FAQEU AI Act

AI Act serious incidents Article 73 FAQ

This FAQ helps separate high-risk AI system serious-incident reporting from GPAI systemic-risk incident reporting under the EU AI Act.

Covers the Article 3 serious-incident definition, Article 73 provider timing, deployer escalation, importer and distributor notices, corrective action, and Article 55 GPAI reporting.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Article 73 of Regulation (EU) 2024/1689 is the serious-incident reporting rule that applies from 2 August 2026 to providers of high-risk AI systems placed on the Union market. The first triage question is whether the event is a under Article 3, point (49); the second is whether the organization is the provider, deployer, importer, distributor, authorised representative, or a GPAI model provider with systemic risk. Regulation (EU) 2026/1744, published on 24 July 2026 and entering into force on 27 July 2026, routes reports for certain AI systems under the AI Office's exclusive competence to the AI Office instead of a national .

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

When does an EU AI Act serious-incident report become required for a high-risk AI system?

For a high-risk AI system, Article 73 normally requires the provider to report any to the market surveillance authorities of the Member States where the incident occurred. From 27 July 2026, amended Article 75(1a) instead sends reports to the AI Office when the system falls under the AI Office's exclusive supervision. Article 3, point (49), defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to death or serious harm to health, serious and irreversible disruption of critical infrastructure management or operation, infringement of Union-law obligations protecting fundamental rights, or serious harm to property or the environment.

The provider does not wait for perfect certainty about root cause. The Article 73 clock is tied to awareness of the and to establishing a causal link between the AI system and the incident, or a reasonable likelihood of that link. A malfunction without one of the Article 3(49) outcomes is not a serious incident under this definition, although it may still trigger monitoring, risk, non-conformity, or corrective-action duties.

Article 73 has sector-specific reporting limits. For Annex III systems whose providers are already subject to equivalent Union reporting duties, the AI Act notification is limited to incidents involving infringement of Union-law obligations protecting fundamental rights. The same limit applies to high-risk AI that is, or is a safety component of, a medical device or in vitro diagnostic device under Regulations (EU) 2017/745 or 2017/746; that report goes to the national competent authority selected by the Member State where the incident occurred.

  • Confirm that the system is a high-risk AI system and that the event fits one of the Article 3 serious-incident outcomes.
  • Identify the Member State or Member States where the incident occurred because Article 73 points the report to those market surveillance authorities.
  • Record when the provider, or where applicable the deployer, became aware of the .
  • Record when the causal link or reasonable likelihood of a causal link was established, because that determines when the report must be made immediately.

Who reports a under EU AI Act Article 73 for a high-risk AI system?

The provider of the high-risk AI system owns the report. It normally reports to the market surveillance authorities of the Member States where the incident occurred. From 27 July 2026, amended Article 75(1a) requires a provider whose system falls under the AI Office's exclusive competence to report to the AI Office instead. A deployer that identifies a must immediately inform the provider first, then the importer or distributor and the relevant authority; if the provider cannot be reached, Article 73 applies mutatis mutandis.

Does EU AI Act Article 73 require proof that the high-risk AI system caused the incident before reporting?

No. Article 73 triggers reporting immediately after the provider has established either a causal link between the AI system and the or the reasonable likelihood of such a link. For a death-related incident, the report is due immediately after the provider or deployer establishes, or as soon as it suspects, a causal relationship, subject to the Article 73 outer deadline.

Do equivalent sector reporting rules remove every Article 73 report?

No. Article 73(9) limits AI Act reports for Annex III systems covered by equivalent Union reporting duties to incidents involving infringement of Union-law obligations protecting fundamental rights. Article 73(10) applies the same limited category to high-risk AI that is, or is a safety component of, a medical device or in vitro diagnostic device, with reporting to the Member State's selected national competent authority. The provider should document the equivalent regime and the specific Article 3(49)(c) screening result.

Citations
Question 2

What timing and follow-up steps should the provider track under Article 73?

Article 73 requires reporting immediately after the provider establishes a causal link or reasonable likelihood of a link and sets a default outer deadline of 15 days after the provider, or where applicable the deployer, becomes aware of the . Shorter outer deadlines apply for two categories: a or a serious and irreversible disruption of critical infrastructure management or operation must be reported immediately and no later than two days after awareness, and a death-related incident must be reported immediately after a causal relationship is established or suspected and no later than 10 days after awareness.

If a complete report would delay timely reporting, Article 73 allows an incomplete initial report followed by a complete report. After reporting, the provider must without delay investigate the and the AI system concerned, including a risk assessment and corrective action, and must cooperate with competent authorities and, where relevant, the notified body.

  • Keep separate timestamps for awareness, causal-link or reasonable-likelihood assessment, initial report, complete report, authority acknowledgements, and corrective actions.
  • Escalate critical-infrastructure disruption, widespread-infringement, and death-related cases into the shorter Article 73 timing track instead of using the default timing.
  • Do not alter the AI system in a way that may affect later evaluation of incident causes before informing competent authorities of that action.
  • Link the Article 73 report to the provider quality-management procedure for serious incidents and to the post-market monitoring evidence for the affected high-risk AI system.

Can a provider submit an incomplete EU AI Act Article 73 serious-incident report?

Yes. Article 73 allows an initial incomplete report when necessary to ensure timely reporting, followed by a complete report. The incomplete report should not be treated as closure; the provider still needs the investigation, risk assessment, corrective-action record, and authority cooperation required after reporting.

What corrective-action evidence matters after an EU AI Act serious-incident report?

The provider should preserve the incident facts, causal-link analysis, risk assessment, corrective actions, authority communications, notified-body communications where relevant, and any decision not to alter the AI system before notifying competent authorities. Article 20 also requires providers that consider or have reason to consider their high-risk AI system is non-conforming to take corrective actions such as bringing it into conformity, withdrawing it, disabling it, or recalling it as appropriate.

Citations
Question 3

How should deployers, importers, distributors, and GPAI model providers be separated?

A deployer is not the normal Article 73 reporter, but it has an explicit escalation duty when it identifies a : inform the provider first, then the importer or distributor and the relevant market surveillance authorities. Importers and distributors have their own high-risk AI system duties to withhold, notify, or help correct non-conforming or risky systems, so incident intake should route them into the communication record even when the provider owns the Article 73 report.

From 27 July 2026, the AI Office has exclusive supervision over specified AI systems. The covered set includes certain systems based on a general-purpose AI model where the model and system share the same provider or undertaking, subject to the listed exclusions for product-related systems, critical infrastructure, systems provided by law-enforcement or border-management authorities, financial-institution systems within Article 74(6), and justice systems, plus systems that constitute or are integrated into a designated very large online platform or very large online search engine. Providers in that set report Article 73 incidents to the AI Office, which transmits the relevant information to the national .

Do not merge this system-level route with the EU AI Act rule for providers of general-purpose AI models with systemic risk. Article 55 requires those model providers to keep track of, document, and report without undue delay to the AI Office and, as appropriate, national competent authorities relevant information about serious incidents and possible corrective measures. The Commission's GPAI serious-incident template is for that Article 55 model-provider context, not a replacement for an Article 73 high-risk AI system report.

  • Check whether an importer, distributor, deployer, or other third party has become the provider by putting its name or trademark on the high-risk AI system, making a substantial modification, or changing intended purpose so the system becomes high-risk.
  • Use Article 23 importer records for provider, authorised-representative, and notice when the importer has sufficient reason to consider the high-risk AI system is non-conforming, falsified, or risky.
  • Use Article 24 distributor records for provider or importer notice, authority notice, and corrective-action handling when the distributor has sufficient reason to consider a high-risk AI system it made available is non-conforming or risky.
  • Check amended Article 75 before selecting the recipient. Record whether the system is under the AI Office's exclusive competence, which inclusion or exclusion applies, and whether the report went to the AI Office or the Member State authorities where the incident occurred.
  • Use a separate Article 55 record when the incident concerns a general-purpose AI model with systemic risk, including the model involved, resulting harm, chain of events, evidence of model involvement, response, root-cause analysis, and any corrective measures.

Should GPAI systemic-risk serious incidents be reported through the same EU AI Act Article 73 process?

No. Article 73 is for providers of high-risk AI systems. Providers of general-purpose AI models with systemic risk have a separate Article 55 duty to keep track of, document, and report without undue delay to the AI Office and, as appropriate, national competent authorities relevant information about serious incidents and possible corrective measures.

Why should importers and distributors be included in an EU AI Act serious-incident workflow?

They may not own the provider's Article 73 report, but Articles 23 and 24 require them to act on information that a high-risk AI system is non-conforming or presents a risk. Distributors may need to take or ensure corrective actions, and both importers and distributors may need to notify the provider, other operators, and competent authorities depending on their role and the facts.

When does a high-risk AI system provider report an Article 73 incident to the AI Office?

From 27 July 2026, amended Article 75(1a) routes the report to the AI Office when the AI Office has exclusive competence over the system under Article 75(1). This includes specified systems based on a general-purpose AI model where the model and system share a provider or undertaking, subject to the listed exclusions, and systems that constitute or are integrated into a designated very large online platform or very large online search engine. The provider should document the exact inclusion or exclusion instead of routing by product label alone.

Citations
Recommended next step

Turn Article 73 intake into reportable facts, roles, and corrective actions

Sorena can help structure high-risk AI system incident intake around Article 73 timing, deployer escalation, importer and distributor notices, corrective-action evidence, and GPAI systemic-risk separation.

Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Supports the distinction between Article 55 GPAI systemic-risk incident reporting and Article 73 high-risk AI system serious-incident reporting.
"serious incidents involving general-purpose AI models with systemic risk"
eur-lex.europa.eu
Referenced sections
  • Supports Article 23 importer duties, Article 24 distributor duties, Article 25 value-chain role changes, Article 26 deployer escalation, and Article 55 GPAI systemic-risk reporting.
"keep track of, document, and report, without undue delay"
eur-lex.europa.eu
Referenced sections
  • Binding amendment published on 24 July 2026, entering into force on 27 July 2026, which gives the AI Office exclusive supervision over specified AI systems and routes their Article 73 serious-incident reports to the AI Office.
"shall report any serious incidents to the AI Office"
Related guides

Explore more topics

Are industry AI use cases high-risk under EU AI Act Annex III?
FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
EU AI Act AI System Classification Edge Cases FAQ
Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence
Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
EU AI Act applicability test: scope, role, and risk classification
Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
EU AI Act Article 50 transparency disclosures FAQ
Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
EU AI Act deadlines and compliance calendar | Article 113 dates
EU AI Act compliance calendar for Regulation (EU) 2026/1744, Article 113 dates, Article 111 transitions, GPAI enforcement, Article 50, and high-risk systems.
EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates
Source-backed EU AI Act FAQ covering scope, roles, risk classification, GPAI, transparency, AI literacy, rights and complaints, sandboxes, authorities, SME provisions, and current legal status.
EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification
Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ
FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
EU AI Act high-risk conformity assessment route selector
Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
EU AI Act penalties and fines: Article 99 tiers and GPAI exposure
EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
EU AI Act post-market monitoring and serious incident reporting
Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
EU AI Act post-market monitoring FAQ for high-risk AI systems
Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ
FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
EU AI Act risk classification intake workflow
A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
EU AI Act serious incident reporting triage workflow: Article 73 and Article 55
Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
EU AI Act technical documentation FAQ | Article 11 and Annex IV
What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
EU AI Act Timeline Roadmap: Dates, Legal Status, Owners, and Evidence
Turn EU AI Act milestones into an implementation roadmap by separating enacted dates, political agreements, draft guidance, consultations, and voluntary codes, then assigning actions and evidence.
EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits
Compare the EU AI Act and ISO/IEC 42001:2023, including legal status, Article 17 quality management, high-risk duties, GPAI, evidence reuse, and assurance limits.
EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries
Compare the EU AI Act with NIST AI RMF 1.0 across legal status, GOVERN-MAP-MEASURE-MANAGE, high-risk duties, GPAI, evidence reuse, and revision limits.
FAQ: EU AI Act conformity assessment procedures and notified body selection
cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.