Compliance

AI Incident

An event where an AI system causes or nearly causes harm, malfunction, or violation of requirements warranting investigation.

Definition

AI Incident refers to an event involving an AI system that results in harm, near-harm, malfunction, security breach, or violation of legal requirements, warranting reporting, investigation, or corrective action. The EU AI Act specifically defines and mandates reporting of "serious incidents."

EU AI Act Definition: Article 3(49) defines "serious incident" as an incident or malfunctioning of an AI system that directly or indirectly leads to: death or serious damage to health, property, or environment; serious and irreversible disruption of critical infrastructure management; or breach of fundamental rights obligations.

Reporting Requirements:

  • High-Risk Systems (Art. 73): Providers must report serious incidents to market surveillance authorities immediately upon becoming aware, within 15 days maximum. Investigation and corrective measures required
  • GPAI with Systemic Risk (Art. 55): Providers must document, report, and share relevant information about serious incidents with AI Office
  • Record Keeping: All incidents must be logged and retained

Incident Categories:

  • Safety incidents (physical harm, property damage)
  • Security incidents (breaches, unauthorized access)
  • Rights violations (discrimination, privacy breaches)
  • Performance failures (systematic errors, drift)
  • Compliance incidents (regulatory violations)

Investigation Process: Incidents typically require root cause analysis, impact assessment, corrective actions, preventive measures, and regulatory notification where required.

Related concepts: Serious Incident, Post-Market Monitoring, Risk Management System, Market Surveillance

Sources

  • EU AI Act Article 73
  • Incident Response Standards