Skip to content
Topic Contested in court

AI Incident Notification

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated coverage distinct from general information duties and incident reporting.

14 linked items 11 Laws2 Guidance1 Literature

Overview

14 sources · Jul 23, 2026

AI Incident Notification

Legal Framework

The AI Act establishes a structured incident notification regime for high-risk AI systems, primarily governed by Article 73, which obliges providers to notify the relevant market surveillance authority without undue delay — and in any event within 15 days of becoming aware — of serious incidents involving their AI systems. A "serious incident" is defined as any incident or malfunctioning of an AI system that has led or may lead to death or serious harm to a person's health, a serious and irreversible disruption of critical infrastructure, or a breach of fundamental rights protected under Union law.

Article 85 complements this by granting any natural or legal person the right to lodge complaints with the relevant market surveillance authority where they have grounds to consider that an infringement of the Regulation has occurred. Recital 170 confirms that this complaint mechanism operates without prejudice to existing remedies under Union and national law.

Recital 36 imposes additional, sector-specific notification obligations for real-time biometric identification systems, requiring that both the market surveillance authority and the national data protection authority be notified of each use. These authorities must then submit annual reports to the Commission.

The rationale is twofold: first, to ensure that authorities can act swiftly when AI systems cause or risk causing serious harm; second, to create a feedback loop that informs future regulatory and supervisory action.

Key Developments

The AI Act's incident notification regime draws conceptual parallels with the GDPR's personal data breach notification framework under Article 33 GDPR, but extends the scope beyond data protection harms to encompass physical safety, infrastructure disruption, and fundamental rights violations. Enforcement practice under Article 33 GDPR — particularly decisions by the Irish DPC and CNIL — has established that the "undue delay" standard typically requires notification within 72 hours, and that organizations must document the rationale for any delayed notification. While the AI Act's 15-day window is more generous, the same principle of demonstrating diligence applies.

The interplay between AI Act incident notification and GDPR breach notification obligations creates a dual-reporting scenario where an AI system malfunction involving personal data may trigger both regimes simultaneously. Providers must assess whether an incident meets both thresholds and coordinate notifications to both market surveillance authorities and data protection authorities.

Practical Guidance

  • Establish internal incident classification criteria that map to the Article 73 definition of "serious incident," distinguishing between incidents requiring notification and those that fall below the threshold — document the reasoning for each determination.
  • Implement a 15-day notification clock triggered from the moment any personnel become aware of a potential serious incident, not from the conclusion of an internal investigation; build in buffer time for assessment and drafting.
  • Designate a single accountable role responsible for coordinating notifications to market surveillance authorities, data protection authorities (where GDPR obligations are triggered), and, for biometric systems, the dual-notification pathway required by Recital 36.
  • Prepare notification templates in advance covering the required content: incident description, AI system identifier, nature of harm, corrective measures taken, and cross-references to the system's technical documentation and risk management records under Article 9.
  • Maintain an incident register that captures all incidents regardless of whether they met the notification threshold, as this record may be requested during market surveillance audits and will support the annual reporting obligations applicable to biometric identification system deployments.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 11
Art. 3(26) ‘market surveillance authority’ means the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020… AI Act Art. 3(48) ‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union… AI Act Art. 3(49) ‘serious incident’ means an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following: AI Act Art. 5(4) Without prejudice to paragraph 3, each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for law enforcement p… AI Act art 85 Right to lodge a complaint with a market surveillance authority AI Act Jun 2024 rec 170 Recital 170 — complaint rights for AI regulation infringement AI Act Jun 2024 rec 141 Recital 141 — real world testing conditions without sandbox AI Act Jun 2024 rec 156 Recital 156 — market surveillance and compliance enforcement framework AI Act Jun 2024 rec 159 Recital 159 — biometric AI surveillance authority powers AI Act Jun 2024 rec 161 Recital 161 — Union and national supervision responsibilities for general-purpose AI AI Act Jun 2024 rec 153 Recital 153 — national competent authorities designation AI Act Jun 2024 rec 36 Recital 36 — biometric system use notification and reporting AI Act Jun 2024 rec 115 Recital 115 — systemic risk management for general-purpose AI AI Act Jun 2024 rec 130 Recital 130 — rapid deployment of innovative AI systems AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024
Guidance 2
edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 32024 on data protection authorities role in the Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework EDPB Jul 2024
Literature 1
Zeszyt Prawniczy UAM Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act Zeszyt Prawniczy UAM Dec 2025