What it’s about
Art. 73 of the AI Act requires providers of high-risk AI systems to report serious incidents to the relevant market surveillance authority – specifically, the authority of the Member State in which the incident occurred (Art. 73(1)). The duty falls primarily on the provider, though the deployer is also named in several scenarios, for instance in relation to when the deployer becomes aware of an incident (Art. 73(2), (3), (4)).
Important for practice: this reporting duty is not an abstract exercise for the future. True, the high-risk obligations for Annex III systems have been pushed back to 2 December 2027 under the Digital Omnibus on AI (originally 2 August 2026), and for high-risk systems falling under Annex I product legislation the new date is 2 August 2028 (instead of 2 August 2027). But anyone developing or deploying high-risk AI today should be building reporting processes now, not just before the respective deadline.
Deadlines: severity is what matters
Art. 73 does not set a single deadline but rather three tiers:
- Standard case: notification immediately after establishing the causal link (or the reasonable likelihood of one) between the AI system and the incident, but no later than 15 days after becoming aware of it (Art. 73(2)). The timing must be geared to the severity of the incident – “15 days” is the upper limit, not the default.
- Widespread infringement / incident under Art. 3(49)(b): notification without delay, but no later than 2 days after becoming aware of it (Art. 73(3)).
- Death: notification without delay after establishing or suspecting the causal link, but no later than 10 days after becoming aware of it (Art. 73(4)).
Anyone unfamiliar with this distinction risks missing the short 2-day deadline by reflexively working to the “15-day rule”. Classifying the incident – working out which category under Art. 3(49) applies – must therefore sit at the start of every internal escalation process, not the end.
An incomplete initial report is explicitly permitted
Art. 73(5) allows an incomplete initial report to be submitted to meet the deadline, followed later by a full report. This matters in practice: if an internal investigation is still ongoing, there’s no need to let the deadline lapse – you can report on the basis of what is currently known and follow up afterwards. This is precisely where many organisations have a gap – there’s no defined process for a “provisional” report draft, so in the end nothing gets reported at all because the full facts aren’t yet available.
Duty to investigate and cooperate
Submitting the report is not the end of the matter. Under Art. 73(6), the provider must promptly carry out the necessary investigations, including a risk assessment and any corrective action. There is a notable restriction here: the provider may not carry out any investigation that alters the affected system in a way that could compromise a later assessment of the root cause, without first informing the competent authority. In concrete terms: before any hotfix or rollback on the affected system, it should be checked whether the authority needs to be informed so that forensic evidence is not lost.
Competent market surveillance authorities, for their part, must take appropriate action under Art. 19 of Regulation (EU) 2019/1020 within 7 days of receiving the report (Art. 73(8)), and for certain categories of incident must inform other national bodies under Art. 77(1) (Art. 73(7)). National authorities, in turn, notify the Commission of every serious incident without delay, regardless of whether they have taken action (Art. 73(11), in conjunction with Art. 20 of Regulation (EU) 2019/1020).
Special cases: other frameworks take precedence
For high-risk systems under Annex III that are already subject to equivalent reporting obligations under other Union legal instruments, the duty is narrowed to the incidents referred to in Art. 3(49)(c) (Art. 73(9)). The same applies to high-risk AI acting as a safety component of medical devices under Regulations (EU) 2017/745 and (EU) 2017/746 – here, the national authority designated by the Member States for that purpose is responsible, rather than the general market surveillance authority automatically (Art. 73(10)). Anyone operating in a regulated sector such as medical technology therefore needs to check separately which authority actually has jurisdiction – a point often overlooked in generic compliance checklists.
What this means for your organisation
The typical gap in practice is not a lack of awareness of Art. 73 itself, but the absence of a working internal process: who recognises a “serious incident” as such in the first place, who decides on the applicable deadline category, who drafts the initial report, who documents the investigation? These questions should be answered before the high-risk obligations apply to your systems – in good time before 2 December 2027 (Annex III) or 2 August 2028 (Annex I product legislation).
Whether, and when, your systems actually qualify as high-risk AI can be clarified with our free risk check at /einstufung.