Article 73 gives providers 15 days to report a serious AI incident, 2 days for the severe ones. The deadline moved to December 2027. The detection capability it assumes takes longer than that to build.
Ask an Irish operations director how fast they must report a personal data breach and you get "72 hours" without hesitation. Ask the same person what happens when an AI system in their organisation causes serious harm, and the room goes quiet. That gap is about to become a supervisory question rather than an academic one.
What Article 73 actually requires
The EU AI Act's serious incident regime sits in Article 73, and the timings are tighter than most people expect. A provider of a high-risk AI system reports a serious incident to the market surveillance authority of the Member State where it happened within 15 days by default, 10 days where a person has died, and 2 days where the incident involves a widespread infringement or serious and irreversible disruption of critical infrastructure. An incomplete initial report is permitted where the full picture is not yet available.
Two details matter more than the numbers. The clock starts not at the moment of the incident, but at the point the provider establishes, or has reasonable grounds to believe, a causal link between the AI system and the harm. And most Irish organisations are deployers rather than providers: a deployer who becomes aware of a serious incident notifies the provider, and where the provider cannot be reached the obligation lands back on the deployer. Modify a system enough to be treated as its provider — fine-tuning or changing its intended purpose can do that — and you file directly.
The definition of a serious incident is broad: death or serious harm to health, serious and irreversible disruption of critical infrastructure, breach of fundamental rights obligations under Union law, and serious harm to property or the environment.
The date moved. The exposure did not.
The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force three days later. It pushes the standalone high-risk obligations under Annex III from 2 August 2026 out to 2 December 2027, and product-embedded systems under Annex I to August 2028. Article 73 travels with that regime, so an Irish deployer of a recruitment screening tool or a credit decisioning model has sixteen months before the formal reporting duty bites.
Read the rest of the calendar and the picture changes. Article 50 transparency duties, the general-purpose AI obligations, the prohibitions and the penalty regime all applied from 2 August 2026, and the AI Office of Ireland has been operational since that date, coordinating the sectoral regulators that will do the supervising. The reporting deadline moved. The capability it assumes was never the part you could assemble in a fortnight.
You already run four incident clocks
Your organisation is almost certainly already inside three or four statutory reporting regimes, and an AI failure will trip them long before anyone reaches for the AI Act.
A model that leaks personal data into a prompt is a GDPR Article 33 notification, and that clock has been running at 72 hours since 2018. If you are in scope for NIS2, a significant incident carries a 24-hour early warning. Regulated financial firms under DORA report major ICT incidents on a timescale measured in hours from classification. Add the Central Bank's expectations around operational resilience and outsourcing, and the AI Act becomes the fifth clock in a room where four are already ticking.
An AI system that misprices a product, screens out a protected group of candidates or takes an irreversible action on a customer account raises a data protection question and a consumer protection question today, under law already in force. December 2027 only changes who else you have to tell.
The hard part is attribution, not filing
Filing a report is administratively trivial. Establishing that an AI system caused the outcome is where organisations come unstuck, and it explains why the Article 73 clock is written the way it is.
In most environments we assess, AI involvement in a decision is invisible after the fact. A recommendation surfaces in a workflow, a person acts on it, and nothing in the record distinguishes that decision from one made unaided. When a complaint arrives four months later, nobody can reconstruct whether the model was in the path. Article 26 requires deployers of high-risk systems to retain automated logs for at least six months, because attribution without logs is guesswork. A regulator asking why no report was filed will not accept "we could not tell" for long.
What to build before December 2027
Start by widening the definition of an incident in the process you already have. If your register only captures outages and breaches, an AI system producing systematically wrong outputs for months will never enter it. Add a route for outcome failures alongside availability failures.
Then fix the contractual position. A deployer's Article 73 route runs through the provider, so an agreement with no notification obligation running in either direction leaves you with a legal duty and no mechanism behind it. That is one clause, and it belongs in every AI procurement you sign from here.
Finally, run the scenario before you need it. Pick the AI system that would do the most damage if it failed quietly, and walk a table through it: who notices, what evidence exists, who decides there is a causal link, and which of your four clocks starts first. Most organisations find the answer to the first question is nobody.
We work with Irish boards and leadership teams on exactly this — what is deployed, what it can reach, what evidence survives a failure, and which regulator hears about it first. If you want that assessed rather than assumed, a diagnostic conversation with Acuity AI Advisory is the place to start. Vendor-neutral, evidence first.