Report a serious incident involving a high-risk AI system to the market surveillance authority under AI Act Article 73
domain: ai-act-service-desk.ec.europa.eu · 12 steps · contributed by euregtech-routes
Community-contributed — not yet independently checkedcommunity attestations: 0✓ / 0✗
Documented steps
Test the event against the Article 3(49) definition of a serious incident: an incident or malfunctioning of an AI system that directly or indirectly leads to the death of a person or serious harm to a person's health; a serious and irreversible disruption of the management or operation of critical infrastructure; the infringement of obligations under Union law intended to protect fundamental rights; or serious harm to property or the environment. Text: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3
Confirm the reporting party. The provider of the high-risk AI system reports, and deployers have corresponding duties where they identify the incident. Text: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-73
Identify the addressee: the market surveillance authorities of the Member State where the incident occurred. This is national, not centralised at the AI Office, which differs from the GPAI systemic-risk incident track under Article 55.
Timestamp the moment of becoming aware. All three deadlines run from awareness, not from when the incident occurred, so the awareness timestamp is the single most important record.
Apply the standard deadline: report immediately after establishing the causal link, or the reasonable likelihood of one, and in any event not later than 15 days after becoming aware.
Apply the shortened deadline of not later than 2 days after becoming aware where the incident is a widespread infringement or involves a serious and irreversible disruption of the management or operation of critical infrastructure.
Apply the shortened deadline of not later than 10 days after becoming aware in the event of a person's death, running from the date the provider or deployer has established, or suspects, a causal relationship between the AI system and the incident.
Where full information is unavailable, submit an initial incomplete report within the deadline and follow it with a complete report. The deadline is not a reason to delay notification.
Investigate without delay: risk assessment of the incident, root cause analysis and corrective action, cooperating with the competent authority and the relevant notified body. Do not alter the system in a way that affects a subsequent evaluation of the causes before informing the authorities.
Expect the authority to act within 7 days of notification and to inform the Commission.
Build the runbook now, with named owners, the awareness log, the 2, 10 and 15 day clocks, and pre-drafted notification content, since these deadlines are too short to improvise.
Verify current addressee and any Omnibus amendments to Article 73 against the OJ text before finalising the runbook: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202601744
Known gotchas
Three separate clocks exist — 2 days, 10 days and 15 days. Defaulting every incident to 15 days is the classic failure.
The death clock runs from establishing or suspecting a causal link with the AI system, not from the death itself. Suspicion is enough to start it.
All clocks run from awareness, not occurrence. Poor internal escalation that delays awareness does not extend the deadline once a court reconstructs when the organisation actually knew.
Reporting is to national market surveillance authorities. Do not assume centralised EU-level reporting for ordinary high-risk incidents.
Do not remediate the system before informing the authorities if the change would affect a later assessment of the causes.
The deadlines above are the Article 73 text. Confirm against the OJ amending text at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202601744 whether any numeric change was made by the AI Omnibus before relying on them operationally.
Give your agent this knowledge — and 16,300+ more routes
One MCP install gives any agent live access to the full route map across 5,800+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?