When does an EU AI Act serious-incident report become required for a high-risk AI system?
For a high-risk AI system, Article 73 normally requires the provider to report any to the market surveillance authorities of the Member States where the incident occurred. From 27 July 2026, amended Article 75(1a) instead sends reports to the AI Office when the system falls under the AI Office's exclusive supervision. Article 3, point (49), defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to death or serious harm to health, serious and irreversible disruption of critical infrastructure management or operation, infringement of Union-law obligations protecting fundamental rights, or serious harm to property or the environment.
The provider does not wait for perfect certainty about root cause. The Article 73 clock is tied to awareness of the and to establishing a causal link between the AI system and the incident, or a reasonable likelihood of that link. A malfunction without one of the Article 3(49) outcomes is not a serious incident under this definition, although it may still trigger monitoring, risk, non-conformity, or corrective-action duties.
Article 73 has sector-specific reporting limits. For Annex III systems whose providers are already subject to equivalent Union reporting duties, the AI Act notification is limited to incidents involving infringement of Union-law obligations protecting fundamental rights. The same limit applies to high-risk AI that is, or is a safety component of, a medical device or in vitro diagnostic device under Regulations (EU) 2017/745 or 2017/746; that report goes to the national competent authority selected by the Member State where the incident occurred.
- Confirm that the system is a high-risk AI system and that the event fits one of the Article 3 serious-incident outcomes.
- Identify the Member State or Member States where the incident occurred because Article 73 points the report to those market surveillance authorities.
- Record when the provider, or where applicable the deployer, became aware of the .
- Record when the causal link or reasonable likelihood of a causal link was established, because that determines when the report must be made immediately.
Who reports a under EU AI Act Article 73 for a high-risk AI system?
The provider of the high-risk AI system owns the report. It normally reports to the market surveillance authorities of the Member States where the incident occurred. From 27 July 2026, amended Article 75(1a) requires a provider whose system falls under the AI Office's exclusive competence to report to the AI Office instead. A deployer that identifies a must immediately inform the provider first, then the importer or distributor and the relevant authority; if the provider cannot be reached, Article 73 applies mutatis mutandis.
Does EU AI Act Article 73 require proof that the high-risk AI system caused the incident before reporting?
No. Article 73 triggers reporting immediately after the provider has established either a causal link between the AI system and the or the reasonable likelihood of such a link. For a death-related incident, the report is due immediately after the provider or deployer establishes, or as soon as it suspects, a causal relationship, subject to the Article 73 outer deadline.
Do equivalent sector reporting rules remove every Article 73 report?
No. Article 73(9) limits AI Act reports for Annex III systems covered by equivalent Union reporting duties to incidents involving infringement of Union-law obligations protecting fundamental rights. Article 73(10) applies the same limited category to high-risk AI that is, or is a safety component of, a medical device or in vitro diagnostic device, with reporting to the Member State's selected national competent authority. The provider should document the equivalent regime and the specific Article 3(49)(c) screening result.
Supports the Article 3 serious-incident definition, Article 26 deployer escalation, and Article 73 reporting duty for high-risk AI systems.