The Extended Brief
The EU AI Act just gave you a breach notification clock you didn’t know about

Brief by The AI News AI newsroom · Sep 8, 2026, 7:14 AM EDT edition
Original reporting by CIO · published Sep 8, 2026, 6:00 AM EDT
High-risk AI providers in the EU must now report serious incidents in as little as two days, a clock most security teams have no runbook for.
Key points
- Article 73 of the EU AI Act requires high-risk AI providers to report serious incidents to national market surveillance authorities. source ↗
- Providers must report within 15 days by default, or 10 days if a death is involved. source ↗
- The shortest deadline, two days, covers widespread incidents and serious disruption to critical infrastructure. source ↗
- The obligation took effect August 2, while the Digital Omnibus pushed other high-risk enforcement to December 2027. source ↗
- The author says the trigger is broader than a breach — an AI tool giving bad information can qualify. source ↗
The data
Deadlines for providers of high-risk AI systems to report serious incidents to national market surveillance authorities.
Numbers from the original article, machine-verified against its text
Practical applications
- Determine whether any AI systems you provide into the EU are classified as high-risk and therefore fall under Article 73.
- Build an incident runbook with the 15-, 10-, and 2-day deadlines alongside your existing GDPR 72-hour clock.
- Expand your incident triggers beyond breaches to include harmful model outputs, such as a customer-facing tool giving bad information.
Context
Security teams already plan around GDPR's 72-hour breach-notification clock and the SEC's four-business-day rule for material incidents. Article 73 adds a separate deadline triggered by an AI system causing serious harm, not just by personal data exposure, and it took effect even as the rest of the Act's high-risk enforcement was delayed to December 2027.
What to watch
- First guidance or enforcement from national market surveillance authorities will show how broadly 'serious incident' is interpreted in practice.
Related briefs
- Deepseek plans the largest known Huawei chip cluster with 160,000 processors in Inner Mongolia
- Anthropic Breaks With Peers on Massachusetts AI Safety Bill
- Anthropic Has Some Alignment Problems
- OpenAI Says New Model Meets Its ‘Critical’ Cybersecurity Threshold
Editorial score 4.0 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 4.0
Desks: Policy & Society · Security
Topics: Governance & policy · Cybersecurity · Enterprise AI
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.