Article 73: Reporting of serious incidents
Praxikon tracks Article 73 (Reporting of serious incidents) under the EU AI Act, citing the source for every statement.
Article 73 requires providers to report serious incidents with high-risk AI systems immediately to market surveillance authorities, and in any case within 15 days of becoming aware.
Official text
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF) →Official guidance on this article
2- AI Act Service Desk: ResourcesProvides access to the official serious incident reporting template associated with the reporting obligationPublishedQ&AEuropean Commission (AI Act Service Desk)
- Draft guidance and reporting template on serious AI incidents (Article 73)Provides providers of high-risk AI systems with a uniform reporting form and clarifies the timeframe within which each type of incident must be reported to the market supervisorConsultationTemplateEuropean Commission26 Sept 2025
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Related articles
Frequently asked questions
When must a serious incident be reported under Article 73 AI Act?+
What is a serious incident under the AI Act?+
What documentation does Article 73 of the AI Act require?+
What Article 73 requires in practice
Connections
What connects to Article 73 AI Act
Themes where this returns
The counterpart in the other law
GDPR interpretation that also applies here
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB) · via Reporting: data breaches and serious incidents
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB) · via Reporting: data breaches and serious incidents
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB) · via Reporting: data breaches and serious incidents
- Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
2024-03-26 · final, Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht) · via Reporting: data breaches and serious incidents