When AI Incident Reporting Obligations Actually Start
AI-GENERATED IMAGE
If you are building an incident response process for a high-risk AI system, almost every guide tells you the obligation starts on 2 August 2026. That date is incorrect.
For standalone Annex III high-risk systems, Article 73 incident reporting starts on 2 December 2027. For high-risk AI embedded in products already covered by EU sectoral safety law, it starts on 2 August 2028. Sixteen and twelve months later than the date most material still gives.
The mechanics have not changed, and we cover what counts as a serious incident and who you notify separately. This article is about when the clock starts, and what to do in the meantime.
Why the old date is everywhere
Article 73 has no application date of its own. It sits in Chapter IX of the Act, which falls under the general rule in Article 113. The Regulation applies from 2 August 2026, except that Article 6(1) and its corresponding obligations apply from 2 August 2027.
That matters because Article 73 only binds providers of high-risk AI systems. A system with no high-risk obligations cannot generate a reportable incident.
Following the political agreement of 7 May 2026, the Annex III high-risk deadline moved to 2 December 2027 and the Annex I embedded-product deadline to 2 August 2028. Incident reporting moved with them.
The commentary on Article 73 was written in autumn 2025, around the Commission’s draft guidance, and nobody has gone back to re-date it. When a deadline shifts, the old date survives in search results far longer than it survives in law. Check the publication date on anything you rely on for AI Act timing.
What did not change
The delay moved when the obligations apply. It did not change what they require, and the reporting clocks are unchanged.
Three timeframes apply, all running from the moment you become aware of the incident rather than from when it happened:
- 15 days for a serious incident by default (Article 73(2)).
- 2 days for a widespread infringement, or a serious and irreversible disruption of critical infrastructure (Article 73(3)).
- 10 days where a person has died (Article 73(4)).
These are ceilings. Article 73(2) requires the report “immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link”, and only then sets 15 days as the backstop. Establishing causation on day three and filing on day fourteen is not compliance.
If the investigation is still running, Article 73(5) lets you file an incomplete initial report and follow it with a complete one. Filing partial facts on time beats filing late.
Deployers are not the primary reporters, but they are not exempt. Article 26(5) requires a deployer that identifies a serious incident to “immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities”. If you deploy someone else’s high-risk system and cannot reach the provider, Article 73 applies to you directly.
The guidance the Commission still has not published
Article 73(7) obliged the Commission to produce guidance on this duty, and set a date: “That guidance shall be issued by 2 August 2025, and shall be assessed regularly.”
It missed. A draft appeared on 26 September 2025, with a reporting template and a section on how Article 73 interacts with reporting duties under other EU law. The consultation closed on 7 November 2025. As of late July 2026, the final version has still not been published, nearly a year past the Commission’s own statutory deadline.
Do not wait for it. The obligation lives in the Act, not in the guidance. The template will shape the format of your report and the detail an authority expects. It will not change whether you file, or when. A process built from Article 73 and Article 3(49) will need adjusting at the margins when the guidance lands, not rebuilding.
Use the draft, but date-check it. It reads “serious incident” broadly, including harm caused indirectly. Its worked example is an incorrect AI medical analysis causing harm through a later clinical decision, which is still reportable. The substance is useful. The timing statements are not, because the draft assumes it applies from 2 August 2026.
What this means for you
If you provide a standalone Annex III high-risk system (recruitment screening, credit scoring, education, essential services), your reporting duty starts on 2 December 2027. You have roughly sixteen months.
If your high-risk AI is embedded in a regulated product (a medical device, a vehicle, machinery), you have until 2 August 2028. Check Article 73(10) as well: if your system falls under the medical device regulations, your AI Act reporting narrows to fundamental-rights incidents only, because existing device vigilance channels cover the rest. Article 73(9) does the same for providers already subject to equivalent EU reporting obligations.
If your system is already on the market, the grandfathering cut-off tracks the new dates too, so a legacy Annex III system placed before 2 December 2027 stays outside these obligations until its design significantly changes.
If your exposure is Article 50 transparency rather than high-risk, none of this is your near-term deadline. Disclosure applies from 2 August 2026 and the marking of AI-generated content from 2 December 2026. Both land before anything in this article.
What to do now
- Re-date your compliance calendar. If it says 2 August 2026 against incident reporting, correct it to 2 December 2027 or 2 August 2028 depending on your classification. Check where that old date has been copied into policies and board papers.
- Check whether your authority exists yet. Member states had to designate their market surveillance authorities by 2 August 2025, and most missed it. As of June 2026, nine had designated both required authorities, twelve were partway, and six had designated none. Article 74 also hands several sectors to a different authority: regulated products, financial services, law enforcement, and EU bodies. Work out which of those applies to you, then track your member state’s progress.
- Write your severity criteria against Article 3(49), not against the draft guidance. The four limbs of the definition are settled law. Map each one onto what your specific system could plausibly do.
- Build the 2-day path first. Most processes are designed around the 15-day default and quietly fail the 2-day case. Work out who can authorise a filing over a weekend.
- Watch for the final guidance. When it lands, it will carry the reporting template, and it may finally restate the application date correctly.
The extra sixteen months are real and worth using. They buy you the chance to build an incident process deliberately, instead of during your first incident. Treat 2 December 2027 as the date you need to be ready. Organisations that treat it as the date to start will spend the reprieve badly.
Frequently asked questions
When do AI incident reporting obligations start?
For standalone Annex III high-risk AI systems, 2 December 2027. For high-risk AI embedded in products already regulated under EU sectoral law, 2 August 2028. Article 73 has no application date of its own: it attaches to providers of high-risk AI systems, so it travels with the high-risk obligations, and the Digital Omnibus moved those from 2 August 2026 and 2 August 2027 respectively. Most guidance published before May 2026 still gives 2 August 2026, which is now the wrong date for Annex III systems.
Has the Commission published its Article 73 incident reporting guidance?
Not in final form. Article 73(7) required the Commission to issue dedicated guidance by 2 August 2025. It missed that deadline. A draft, including a reporting template, appeared on 26 September 2025 and the consultation closed on 7 November 2025. As of late July 2026 the final version is still unpublished, nearly a year past the statutory deadline. The obligation itself does not depend on the guidance existing.
Do the 2-, 10- and 15-day reporting deadlines change with the delay?
No. The Digital Omnibus moved when the high-risk obligations start applying, not what they require. The three outer limits in Article 73(2) to 73(4) are unchanged: 15 days for a serious incident by default, 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure, and 10 days where a person has died. All three run from when you become aware of the incident, not from when it happened.
Who has to report an AI incident, the provider or the deployer?
Article 73(1) puts the reporting duty on the provider. Deployers are pulled in by Article 26(5), which requires a deployer that identifies a serious incident to inform the provider first, then the importer or distributor and the market surveillance authority. If you are a deployer and cannot reach the provider, Article 73 applies to you directly. Deployers of law enforcement systems have a carve-out for sensitive operational data.
Does the delay apply to systems already on the market?
The grandfathering cut-off in Article 111(2) tracks the moved dates, so legacy standalone Annex III systems placed on the market before 2 December 2027 stay outside the high-risk obligations until their design significantly changes. Note that the Article 5 prohibitions and the Article 50 transparency duties apply to those systems regardless, and neither was delayed.
John holds editorial responsibility for all ComplyDrive content.
About the author →The 47-item checklist, an editable tracker, nine sample documents and nine fill-in templates.
Get the Toolkit