European Tech Incident Rules: Classify at Suspicion, Then Notify and Escalate—Article 73

TakeawayDetail
The reporting window is 15 days from provider awareness.For a qualifying serious incident or malfunction involving a high-risk AI system, the applicable reporting provision ties the 15 days to provider awareness—not to the incident's occurrence or a later finding of certainty.
The 15 days require notice, not just internal escalation.A reasonably suspected qualifying incident requires regulator notice and internal escalation in parallel; internal review does not replace notice to the competent market surveillance authority during the 15-day reporting window.
A report due within 15 days routes to the authority where the incident occurred or had effect.Within 15 days, the report goes to the national competent authority in the Member State where the incident occurred or had effect, with the rule focused on high-risk AI systems.
A report due within 15 days must carry corrective-action detail.Within 15 days, it must describe the incident and AI system, state the intended purpose, and identify corrective actions taken or planned, while supporting post-market monitoring.

According to the European Commission's digital-strategy materials, the AI Act’s applicable serious-incident reporting provision sets a reporting window of 15 days. For providers of high-risk AI systems, awareness of a serious incident or malfunction starts the clock; the period is not a grace period for waiting until an investigation proves what happened.

The 15 days make classification at suspicion the operational rule. A reasonably suspected qualifying incident requires evidence preservation, an internal investigation, escalation, and notice to the competent market surveillance authority in the Member State where the event occurred or had effect. Those tracks run in parallel. Internal escalation cannot substitute for regulator notice, and uncertainty should shape the inquiry rather than suspend the obligation.

Within 15 days, the report must do more than announce a failure. It must describe the incident, identify the AI system and its intended purpose, and explain corrective actions taken or planned. The file should also support post-market monitoring through documentation and analysis. In practice, “wait for certainty” is a warning sign: classify at suspicion, start the response, notify the authority, and escalate while facts are still developing.

rain slicked stone and glass civic incident northern European town cold
rain slicked stone and glass civic incident northern European town cold

Start at Suspicion

The first reporting decision is legal classification, not root cause. The European Union AI Act’s applicability provisions create two commencement lanes. Record whether the system is an Annex III use-case high-risk system or an Article 6(1) regulated product, identify the legal provider, preserve the classification basis, and date the triggering information. Selecting a form before taking that step can route the incident into the wrong regime.

The applicable serious-incident reporting provision is provider-specific, not a general reporting duty for every developer or deployer. Its trigger is the provider’s awareness, or reasonable cause to suspect, an Article 3(49) serious incident: death, serious harm to health, a serious fundamental-rights violation, serious property or environmental damage, or large-scale public-interest harm. Confirmation is not required. A credible support or safety signal that supports suspicion starts the reporting workflow while technical investigation continues.

The reporting provision measures the ordinary reporting period from awareness or reasonable suspicion and requires notice as soon as possible, subject to the hard outer limit shown below. That limit is not an investigation buffer or a period for deciding whether the incident is serious enough to report. Reject the queue-building rule: investigate first, then escalate only if root-cause proof establishes serious harm. Plausible qualifying harm is sufficient. Any parallel internal escalation must preserve, not toll, the external reporting date.

The shorter disruption branch controls only when immediate reporting is likely to cause an immediate and substantial disruption of critical infrastructure. Even on that path, notice remains immediate, subject to the outer cap below. Critical-sector deployment alone does not qualify. Require a written, incident-specific factual basis identifying the expected disruption, critical dependency, timing, magnitude, and why notice is likely to cause it. A rail operator cannot invoke the branch merely because its AI supports transport. Without that basis, use the ordinary route and its as-soon-as-possible duty.

Incomplete facts call for staging, not silence. If a full notification cannot be made within the ordinary outer-limit period, send a preliminary report containing available information, followed by one or more updates inside the statutory follow-up window. Missing data may justify staged delivery; it does not justify resetting the original awareness or reasonable-suspicion date.

The external actor is the provider—or its authorized representative when the provider is outside the Union. It reports to the AI Office and, where applicable, the national competent authority in the Member State where the incident occurred or had effect. Supply Annex XII information as far as possible, including system type, country of service, incident description, harm location, and other requested information; the notification must be in English. Before any handoff, require a classification-and-clock record containing the scope lane, provider or representative, trigger evidence, recipient list, selected route, disruption assessment if applicable, and update owner.

Decision state Action and record Controlling rule and source
Annex III high-risk use-case Use the provider reporting workflow AI Act applicability: the serious-incident reporting workflow operates with the general regime from 2 August 2026
Article 6(1) regulated product Identify the later-scope workflow AI Act applicability: the regulated-product limb and corresponding duties begin on 2 August 2027
Awareness or reasonable suspicion of an Article 3(49) incident Notify the AI Office and applicable national authority The reporting provision: as soon as possible; no later than 15 days
Immediate notice likely to disrupt critical infrastructure immediately and substantially Notify immediately and attach the written disruption basis The reporting provision: no later than 72 hours
Full notification cannot be completed within the ordinary period Send available information, then provide staged updates The reporting provision: updates as soon as possible; no later than two weeks
windswept European plaza pale stone steel shifting from
windswept European plaza pale stone steel shifting from

From 62 to a Higher Count: Why Escalation Cannot Be Optional

Escalation is not optional when the incident stream is accelerating and the law assigns a monetary ceiling to reporting failures. The reliable control is a standing intake-and-escalation system that can classify a signal, name an owner, and transmit the required notice while root-cause investigation continues in parallel—not after it proves the signal was serious.

Start with scope discipline. According to Stanford Institute for Human-Centered AI’s AI Index, the AI Incident Database provides a global baseline, but it does not count only European Union events or events reportable under the AI Act’s serious-incident reporting provision. The baseline is still useful: it shows that providers need an intake route spanning support, security, product, compliance, and public affairs, with preserved receipt time, system identity, and accountable ownership. Without that shared record, an external signal can become internal routing delay.

The next annual observation turns that concern into a measurable management test. According to the same Stanford report, incident volume rose sharply in the following year. A provider should therefore ensure that alerts promptly receive an identifier, timestamp, owner, preliminary facts, and decision status; final causal certainty should not be a prerequisite for any of those steps. For a covered Annex III provider, awareness of—or reasonable suspicion of—a serious incident starts the notice track. The external path to the AI Office and, where applicable, the national competent authority proceeds as soon as possible while internal escalation continues. The ordinary outer limit is not an investigation grace period. This is where the belief that a team may investigate first and escalate only after proving seriousness fails.

Stanford’s AI Index 2025 extends the acceleration rather than presenting the earlier baseline as a one-off. The updated series supports a system that recognizes, timestamps, and escalates incident signals consistently; otherwise, a larger queue increases the chance that a legally significant signal will be treated as ordinary product feedback. The statutory critical-infrastructure disruption branch remains the controlling route when its condition is met. It is not postponed while teams debate upstream causation: the duty-holder must issue the required notice through the applicable disruption path while the technical investigation continues beside it.

The European Union AI Act adds the governance consequence. Under Article 99(4)(g), noncompliance with the serious-incident reporting provision can expose a provider to the statutory ceiling stated below. That figure is maximum legal exposure, not an incurred fine, a forecast, or evidence that a particular provider has been penalized. It makes escalation ownership a governance control rather than an informal favor between teams. The actionable close is to require one named incident owner to maintain the intake record, document the awareness-or-suspicion decision, and keep notice and root-cause work on parallel tracks from the first qualifying signal.

Named source Verified figure Operational consequence
Stanford Institute for Human-Centered AI, AI Index, AI Incident Database 62 AI-related incidents in 2022 Use as global context—not an EU-only or incident-reporting count—and establish cross-functional intake.
Stanford Institute for Human-Centered AI, AI Index A sharp increase from 2022 Make intake and ownership measurable; do not wait for root-cause proof.
Stanford Institute for Human-Centered AI, AI Index 2025 56.4% more incidents than in the preceding year; highest annual count in the series Require consistent recognition, timestamping, escalation, and disruption-route readiness.
The European Union AI Act, Article 99(4)(g) For noncompliance with the serious-incident reporting provision, up to €15 million or, for an undertaking, a turnover-based statutory ceiling for the preceding financial year, whichever is higher Treat this as a statutory ceiling, not an incurred fine, and assign named reporting ownership.
From 62 to a Higher Count: Why Escalation Cannot Be Optional — European Tech Incident Rules

Notify vs Escalate: The Two-Track Response Wins

Escalation is not the alternative to notice; it is the control that makes notice timely and defensible. From the applicability date identified above, a covered provider must notify the AI Office and, where applicable, the national competent authority as soon as possible while activating internal response. The ordinary outer limit already explained is a ceiling, not a grace period. When the statutory critical-infrastructure disruption condition is met, the shorter disruption path already explained controls.

Decision path Provider status Incident signal External step Internal step Verdict
Report and escalate Covered Qualifying suspicion exists Send the applicable full or preliminary notice as soon as possible Open response and corrective work WINNER
Escalate only Covered Any No external notice Investigate Reject
Wait for final root cause Covered Plausible but unresolved Delay notice Investigate Reject
Scope review first Unclear Any Obtain specialist advice while preserving the original awareness record Map every legal role Temporary support, not a substitute for notification

Apply the veto gates in fixed order: provider status, plausible statutory harm, and timeliness. Provider status asks whether the covered-provider condition is present. Plausible statutory harm asks whether the signal creates awareness or reasonable cause to suspect an Article 3(49) serious incident. Timeliness asks whether the applicable notice can issue now, including a preliminary notice when material facts remain incomplete. Record each gate as pass, fail, or unresolved. An unresolved gate triggers immediate legal triage; it never authorizes closure of the reporting lane. If scope is unclear, specialist advice and legal-role mapping proceed in parallel while the original awareness record remains intact.

Maintain one timestamped, append-only evidence-to-decision chain: the first credible signal; facts supporting or opposing seriousness; scope analysis; decision maker; unresolved questions; and the stated reasons for selecting one table path over another. Later evidence that reduces perceived severity must be added, not allowed to reset the original awareness time. According to Pryme Intelligence, governed agents provide traceability by linking every response clause to its authorizing policy, certificate, and execution depth, while escalation gates name a real owner and verify authorized bounds. That is an operational analogy, not authority for legal classification, but it supplies a sound recordkeeping model.

Cross-functional RACI: workstream Accountable Responsible Consulted Informed
Incident classification and notice Provider-level incident owner DPO and legal Engineering; security; product; affected-user operations Leadership
Technical evidence preservation Provider-level incident owner Engineering DPO and legal; security Product; affected-user operations
Operational-harm containment Provider-level incident owner Security and product Engineering; DPO and legal Affected-user operations; leadership
Affected-user remediation Provider-level incident owner Affected-user operations, without resetting the incident clock DPO and legal; engineering; security and product Leadership

Before anyone departs from the winning row, require written legal sign-off identifying the proposed path, factual basis, unresolved questions, and continuing controls. If the statutory rule remains satisfied, the compliant outcome is still report and escalate; sign-off controls deviation but does not authorize omitting notice. Leadership preference, executive visibility, or uncertainty about complete root cause may change containment, communications, or remediation posture, but cannot be the sole recorded reason for withholding notice. Reject the shortcut that permits investigation until root cause proves seriousness: that sequence reverses the legal trigger. Configure the evidence chain and RACI as one incident record before the next qualifying signal.

Notify vs Escalate: The Two-Track Response Wins — European Tech Incident Rules

Counter-Evidence

Once the current notification regime applies, an empty public enforcement record is a weak signal, not a safety finding. Confidentiality, incomplete incident taxonomies, underreporting, and the relative novelty of the serious-incident reporting practice can leave qualifying events invisible. A lack of published cases is therefore not evidence that no qualifying events occurred. The relevant question is whether a covered provider of an Annex III high-risk system is aware of, or has reasonable cause to suspect, a serious incident.

Broad AI-incident totals are not legal totals. Public databases commonly rely on media reports, voluntary disclosures, and technical taxonomies, while a determination under the serious-incident reporting provision turns on the provider, intended use, consequences, evidence of awareness, and organizational context. According to the European Commission’s digital-strategy materials, the report must describe the incident and AI system, state intended purpose, and identify corrective actions taken or planned. Those case-specific fields separate a documented legal assessment from a media or technical label.

Error volume is not harm. The same error count can mean isolated, reversible inconvenience in one deployment and widespread wrongful deprivation of benefits, safety harm, or discrimination in another. Assess affected people, severity, duration, and recoverability separately. If those facts are incomplete, escalate the uncertainty in parallel with the notice analysis; the ordinary outer limit is not an investigation grace period.

An “AI” label establishes neither coverage nor the duty holder. High-risk status can vary with intended purpose, deployment context, and sector, while responsibility can vary with the organization’s role as provider, deployer, importer, or supplier. I would require a written classification memo identifying the role, purpose, context, conclusion, and reasons to reconsider it if deployment changes. Marketing terminology cannot carry that judgment.

The statutory critical-infrastructure disruption branch is not a sector shortcut. Its counterfactual test is whether immediate external notice is likely to cause an immediate and substantial disruption of critical infrastructure—not whether the system supports that sector. Timing, dependencies, notice content, and feasible mitigation must be assessed. If the condition is met, the shorter path controls; if it is not established on known facts, the ordinary outer-limit regime remains relevant, but it is a ceiling rather than permission to wait. An incomplete record should preserve the counterfactual question, not settle it from a logo.

Parallel escalation is not a statutory chain of command. The serious-incident reporting provision prescribes external notification; an internal escalation tree, DPO involvement, executive notification, and a RACI are governance controls, not substitutes or a reason to hold the notice. I would design and audit them as organization-specific systems: designate who may declare suspicion, who owns the classification memo, who coordinates the filing, and how the timestamped record shows both tracks moving together. If the covered-provider or serious-incident predicate is genuinely absent, document why; if the provider is aware of, or has reasonable cause to suspect, the incident, escalate and notify the AI Office and, where applicable, the national competent authority as soon as possible. Uncertainty is a reason to review in parallel, not to wait for root-cause proof.

Counter-Evidence — European Tech Incident Rules

Dutch Families

The Dutch National Ombudsman’s 2021 reporting found that families were subjected to wrongful fraud accusations by the tax authorities after high-risk eligibility and fraud-screening processes. According to the Dutch Data Protection Authority’s announced decision in the same affair, discriminatory nationality processing resulted in a 2.75 million fine. That is historical regulatory context—not a penalty under the AI Act’s serious-incident reporting provision, a damages estimate, or an AI Act judgment. It therefore cannot establish an AI Act violation.

This exercise is explicitly counterfactual. Assume that in 2026 a covered provider uses a high-risk system listed in Annex III to determine eligibility for essential public benefits, and a validated diagnostic recreates the discriminatory-referral pattern. The historical event predates the serious-incident reporting regime; it illustrates the mechanism but cannot prove a present breach. At T0, repeated wrongful adverse referrals create reasonable suspicion of potentially large-scale fundamental-rights harm and, for this assumed case, an Article 3(49) serious incident. The provider must open both a regulatory-notification file and an organizational-response file that day. A diagnostic does not have to establish the ultimate root cause before notice, and an outer reporting limit is not an investigation window.

Checkpoint Required action Control record
T0 Treat the validated diagnostic as reasonable suspicion and open the notification and response files. Time-stamped diagnostic, initial impact hypothesis, and named regulatory owner.
Within 24 hours Suspend automated adverse decisions; preserve the model, deployed version, training data, and decision logs; define potentially affected populations. One incident commander with accountable DPO and legal owners, supported by containment and preservation logs.
Same day Send a preliminary external report to the AI Office and, where applicable, the national competent authority. Known impact, harm locations, containment measures, affected-count range, and unresolved facts.
After initial notice Continue corrective-action updates while investigating and remediating. Close the reporting cycle only after remediation is independently verified.

For this worked case, “as soon as possible” is operationally implemented through a same-day preliminary report rather than a final root-cause memorandum. An affected-count range is valuable because it communicates uncertainty without converting the absence of a precise count into grounds for delay. Corrective action does not suspend the reporting duty, and internal escalation does not replace external notice. The worked-case verdict is therefore external notice plus parallel internal escalation, not escalation alone. Once reasonable suspicion exists at T0, management must simultaneously notify, contain harm, preserve evidence, investigate, and correct until remediation is independently verified.

Dutch Families — European Tech Incident Rules

Five Decision Rules

A defensible incident file is a five-gate control, not a committee calendar. Establish provider status, lock the awareness time, test plausible severity, launch notice beside remediation, and preserve the file until accountable closure. Later executive review may change the investigation, but it cannot reset the awareness record or make the reporting lane internal-only.

Decision gate Decisive test Immediate control Nonnegotiable edge rule
Provider Is the organization a provider of a covered system? If yes, open the provider reporting lane. For deployer, importer, supplier, or mixed roles, map every role and obtain specialist advice. Another organization’s involvement cannot pause the provider’s response.
Awareness Has the first credible internal signal supplied an objective basis for concern? Time-stamp the signal and preserve the original record and time zone. Record later rejection or revision separately; never overwrite the original.
Severity Is there a plausible path to an Article 3(49) consequence? Classify the event as a suspected serious incident and obtain immediate legal triage. Do not wait for a final harm count, confirmed root cause, completed investigation, or regulator concurrence.
Response Can notice and corrective action begin on the information already available? If yes, start both. Use the preliminary-report path for incomplete information and continue investigating. The ordinary outer limit is not a holding period; the statutory disruption path controls when its condition is met.
Closure Are reporting, remediation, and residual-risk decisions demonstrably complete? Maintain the case through follow-

Frequently Asked Questions

When does the 15-day reporting clock start, and what events qualify?

For a provider of a high-risk AI system, awareness or reasonable cause to suspect an Article 3(49) incident—such as death, serious health harm, a serious fundamental-rights violation, serious property or environmental damage, or large-scale public-interest harm—starts the notice track, with reporting due as soon as possible and no later than 15 days.

When do the two high-risk AI scope lanes begin?

The Annex III high-risk use-case lane operates with the general regime from 2 August 2026, while the Article 6(1) regulated-product lane and its corresponding duties begin on 2 August 2027.

Who must notify the regulator, and can an internal investigation replace that duty?

Internal escalation cannot substitute for regulator notice, which the provider—or its authorized representative when the provider is outside the Union—must send to the AI Office and, where applicable, the national competent authority in the Member State where the incident occurred or had effect.

Can a provider delay notification because an immediate report might disrupt critical operations?

Critical-sector deployment alone does not qualify; the shorter route applies only when immediate reporting is likely to cause an immediate and substantial disruption of critical infrastructure, with notice due immediately and no later than 72 hours plus a written incident-specific disruption basis.

What happens if the facts are incomplete when the 15-day deadline arrives?

The provider must send a preliminary report containing available information and provide staged updates as soon as possible and no later than two weeks, without resetting the original awareness or reasonable-suspicion date.

What information must the notification contain?

The notification must be in English and provide Annex XII information as far as possible, including system type, country of service, incident description and harm location, while also stating the intended purpose, corrective actions taken or planned, and documentation and analysis supporting post-market monitoring.

Quick answers

When does the 15-day reporting period begin?It begins when the provider becomes aware of, or has reasonable cause to suspect, a qualifying Article 3(49) serious incident, not when the incident occurs or certainty is established.
Must providers wait for root-cause proof before reporting?No; a credible support or safety signal supporting reasonable suspicion starts the reporting workflow while the technical investigation continues.
Can internal escalation replace notice to the regulator?No; internal escalation and regulator notice run in parallel, and internal review does not toll or extend the external reporting date.
When is immediate notice required?Immediate notice is required when it is likely to cause an immediate and substantial disruption of critical infrastructure, with a written incident-specific disruption basis, and the outer limit is 72 hours.
What must the provider report within the ordinary 15-day period?The report must describe the incident and AI system, identify the system’s intended purpose, explain corrective actions taken or planned, and support post-market monitoring through documentation and analysis.

Research Methodology & Editorial Standards

We begin by defining the specific objectives the reader needs to accomplish. Primary product documentation and authoritative secondary sources are assembled into a verified research corpus; drafting occurs only after this foundation is in place.

Every quantitative claim is subjected to dual-source verification. Any figure that cannot be independently corroborated is either qualified or omitted.

Published · Last reviewed · Owned by the Issues editorial desk (About, Contact, Privacy).