The EU AI Act gives some AI incidents two days to report.
Writing in CIO, technology compliance leader Allan Dabre says Article 73 of the EU AI Act took effect on 2 August 2026, bringing a serious incident reporting duty.
The standard deadline is 15 days. When a death is involved, it drops to 10 days. A widespread incident or serious disruption to critical infrastructure must be reported within 2 days.
GDPR gives 72 hours and SEC rules give public companies four business days. Dabre's point is practical: those deadlines are already in incident response runbooks. Article 73 probably is not.
Guidance from the European Commission says an indirect causal link between an AI output and downstream harm is enough to trigger the duty. That includes a flawed credit assessment that leads to a loan denial.
The December 2027 deferral covers conformity assessments and technical documentation. It does not cover Article 73. These cases may not look like security events, but the reporting clock still starts.
Which of your live AI systems has a named owner who would notice the two-day case?
Sources
Every story here is open to read. The ERP LEADERS brief goes one step further.
One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.
Welcome back. · Issue 01
