Reporting problems
Why reports do not come in, what a reporting route people actually use looks like, and what to do in a serious incident.
Why reports do not come in
- The route is cumbersome: a form with twelve mandatory fields.
- It is unclear what is even worth reporting.
- Whoever reports gets the rework.
- Nothing happens, and the next report never comes.
- It could be read as one's own failure.
All five are organisational and none technical. A reporting route gets used because of how it is built, not because people are asked to use it.
A reporting route that works
- 01
Three fields
What happened, where, and what it should have said. Nothing more.
- 02
At the point where it is noticed
A button beside the result, not a form on the intranet.
- 03
A response within a week
Even where it says: known, will be fixed in the next version.
- 04
Expressly without consequence
In writing, from leadership, and honoured in practice.
Reporting duties under the AI Act
Deployers of high-risk systems inform the provider and, depending on the case, the market surveillance authority about serious incidents. Providers report immediately after establishing the causal link, at the latest within the prescribed deadlines.
| Case | Deadline |
|---|---|
| Serious incident, general | immediately, at the latest 15 days after becoming aware |
| Widespread infringement or serious disruption of critical infrastructure | at the latest 2 days |
| Death of a person | at the latest 10 days |
These deadlines belong documented before the event. Once it happens there is no time left to look them up.
What else can be reportable
- Personal data breach. Art. 33 GDPR, to the supervisory authority within 72 hours, to data subjects where the risk is high.
- ICT incident. For financial entities under DORA, with its own deadlines and reporting formats.
- Product safety. Where the system is part of a product.
- Professional conduct rules. For breaches of confidentiality, to the competent bar or chamber.
The deadlines run in parallel and start at different moments. Sorting them out only once an event is under way means missing the shortest.
The internal sequence
- 01
Record and classify
Within 24 hours: which case, what scope, which deadlines are running.
- 02
Bound it
Determine the affected period and scope from the logs.
- 03
Immediate measure
Switch off, roll back, or raise the review rate. Documented.
- 04
Report
Along the running deadlines, to every competent body.
- 05
Follow up
Cause, lasting measure, and what delayed detection.
The last point is the most valuable and the most frequently skipped.
Related courses and sources
Austrian Data Protection Authority
The competent supervisory authority for Austria, with forms, decisions and guidance on reporting breaches.
For controllers in Austria: the competent authority for notifications and enquiries.