The EU AI Act just gave you a breach notification clock you didn’t know about
Article 73 of the EU AI Act has taken effect, establishing an incident response deadline—requiring high-risk AI providers to report serious incidents within 15 days by default, or as few as two days for critical disruptions—even while other high-risk requirements are deferred to December 2027. Unlike traditional cybersecurity breach notifications triggered by unauthorized system access, this rule triggers when an organization suspects an indirect causal link between an uncompromised AI system's outputs and downstream harms or rights infringements. This regulatory shift forces legal, compliance, and cybersecurity leaders to redesign governance structures and incident response playbooks to trace model outputs to real-world impacts.
Read the original at cio.com Generate teaching or study materials
More in Corporate Law
- Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedentThe Register · September 15, 2026
- Open weights are not open source: Why AI's favorite label is under disputeThe Register · September 15, 2026
- RubyGems say OpenAI agents responsible for undisclosed swarm attack against its infrastructureTechRadar · September 15, 2026
- Using AI for Weapons DevelopmentSchneier on Security · September 15, 2026
- Microsoft commits to sweeping AI privacy rules for students. Will other tech giants follow?Phys.org — Technology · September 15, 2026