Incident Management
AI Incident Escalation and Notification
What this control does
Detect, triage and escalate serious AI incidents and relevant risk conditions within required timelines.
How to implement
Give staff a clear way to report suspected serious AI incidents and relevant risk conditions. Assign a response lead and record when the organization became aware of the issue. Determine the actor, system and applicable notification route, then contact the required parties within the relevant timescale. For deployers, distinguish provider-first serious-incident escalation from the risk-and-suspension route. Use the High-Risk AI Serious Incident Reporting control for the high-risk provider reporting procedure. Real-world testing also has immediate mitigation, suspension or termination duties; its incident reporting follows the applicable statutory route. Protect evidence and track follow-up rather than waiting for a complete investigation before escalating.
Suggested timing and triggers
On incident or relevant risk detection; immediately or within the applicable legal deadline; periodic exercises set by the organization.
Evidence examples
Incident intake record with awareness time Actor-specific escalation matrix and current contacts Classification, notification and suspension decisions Transmission records and response actions Exercises, findings and corrective follow-up
How to check this control
Walk through a realistic incident scenario with the response team. Check that they can identify the required route and contact sequence. Review an actual incident where available, including the recorded awareness time and response evidence.
Related EU AI Act obligations
Article 17(1)(g)-(i)
Integrate Risk Management, Post-Market Monitoring and Serious Incident Reporting Into the QMS
Sub-obligation of Article 17; Article 63(1)-(2): Maintain a Quality Management System for High-Risk AI
Article 26(5)
Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Article 26(5), first subparagraph
Immediately Report Identified Serious Incidents Involving High-Risk AI
Sub-obligation of Article 26(5): Monitor High-Risk AI Operation and Escalate Risks or Serious Incidents
Article 60(7)
Mitigate Serious Incidents During Real-World Testing and Maintain a Recall Procedure
Sub-obligation of Article 60: Conduct High-Risk AI Real-World Testing Only Under the Article 60 Conditions