Article 73: serious incident reporting
The duty to report serious incidents with high-risk AI, under strict deadlines.
Article 73 obliges providers to report serious incidents to the market surveillance authority: immediately after establishing the causal link and at the latest within 15 days, shortened to 10 days in the event of death and to 2 days for widespread infringement or serious disruption of critical infrastructure.
Praxikon tracks Article 73: serious incident reporting under the EU AI Act, checked against the official source on 6 September 2026, citing the source for every statement.
- Status
- Applicable
- Application date
- 2 August 2026
- Version
- 2.0.0
- Last reviewed
- 6 September 2026
Review status: placed against the official source (6 September 2026). Next check due by 5 March 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
From source to evidence
Why this obligation applies, what it asks of you, and what you show for it.
Applies
Applicable · 2 August 2026
For whom
- Deployer
- Provider of an AI system
What you do
Set up an incident process with reporting routes
What you record
Incident register and reports
Official source
Who this is relevant to
When this applies
Deployer
An organisation using an AI system under its authority, excluding personal non-professional use.
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1A serious incident occurs with a high-risk system: death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental-rights protections or serious damage to property or environment.
What the official source establishes
This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.
Our interpretation
The official source remains authoritative. This general interpretation is not legal advice.
The deadlines are too short to design the process during the incident: those who decide who reports at the first incident will not make 15 days, let alone 2. This is the GDPR breach playbook, but for AI.
What you can do now
Connect the AI incident process to the existing breach and security process and add the AI-specific definitions and deadlines.
- 01
Set up an incident process with reporting routes
Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
What to retain
Incident register and reports
Record of incidents, analyses, reports to supervisors and corrective measures.
Control and reassessment
Incident drill and deadline watch
Periodically test whether an incident can be reported within the legal deadlines, including the deployer-to-provider chain.
Public tools
Full text of Article 73
The full legal text in the public AI Act Explorer.
Conditions and exceptions
- For systems under sectoral reporting regimes with equivalent duties, reporting may run through that regime to avoid duplication.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 73(1)-(11)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 113, second paragraph
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Article 73: serious incident reporting", praxikon:eu:ai-act:obligation:article-73-incident-reporting@2.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0), effective_at 2026-07-27T00:00:00.000Z, known_at 2026-09-06T00:00:00.000Z, sha256 5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df, https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-73-incident-reporting&effective_at=2026-07-27&known_at=2026-09-06&lang=en, accessed 2026-09-07)
Short form
praxikon:eu:ai-act:obligation:article-73-incident-reporting@2.0.0 (sha256 5133c7de)
BibTeX
@misc{praxikon-eu-ai-act-obligation-article-73-incident-reporting-2-0-0,
author = {{Praxikon}},
title = {Article 73: serious incident reporting},
year = {2026},
version = {2.0.0},
number = {praxikon:eu:ai-act:obligation:article-73-incident-reporting},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
note = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df},
url = {https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting},
urldate = {2026-09-07},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:article-73-incident-reporting@2.0.0",
"type": "dataset",
"title": "Article 73: serious incident reporting",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "2.0.0",
"number": "praxikon:eu:ai-act:obligation:article-73-incident-reporting",
"URL": "https://www.praxikon.com/en/verplichtingen/article-73-incident-reporting",
"language": "en",
"issued": {
"date-parts": [
[
2026,
9,
6
]
]
},
"accessed": {
"date-parts": [
[
2026,
9,
7
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 5133c7de1c1f4ab76d5901cc7ac501afaca878740d840f576cbd3a528e3bd2df; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-73-incident-reporting&effective_at=2026-07-27&known_at=2026-09-06&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Version history
v2.0.0
27 July 2026
Article 73: serious incident reporting
The duty to report serious incidents with high-risk AI, under strict deadlines.
v1.0.0
27 July 2026
Article 73: serious incident reporting
The duty to report serious incidents with high-risk AI, under strict deadlines.
Corrections to this obligation
No substantive correction to this object has been recorded.
Open the correction logExecution
From obligation to arranged and demonstrable
Knowing where you stand is step one. Embed AI translates this obligation into a concrete approach for your organisation: scope, ownership, register and evidence.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.
