Blog Post

The AI Incident Reporting Duty Nobody Can Date

October 4, 2026

Table of Contents

Compliance content answers the question of when an obligation starts. For the serious incident reporting duty in the AI Act, the honest answer is that it is disputed, and the dispute is not a failure of research.

‍

Two readings of the text point in different directions, neither is obviously wrong, and no authority has resolved it. What follows is the reasoning on both sides and what to do without picking one.

‍

Where Does the Provision Sit?

‍

In Chapter IX, Section 2, which is the fact the textual argument rests on.

‍

Article 73 requires providers of high-risk AI systems placed on the Union market to report serious incidents to the market surveillance authorities of the member states where the incident occurred. It is located under post-market monitoring, information sharing and market surveillance rather than among the high-risk requirements. The Act's structure is what the commencement question turns on.

‍

Which Matters Because of How the Dates Work

‍

Article 113 sets a general application date and then lists exceptions by chapter and section. Chapter IX appears in none of them, either as originally drafted or as amended, so on the face of the provision the reporting duty falls under the general date of 2 August 2026.

‍

What Is the Counter-Argument?

‍

The duty attaches to a population defined by provisions that were deferred, which is a substantive reading rather than a textual one.

‍

Regulatory landscape table listing each applicable regime with its jurisdiction, who it applies to and the assessed exposure level
A per-regime record with a stated position is what an unresolved commencement date requires, since the answer cannot be a single date.

Regulation (EU) 2026/1744 deferred Chapter III Sections 1 to 3 to December 2027 for standalone high-risk systems and August 2028 for those embedded in regulated products. Those sections contain the classification rules and the provider obligations. So the argument runs that a duty on providers of high-risk systems has no population while the provisions constituting that category are not yet in force.

‍

Which Leaves Both Readings Standing

‍

One says the reporting article applies because nothing deferred it. The other says it applies to nobody yet because the category it references does not operate. The Omnibus did not address the interaction, and specialist analyses have landed on both sides.

‍

What Does the Commission's Own Timetable Suggest?

‍

August 2026 was the working assumption, though the evidence predates the amendment.

‍

The Commission consulted on draft guidance on reporting serious incidents in late 2025, with the final version expected to apply from 2 August 2026. Guidance prepared on that timetable indicates the reporting duty was planned as live from that date. It was drafted before the Omnibus deferred the high-risk sections, so it does not resolve the question it precedes.

‍

Which Is Suggestive Rather Than Decisive

‍

An organization treating that timetable as settling the matter is relying on a document overtaken by a later regulation. It is a reason to think the duty was intended to be live, and it is not an authority on whether it is.

‍

How Asymmetric Are the Two Errors?

‍

Very, and the asymmetry is what makes the decision easy despite the uncertainty.

‍

Assessment setup showing how many evidence requirements can be satisfied from connected systems against the total the assessment requires
Where a duty's start date is unresolved, what matters is how much of the response already exists rather than when it becomes required.

Preparing for a duty that turns out not to be live costs the preparation, which is a runbook, a named owner and a set of authority contacts. Failing to prepare for one that is live costs a missed deadline, and the deadlines run to fifteen days by default, ten where a death may have been caused and two for a widespread infringement. Producing anything on somebody else's timeline is what those windows test.

‍

Which Deadline Decides It

‍

The two-day one. A legal question about whether a duty exists cannot be resolved inside a two-day reporting window, so the ambiguity has to be settled as a matter of policy before an event rather than researched during one. The asymmetry is the argument for treating it as live regardless of which reading prevails.

‍

What Should the Runbook Contain?

‍

Four things, and three of them are needed for other regimes anyway.

‍

  • Authority contacts per member state: Market surveillance authorities differ by country and the report goes to where the incident occurred.
  • A named determination owner: Somebody who can decide that a causal link between a system and a harm is established or reasonably likely.
  • An evidence threshold: What that person requires before the clock is treated as running.

‍

A recorded position completes it, meaning a documented decision about how the organization treats the commencement question and why. A written decision distinguishes a considered stance from an oversight, and an AI incident response process is where the other three live already.

‍

What Does the Recorded Position Buy?

‍

A defensible answer to a question that may never be asked, at almost no cost.

‍

An organization that considered the ambiguity, took a view and wrote down the reasoning is in a different position from one that never looked, and the difference matters more than which view it took. A regulator or an acquirer asking how the organization handled a disputed commencement date is testing whether anybody thought about it.

‍

Which Is the Same Structure as Scope Self-Assessment

‍

Elsewhere in European cyber regulation the burden of determining whether you are in scope sits with the entity rather than with a regulator, and the defensible position is having applied a test rather than having reached a particular answer. The pattern transfers, and a directive nobody notifies you about sets it out where the uncertainty is scope rather than timing.

‍

Does the Deployer Have a Position Too?

‍

A separate one, and it is subject to the same uncertainty from a different direction.

‍

The reporting article names the deployer alongside the provider in its timing language, and the deployer obligations elsewhere in the Act sit inside the sections that were deferred. So an organization using somebody else's high-risk system faces the same unresolved question about its own escalation duty, with the added difficulty that it depends on somebody else acting.

‍

Which Makes the Vendor Conversation the Cheaper Route

‍

Asking a provider what position it has taken on commencement, and what it expects from customers if an incident occurs, costs one email and produces a documented answer. A provider that has thought about it will say so, and one that has not is itself a finding, and assessing an AI vendor rarely reaches this question.

‍

What Should the Answer Be Recorded Against?

‍

The deployment rather than the vendor, since the same provider may take different positions for different products and the obligation attaches to a system in use. One field per deployment, holding the provider's stated position and the date it was given.

‍

What Should Be Done Now?

‍

Three things, and none requires the question to be answered.

‍

Assemble the runbook, since it is cheap and mostly reusable across reporting regimes. Record the position taken on commencement with the reasoning, because that is what turns uncertainty into a decision. Then identify which systems would be in scope on the wider reading, since a duty with no identified population is a duty nobody can execute even if it applies, and categorizing systems by what they do is the exercise that produces the list. AI compliance readiness assessed per requirement rather than per regime is what keeps a disputed date visible rather than resolved by assumption.

‍

Prepare Without Deciding

‍

The serious incident reporting duty sits in Chapter IX and Chapter IX appears in none of the exceptions to the general application date, so on the text the duty applies from 2 August 2026. The counter-argument is that it attaches to providers of high-risk systems while the provisions classifying and obligating those were deferred to December 2027 and August 2028, so the category does not yet operate. The Commission's own guidance timetable assumed the earlier date and predates the amendment, which is suggestive rather than decisive. The two readings both stand and no authority has resolved them. The errors are wildly asymmetric, and a two-day deadline cannot accommodate resolving a legal question, so the practical answer is a runbook and a recorded position rather than a conclusion. Kovrr's AI compliance readiness tracks obligations per requirement, which keeps a disputed date visible.

‍

To see which of your systems would fall in scope on either reading of the commencement date, book a demo mapped to your own estate.

Yakir Golan

CEO

Article 73 Commencement FAQs

Speak to an Expert

When does EU AI Act Article 73 apply?

Did the Digital Omnibus defer Article 73 serious incident reporting?

Which chapter of the EU AI Act contains Article 73?

What are the Article 73 reporting deadlines?

Did the Commission expect Article 73 to be live from August 2026?

Should you prepare for a reporting duty whose start date is disputed?