Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When must you report a serious incident under the EU AI Act?
Updated
Articles 73 and 55 of Regulation (EU) 2024/1689 are distinct serious-incident duties: high-risk systems to market-surveillance authorities on 15/2/10-day clocks, and systemic-risk GPAI to the AI Office without undue delay. Not legal advice. This page does not determine that YOUR event is a reportable serious incident.
AI Act incident reporting, last verified 9 September 2026 against Articles 3(49), 3(61), 55, 73 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). Regulation (EU) 2024/2847 Article 14 is a different statute — CRA, not the AI Act. NIS2 and DORA are different instruments. Commission AI Act pages and any Article 73(7) Commission guidance are Commission materials — guidance, not the regulation. This page is not legal advice, not a filing, not a determination that YOUR event is a reportable serious incident, and does not start a clock. This product does not file with the AI Office.
This is Articles 3(49), 55 and 73, not YOUR filing
Audience: an incident responder, CISO, product, engineering, or counsel walking Regulation (EU) 2024/1689 on serious-incident reporting. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, that YOUR system is high-risk, that YOUR model has systemic risk, or that YOUR event is a reportable serious incident. This page does not file with the AI Office. This product does not file with the AI Office.
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 3(49) defines a serious incident. Article 73 is the high-risk-system reporting duty to market-surveillance authorities. Article 55(1)(c) is a different GPAI-with-systemic-risk duty to the AI Office without undue delay. The CRA docs hub on this site is Regulation (EU) 2024/2847 — a different instrument. The GPAI-systemic-risk guide on this site is the Article 51–55 page. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance: Articles 3(49), 3(61), 55, 73 and 113 of 2024/1689 are legal requirements only if they apply. Recitals are recitals, not operative articles. Commission AI Act pages and any guidance issued under Article 73(7) are Commission materials — guidance, not the regulation. This page quotes which kind of text it is relying on.
- The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The CRA docs hub on this site is live. A dedicated AI-cybersecurity-requirements, model-evaluation-requirements, and readiness-checklist guide is not on this site yet. Naming them is not a link.
- This page does not invent a 2 August 2025 start date for Article 73. Article 73 sits in Chapter IX. Article 113 of 2024/1689 does not name Chapter IX in points (a), (b), or (c). The residual second paragraph therefore applies Article 73 from 2 August 2026. Article 55 sits in Chapter V. Article 113(b) applies Chapter V from 2 August 2025, with the exception of Article 101. Those are two clocks. Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. This page does not invent a 2 August 2026 date for Annex I.
Article 73 is not Article 55, and is not CRA Article 14
Do not conflate them. Article 73 is a high-risk AI-system duty: providers report serious incidents to the market-surveillance authorities of the Member States where that incident occurred, on 15-day, two-day, and 10-day clocks. Article 55(1)(c) is a GPAI-model-with-systemic-risk duty: keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities. CRA Article 14 of Regulation (EU) 2024/2847 is a manufacturer duty to a CSIRT and ENISA on a 24-hour / 72-hour / 14-day ladder. NIS2 Article 23 and DORA Articles 18–19 are different instruments. Mapping a row is not a finding that any of those texts bind YOU. Last verified 9 September 2026. Not legal advice.
| Track | What the cited text is | Kind of text | Last verified |
|---|---|---|---|
| Article 73 — high-risk AI-system serious-incident reporting | Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred. Default outer cap 15 days from awareness after a causal link or reasonable likelihood; two days for a widespread infringement or Article 3(49)(b); 10 days for death. In force 2 August 2026 via the Article 113 residual second paragraph. This page does not determine that YOUR event is a reportable serious incident and does not start a clock. | Article 73 of 2024/1689. Legal requirement, only if it applies. Distinct from Article 55(1)(c) and from CRA Article 14. This product does not file with a market-surveillance authority. | 9 September 2026 |
| Article 55(1)(c) — systemic-risk GPAI serious-incident reporting | Providers of general-purpose AI models with systemic risk shall keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them. No 15/2/10-day ladder in Article 55. In force 2 August 2025 via Article 113(b), except Article 101. The GPAI-systemic-risk guide on this site is the Article 51–55 page. | Article 55(1)(c) of 2024/1689. Legal requirement, only if it applies. Distinct from Article 73. This product does not file with the AI Office. | 9 September 2026 |
| CRA Article 14 — manufacturer notification of actively exploited vulnerabilities and severe incidents | Regulation (EU) 2024/2847 Article 14 is a manufacturer duty to notify the CSIRT designated as coordinator and ENISA via the single reporting platform. It is a 24-hour early warning, 72-hour notification, and 14-day final report on the actively-exploited track, from 11 September 2026 under CRA Article 71(2). It is not AI Act Article 73. The CRA docs hub on this site is that instrument. | Regulation (EU) 2024/2847 Article 14. A different statute. Legal requirement of the CRA, only if it applies. Distinct from AI Act Articles 73 and 55. This page is not CRA Article 14. | 9 September 2026 |
| NIS2 Article 23 and DORA Articles 18–19 | NIS2 (Directive (EU) 2022/2555) Article 23 is a 24-hour early warning, 72-hour notification, and one-month final report for essential and important entities. DORA (Regulation (EU) 2022/2554) Articles 18–19 classify and report major ICT-related incidents in stages. They are not AI Act Article 73. A dedicated NIS2 or DORA walkthrough is not this page. | Different instruments. Named in prose. Distinct from Articles 73 and 55 and from CRA Article 14. | 9 September 2026 |
What original Article 3(49) actually says
Last verified 9 September 2026 against Article 3 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation's definitions, only if they apply. This page does not apply them to YOUR event. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 3(49) chapeau | Authentic Article 3(49): 'serious incident' means an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following. | Article 3(49) of 2024/1689. Legal requirement of the definition. This page does not find that YOUR event is a serious incident. | 9 September 2026 |
| Article 3(49)(a) — death or serious harm to health | the death of a person, or serious harm to a person's health; | Article 3(49)(a) of 2024/1689. Legal requirement of the definition. Article 73(4) sets a separate 10-day outer cap where a person has died. This page does not score YOUR harm. | 9 September 2026 |
| Article 3(49)(b) — critical infrastructure | a serious and irreversible disruption of the management or operation of critical infrastructure; | Article 3(49)(b) of 2024/1689. Legal requirement of the definition. Article 73(3) pairs this point with widespread infringement on a two-day outer cap. This page does not classify YOUR infrastructure. | 9 September 2026 |
| Article 3(49)(c) — fundamental-rights obligations | the infringement of obligations under Union law intended to protect fundamental rights; | Article 3(49)(c) of 2024/1689. Legal requirement of the definition. Article 73(7) and 73(9)–(10) treat this point specially. This page does not find a fundamental-rights infringement. | 9 September 2026 |
| Article 3(49)(d) — property or the environment | serious harm to property or the environment. | Article 3(49)(d) of 2024/1689. Legal requirement of the definition. This page does not score YOUR property or environmental harm. | 9 September 2026 |
| Article 3(61) — widespread infringement, which Article 73(3) names | Authentic Article 3(61): 'widespread infringement' means any act or omission contrary to Union law protecting the interest of individuals which has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which the act or omission originated or took place, the provider or authorised representative is located or established, or the deployer is established when the infringement is committed by the deployer; or which has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States. Counsel reads the authentic paragraph. This page does not abridge it into YOUR finding. | Article 3(61) of 2024/1689. Legal requirement of the definition. Distinct from Article 3(49). This page does not find a widespread infringement. | 9 September 2026 |
What original Article 73 actually says
Last verified 9 September 2026 against Article 73 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation, only if they apply. The article says 'days', not working days and not calendar days as a defined term. This page does not rewrite that. It does not apply the clocks to YOU. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 73(1) — who reports, and to whom | Authentic Article 73(1): Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred. | Article 73(1) of 2024/1689. Legal requirement, only if it applies. The addressee is the market-surveillance authority, not the AI Office. This page does not file that report. | 9 September 2026 |
| Article 73(2) — default clock: immediately after causal link, outer cap 15 days from awareness | Authentic Article 73(2): The report referred to in paragraph 1 shall be made immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link, and, in any event, not later than 15 days after the provider or, where applicable, the deployer, becomes aware of the serious incident. The period for the reporting referred to in the first subparagraph shall take account of the severity of the serious incident. | Article 73(2) of 2024/1689. Legal requirement, only if it applies. Awareness, not occurrence, is the outer-cap trigger. This page does not start that clock. | 9 September 2026 |
| Article 73(3) — two days: widespread infringement or Article 3(49)(b) | Authentic Article 73(3): Notwithstanding paragraph 2 of this Article, in the event of a widespread infringement or a serious incident as defined in Article 3, point (49)(b), the report referred to in paragraph 1 of this Article shall be provided immediately, and not later than two days after the provider or, where applicable, the deployer becomes aware of that incident. | Article 73(3) of 2024/1689. Legal requirement, only if it applies. Two days, not 15. This page does not classify YOUR incident as 3(49)(b) or as a widespread infringement. | 9 September 2026 |
| Article 73(4) — 10 days: death of a person | Authentic Article 73(4): Notwithstanding paragraph 2, in the event of the death of a person, the report shall be provided immediately after the provider or the deployer has established, or as soon as it suspects, a causal relationship between the high-risk AI system and the serious incident, but not later than 10 days after the date on which the provider or, where applicable, the deployer becomes aware of the serious incident. | Article 73(4) of 2024/1689. Legal requirement, only if it applies. Ten days, not 15, and suspicion of a causal relationship is enough for the 'immediately' limb. This page does not start that clock. | 9 September 2026 |
| Article 73(5) — incomplete initial report | Where necessary to ensure timely reporting, the provider or, where applicable, the deployer, may submit an initial report that is incomplete, followed by a complete report. | Article 73(5) of 2024/1689. Legal requirement of a permission, only if it applies. This page does not file YOUR initial report. | 9 September 2026 |
| Article 73(6) — investigation and no silent alteration | Following the reporting of a serious incident pursuant to paragraph 1, the provider shall, without delay, perform the necessary investigations in relation to the serious incident and the AI system concerned. This shall include a risk assessment of the incident, and corrective action. The provider shall cooperate with the competent authorities, and where relevant with the notified body concerned, and shall not perform any investigation which involves altering the AI system concerned in a way which may affect any subsequent evaluation of the causes of the incident, prior to informing the competent authorities of such action. | Article 73(6) of 2024/1689. Legal requirement, only if it applies. This product does not run YOUR investigation. | 9 September 2026 |
| Article 73(7) — fundamental-rights notifications and Commission guidance | Upon receiving a notification related to a serious incident referred to in Article 3, point (49)(c), the relevant market surveillance authority shall inform the national public authorities or bodies referred to in Article 77(1). The Commission shall develop dedicated guidance to facilitate compliance with the obligations set out in paragraph 1 of this Article. That guidance shall be issued by 2 August 2025, and shall be assessed regularly. | Article 73(7) of 2024/1689. Legal requirement on the authority, plus a Commission duty to issue guidance. That guidance, if issued, is Commission material — guidance, not the regulation. | 9 September 2026 |
| Article 73(8)–(11) — authority action and Commission notice | Article 73(8): the market surveillance authority shall take appropriate measures, as provided for in Article 19 of Regulation (EU) 2019/1020, within seven days from the date it received the notification. Article 73(9): for Annex III high-risk systems whose providers are already subject to equivalent Union reporting instruments, notification of serious incidents shall be limited to Article 3(49)(c). Article 73(10): for high-risk AI systems that are safety components of devices, or are themselves devices, covered by Regulations (EU) 2017/745 and (EU) 2017/746, notification is likewise limited to Article 3(49)(c) and is made to the national competent authority chosen for that purpose. Article 73(11): national competent authorities shall immediately notify the Commission of any serious incident, whether or not they have taken action on it, in accordance with Article 20 of Regulation (EU) 2019/1020. | Article 73(8)–(11) of 2024/1689. Legal requirements, only if they apply. This page does not run the equivalent-instrument test and does not notify the Commission. | 9 September 2026 |
What original Article 55(1)(c) actually says
Last verified 9 September 2026 against Article 55 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 55 is in Chapter V. It is not Article 73. The GPAI-systemic-risk guide on this site is the Article 51–55 page. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 55(1)(c) | Authentic Article 55(1)(c): In addition to the obligations listed in Articles 53 and 54, providers of general-purpose AI models with systemic risk shall keep track of, document, and report, without undue delay, to the AI Office and, as appropriate, to national competent authorities, relevant information about serious incidents and possible corrective measures to address them. | Article 55(1)(c) of 2024/1689. Legal requirement, only if Article 55 applies. Without undue delay. No 15/2/10-day ladder. Addressee is the AI Office, and as appropriate national competent authorities — not the Article 73 market-surveillance authority of the Member State where the incident occurred. This product does not file with the AI Office. | 9 September 2026 |
| Article 55(2) — codes of practice do not replace paragraph 1 | Providers of general-purpose AI models with systemic risk may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published. Providers who do not adhere to an approved code of practice or do not comply with a European harmonised standard shall demonstrate alternative adequate means of compliance for assessment by the Commission. | Article 55(2) of 2024/1689. Legal requirement of the permission, only if it applies. Does not replace Article 55(1)(c). The GPAI Code of Practice is guidance, not the regulation. | 9 September 2026 |
Who to contact — Article 73, Article 55, and not CRA Article 14
Last verified 9 September 2026. This block is a map of addressees as the cited text states them. It is not YOUR contact list and not a filing. This product does not file. Not legal advice.
| Duty | Who the cited text names | What this page does not do |
|---|---|---|
| Article 73(1) | The market surveillance authorities of the Member States where that incident occurred. | Does not identify YOUR market-surveillance authority. Does not file. |
| Article 73(7) for Article 3(49)(c) | The market surveillance authority informs the national public authorities or bodies referred to in Article 77(1). | Does not notify those bodies. Does not find a 3(49)(c) incident. |
| Article 73(11) | National competent authorities immediately notify the Commission of any serious incident, whether or not they have taken action on it. | Does not notify the Commission. That duty is on the authority, not this page. |
| Article 55(1)(c) | The AI Office and, as appropriate, national competent authorities. | Does not file with the AI Office. Distinct from Article 73. |
| CRA Article 14 | The CSIRT designated as coordinator and ENISA, via the single reporting platform established pursuant to CRA Article 16. | Is not CRA Article 14. The CRA docs hub on this site is that instrument. |
Is this a reportable serious incident? — questions, not a filing
The table below is a question list. Answering a row is not a determination that YOUR event is a reportable serious incident, not an Article 73 report, and not an Article 55(1)(c) filing. Walk it with counsel. Last verified 9 September 2026. Not legal advice.
| Question | What the cited text points at | What this page does not do |
|---|---|---|
| Does the Act apply to YOU at all? | Articles 2 and 3 — AI system or GPAI model placed on the Union market, put into service in the Union, or producing output used in the Union, and the Article 2 exclusions. | Does not run applicability for YOU. |
| Are YOU a provider of a high-risk AI system placed on the Union market? | Articles 3(3), 6 and 73(1). Article 73(1) is a provider duty. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. | Does not determine that YOU are a provider. Does not classify YOUR system as high-risk. |
| Did an incident or malfunctioning of an AI system directly or indirectly lead to an Article 3(49)(a), (b), (c), or (d) outcome? | Article 3(49). Death or serious harm to health; serious and irreversible disruption of critical infrastructure; infringement of Union-law fundamental-rights obligations; serious harm to property or the environment. | Does not determine that YOUR event is a serious incident. |
| Has a causal link, or the reasonable likelihood of such a link, been established? | Article 73(2): report immediately after that establishment, and in any event not later than 15 days after the provider or, where applicable, the deployer becomes aware. Article 73(4) for death also names suspicion of a causal relationship. | Does not establish YOUR causal link. Does not start a clock. |
| Which Article 73 outer cap, if any — 15 days, two days, or 10 days? | Default Article 73(2) 15 days. Article 73(3) two days for a widespread infringement or Article 3(49)(b). Article 73(4) 10 days for death of a person. The article says days, not a defined working-day or calendar-day term. | Does not pick YOUR cap. Does not start a clock. |
| Are YOU a provider of a GPAI model with systemic risk? If so, Article 55(1)(c) is a different duty. | Article 55(1)(c): without undue delay, to the AI Office and, as appropriate, national competent authorities. In force 2 August 2025 under Article 113(b), except Article 101. The GPAI-systemic-risk guide on this site is the Article 51–55 page. | Does not designate YOUR model. Does not file with the AI Office. |
| Is this CRA Article 14? | No. CRA Article 14 is Regulation (EU) 2024/2847. Different addressees (CSIRT and ENISA), different clocks (24-hour / 72-hour / 14-day), different trigger (actively exploited vulnerability or severe incident having an impact on the security of a product with digital elements). The CRA docs hub on this site is that instrument. | Does not run the CRA test. Is not CRA Article 14. |
| Does NIS2 or DORA apply on its own facts? | NIS2 Article 23 and DORA Articles 18–19 are different instruments. Filing one does not discharge the other, and does not discharge Article 73 or Article 55(1)(c). | Does not run those tests. Names them in prose. |
Article 113: Article 55 is 2 August 2025; Article 73 is residual 2 August 2026
Last verified 9 September 2026 against Article 113 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 55 sits in Chapter V. Article 113(b): Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. The GPAI serious-incident duty in Article 55(1)(c) therefore applies from 2 August 2025 under Article 113(b), except Article 101. It did not start on 2 August 2026. This page does not invent a 2 August 2026 start date for GPAI.
Article 73 sits in Chapter IX (post-market monitoring, information sharing and market surveillance). Article 113 of 2024/1689 does not name Chapter IX in points (a), (b), or (c). The residual second paragraph — 'It shall apply from 2 August 2026' — therefore applies Article 73 from 2 August 2026. This page does not invent a 2 August 2025 start date for Article 73 high-risk serious-incident reporting. Those two clocks are not one number.
Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. This page does not invent a 2 August 2026 date for Annex I. Regulation (EU) 2026/1744 is an amending regulation. Counsel reads the authentic operative article of any amendment. This page does not apply 2026/1744 to YOU. It does not rewrite Article 113(b) for Chapter V, and it does not rewrite the original residual date for Chapter IX, in the original regulation. Not legal advice.
Legal requirement versus guidance versus ShipReady recommendation
The table below labels each text. Do not treat Article 55 as Article 73, do not treat CRA Article 14 as the AI Act, and do not treat a product surface as a determination. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Article 73 | Legal requirement — high-risk AI-system serious-incident reporting to the market-surveillance authorities of the Member States where the incident occurred, only if it applies. Residual application 2 August 2026 under Article 113 second paragraph. Distinct from Article 55(1)(c). | Does not determine that YOUR event is a reportable serious incident. Does not start a clock. Does not invent a 2 August 2025 start date for Article 73. This product does not file. |
| Regulation (EU) 2024/1689 Article 55(1)(c) | Legal requirement — systemic-risk GPAI serious-incident tracking, documentation, and reporting without undue delay to the AI Office and, as appropriate, national competent authorities, only if Article 55 applies. In force 2 August 2025 under Article 113(b), except Article 101. | Does not designate YOUR model. Does not invent a 2 August 2026 start date for GPAI. This product does not file with the AI Office. |
| Regulation (EU) 2024/1689 Articles 3(49), 3(61) and 113 | Legal requirements of the definitions and of the application dates, only if they apply. Article 113(c) Annex I is 2 August 2027, not 2 August 2026. | Does not apply those definitions to YOUR event. Does not invent a 2 August 2026 date for Annex I. |
| Regulation (EU) 2024/2847 Article 14 | A different statute — CRA manufacturer notification to a CSIRT and ENISA. Not Article 73. | Does not treat a CRA filing as discharging Article 73 or Article 55(1)(c). Is not CRA Article 14. |
| Article 73(7) Commission guidance and Commission AI Act pages | Commission materials. Guidance, not the regulation. Article 73(7) required dedicated guidance by 2 August 2025, to be assessed regularly. | Does not treat that guidance as rewriting Article 73. |
| This product's AI-governance surface | ShipReady recommendation: an inventory, posture, and incident register of facts the organisation recorded. Not an Article 73 file. Not legal advice. | Does not start a reporting clock. Does not determine that YOUR event is reportable. Does not file with the AI Office. A named human still owns the assessment. |
What to do now
As of last verification on 9 September 2026, Article 55 GPAI duties, including Article 55(1)(c), have applied since 2 August 2025 under Article 113(b), except Article 101. Article 73 high-risk serious-incident reporting has applied since 2 August 2026 under the Article 113 residual second paragraph. Article 113(c) Annex I remains 2 August 2027 in the original regulation. The list below is operational preparation. It is not a determination that YOUR event is a reportable serious incident. Walk it with counsel.
- Ask counsel whether YOU are a provider of a high-risk AI system under Articles 3(3) and 6, or a provider of a GPAI model with systemic risk under Articles 51–55. This page does not run those tests. Marking eu_ai_act in an obligation map is not that determination and is not a reportability determination.
- If counsel finds Article 73 in play, walk Article 3(49) and the Article 73(2)–(4) clocks as written: immediately after a causal link or reasonable likelihood, outer cap 15 days from awareness; two days for a widespread infringement or Article 3(49)(b); 10 days for death. Do not date Article 73 from 2 August 2025. Do not treat it as CRA Article 14. This product does not file.
- If counsel finds Article 55(1)(c) in play, walk that point as written: without undue delay, to the AI Office and, as appropriate, national competent authorities. That is not the Article 73 15/2/10-day ladder. Do not date Article 55 from 2 August 2026. Article 113(b) is 2 August 2025.
- The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The CRA docs hub on this site is live. A dedicated AI-cybersecurity-requirements, model-evaluation-requirements, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a determination that YOUR event is a reportable serious incident, and not a filing. Walk it with counsel. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The CRA docs hub on this site is live.
- Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
- Are YOU a provider of a high-risk AI system placed on the Union market? Article 73(1). This page does not determine that YOU are a provider and does not classify YOUR system.
- Did YOUR event meet Article 3(49)? This page does not determine that YOUR event is a reportable serious incident.
- Which Article 73 outer cap, if any — 15 days, two days, or 10 days? This page does not pick it and does not start a clock.
- Is Article 55(1)(c) a different duty on YOUR facts? Without undue delay to the AI Office, in force 2 August 2025 under Article 113(b). This page does not file with the AI Office.
- Is this CRA Article 14? No. Different statute, different clocks, different recipients.
- Did Article 73 high-risk reporting start 2 August 2025? No. Residual Article 113 second paragraph is 2 August 2026.
- Did Article 55 GPAI reporting start 2 August 2026? No. Article 113(b) is 2 August 2025.
- Does this page start our reporting clock, or does the product file? No. This product does not file with the AI Office and does not start a clock.
- Document the assessment, including a not-reportable decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture. The AI risk register lives with that AI-governance surface. That inventory can record facts the organisation declared, including incidents the organisation classified. Recording a row is not an Article 73 report, is not an Article 55(1)(c) filing, is not a determination that YOUR event is a reportable serious incident, and is not a clock. Marking in-scope is not a reportability determination and not auto-filing. A named human still owns the assessment.
This product does not file with the AI Office, does not file with a market-surveillance authority, does not start a reporting clock, does not decide that YOUR event is a serious incident, and does not issue certifications. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking eu_ai_act in-scope is not a determination that you have a reportable serious incident. The cyber risk register lives under Security. It is not an Article 73 serious-incident file.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 3(49), 3(61), 55, 73 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. Article 55 is Chapter V and applies from 2 August 2025 under Article 113(b), except Article 101. Article 73 is Chapter IX and applies from 2 August 2026 under the residual second paragraph. Regulation (EU) 2024/2847 Article 14 is a different statute. NIS2 (Directive (EU) 2022/2555) and DORA (Regulation (EU) 2022/2554) are different instruments. Commission AI Act pages and any Article 73(7) Commission guidance are Commission materials — guidance, not the regulation. Regulation (EU) 2026/1744 is an amending regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The EU AI Act framework guide on this site is the education page under frameworks. The CRA docs hub on this site is live. A dedicated AI-cybersecurity-requirements, model-evaluation-requirements, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated map of serious-incident reporting distilled from Regulation (EU) 2024/1689 Articles 3(49), 55 and 73, with CRA Article 14, NIS2 and DORA labelled as different instruments and Commission materials labelled as guidance, not the regulation. Whether those articles apply to YOU, and whether YOUR event is a reportable serious incident, is a legal question for counsel on your facts. This page does not start a clock and does not file with the AI Office.
Does this page start our reporting clock?
No. Reading this page does not start a clock. Mapping a row does not start a clock. Recording an incident in this product does not start an Article 73 or Article 55 clock. Article 73(2)–(4) clocks run from awareness after a causal link, reasonable likelihood, or, for death, suspicion — only if those articles apply. This product does not start a reporting clock. Last verified 9 September 2026.
Is this CRA Article 14?
No. CRA Article 14 is Regulation (EU) 2024/2847. It is a manufacturer duty to a CSIRT and ENISA on a 24-hour / 72-hour / 14-day ladder. AI Act Article 73 is a high-risk-system duty to market-surveillance authorities on 15/2/10-day clocks. AI Act Article 55(1)(c) is a systemic-risk GPAI duty to the AI Office without undue delay. Filing one does not discharge the others. The CRA docs hub on this site is the CRA instrument. Last verified 9 September 2026.
Does this page determine that our event is a reportable serious incident?
No. Article 3(49) is a definition. Article 73 and Article 55(1)(c) are duties only if they apply. Mapping a row is not a finding that the Act applies, that YOU are a provider, that YOUR system is high-risk, that YOUR model has systemic risk, or that YOUR event is a reportable serious incident. Counsel applies those articles to YOUR facts. Last verified 9 September 2026.
Did Article 73 high-risk reporting start on 2 August 2025?
No. Article 73 sits in Chapter IX. Article 113 of Regulation (EU) 2024/1689 does not name Chapter IX in points (a), (b), or (c). The residual second paragraph applies Article 73 from 2 August 2026. Article 55, in Chapter V, applies from 2 August 2025 under Article 113(b), except Article 101. Those are two clocks. Article 113(c) Annex I is 2 August 2027, not 2026. Last verified 9 September 2026.
Did Article 55 GPAI incident reporting start on 2 August 2026?
No. Article 113(b) of Regulation (EU) 2024/1689 applies Chapter V from 2 August 2025, with the exception of Article 101. Chapter V includes Article 55. That is not 2 August 2026. This page does not invent a 2 August 2026 start date for GPAI. Article 73 residual application is 2 August 2026. Article 113(c) Annex I is 2 August 2027, not 2026. Last verified 9 September 2026.
Does ShipReady file with the AI Office?
No. This product does not file with the AI Office and does not file with a market-surveillance authority. Signed-in app → Compliance → AI governance can record facts the organisation declared. That record is not an Article 73 report and is not an Article 55(1)(c) filing. Marking eu_ai_act in-scope is not a reportability determination and not auto-filing. A named human still owns the assessment.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.