AIPolicyTracker
Legal requirement Incident reporting and handling European Union Partially applicable

Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office

Context fileUnder EU AI Act, Article 55(1)(c)

Source-linked Open official source

What does it require?

Providers of general-purpose AI models with systemic risk must keep track of, document and report without undue delay to the AI Office and, where relevant, to national competent authorities the relevant information about serious incidents and the possible corrective measures to address them. The General-Purpose AI Code of Practice sets out timelines and content that providers may follow to demonstrate compliance.

Practical action

Define serious-incident criteria for the model, a tracking log and an AI Office notification template with owner and clock.

Who does it apply to?

Providers of general-purpose AI models classified as having systemic risk under Article 51.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessIncident coordinator · continuous
    AI incident management and regulatory reporting

    Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority

    Model-level incident criteria, log and AI Office reporting.

  • supportsPolicyHead of AI safety · annual
    Frontier model safety and security framework

    Serves 9 recorded duties · evidence: Published frontier safety framework, Dangerous-capability evaluation report, Threshold notification to an authority

    Framework defines the incident types and escalation.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Serious incident tracking log for the modelregister
AI Office incident notificationdocument

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 10.2; Annex A.8.4Corrective action and incident communication.high
NIST AI RMF 1.0MANAGE 4.3, MEASURE 3.1Incident response and tracking of emergent risks.high

Cite this record

AIPolicyTracker (2026). “Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-55-systemic-risk-incident-reporting (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.