Article 50 applies 2 Aug 2026 EU AI Act transparency rules were not deferred by the Omnibus, and are not limited to high-risk systems. What it requires →
EU AI Act · Article 73 · Annex III obligations now apply from 2 December 2027

EU AI Act Article 73: tiered serious-incident reporting built into the toolkit

High-risk AI providers placed on the EU market must report serious incidents within 2, 10, or 15 days depending on incident type. Under the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, Annex III high-risk obligations including Article 73 apply from 2 December 2027 instead of the original 2 August 2026 date. The architecture is unchanged, the deadline moved. AIMS-22 in the Starter tier implements the tiered structure; PRO-AnnexA-08 in Professional extends it with detailed workflows.

Latest · 27 July 2026, Digital Omnibus in force

The Digital Omnibus is now law. The European Parliament adopted it on 16 June 2026 (423–57) and the Council on 29 June 2026. It was signed on 8 July, published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026, and entered into force on 27 July 2026. Annex III high-risk obligations, which include Article 73, now apply from 2 December 2027; Annex I embedded high-risk obligations from 2 August 2028.

The nearer deadline is Article 50. The Omnibus deferred the high-risk rules but not the transparency rules. Article 50 applies from 2 August 2026 and is not limited to high-risk systems — see the section below.

Full Omnibus analysis on euaiactchecklist.com →

The nearer deadline

Article 50, transparency, applies from 2 August 2026

Article 50 is separate from Article 73, and it lands first. The Digital Omnibus deferred the high-risk obligations to 2 December 2027. It did not defer the transparency obligations. Article 50 applies from 2 August 2026, and it is not limited to high-risk systems, so it reaches far more organisations than Article 73 does.

If you run a customer-facing chatbot, generate synthetic content, publish deep fakes, or deploy emotion-recognition or biometric-categorisation systems, Article 50 applies to you whether or not anything you operate is classified as high-risk.

The four duties

The transitional relief is narrow

Only the Article 50(2) marking obligation is deferred, and only for AI systems placed on the market before 2 August 2026. Those systems must comply from 2 December 2026. Systems placed on the market on or after 2 August 2026 comply immediately. Content generated before 2 August 2026 does not need to be labelled retroactively. Every other Article 50 duty applies from 2 August 2026 with no grace period.

Penalties for infringement reach €15 million or 3% of worldwide annual turnover.

What the Commission has published

The European Commission has adopted Guidelines on the Article 50 transparency obligations, and a voluntary Code of Practice on Transparency of AI-Generated Content. The Code is not conclusive evidence of compliance, but adherence is a recognised way to demonstrate good faith. Neither instrument is binding.

Where this sits in your AIMS

Article 50 is a disclosure and labelling duty rather than a management-system duty, so ISO 42001 does not discharge it on its own. What the AIMS gives you is the evidence trail: record, for every system in your AIMS-18 AI System Inventory, whether it interacts with people, generates synthetic content, or performs emotion recognition or biometric categorisation, and what disclosure is made. The Annex A.9 controls (use of AI systems) and A.8 (information for interested parties) are where an auditor will look for it.

Being straight with you: the toolkit documents Article 50 in the Master Guide and gives you the inventory structure to evidence it. It does not currently ship a dedicated Article 50 disclosure procedure or content-labelling register. Those are the primary content items in the next release. If Article 50 is your immediate pressure, buy on the strength of the AIMS documentation, not on the expectation of a ready-made Article 50 pack.

Article 73 in plain language

The tiered reporting deadlines

Article 73 of the EU AI Act (Regulation (EU) 2024/1689) imposes serious-incident reporting obligations on providers of high-risk AI systems. The deadline to report depends on the severity and type of incident:

DeadlineIncident type
2 daysWidespread infringement; serious and irreversible disruption of the management or operation of critical infrastructure
10 daysIncidents where a death may be caused by the AI system
15 daysOther serious incidents (general rule)

Reports go to the relevant Member State's market surveillance authority. Under the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), Annex III high-risk obligations including Article 73 apply from 2 December 2027. Administrative fines reach €15 million or 3% of worldwide annual turnover, whichever is higher, for Article 73 violations.

Guidance status

The European Commission published draft serious-incident reporting guidance on 26 September 2025; the consultation closed 7 November 2025. With the Omnibus-driven shift in the Article 73 application date to 2 December 2027, the timeline for final Commission guidance is expected to adjust correspondingly. The toolkit's 24-month update window covers material changes when final guidance issues.

How the toolkit implements Article 73

Starter tier, AIMS-22 Incident Response Procedure

The AIMS-22 artefact in the Starter tier implements the tiered reporting structure directly:

Professional tier, PRO-AnnexA-08 deep-dive

The Professional tier extends AIMS-22 with PRO-AnnexA-08_Information.docx, which covers Annex A.8 information-security and incident-handling controls in depth. The deep-dive adds:

Who Article 73 applies to

The reporting obligation falls on providers of high-risk AI systems placed on the EU market, including providers established outside the EU whose systems are used by EU-established deployers or whose output affects people in the EU.

"High-risk" is defined by Annex III of the EU AI Act, covering eight domains: biometric identification; critical infrastructure; education; employment; access to essential private and public services; law enforcement; migration and border management; and administration of justice. For detailed classification guidance, see our sister site euaiactchecklist.com.

Four-Way Crosswalk, the full regulatory map

The Professional tier's PRO-Four_Way_Crosswalk.docx maps every ISO 42001 clause and Annex A control to: (1) ISO 27001:2022, (2) NIST AI RMF 1.0, (3) EU AI Act. Article 73 specifically appears in the crosswalk under:

For providers pursuing both ISO 42001 certification and EU AI Act compliance, the crosswalk means you build one evidence base that satisfies both frameworks.

Related: the GPAI Code of Practice

General-Purpose AI model providers have had separate obligations live since 2 August 2025. Models released before 2 August 2025 must comply by 2 August 2027. Our Four-Way Crosswalk (Professional tier) includes maintenance notes on the GPAI Code of Practice so organisations maintaining foundation models can trace applicable obligations.

Article 73 reporting obligations are complex and fact-specific. This page summarises the toolkit's implementation of Article 73 requirements but does not constitute legal advice. The Digital Omnibus was adopted by the European Parliament on 16 June 2026 (423-57); only formal Council adoption and Official Journal publication remain. The new dates are the operative planning baseline. Consult qualified EU counsel and the final Commission guidance for compliance decisions.

Article 27 requires a FRIA

Most organisations produce one that reads well and would not survive scrutiny. Here is a free starter that would.

Free. No sales call. Unsubscribe whenever.