Skip to main content

Serious incident

A significant failure of a high-risk AI system that causes real harm to people or critical services, which must be reported to regulators.

The Simple Version

A significant failure of a high-risk AI system that causes real harm to people or critical services, which must be reported to regulators.

Detailed Explanation

Article 73 requires providers who become aware of a serious incident to report it to the market-surveillance authority of the member state where it occurred. Reporting timelines depend on severity: immediately for death or critical infrastructure, within 15 days for other serious harm. Deployers must inform providers of serious incidents and must cooperate with investigations. The incident must be logged, investigated, and the root cause documented. Corrective action and updated risk assessments are typically required following a serious incident.

Key Characteristics

  • Defined in Article 3(49) with reference to death, serious health harm, infrastructure disruption, or fundamental rights violations
  • Reportable to national market-surveillance authorities within defined timeframes
  • Both providers and deployers have notification and cooperation duties
  • Must be documented in post-market monitoring records

Why It Matters

AI operations teams must establish clear incident triage procedures that can distinguish serious incidents (requiring regulatory reporting) from minor malfunctions (requiring internal logging only).

Real-World Analogy

Like a 'serious adverse event' in a clinical trial, defined with precision, subject to mandatory reporting, and triggering a formal investigation and corrective action process.

Common Misconceptions

  • Any AI system error qualifies as a serious incident, the definition requires actual harm to health, life, infrastructure, or fundamental rights to be triggered.
  • Only the provider must report serious incidents, deployers also have reporting duties under Article 73.

Related Terms

Sources & Further Reading