EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · SERIOUS INCIDENT · ARTICLE 73
AN INCIDENT IS NOT JUST AN EVENT. IT IS A CHAIN OF EVIDENCE.
When a high-risk AI incident occurs, the organization needs more than a ticket number. It needs a reconstructable record of the system state, facts, evidence, authority, escalation, corrective action and reporting position before the evidence disappears or the system changes.
BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR
EUR-Lex · Regulation (EU) 2024/1689 · Article 73
Use the current consolidated Regulation as the controlling source for the serious-incident definition, operator responsibilities and Article 73 reporting requirements. Reporting timelines and duties depend on the actual system, role and incident circumstances.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
01
IS IT A SERIOUS INCIDENT UNDER THE ACT?
Do not label every malfunction a reportable serious incident or dismiss a harmful event as merely technical. Preserve the facts, consequences, system identity and applicable definition before making the reporting determination.
02
WHO KNOWS WHAT, AND WHEN?
Incident governance depends on chronology. Record detection time, evidence sources, affected system version, people notified, provider/deployer communications, escalation and the basis for each consequential action.
03
WHAT MUST BE PRESERVED BEFORE THE SYSTEM CHANGES?
Logs, prompts or inputs where relevant, outputs, model and software versions, configuration, monitoring data, human interventions and other volatile evidence can disappear during remediation. Preserve the record before overwriting the state.
04
WHAT CORRECTIVE ACTION CHANGED THE REALITY?
Suspension, rollback, restriction, notification, provider action, technical repair and other interventions should be connected to authority, evidence and outcome so the organization can show what happened after the incident was identified.
THE TA-14 OPERATING ROUTE
Turn the question into a governed record.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
01
Freeze system and incident identity
Identify the AI system, version, use context, operator role, time window, reported harm or risk and the source of the initial signal.
02
Preserve evidence and establish chronology
Capture relevant logs, records, communications, decisions and system state before remediation destroys the ability to reconstruct what occurred.
03
Determine reporting and escalation path
Map the facts to the current legal definition, applicable operator duties and competent reporting route. Preserve uncertainty and escalate rather than inventing a reportability conclusion.
04
Track corrective action through outcome and revalidation
Record what authority acted, what changed, what evidence supports closure, and whether the system may return to use or requires further review.
READY TO OPERATE · START PAID ACCESS NOW
Move from reading about the EU AI Act to maintaining the record.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
1–3 AI systems
Evidence Passport
$19/MO
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
The Regulation defines serious incident in Article 3 and uses that definition in the applicable reporting framework. The determination depends on the actual event and consequences, so organizations should check the current consolidated legal text rather than rely on a generic incident label.
Who has serious-incident reporting duties?
Article 73 establishes reporting duties for providers of high-risk AI systems in the circumstances covered by that provision. Other operators can have related monitoring, notification, cooperation or escalation duties, so role and system classification should be established first.
How quickly must a serious incident be reported?
Article 73 contains timing requirements that vary with the circumstances, including accelerated treatment for certain serious events. Because timing can be legally consequential, the current consolidated provision and the actual incident facts should be checked immediately rather than relying on a static summary.
What evidence should be preserved after an AI incident?
Relevant material can include system and model version, configuration, logs, inputs and outputs where appropriate, monitoring data, notices, communications, human interventions, decisions, corrective actions and the chronology connecting them.
Should we fix the system before collecting evidence?
Urgent safety or legal action may need to occur immediately, but evidence preservation should be incorporated into the response wherever possible. Uncontrolled remediation can destroy the record needed to understand the event and demonstrate what was done.
Can TA-14 decide whether an incident is legally reportable?
TA-14 can structure the facts, role, evidence, chronology, gaps, authority and escalation record. It does not replace competent legal advice or the authority responsible for a binding regulatory determination.
EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION
Understand the requirement. Preserve the evidence. Revalidate when reality changes.