EU AI Act Compliance
AI Act Serious Incident Reporting: What Article 73 Requires in Practice
Under Article 73 of the EU AI Act, deployers of high-risk AI systems must report serious incidents to national authorities within 72 hours. Here is exactly what that means for your organisation and how to do it.
AI act serious incident reporting is not optional, not theoretical, and not far off. For any European SME deploying a high-risk AI system, Article 73 of the EU AI Act creates a concrete legal obligation with a hard deadline, a specific reporting target, and real penalties if you miss it.
Let us be precise about what the law says, when it applies, and what your internal process needs to look like.
What Article 73 Actually Says
Under Article 73 of the EU AI Act, deployers of high-risk AI systems are required to report any serious incident to the national market surveillance authority of the Member State where the incident occurred. The report must be made without undue delay, and the regulation sets a maximum of 72 hours from the moment you become aware of the incident.
That 72-hour clock is not a soft guideline. It mirrors the breach notification window in GDPR Article 33, and it is just as binding. Missing it exposes your organisation to administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, under Article 99 of the AI Act.
If your organisation is based in the Netherlands, the competent authority is the Rijksdienst voor Ondernemend Nederland (RVO) acting under the Autoriteit Persoonsgegevens framework for AI oversight. Belgian companies report to the relevant sectoral authority coordinated through the existing market surveillance structure.
The Legal Definition of "Serious Incident"
Not every AI malfunction triggers Article 73. The regulation defines a serious incident as any incident or malfunction of a high-risk AI system that directly or indirectly leads to:
- Death or serious harm to health of a natural person
- A serious and irreversible disruption to critical infrastructure
- Breach of fundamental rights obligations under Union or Member State law
- Serious damage to property or the environment
The key word is "directly or indirectly." You do not have to wait for confirmed causation before reporting. If a high-risk AI system was in use and the outcome occurred in its operational context, you report and investigate simultaneously.
Recital 161 clarifies that the intent is to capture harms that are material and non-trivial. A system generating an incorrect output that causes minor inconvenience does not qualify. A CV-screening tool that systematically excludes a protected group and that exclusion results in documented employment discrimination with legal consequences? That qualifies.
Examples That Trigger Reporting
Here are four scenarios where Article 73 reporting is required:
Recruitment AI and discriminatory outcomes. Your AI recruitment tool rejects all applicants from a specific age group due to a model bias. A formal complaint is filed and an employment tribunal becomes involved. This constitutes a fundamental rights breach and a serious incident.
Medical AI and patient harm. A clinical decision support tool deployed in your healthcare facility generates a diagnostic recommendation that a clinician follows, leading to delayed treatment and serious patient injury.
Credit-scoring AI and financial exclusion. An AI-assisted credit decisioning tool incorrectly flags hundreds of individuals as high-risk, resulting in systemic denial of access to essential financial services.
Safety monitoring AI failure. An AI system used to monitor a manufacturing plant misses a critical equipment fault. The resulting failure causes a workplace injury requiring hospitalisation.
In each case: high-risk AI system, real-world serious harm, direct or indirect causal link. Report within 72 hours.
Examples That Do Not Trigger Reporting
Article 73 does not apply to every error or complaint. These situations fall outside the serious incident definition:
- An AI-generated document contains factual inaccuracies that are caught and corrected before use
- A high-risk AI system produces an unexpected output but no downstream harm occurs
- A system experiences a temporary outage with no decision-making impact
- An employee raises a concern about AI output quality, but no individual suffers material harm
These situations should still be logged in your internal incident register. They may be material for your Article 26 obligations around post-market monitoring. But they do not require immediate notification to a national authority.
Your 72-Hour Response Window
Seventytwo hours sounds like a long time. It is not, especially if you discover an incident on a Friday afternoon. Here is how the clock breaks down in practice:
Hours 0-4: Detect and confirm. Identify that a high-risk AI system was involved. Confirm that a serious outcome occurred or is plausible. Do not wait for a legal opinion before acting.
Hours 4-24: Assess and escalate. Your designated AI compliance lead (required under Article 26) reviews the facts. Preliminary classification: serious incident or not? If yes, begin drafting the notification.
Hours 24-48: Draft notification. Prepare the incident report. Include the system involved, the nature of the incident, the harm caused or risked, and the immediate containment steps taken.
Hours 48-72: Submit to national authority. File using the official channel of your Member State's market surveillance authority. Retain a timestamped copy of every submission.
If the full picture is not available within 72 hours, you submit what you know and follow up with supplementary information. Partial early reporting is always better than complete late reporting.
Building an Internal Incident Response Template
Every deployer of a high-risk AI system needs a written incident response procedure before an incident occurs. At minimum, your template should capture:
- Date and time the incident was detected
- AI system identifier (name, version, provider, intended purpose)
- Description of what occurred (factual, not interpretive at this stage)
- Persons affected (number, category, nature of harm)
- Immediate actions taken (system paused, escalation path activated)
- Causal analysis status (ongoing, preliminary finding, confirmed)
- Notification reference number once filed with the authority
This template does two things. First, it ensures you can meet the 72-hour deadline without scrambling for information. Second, it creates the documentation trail that national authorities will want to review during any subsequent investigation.
Your incident log should be maintained as a living document. Every near-miss, every complaint, every anomaly in AI output gets a record. Most entries will never escalate to Article 73 territory. But when one does, your log demonstrates that you operate a serious post-market monitoring system as required by Article 26(5).
The Link to GDPR Incident Reporting
Many serious AI incidents will simultaneously involve personal data. A biometric identification failure, a credit-scoring breach, a discriminatory recruitment outcome: all of these involve personal data processing, which means GDPR Article 33 may also apply alongside Article 73 of the AI Act.
The two obligations run in parallel. You cannot satisfy one by filing the other. Your incident response procedure must explicitly address both notification tracks and identify who is responsible for each. In practice, your Data Protection Officer and your AI compliance lead need to be in the same room within the first four hours of any confirmed serious incident.
The European Commission's guidance on the AI Act implementation confirms that sectoral regulators and data protection authorities are expected to coordinate on AI incident investigations. Do not assume your DPA will not find out about an AI Act filing, or vice versa.
One Action to Take This Week
If you deploy any high-risk AI system (in recruitment, credit, healthcare triage, access control, or any other Annex III category), do one thing this week: name the person in your organisation who is responsible for making the Article 73 notification. Write their name down, give them the authority to act within 72 hours, and make sure they have a direct line to your legal counsel and your DPA contact.
That single step, putting a name to the obligation, is the difference between a managed incident and a compliance failure.
Ready to check whether your AI systems fall under Article 73? Run the free 2-minute compliance check at comply.khairos.ai to get a clear picture of your current obligations before an incident forces the question.
# Need help getting compliant?
The free 2-minute compliance check shows you exactly where your gaps are. No email gate to see your score.
Start the free check →