23 June 2026
When AI fails quietly, the clock still starts
Article 73 of the EU AI Act gives high-risk providers as little as two days to report a serious incident — for a failure mode no SIEM was built to see.
A breach announces itself.
Data gone, systems down, alarms everywhere.
An AI failure can be silent. A model that quietly starts making the wrong calls. A decision that's subtly unfair. Harm that only surfaces three steps downstream, long after the system did its part.
From August, in Europe, that silence comes with a deadline.
The EU AI Act's Article 73 takes effect on 2 August 2026, and it requires providers of high-risk AI to report serious incidents to the authorities within as little as two days, and no more than fifteen. We've had breach disclosure for two decades. This is its successor, written for a different kind of failure.
And the definition is broader than most people expect. It isn't only the dramatic cases. The Commission has been explicit that indirect causation counts - an AI system that produces a flawed medical analysis that harms a patient through a later clinical decision, a loan wrongly denied on a faulty AI assessment, a hiring screen that quietly disadvantages qualified people. Each of those is a reportable event now, not an internal post-mortem.
Here is the uncomfortable part. We are good at detecting breaches; we have built twenty years of tooling to see them.
We have built almost nothing to see a model degrading. There's no alarm for "accuracy fell four points this quarter," no alert for "this model started declining a particular kind of applicant."
Most organisations wouldn't know their AI had failed until a customer, a regulator, or a journalist told them first.
For anyone in financial services this should land hard. The fines reach €15 million or 3% of global turnover - but the deeper exposure is that your credit, fraud and underwriting models feed human decisions every day, which is precisely the indirect-causation territory the rule is built around.
This is incident response again, pointed at a failure mode a SIEM was never designed to see.
It means defining what an "AI incident" actually is for your business, monitoring for drift and unfair outcomes rather than only downtime, preserving the evidence, and rehearsing the reporting path before the clock is running. And while this is European law, the direction of travel - and the Brussels effect... means it won't stay European for long.
So the question worth sitting with: when your AI quietly starts getting it wrong, who finds out - and how fast?