Report serious incidents to market surveillance authorities
Under EU AI Act, Article 73
What does it require?
Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.
Practical action
Add AI serious-incident criteria and time limits to your existing incident-response playbook.
Who does it apply to?
Providers and deployers of high-risk AI systems.
- Sectors
- Cross-sector / all sectors
Applies from:
Evidence examples
- AI incident response procedure (document)
- Incident log and authority notifications (record)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 10 Improvement; Annex A control on incident handling | Original editorial mapping. | medium |
| NIST AI RMF 1.0 | MANAGE 4.3 | Incident response and communication. | high |
Similar obligations in other instruments
- Implement reasonable security safeguards and notify breaches — India DPDP Act, India
- Report critical safety incidents to the Office of Emergency Services — California SB 53, California (United States)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.