Legal requirement Incident reporting and handling European Union Partially applicable

Report serious incidents to market surveillance authorities

Under EU AI Act, Article 73

Source-linked Open official source

What does it require?

Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.

Practical action

Add AI serious-incident criteria and time limits to your existing incident-response playbook.

Who does it apply to?

Providers and deployers of high-risk AI systems.

Applies from:

Evidence examples

  • AI incident response procedure (document)
  • Incident log and authority notifications (record)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 10 Improvement; Annex A control on incident handlingOriginal editorial mapping.medium
NIST AI RMF 1.0MANAGE 4.3Incident response and communication.high

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.