What timing and follow-up steps should the provider track under Article 73?
Article 73 requires reporting immediately after the provider establishes a causal link or reasonable likelihood of a link and sets a default outer deadline of 15 days after the provider, or where applicable the deployer, becomes aware of the serious incident. Shorter outer deadlines apply for two categories: a widespread infringement or a serious and irreversible disruption of critical infrastructure management or operation must be reported immediately and no later than two days after awareness, and a death-related incident must be reported immediately after a causal relationship is established or suspected and no later than 10 days after awareness.
If a complete report would delay timely reporting, Article 73 allows an incomplete initial report followed by a complete report. After reporting, the provider must without delay investigate the serious incident and the AI system concerned, including a risk assessment and corrective action, and must cooperate with competent authorities and, where relevant, the notified body.
- Keep separate timestamps for awareness, causal-link or reasonable-likelihood assessment, initial report, complete report, authority acknowledgements, and corrective actions.
- Escalate critical-infrastructure disruption, widespread-infringement, and death-related cases into the shorter Article 73 timing track instead of using the default timing.
- Do not alter the AI system in a way that may affect later evaluation of incident causes before informing competent authorities of that action.
- Link the Article 73 report to the provider quality-management procedure for serious incidents and to the post-market monitoring evidence for the affected high-risk AI system.
Can a provider submit an incomplete EU AI Act Article 73 serious-incident report?
Yes. Article 73 allows an initial incomplete report when necessary to ensure timely reporting, followed by a complete report. The incomplete report should not be treated as closure; the provider still needs the investigation, risk assessment, corrective-action record, and authority cooperation required after reporting.
What corrective-action evidence matters after an EU AI Act serious-incident report?
The provider should preserve the incident facts, causal-link analysis, risk assessment, corrective actions, authority communications, notified-body communications where relevant, and any decision not to alter the AI system before notifying competent authorities. Article 20 also requires providers that consider or have reason to consider their high-risk AI system is non-conforming to take corrective actions such as bringing it into conformity, withdrawing it, disabling it, or recalling it as appropriate.
Supports Article 73 timing, incomplete initial reports, post-report investigations, risk assessment, corrective action, and Article 20 corrective-action options.