Incident reporting and handling: AI obligations

Practical requirements extracted from policy instruments, with the source article, the actors they bind, evidence examples and original framework mappings. Legal requirements are marked; everything else is voluntary guidance.

3 results

Legal requirement incident handling India

Implement reasonable security safeguards and notify breaches

India DPDP Act · Section 8(5) and 8(6); DPDP Rules on breach intimation

Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.

Source-linked
Legal requirement incident handling European Union

Report serious incidents to market surveillance authorities

EU AI Act · Article 73

Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediately after establishing a causal link (or reasonable likelihood) and no later than 15 days after becoming aware, with shorter limits for the most serious cases such as widespread infringements or death. Deployers must inform the provider and authorities when they identify a serious incident.

Source-linked Applies from 2 Aug 2026
Search