{"answer_id":"praxikon:eu:ai-act:answer:incidenten-melden","canonical_page":"https://www.praxikon.com/en/antwoord/incidenten-melden","query":"Do we have to report serious incidents with our AI system?","lang":"en","view":"full","mode":"scenario","question":"Do we have to report serious incidents with our AI system?","situation":"Something goes wrong with a high-risk AI system and you need to know whether that is a reportable incident, who to report it to and within what deadline.","likely_role":"Provider (you place the system on the market)","note":"The deadline depends on severity: at most 15 days after establishing the causal link, 10 days in case of death and 2 days for a widespread infringement or serious disruption of critical infrastructure. As a deployer you do not report to the authority yourself but inform the provider without delay.","matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.2.0","schema_version":"1.5.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-73-incident-reporting","label":"Article 73: serious incident reporting","summary":"The duty to report serious incidents with high-risk AI, under strict deadlines.","legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","high_risk_regime_from":"2027-12-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure. Deployers inform the provider without delay.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 73(1)-(11)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"annex-iii-high-risk","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-72-post-market-monitoring","label":"Article 72: post-market monitoring","summary":"Systematic monitoring of high-risk AI in real use, after market placement.","legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","high_risk_regime_from":"2027-12-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/article-72-post-market-monitoring","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 72 obliges providers to operate a post-market monitoring system with a plan forming part of the technical documentation, collecting relevant real-world data to evaluate continued compliance with Section 2.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Compliance does not stop at go-live: this article turns compliance into a continuous state. For deployers it is also the basis to force suppliers to act on deviations.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Design the monitoring together with the Article 12 logging: the same data flows feed both duties.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 72(1)-(4)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-20-corrective-actions","label":"Article 20: corrective actions and duty of information","summary":"A provider that considers, or has reason to consider, that a high-risk AI system it has placed on the market or put into service is not in conformity with the Regulation must immediately take the necessary corrective actions and inform the distributors accordingly, and, where applicable, also the deployers, the authorised representative and the importers. Where that system also presents a risk within the meaning of Article 79(1), the provider must immediately investigate the causes and inform the competent market surveillance authorities and, where applicable, the notified body that issued a certificate under Article 44.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-20-corrective-actions","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Paragraph 1. Providers of high-risk AI systems which consider or have reason to consider that a high-risk AI system that they have placed on the market or put into service is not in conformity with this Regulation shall immediately take the necessary corrective actions to bring that system into conformity, to withdraw it, to disable it, or to recall it, as appropriate. They shall inform the distributors of the high-risk AI system concerned and, where applicable, the deployers, the authorised representative and importers accordingly. Paragraph 2. Where the high-risk AI system presents a risk within the meaning of Article 79(1) and the provider becomes aware of that risk, it shall immediately investigate the causes, in collaboration with the reporting deployer, where applicable, and inform the market surveillance authorities competent for the high-risk AI system concerned and, where applicable, the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"For the Annex III route this requirement applies from 2 December 2027; for high-risk AI in regulated products (Annex I) from 2 August 2028.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), of Regulation (EU) 2026/1744, replacing Article 113, third paragraph, point (c), of Regulation (EU) 2024/1689","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"This provision is rarely read as a procedure, and that is exactly where it goes wrong. Article 20 places four measures side by side that differ sharply in practice, and those four are not legally equivalent. Recall and withdrawal are defined in Article 3(16) and (17), and the knowledge base carries those terms separately; the difference between them is the point in the chain. Bringing a system into conformity is the patch. Disabling is the odd one out: it is practically the heaviest switch, because it stops a customer who is running the system, and it is at the same time the only one of the four the Regulation nowhere defines. Anyone who copies that word into a contract or procedure without deciding for themselves what it means leaves the heaviest measure the vaguest. The second half is the notification, and in practice that is what fails most often. Paragraph 1 asks you to reach your distributors and, where applicable, your deployers, authorised representatives and importers, which is only possible if you hold a current list of who runs the system in which version and through which contact you reach them. That list is not a by-product of your CRM: resale, white labelling and integration mean you have customers you do not know.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"Paragraph 2 and Article 73 are often built as a single reporting channel, and that goes wrong in two ways. The trigger differs: Article 73 concerns a serious incident that has occurred, Article 20(2) a risk within the meaning of Article 79(1), that is, a risk to the health, safety or fundamental rights of persons. That is not a tidy split between past and future: a serious incident that has occurred usually also means the system presents a risk, so in practice both provisions often fire at the same time. Nor do the recipients differ entirely, because both routes run to market surveillance authorities. The difference sits in the detail: Article 73(1) points to the authorities of the Member States where the incident occurred, Article 20(2) to the authorities competent for the system concerned, and only Article 20(2) adds the notified body that issued a certificate under Article 44. Only Article 73, moreover, sets hard deadlines. So build one internal process with two exits, not two separate channels and not one channel that forgets the notified body.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(2), Article 73(1)-(2) and Article 79(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Write out the four measures in paragraph 1 as four concrete scenarios with an owner, a decision maker and a lead time, and decide for yourself what disabling means in your system, because the Regulation does not define that term. Test at least once whether you can actually disable or recall a system without needing a fresh decision to do so. Also keep a record, per system version, of who runs it and through which contact you reach that party, and record which signal meets the \"reason to consider\" threshold in your organisation, so that the moment of becoming aware is demonstrable rather than something reconstructed after the fact.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 20(1)-(2)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-4-ai-literacy","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null},{"kind":"recommended_action","statement":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}]}],"conditional":[{"slug":"article-61-informed-consent","id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","label":"Article 61: informed consent of test subjects for testing in real world conditions","status":"possibly_applies","source_locator":"Article 60(4), point (i), with Article 61(1)","addressee":"reader","human_page":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent"}],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":"Digital Omnibus on AI 2026/1744","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":"AI literacy questions and answers","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":"Draft guidelines on the classification of high-risk AI systems","publisher":"European Commission (AI Office)","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Set up an incident process with reporting routes","summary":"Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process."},{"label":"Justify the Article 6(3) exception against each individual condition","summary":"Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making."},{"label":"Draw up a post-market monitoring plan","summary":"Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime."}],"evidence":[{"label":"Incident register and reports","summary":"Record of incidents, analyses, reports to supervisors and corrective measures.","url":null},{"label":"Article 49(2) registration record for the system assessed as not high-risk","summary":"Proof that the system for which you invoke the Article 6(3) exception is registered as Article 49(2) requires, with the registration number linked to the underlying assessment.","url":null},{"label":"Monitoring plan and reports","summary":"The plan as part of the technical documentation plus the periodic analyses and follow-up actions.","url":null}],"guidance":[{"label":"No mandatory course format, no certificate, no exam and no AI officer","statement":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)"},{"label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","statement":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)"},{"label":"Article 6 has two separate routes to high-risk","statement":"The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)"},{"label":"Broadly positioned and general purpose AI systems: a disclaimer is not enough","statement":"According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.","source_locator":"Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)"}],"examples":[{"label":"Performance scoring for staff goes wrong: report or not","situation":"An employer uses an AI system that scores employee performance and lets that score weigh in promotion and dismissal. After a change to the model it turns out that a group of staff was scored too low for months, and decisions have already been taken on those scores. HR wonders whether this is a serious incident and who would have to report it.","outcome":"Article 3, point (49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to, among other things, the infringement of obligations under Union law intended to protect fundamental rights. Article 73(1) places the duty to report serious incidents on the provider of the high-risk AI system placed on the Union market, towards the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires the report to be made immediately after the provider has established a causal link between the AI system and the serious incident, or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident, with the period taking account of the severity of the incident. Article 73(6) obliges the provider, after reporting, to perform the necessary investigations without delay in relation to the serious incident and the AI system concerned, including a risk assessment and corrective action, cooperating with the competent authorities and, where relevant, with the notified body concerned. Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities.","lesson":"In the workplace the hard part is the awareness trigger in Article 73(2): harm spread thinly across many employees does not arrive as an alarm but trickles in through complaints, a performance review or the works council. Whether systematically low scores that feed into promotion and dismissal amount to a serious incident depends, on our reading, on whether obligations protecting fundamental rights have thereby been infringed within the meaning of Article 3, point (49)(c); Article 73 does not make that assessment for you. Decide in advance which HR signal counts as an incident signal and who puts it in front of the provider that same week, rather than reconstructing that afterwards; Article 26(5) also requires you as deployer, once you have identified a serious incident, to inform the provider immediately and then the importer or distributor and the market surveillance authority. Note finally that the corrective action in Article 73(6) concerns the system; what should happen to promotion or dismissal decisions already taken is, on our reading, not answered by this article and runs through other rules, employment law among them.","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2) and (6)","provenance":"editorial"},{"label":"Serious incident on the production line: who reports and within what deadline","situation":"A manufacturer supplies an AI system that runs as a safety component in a machine on the production line and at the same time drives quality control. At a customer's factory an operator is seriously injured after the machine failed to stop on an anomaly. The question is who reports, to whom, and which clock is already running at that moment.","outcome":"Article 73(1) places the reporting of serious incidents on the provider of the high-risk AI system placed on the Union market, addressed to the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires that report to be made immediately after the provider has established a causal link between the AI system and the serious incident, or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the incident, with the reporting period taking account of the severity of the incident. Article 73(4) shortens that to no later than 10 days in the event of the death of a person. Article 73(6) obliges the provider, following the report, to perform the necessary investigations without delay, including a risk assessment and corrective action, and not to perform any investigation involving alteration of the AI system in a way that may affect the subsequent evaluation of the causes of the incident without first informing the competent authorities. Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities, and makes Article 73 apply mutatis mutandis where the deployer cannot reach the provider.","lesson":"We read Article 73(2) as meaning that the clock can already start at the deployer on the factory floor, while the report under Article 73(1) sits with you as the provider of the AI system. That does not leave your customer free to sit still: Article 26(5) gives the deployer a notification route of its own, running past you, the importer or distributor and the market surveillance authority, and makes Article 73 apply mutatis mutandis if you cannot be reached. Fix that route in the contract and in the service line before anything happens. Where an operator is seriously injured but does not die, we read the outer limit of Article 73(2) as the one in play rather than the 10 days of Article 73(4); how much sooner than that outer limit you must report is left open by the text and turns on severity. Bear in mind as well that the reflex to repair the machine immediately and resume production can collide with Article 73(6), because an investigation that alters the system first requires notice to the competent authority. Working that out only during the incident costs days that these deadlines do not allow.","source_locator":"Article 73(1), (2), (4) and (6), and Article 26(5)","provenance":"editorial"},{"label":"Proctoring during an exam overshoots: from signal to reporting duty","situation":"A university of applied sciences uses proctoring software during an online exam and finds that a group of students is systematically and wrongly flagged as suspicious, after which grades were withdrawn. Teaching staff and the examination board want to know whether this pattern is a serious incident and, if so, who has to report it and within what time.","outcome":"Article 3, point (49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to, among other things, the infringement of obligations under Union law intended to protect fundamental rights. Article 73(1) obliges the provider of a high-risk AI system placed on the Union market to report serious incidents to the market surveillance authorities of the Member State where the incident occurred. Article 73(2) requires the report to be made immediately after the provider has established the causal link or the reasonable likelihood of such a link, and in any event no later than 15 days after the provider or, where applicable, the deployer becomes aware of the serious incident. Article 73(5) allows an initial, incomplete report followed by a complete report where this is necessary to ensure timely reporting. Article 73(7) provides that upon receiving a report concerning a serious incident as referred to in Article 3, point (49)(c), the market surveillance authority informs the national public authorities or bodies referred to in Article 77(1). Article 26(5) requires a deployer that has identified a serious incident to inform, immediately, first the provider and then the importer or distributor and the relevant market surveillance authorities.","lesson":"We read Article 73 as meaning that an incident in education is rarely a single dramatic moment: the signal sits in the pattern in exam results, and the institution sees that pattern before the software supplier does. Whether that pattern amounts to a serious incident is a separate question: it turns on whether the wrongful flagging and the withdrawal of grades count as an infringement of obligations protecting fundamental rights within the meaning of Article 3, point (49)(c), and Article 73 does not make that assessment for you. Leaving the question open until your own investigation is finished carries a risk, because the Article 73(2) period runs from awareness. Set up your examination and complaints process so that such a pattern reaches the provider within days; Article 26(5) also puts a notification duty on the institution itself as deployer, towards the provider, the importer or distributor and the market surveillance authority. The initial, incomplete report of Article 73(5) is the pressure valve here; waiting for a finished investigation report is not.","source_locator":"Article 3(49), Article 26(5) and Article 73(1), (2), (5) and (7)","provenance":"editorial"},{"label":"Candidate recommendation that automatically becomes a decision","situation":"An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.","outcome":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","lesson":"Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","provenance":"official"}],"standards":[],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/incidenten-melden","follow_up_questions":[{"question":"Do we have to keep logs of our AI system?","url":"https://www.praxikon.com/en/antwoord/logs-bewaren"},{"question":"How do we monitor our AI system after it goes live?","url":"https://www.praxikon.com/en/antwoord/monitoring-na-livegang"},{"question":"Do we need to register our AI system in the EU database?","url":"https://www.praxikon.com/en/antwoord/eu-databank-registratie"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}