Skip to main content
Praxikon
All obligations
Applicablev2.0.0

Article 73: serious incident reporting

The duty to report serious incidents with high-risk AI, under strict deadlines.

Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure.

Praxikon tracks Article 73: serious incident reporting under the EU AI Act, checked against the official source on 6 September 2026, citing the source for every statement.

Status
Applicable
Application date
2 August 2026
Version
2.0.0
Last reviewed
6 September 2026

Review status: placed against the official source (6 September 2026). Next check due by 5 March 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Applicable · 2 August 2026

For whom

  • Deployer
  • Provider of an AI system

What you do

Set up an incident process with reporting routes

What you record

Incident register and reports

Official source

Article 73(1)-(11)

Who this is relevant to

When this applies

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.

What the official source establishes

This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.

What you can do now

Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.

  1. 01

    Set up an incident process with reporting routes

    Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.

What to retain

Incident register and reports

Record of incidents, analyses, reports to supervisors and corrective measures.

Control and reassessment

  • Incident drill and deadline watch

    Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.

Public tools

Conditions and exceptions

  • For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 73(1)-(11)

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 113, second paragraph

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 73: serious incident reporting",
praxikon:eu:ai-act:obligation:article-73-incident-reporting@2.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-09-06T00:00:00.000Z,
sha256 5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df,
https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-73-incident-reporting&effective_at=2026-07-27&known_at=2026-09-06&lang=en, accessed 2026-09-07)

Short form

praxikon:eu:ai-act:obligation:article-73-incident-reporting@2.0.0 (sha256 5133c7de)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-73-incident-reporting-2-0-0,
  author       = {{Praxikon}},
  title        = {Article 73: serious incident reporting},
  year         = {2026},
  version      = {2.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-73-incident-reporting},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df},
  url          = {https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting},
  urldate      = {2026-09-07},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-73-incident-reporting@2.0.0",
    "type": "dataset",
    "title": "Article 73: serious incident reporting",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "2.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-73-incident-reporting",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          9,
          6
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          7
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-73-incident-reporting&effective_at=2026-07-27&known_at=2026-09-06&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

Version history

  1. v2.0.0

    27 July 2026

    Article 73: serious incident reporting

    The duty to report serious incidents with high-risk AI, under strict deadlines.

  2. v1.0.0

    27 July 2026

    Article 73: serious incident reporting

    The duty to report serious incidents with high-risk AI, under strict deadlines.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, lawyer and AI governance specialist

Expert behind this page

Zahed Ashkara

Lawyer and AI governance specialist

Execution

From obligation to arranged and demonstrable

Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.