AI Compass
Compass

Reporting problems

Why reports do not come in, what a reporting route people actually use looks like, and what to do in a serious incident.

·2 min read·By Redaktion KI-Kompass
DETAIL
2 sections

Why reports do not come in

  • The route is cumbersome: a form with twelve mandatory fields.
  • It is unclear what is even worth reporting.
  • Whoever reports gets the rework.
  • Nothing happens, and the next report never comes.
  • It could be read as one's own failure.

All five are organisational and none technical. A reporting route gets used because of how it is built, not because people are asked to use it.

A reporting route that works

  1. 01

    Three fields

    What happened, where, and what it should have said. Nothing more.

  2. 02

    At the point where it is noticed

    A button beside the result, not a form on the intranet.

  3. 03

    A response within a week

    Even where it says: known, will be fixed in the next version.

  4. 04

    Expressly without consequence

    In writing, from leadership, and honoured in practice.

Reporting duties under the AI Act

Deployers of high-risk systems inform the provider and, depending on the case, the market surveillance authority about serious incidents. Providers report immediately after establishing the causal link, at the latest within the prescribed deadlines.

CaseDeadline
Serious incident, generalimmediately, at the latest 15 days after becoming aware
Widespread infringement or serious disruption of critical infrastructureat the latest 2 days
Death of a personat the latest 10 days

These deadlines belong documented before the event. Once it happens there is no time left to look them up.

What else can be reportable

  • Personal data breach. Art. 33 GDPR, to the supervisory authority within 72 hours, to data subjects where the risk is high.
  • ICT incident. For financial entities under DORA, with its own deadlines and reporting formats.
  • Product safety. Where the system is part of a product.
  • Professional conduct rules. For breaches of confidentiality, to the competent bar or chamber.

The deadlines run in parallel and start at different moments. Sorting them out only once an event is under way means missing the shortest.

The internal sequence

  1. 01

    Record and classify

    Within 24 hours: which case, what scope, which deadlines are running.

  2. 02

    Bound it

    Determine the affected period and scope from the logs.

  3. 03

    Immediate measure

    Switch off, roll back, or raise the review rate. Documented.

  4. 04

    Report

    Along the running deadlines, to every competent body.

  5. 05

    Follow up

    Cause, lasting measure, and what delayed detection.

The last point is the most valuable and the most frequently skipped.

Related courses and sources

ArticleFreeDE

Austrian Data Protection Authority

The competent supervisory authority for Austria, with forms, decisions and guidance on reporting breaches.

For controllers in Austria: the competent authority for notifications and enquiries.

Was this page helpful?
Reporting problems