Skip to main content
Notifications
You're all caught up.
View all notifications
Backsplice
  • Product
  • Watney AI
  • Why us
  • Pricing
  • Docs
  • Security
  • About
  • Log in
  • Start your demo
Log in Start your demo
← Docs
← All documentation

AI Incidents

The incident register records what went wrong with AI: harmful or inaccurate output that reached someone, a biased outcome, an attack such as a jailbreak or prompt injection, data exposed through an AI tool, a system that drifted, or AI used without approval. Recording each incident, and the system it involved, is how a problem becomes a fix and how the system's approvers learn what has happened.

The register is for organization administrators: it can describe harm to people and name personal data, so contributors and auditors do not see it. A system's approvers see a summary of its incidents on its Approval page (title, type, severity, status, whether it is serious, and when it was found), without the timeline, notes or what was sent to an authority.

An incident record

  • Type: harmful output, inaccurate output, biased outcome, performance degradation or drift, misuse or attack, data exposure, safety harm, impact on people's rights, AI used without approval, outage, or other.
  • Severity: low, medium, high or critical.
  • AI system and model involved, if any. An incident about a tool that was never approved may have no system in the registry yet; record it anyway.
  • Discovery date: when your organization became aware of it.
  • Personal data involved, and people affected. Leave people affected blank while you do not yet know: blank means not yet known, which is different from none, and the register shows it that way.
  • Status: open, under review, resolved, or reported to an authority. A new incident starts open or under review, and is triaged (under review) before it can be resolved or reported. Marking it reported needs the time the authority was notified.
  • Timeline and investigation notes: how it was detected and contained, the root cause, and the corrective action.

Serious incidents and authorities

Mark an incident serious when your organization has judged it to be a serious incident under a law that applies to it. The EU AI Act, for example, defines serious incidents and requires providers of high-risk AI systems to report them; whether that duty falls on your organization depends on its role. For how bad an incident is in your own terms, use Severity. Record when an authority was notified, in your organization's time zone, and what was sent (authority notes).

Whether you must tell an authority, and by when, depends on the laws that apply to your organization. Backsplice records what you decide and when you acted, and this is not legal advice. Ask your legal or compliance team as soon as an incident might be serious.

The EU AI Act reporting deadline (Article 73)

Article 73 of the EU AI Act sets reporting deadlines for providers of high-risk AI systems. A deployer must immediately inform the provider, then the importer or distributor and the market surveillance authorities (Article 26(5)). Article 73's deadlines apply to a deployer that cannot reach the provider. Backsplice shows that deadline on an incident when all of these are recorded:

  • the incident is marked serious;
  • its AI system is classed high-risk (Annex I or Annex III), and is not an Annex I Section B product (Article 2(2), as amended, leaves those outside Chapter III);
  • your organization is recorded as the system's provider or deployer;
  • the system has a link to the EU.

The deadline counts from when your organization became aware of the serious incident: 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure, 10 days for a death, and 15 days otherwise. Each deadline is a latest date; Article 73 requires the report immediately. While the category is not yet known, the shortest period (2 days) is shown. If you leave Became aware at blank, the discovery date is used; it is earlier, so it shortens the deadline.

Article 73(5) allows an initial report that is incomplete, followed by a complete report, where necessary to ensure timely reporting. Record when you submitted it (Initial report sent at); the deadline is shown as met from the earlier of that and Authority notified at. A deployer also records when it informed the provider (Article 26(5): immediately).

For each class, the high-risk rules apply from a set date: 2 December 2027 for Annex III and 2 August 2028 for Annex I (Regulation (EU) 2026/1744). For an incident before that date, the deadline is shown for readiness and marked as not yet in force on this service's reading of Articles 111(2) and 113, as amended; confirm with counsel. The people on the incident and the system's owners are reminded at the halfway point and on the due day, and the dashboard lists every serious incident still awaiting a report.

Whether Article 73 applies to an incident is a legal judgment for your organization. The category definitions on the form quote the Regulation. This is not legal advice.

From an incident to the system

Open an AI system's page to see the incidents recorded against it, and use Log an incident with this system to start one with the system already chosen. An incident is part of the system's history: a system with incidents cannot be deleted, only retired.

Score and exports

Incidents left open or under review for more than 30 days lower the Incident Response dimension of the compliance score. The register exports as CSV and PDF, with the same filters as the screen.

Backsplice

Governance for the AI systems your organization builds, buys and runs.

NIST AI RMF 1.0 NIST AI 600-1 (Generative AI Profile)

View our security posture →

Product

  • Why Backsplice
  • Frameworks
  • Watney AI
  • Review & Approval
  • Governance Registers
  • Reporting
  • Integrations & API
  • Pricing

Company

  • About Us
  • Team
  • Mission
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • Documentation
  • Blog
  • Status Page

© 2026 Backsplice LLC. All rights reserved.

Backsplice provides tools to run an AI governance program; it does not confer compliance with any law or standard and does not constitute legal advice. Consult qualified legal counsel for specific compliance guidance.