AI Failures: When Reporting Becomes a Legal Mandate
Under the EU AI Act, companies can no longer treat critical system failures as internal glitches, as specific reporting mechanisms are now required when AI impacts human safety or fundamental rights....
Under the EU AI Act, companies can no longer treat critical system failures as internal glitches, as specific reporting mechanisms are now required when AI impacts human safety or fundamental rights.
Table Of Content
The threshold for reporting AI incidents
Not every AI error constitutes a reportable incident, but the EU AI Act establishes a clear boundary. When an AI system causes or contributes to death, health damage, human rights violations, or significant property and environmental harm, formal reporting mechanisms are triggered.
Defining serious AI incidents
The regulation identifies four categories of impact: loss of life or serious health impairment, irreversible damage to critical infrastructure, breaches of EU fundamental rights, and significant property or environmental damage. These impacts can arise directly from system control or indirectly through flawed recommendations that influence human decisions.
Mandatory reporting for high-risk providers
Article 73 of the AI Act mandates that providers of high-risk AI systems report incidents to market surveillance authorities. Reporting must occur immediately upon establishing a causal link, with strict deadlines ranging from two to ten days depending on the severity of the outcome, such as in cases involving human death.
Phased reporting instead of silence
Companies are not required to wait for a full investigation before notifying authorities. The AI Act allows for partial initial reports followed by supplementary updates once a detailed analysis of logs, inputs, and system behavior is completed, ensuring regulators are informed without unnecessary delay.
Obligations for AI users
Beyond the provider’s duties, organizations deploying high-risk AI must monitor system performance as per the user manual. If a risk to health, safety, or fundamental rights is identified, the deploying entity must inform the provider and relevant authorities immediately, rather than simply restarting the system.
Evidence and oversight
To facilitate incident analysis, organizations must maintain accurate logs and documentation. Providers are further required to perform post-market monitoring to collect real-world performance data, allowing for timely corrective or preventive actions.
Reporting without admitting liability
The AI Act includes a safeguard ensuring that reporting an incident does not equate to an admission of liability. This provision encourages rapid disclosure, though it does not exempt the provider from the duty to investigate the root cause and implement necessary repairs.


