the Member State where the incident occurred.
The design implication is that the AI Act should not get its own incident process. It should get an additional branch on the one that already exists, with one owner who decides which regimes are engaged, because the 24 hour clock will have expired long before a separate AI governance workflow convenes.
The other implication is jurisdictional. Article 73 points at the Member State where the incident occurred, which for a system serving several markets can mean more than one authority and more than one language.
06Frequently asked questions
How many days do you have to report a serious AI incident in the EU?
Fifteen days from becoming aware, as a general rule. That drops to ten days where the incident may have caused a death, and to two days for a widespread infringement or serious and irreversible disruption of critical infrastructure.
Does Article 73 apply to deployers or only to providers?
The reporting duty in Article 73 sits on providers of high-risk AI systems. A deployer can inherit it: under Article 25 an organisation that puts its own trademark on a high-risk system, or substantially modifies one, is treated as the provider and takes on the provider obligations.
What if you do not know the cause of the incident within the deadline?
You report anyway. Article 73(5) allows an incomplete initial report followed by a complete one, and Article 73(2) requires notification once there is a reasonable likelihood of a causal link, not proof of one.
When do the Article 73 obligations actually start applying?
They attach to high-risk systems, so they bite when the high-risk regime does. Following the amendments approved on 16 June 2026, that is 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
07References and method
- Regulation (EU) 2024/1689, Article 73 (reporting of serious incidents) and Article 3(49) (definition). Primary source for the three deadlines, the awareness trigger and the incomplete report provision.
- Regulation (EU) 2024/1689, Article 25, for the circumstances in which a deployer, distributor or importer is treated as a provider.
- Amendments to the AI Act agreed provisionally on 7 May 2026 and approved by the European Parliament on 16 June 2026, deferring Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 2028. Verified against contemporaneous law firm analyses on 12 September 2026; the deferral is widely reported and we have not seen it contradicted.
- Regulation (EU) 2016/679, Article 33, for the 72 hour personal data breach deadline. Directive (EU) 2022/2555 (NIS2), Article 23, for the 24 hour early warning and 72 hour incident notification.