By Rafael Luque Ocaña

Serious incidents: the provider reports, but the clock starts when you find out

Article 73 requires the provider to report serious incidents. Its deadlines — fifteen days, ten or two depending on the case — are counted from when the provider or the deployer becomes aware. Your delay eats into someone else's deadline.

This is the last article in the attribution block, and the one that best shows why the block couldn't close with a plain "this isn't yours."

The previous post left the limit of the method on record: ruling out the subject of an article doesn't rule out the matter. Article 73 takes that idea to its most uncomfortable form, because here the obligation is unambiguously someone else's and your conduct still decides whether it gets met.

Who reports it

"Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred."

No ambiguity. Reporting to the authority is the provider's, and so are the obligations that follow: investigate without delay, assess the risk of the incident and the corrective measures, cooperate with the authorities, and not alter the system in a way that could affect the investigation without notifying them first.

None of that is yours. And yet.

The deadlines, and when they start counting

The article sets three windows depending on severity:

  • General rule: immediately after establishing the causal link — or the reasonable likelihood that one exists — and, in any event, no later than fifteen days.
  • Widespread infringement or a serious incident under Article 3, point (49)(b): immediately, and no later than two days.
  • Death of a person: immediately after having established —or "as soon as it suspects"— a causal relationship, within a period of no more than ten days.

The third one is worth pausing on, because a quick read gets it wrong. Ten days is more than the two in the previous case, so it isn't "the shortest deadline." What changes is the trigger: there's no need to have established the causal relationship, suspecting it is enough. It's stricter about when it starts, not about how long it lasts.

And now the sentence that carries this entire article. All three windows are counted from when "the provider or, where applicable, the deployer, becomes aware of the serious incident."

Your awareness starts the provider's clock.

What that means in practice

Combine that with what Article 26(5) already requires you to do: faced with a serious incident, inform "immediately", first the provider.

The result is concrete, and it isn't usually said out loud:

A deployer who takes a week to escalate a serious incident has used up half of the provider's window. If the case falls under the two-day scenario, it has used up all of it — and the missed deadline will be the provider's, on a clock that started running in your office.

It isn't that the reporting is yours. It's that your delay breaches someone else's deadline. It's the most subtle form in the whole block, and the one that shows up least on task lists, because it doesn't look like an obligation: it looks like a courtesy.

The article also provides that, where necessary to report on time, the provider — or, where applicable, the deployer — may submit an incomplete initial report first, followed by the complete one. In other words: the Regulation prefers an imperfect report on time to a perfect one that's late. Waiting until you have all the facts before raising the alarm isn't caution — it runs against the logic of the article.

Three things, and all three are prepared beforehand, not during.

Know what counts as a serious incident. It has its own definition in the Regulation, and it doesn't match the intuition of "something went wrong." Without that criterion written down, the decision to escalate is made by whoever sees it first, using whatever judgement they have that day.

Know who to notify and through which channel. Provider first. Looking for the right contact while the clock is running is exactly the time the article treats as critical.

Know who decides. An incident spotted on a Friday afternoon by someone who doesn't know whether escalating it is their call is exactly what turns fifteen days into two weeks of silence.

None of the three requires legal judgement. All three require the answer to be written down beforehand, with a name and a date.

Closing the block

Five articles, five different reasons: you don't build it, you don't hold what has to be kept, Annex IV doesn't even impose anything, monitoring is the provider's but you're its informant, and reporting is the provider's but you start the clock.

If the block had ended at "none of these five are yours," it would have been reassuring and wrong in its second half. The useful thing is the opposite: checking article by article costs more than ruling them out as a block, and it's the only way to find the two cases where the matter does reach you even though you aren't the subject.

That check is done once. What isn't done once is remembering it: that's why what decides things, on the day of the incident, isn't having read the Regulation — it's having written down who notifies whom, in what order and on what criteria, with the date of the last time someone reviewed it.

Content in accordance with Articles 26 and 73 of Regulation (EU) 2024/1689.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.