Editor's note.
Articles 73, 26 and 3 of Regulation (EU) 2024/1689 were read at the European Commission AI Act Service Desk on 25 September 2026, and Articles 9 and 10 of Directive (EU) 2024/2853 in the Official Journal text served by the Publications Office of the European Union. The descriptions of notice conditions, claims-made and occurrence triggers, circumstance notification, consent and cooperation clauses are general descriptions of how liability insurance is commonly structured. They are not attributed to any insurer, no policy wording was read for this article, and no insurer, broker or market body is named in it. Whether a given policy responds, and on what terms, is a matter of its own wording.
- Article 73 of the AI Act sets three statutory deadlines for serious incidents involving high-risk systems: 15 days generally under Article 73(2), immediately and not later than two days for a widespread infringement or serious incident of the kind described in Article 73(3), and not later than 10 days in the event of the death of a person under Article 73(4). All three run from awareness, and Article 73(5) permits an initial incomplete report.
- The reporting duty sits on the provider. The deployer's duty is to monitor and to inform the provider under Article 26(5). The statutory clock nonetheless runs from the moment the provider or, where applicable, the deployer becomes aware, so a deployer's silence does not stop it.
- A liability policy runs its own clock from its own trigger, and on a claims-made basis the act of notifying inside the policy period is frequently what brings a matter within the cover at all. The two clocks share a starting event and share nothing else.
- Four collision points recur: who counts as aware, the consent clause against the Article 73(6) duty to take corrective action, the instruction not to alter the system against the ordinary instinct to fix it, and the fact that the report itself becomes a document that a claimant may later seek under Article 9 of the Product Liability Directive.
- None of this is decided well on the day. The deliverable is a written sequence, agreed before an incident, naming who declares awareness, who files, who notifies, and who is told not to change the system.
Section 1. The clock the Act starts
Article 73(1) places the reporting duty on providers of high-risk AI systems placed on the Union market, and directs the report to the market surveillance authorities of the Member State where the serious incident occurred. Serious incident is defined in Article 3(49) as an incident or malfunctioning of an AI system that directly or indirectly leads to one of a listed set of consequences, which include the death of a person or serious harm to a person's health, a serious and irreversible disruption of the management or operation of critical infrastructure, infringement of obligations under Union law intended to protect fundamental rights, and serious harm to property or the environment.
The deadlines then sit in three paragraphs. Article 73(2) sets the general one: not later than 15 days after the provider or, where applicable, the deployer, becomes aware of the serious incident. Article 73(3) shortens it in the event of a widespread infringement or a serious incident of the kind it describes, where the report is to be provided immediately and not later than two days. Article 73(4) sets not later than 10 days in the event of the death of a person. Article 73(5) provides that where necessary to ensure timely reporting, an initial report that is incomplete may be submitted, followed by a complete report.
Two features of that structure matter more than the numbers. The first is that the clock runs from awareness and not from confirmation. An organisation that waits for certainty about causation before starting the clock has misread the trigger, which is why Article 73(5) exists at all. The second is that the clock is stated to run from the awareness of the provider or, where applicable, the deployer. A deployer who knows and has not told the provider is not thereby holding the clock still.
After the report, Article 73(6) requires the provider without delay to perform the necessary investigations, including a risk assessment of the incident and corrective action, to cooperate with the competent authorities and where relevant the notified body concerned, and not to alter the AI system in a way that may affect any subsequent evaluation of the causes of the incident before informing those authorities. Article 73(8) gives the market surveillance authority seven days from receipt to take appropriate measures. The full provision is read paragraph by paragraph on the regulatory desk in the Article 73 guide.
One calendar point. These are high-risk obligations, and following Regulation (EU) 2026/1744 the obligations for stand alone Annex III high-risk systems apply from 2 December 2027 and those for Annex I systems from 2 August 2028. The reason to build the sequence now is not that the duty bites this quarter. It is that an incident runbook is the one document nobody can write while it is needed.
Section 2. The clock the policy starts
Liability policies handle time in their own vocabulary, and the vocabulary is older than this regulation. Three structures recur across the classes of cover an AI operator is likely to hold.
The notice condition. A policy requires the insured to give notice of a claim, and usually also of a circumstance that might give rise to a claim, within a stated period or in stated terms such as as soon as practicable. Late notice is the oldest coverage dispute there is, and it turns on when the insured knew what.
The trigger. An occurrence policy responds to events happening during the period, whenever the claim arrives. A claims-made policy responds to claims first made during the period, and often requires that they also be notified during it. Where a programme is written on a claims-made basis, notification is not an administrative step after the fact. It is part of what brings the matter within the cover. The distinction, and the retroactive date that sits behind it, are examined in retroactive dates and prior acts.
Circumstance notification. Most professional and technology liability wordings allow, and some require, the notification of circumstances that have not yet produced a claim. That is the mechanism by which an incident with no claimant yet can be attached to the policy year in which it happened. An AI incident that triggers a statutory report and no customer complaint is exactly the shape of matter this mechanism exists for, and exactly the shape that gets left unnotified because nobody has demanded anything yet.
Alongside these sit two clauses that do work in the days after an incident rather than at renewal: a consent or admissions clause, which typically requires the insurer's agreement before liability is admitted or settlement offered, and a cooperation clause, which requires the insured to assist the insurer in investigating. Neither is unusual. Both were drafted for a world in which the insured's first outward act after a loss was to speak to its insurer.
Section 3. Four places where the two pull against each other
Who counts as aware. The statutory clock runs from the awareness of the provider or, where applicable, the deployer, which is an organisational fact. A policy's notice condition usually turns on the knowledge of the insured, which many wordings define by reference to named roles or to senior management. Those are rarely the same person and almost never the same moment. A support engineer who sees the pattern at 09:00 on Tuesday may have started one clock and not the other. The practical fix is a single internal declaration of awareness, timestamped, that starts both.
Corrective action against the consent clause. Article 73(6) requires the provider without delay to perform the necessary investigations and corrective action. A consent clause requires the insurer's agreement before liability is admitted. These are not in direct conflict, because withdrawing a feature, retraining staff or issuing a fix is not an admission of legal liability. They collide in the surrounding communications: the customer notice explaining what went wrong, the public statement, the regulator correspondence. That is where a sentence written for candour can read later as an admission. The answer is not to say less to the regulator. It is to notify the insurer early enough that the drafting of the outward communications happens with everybody in the room.
Do not alter the system, against the instinct to fix it. Article 73(6) provides that the provider shall not alter the AI system in a way that may affect any subsequent evaluation of the causes of the incident before informing the authorities. An insurer investigating a loss has a parallel interest in preservation, and a claimant will later have a third. Everybody wants the same thing here and the engineering organisation wants the opposite, because the engineering organisation's entire training is to ship the fix. The practical control is a preservation step that runs before the fix: a captured system state, the model and prompt versions in force, the logs for the window, the configuration. Article 26(6) requires deployers to keep automatically generated logs for a period appropriate to the intended purpose and of at least six months, which is a floor and not a plan.
The report becomes a document. A serious incident report is a written, dated, structured account of what an organisation believed about its own system's failure. Under Article 9 of Directive (EU) 2024/2853 a national court may order a defendant to disclose relevant evidence at its disposal where a claimant has presented facts and evidence sufficient to support the plausibility of the claim, and Article 10(2)(a) presumes the product defective where the defendant fails to disclose. The conclusion to draw from that is not to write a thinner report. It is that the report should be accurate, should distinguish what is known from what is provisional, and should be written knowing that it has more than one future reader. The disclosure regime is examined at agentcertified.eu, on Articles 9 and 10 as an evidence standard.
Section 4. The third clock, named and not described
Many AI incidents are also personal data incidents, and data protection law carries its own notification duty on its own clock, running to a supervisory authority and in some cases to affected individuals. That regime was not read for this article and is not described here beyond noting that it exists, that it is independent of both clocks above, and that an organisation whose runbook has two branches and needs three will discover it at the worst time. A sector regulated for operational resilience may carry a fourth. The point of listing them is that the number of clocks is a question to settle in advance, in writing, per system.
Section 5. The sequence to write down now
An incident runbook for an AI system needs seven lines, and they should fit on one page.
One. Who can declare awareness, and how it is timestamped. A named role, a deputy, and a record.
Two. Preserve before you fix. What is captured, by whom, within what period: system state, model and prompt versions, logs for the window, configuration, and the instruction set given to the system.
Three. Classify against Article 3(49) and against the policy. Is this a serious incident within the definition, and separately, is it a claim or a circumstance under the wording. Two questions, two answers, one form.
Four. Notify the insurer, and record the time. If the answer to the second question in line three is uncertain, the conservative act is the circumstance notification, which is the cheapest insurance decision available on the day.
Five. File the statutory report on the applicable deadline, using the initial incomplete report where the facts are not yet settled. Do not trade the statutory deadline against an internal approval cycle.
Six. Route the outward communications through one person, with the insurer informed. Customer notice, public statement and authority correspondence are one workstream, not three.
Seven. Close the loop into the evidence file. What the incident showed about the system belongs in the same records that any later reader will ask for, and the case for building those records once is made in the documentation and insurance evidence chain.
For a smaller operator without a compliance function, the plain language version of the first seventy two hours is set out at insureyouragent.com.
Section 6. Seven questions for the next renewal
These are questions about the wording. None of them has a market standard answer, and this desk does not suggest one.
Whose knowledge triggers the notice condition, and is that definition compatible with the awareness trigger in Article 73?
Does the policy permit circumstance notification, and is it permissive or mandatory?
Is the cover claims-made or occurrence, and if claims-made, what is the retroactive date and does it reach back to the deployment of the systems in use?
Does the consent or admissions clause carve out communications made in compliance with a statutory reporting duty?
Does the cooperation clause contemplate an insured that is simultaneously cooperating with a market surveillance authority, and does anything in it conflict with the Article 73(6) duties?
Are defence costs inside or outside the limit, since a regulatory process and a civil claim arising from one incident can run together? That question is taken apart in defence costs inside or outside the limit.
What, if anything, does the policy say about regulatory investigation costs, as distinct from fines? The insurability of a fine is a different question and is covered in does AI insurance cover regulatory fines.
Questions
What are the serious incident reporting deadlines under the EU AI Act?
Article 73 sets three. The general deadline in Article 73(2) is not later than 15 days after the provider or, where applicable, the deployer, becomes aware of the serious incident. Article 73(3) requires a report immediately and not later than two days in the event of a widespread infringement or a serious incident of the kind described there. Article 73(4) sets not later than 10 days in the event of the death of a person. Article 73(5) allows an initial report that is incomplete, followed by a complete report.
Does a deployer report a serious AI incident, or does the provider?
The reporting obligation in Article 73 sits on the provider of the high-risk AI system, reporting to the market surveillance authority of the Member State where the incident occurred. The deadlines run from the moment the provider or, where applicable, the deployer becomes aware. A deployer's own duty is in Article 26(5), which requires it to monitor operation on the basis of the instructions for use and to inform the provider where it identifies a risk or a serious incident.
Should you notify your insurer before or after reporting to the regulator?
The two are not sequential and should not be treated as such. The statutory clock runs on the Act's terms and cannot be paused for an insurance process; the policy clock runs on the wording's terms. For most operators both are triggered from the same internal moment, which is why the decision about who notifies whom, and within how long, belongs in a runbook written in advance rather than in a judgement made on the day.
Can a regulatory incident report be used against you later?
It is a document that exists, and documents that exist can be sought. Under Article 9 of Directive (EU) 2024/2853 a national court may order a defendant to disclose relevant evidence at its disposal where a claimant has presented facts and evidence sufficient to support the plausibility of a compensation claim, and Article 10(2)(a) presumes the product defective where the defendant fails to disclose. Whether legal privilege attaches to any part of an internal investigation is a question of the applicable national law and is not addressed here.
What does Article 73 require after the report is filed?
Article 73(6) requires the provider, without delay, to perform the necessary investigations, including a risk assessment of the incident and corrective action, to cooperate with the competent authorities and where relevant the notified body concerned, and not to alter the AI system in a way that may affect any subsequent evaluation of the causes of the incident before informing those authorities. Under Article 73(8) the market surveillance authority is to take appropriate measures within seven days of receiving the notification.
How long should logs be kept for this purpose?
Article 26(6) requires deployers of high-risk AI systems to keep the logs automatically generated by the system, to the extent those logs are under their control, for a period appropriate to the intended purpose and of at least six months. That is a statutory floor. It is shorter than the period over which a product liability claim can arrive, which is examined in this publication's article on the ten year expiry period and claims-made cover.