AI Incident Notification
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated coverage distinct from general information duties and incident reporting.
Overview
14 sources · Jul 23, 2026AI Incident Notification
Legal Framework
The AI Act establishes a structured incident notification regime for high-risk AI systems, primarily governed by Article 73, which obliges providers to notify the relevant market surveillance authority without undue delay — and in any event within 15 days of becoming aware — of serious incidents involving their AI systems. A "serious incident" is defined as any incident or malfunctioning of an AI system that has led or may lead to death or serious harm to a person's health, a serious and irreversible disruption of critical infrastructure, or a breach of fundamental rights protected under Union law.
Article 85 complements this by granting any natural or legal person the right to lodge complaints with the relevant market surveillance authority where they have grounds to consider that an infringement of the Regulation has occurred. Recital 170 confirms that this complaint mechanism operates without prejudice to existing remedies under Union and national law.
Recital 36 imposes additional, sector-specific notification obligations for real-time biometric identification systems, requiring that both the market surveillance authority and the national data protection authority be notified of each use. These authorities must then submit annual reports to the Commission.
The rationale is twofold: first, to ensure that authorities can act swiftly when AI systems cause or risk causing serious harm; second, to create a feedback loop that informs future regulatory and supervisory action.
Key Developments
The AI Act's incident notification regime draws conceptual parallels with the GDPR's personal data breach notification framework under Article 33 GDPR, but extends the scope beyond data protection harms to encompass physical safety, infrastructure disruption, and fundamental rights violations. Enforcement practice under Article 33 GDPR — particularly decisions by the Irish DPC and CNIL — has established that the "undue delay" standard typically requires notification within 72 hours, and that organizations must document the rationale for any delayed notification. While the AI Act's 15-day window is more generous, the same principle of demonstrating diligence applies.
The interplay between AI Act incident notification and GDPR breach notification obligations creates a dual-reporting scenario where an AI system malfunction involving personal data may trigger both regimes simultaneously. Providers must assess whether an incident meets both thresholds and coordinate notifications to both market surveillance authorities and data protection authorities.
Practical Guidance
- Establish internal incident classification criteria that map to the Article 73 definition of "serious incident," distinguishing between incidents requiring notification and those that fall below the threshold — document the reasoning for each determination.
- Implement a 15-day notification clock triggered from the moment any personnel become aware of a potential serious incident, not from the conclusion of an internal investigation; build in buffer time for assessment and drafting.
- Designate a single accountable role responsible for coordinating notifications to market surveillance authorities, data protection authorities (where GDPR obligations are triggered), and, for biometric systems, the dual-notification pathway required by Recital 36.
- Prepare notification templates in advance covering the required content: incident description, AI system identifier, nature of harm, corrective measures taken, and cross-references to the system's technical documentation and risk management records under Article 9.
- Maintain an incident register that captures all incidents regardless of whether they met the notification threshold, as this record may be requested during market surveillance audits and will support the annual reporting obligations applicable to biometric identification system deployments.