Ongoing operations
Serious incident reporting
When a high-risk AI system causes serious harm, Article 73 creates a reporting duty entirely separate from anything in data protection law, owed to a different authority on a different timescale.
Transcript
When a high-risk AI system causes serious harm, Article 73 creates a reporting duty owed to a market surveillance authority, entirely separate from anything in data protection law.
Open Incidents & Alerts from the Operations section and open the Monitoring & Incidents view. This is where Article 73 reports are logged and tracked.
Report a new incident: pick the system, choose the incident type and severity, and describe what happened. The form captures the impact and the corrective actions taken.
Submit the report. The platform starts the Article 73 clock and attaches it to the system's record.
A countdown tracks the regulatory deadline. In the worst cases that window tightens to two days, so the clock matters.
Attach evidence and add corrective actions. Mark it investigating while you work it, and the status filters above sort it there immediately, right alongside every other open case at that stage.
Resolve it once it's actually handled, and it moves to the Resolved filter. Nothing is deleted; the timeline shows what happened and when, so your Article 73 reporting history is ready to hand over.
Why this is required
Article 3(49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to the death of a person or serious harm to their health, a serious and irreversible disruption of the management or operation of critical infrastructure, an infringement of obligations under Union law intended to protect fundamental rights, or serious harm to property or the environment.
The general deadline under Article 73(2) is immediately after establishing the causal link, and in any event no later than fifteen days after becoming aware of the serious incident.
That tightens sharply in the worst cases. Where the incident is widespread or involves a serious and irreversible disruption of critical infrastructure, Article 73(3) requires the report immediately and no later than two days. Where a person has died, Article 73(4) sets ten days.
You are not permitted to wait for a complete investigation. Article 73(5) provides that where necessary to ensure timely reporting, an initial incomplete report may be submitted, followed by a complete one. The duty to report is not suspended by uncertainty about cause.
Reporting also feeds back into your own obligations. An incident is evidence that your Article 9 risk assessment was incomplete, and Article 73(6) requires you to take the necessary investigative and corrective measures following the incident.
What EuroCompliant does
Incidents are logged against the affected system with the date of awareness, so the applicable Article 73 clock is visible from the moment the record exists.
The record ties the incident to the system, its risk classification and its monitoring history, which is the chain a market surveillance authority will follow afterwards.
Incident records feed the post-market monitoring evidence and the system's risk management documentation.
Deadlines
Walking through it
Log the incident on awareness
Record when you became aware and what you knew at that point. The deadline runs from awareness of the incident and its causal link to the system.
Open /operations →Classify the severity
Death, critical infrastructure disruption, fundamental rights infringement, or serious harm to health, property or the environment. The category sets the deadline: two, ten or fifteen days.
Report to the market surveillance authority
Report in the authority's member state. Submit an initial report if that is what it takes to meet the deadline.
Investigate and correct
Article 73(6) requires investigative and corrective measures. Do not perform a risk assessment of the incident without informing the authority first.
Check the GDPR duty in parallel
If personal data was compromised, the seventy-two hour Article 33 clock runs alongside this one, to a different regulator.
Open /privacy-hub →The law
Reporting of serious incidents
Providers must report serious incidents to the market surveillance authority of the member state where the incident occurred.
Definition of serious incident
Death or serious harm to health, serious and irreversible disruption of critical infrastructure, infringement of fundamental rights obligations, or serious harm to property or the environment.
Shortened deadlines
Two days for widespread infringements or critical infrastructure disruption; ten days where a person has died; fifteen days otherwise.
Corrective actions
Corrective action and supply-chain notification where the system is not in conformity.
Frequently asked
What if we are not certain the system caused the harm?
The deadline runs from establishing the causal link, or a reasonable likelihood of one, not from proving it. Article 73(5) exists precisely so uncertainty does not become a reason to miss the window: file an initial report and complete it later.
Is a serious incident the same as a personal data breach?
No, and one event can be both. They have different definitions, different deadlines, different regulators and separate penalties. Assess each independently.
Related guides
Post-market monitoring
The Article 72 duty to actively watch a high-risk system for its whole life, and why AI systems degrade without anyone changing the code.
Breach notification
The seventy-two hour clock under Article 33, what the notification must contain, and when you must tell individuals directly.
Compliance checklists
How Articles 9 to 15 become tracked, owned, evidenced work rather than a document nobody reads.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial