Free tool · EU AI Act Article 73
EU AI Act Article 73 Incident Report Builder (2026)
Draft a serious-incident notification to your national market surveillance authority. Auto-computes the 2-day, 10-day, or 15-day reporting deadline based on the incident classification.
1. Filing metadata
2. Incident classification
3. AI system identification
4. Description
5. Mitigation & corrective actions
6. Overlapping notifications
# EU AI Act — Article 73 Serious Incident Report _This is an initial notification. Supplementary reports may follow as the investigation progresses (Art. 73(5))._ ## 1. Filing metadata - Reporter role: Provider (developer) - Reporter organisation: _[not provided]_ - Contact person: _[not provided]_ - Contact email: _[not provided]_ - Reporting Member State: _[not provided]_ - National market-surveillance authority: _[not provided]_ ## 2. Incident classification and deadline - Classification: Serious harm to a person’s health (Art. 73(2) — 15 day deadline) - Date incident occurred: _[not provided]_ - Date causal link established: _[not provided]_ - Reporting deadline: **15 calendar days** from the date the causal link was established. - Deadline rule: Other serious incident: initial report within 15 days of establishing the causal link. - Citation: EU AI Act, Article 73(2)-(4). ## 3. AI system identification - System name: _[not provided]_ - Provider name: _[not provided]_ - Intended purpose: _[not provided]_ - Annex III high-risk category: _[not provided]_ - Current status of the system: Still in use - Incident location (city / facility): _[not provided]_ - Approximate number of natural persons affected: _[not provided]_ ## 4. Description of the incident ### 4.1 Short description _[not provided]_ ### 4.2 Detailed description _[not provided]_ ### 4.3 Suspected root cause _[not provided]_ ## 5. Mitigation and corrective actions ### 5.1 Immediate mitigation (within 24 hours) _[not provided]_ ### 5.2 Longer-term mitigation _[not provided]_ ### 5.3 Corrective actions already taken _[not provided]_ ## 6. Concurrent notifications and legal overlaps - GDPR personal-data breach (Art. 33 GDPR): No / not applicable. - General Product Safety Regulation (EU) 2023/988: No / not applicable. - Suspected criminal activity: No. ## 7. Attestation The undersigned confirms that the information above is accurate to the best of their knowledge at the time of filing and that supplementary information will be provided without undue delay as the investigation progresses (Article 73(5) EU AI Act). Signed: __________________________ Date: 2026-08-23 --- _Generated by aicompliancevendors.com/tools/eu-ai-act-incident-report-builder — free tool. Not legal advice._
Article 73 reporting-deadline timeline
| Incident classification | Deadline | Legal basis |
|---|---|---|
| Widespread infringement of fundamental rights | 2 days | Art. 73(3) |
| Serious/irreversible disruption of critical infrastructure | 2 days | Art. 73(3) |
| Death of a person | 10 days | Art. 73(4) |
| Serious harm to a person’s health | 15 days | Art. 73(2) |
| Serious harm to property or environment | 15 days | Art. 73(2) |
Deadlines start on the date the provider (or deployer) established the causal link, or the reasonable likelihood thereof, between the AI system and the incident.
How the builder works
- 1Identify the reporter role and authoritySelect provider, deployer, importer, distributor, or authorized representative. Enter the Member State and the national market surveillance authority.
- 2Classify the incidentPick one of the five Article 3(49) categories. The tool computes whether the 2-day, 10-day, or 15-day deadline applies.
- 3Identify the AI systemSystem name, provider, intended purpose, Annex III category, current status, incident location, and number of natural persons affected.
- 4Describe the incidentShort summary, detailed timeline, and suspected root cause. Include upstream vendors or data changes where relevant.
- 5Log mitigation & overlapping notificationsImmediate and longer-term mitigation, corrective actions taken, and parallel obligations under GDPR, GPSR, or law enforcement.
- 6Preview and exportCopy or download the Markdown filing. Route it through the authority-prescribed channel and archive in your GRC system.
When to use it
- Preparing an initial Article 73 notification within the 2/10/15-day window
- Tabletop exercises and incident-response rehearsals
- Aligning GRC playbooks across GDPR Art. 33, GPSR, and AI Act Art. 73
- Vendor / deployer contract obligations for pass-through notification
- Board-level incident briefings and post-mortem documentation
Article 73 incident-report FAQ
What counts as a serious incident under the EU AI Act?
Article 3(49) defines a serious incident as an incident or malfunctioning of an AI system that directly or indirectly leads to: (a) death or serious harm to a person’s health; (b) a serious and irreversible disruption of critical infrastructure; (c) infringement of Union law protecting fundamental rights; or (d) serious harm to property or the environment.
What is the reporting deadline for a serious incident?
Under Article 73(2)-(4), the initial notification must reach the market surveillance authority within 15 days for a general serious incident, 10 days if the incident resulted in the death of a person, and 2 days for widespread infringement of fundamental rights or a serious/irreversible disruption of critical infrastructure. The clock starts on the date the provider (or deployer) established the causal link.
Who has to file the report?
Primarily the provider of the high-risk AI system. If the incident is caused by conduct attributable to the deployer, the deployer must inform the provider (Article 26(5)) and, where the provider is unreachable, may file directly. Importers, distributors, and authorized representatives can also be filers depending on the market role.
Which authority do I file with?
The market surveillance authority of the Member State where the incident occurred. Each Member State has designated (or is designating) national competent authorities; the European AI Board publishes the list. If the incident occurred across multiple Member States, notify each affected authority.
Does an AI hallucination that misleads a user count as a serious incident?
Only if the misleading output caused one of the four Article 3(49) harms. A hallucination that leads to serious harm to a person’s health (e.g., wrong medical instruction) or a widespread fundamental-rights infringement (e.g., systemic discriminatory hiring outcomes) is reportable. A single unhelpful answer is not.
Does Article 73 apply to general-purpose AI (GPAI) models?
The core serious-incident duty in Article 73 attaches to high-risk AI systems (Annex III + Annex I product-safety AI). Article 55 imposes separate incident-tracking duties on providers of GPAI models with systemic risk. This generator focuses on Article 73; a separate flow is planned for Article 55 systemic incidents.
Do I still need to file if I already notified the GDPR supervisory authority?
Yes. Article 73 is a distinct duty. GDPR Article 33 requires notification for personal-data breaches within 72 hours; Article 73 covers a broader set of harms. Both may apply simultaneously and require separate filings. This tool includes an overlap checklist so you can track parallel notifications.
Can I amend the report as the investigation continues?
Yes. Article 73(5) explicitly contemplates a completeness principle: providers must submit supplementary reports as more information becomes available. The generator flags the filing as an "initial notification" and reserves space for later supplements.
What are the penalties for missing an Article 73 deadline?
Under Article 99(4)(g), non-compliance with Article 73 obligations is subject to administrative fines of up to €15 million or 3% of total worldwide annual turnover for the previous financial year, whichever is higher. Penalties are enforced by national authorities.
Do micro-enterprises get relief?
The Article 73 duty is not exempt for micro-enterprises. Article 99(6) does allow national authorities to take size into account when setting a specific fine, but the notification duty itself still applies.
Is this generator legally binding?
No. This is a drafting aid. The output is a structured Markdown filing that mirrors the fields Article 73 requires. Final submission must go through the channel prescribed by your national market surveillance authority (portal, secure email, etc.) and should be reviewed by counsel.
Does the tool send my data anywhere?
No. The generator runs entirely client-side. Nothing is transmitted to our servers. Download the .md file and store it in your GRC repository.
Official sources
Vendors with incident-response workflow
Article 73 filings must be reproducible: evidence, timestamps, model versions, and downstream affected users. Vendors below provide the audit trail and detection layer that turns a form into a defensible filing.
Embed this builder
Free to embed on your GRC or legal blog. Attribution appreciated.
<iframe src="https://aicompliancevendors.com/tools/eu-ai-act-incident-report-builder" width="100%" height="1600" loading="lazy" style="border:0" title="EU AI Act Article 73 Incident Report Builder" ></iframe>
This builder produces a draft Article 73 initial notification reflecting the plain text of Regulation (EU) 2024/1689. It is not legal advice. Follow the submission channel prescribed by your national market surveillance authority and route the filing through counsel before dispatch.