Glossary · term

AI incident reporting

AI incident reporting is the structured notification of an event in which an AI system caused, contributed to, or created a defined risk of harm. A report commonly identifies the system, event, impact, timeline, reporter, and response. Reporting can be voluntary, contractual, or legally required; who must report, what qualifies, to whom, and by when depend on the governing scheme.

Regulation2020-11-18Wave 2 · 2024Maturity: 5/5

Origin and context

Partnership on AI launched a public AI Incident Database in November 2020, inviting incident submissions and drawing on aviation and cybersecurity practice. The EU AI Act later enacted serious-incident reporting for specified high-risk AI providers. In February 2025, the OECD published a 29-criterion common reporting framework intended to support comparison while allowing jurisdictional variation. California's SB 53 subsequently used the narrower phrase critical safety incident for covered frontier-model developers.

Sources: s1, s2, s3, s4

Why it matters

Pre-deployment tests cannot anticipate every interaction between a system, its users, and its operating environment. Consistent reports can reveal recurring failure patterns, support investigation and corrective action, and help authorities or industry groups compare events. Reporting duties also assign operational responsibilities after deployment. The mechanism works only if scope, thresholds, confidentiality, and follow-up are clear; a large database of inconsistent reports may be informative without being legally complete or statistically representative.

Sources: s1, s2, s3, s4

Example

Suppose a covered high-risk system contributes to a serious injury. Under an applicable regime, the provider may need to assess whether the legal incident definition and causal threshold are met, notify the named authority within the relevant deadline, and submit follow-up information. Sending the same event to a voluntary public database can support shared learning, but it does not automatically satisfy a statutory notice and may require different disclosure handling.

Sources: s1, s2, s3

How it differs

EU AI Act

Article 73 of the EU AI Act is one legal implementation for defined high-risk systems. AI incident reporting is the broader practice and also includes voluntary databases, sectoral rules, and other jurisdictions. The Act's actors, causal thresholds, authority, and deadlines should not be exported to every incident scheme.

Maturity and evidence

Maturity is rated 5 because serious-incident reporting is enacted in the EU AI Act and critical-safety-incident reporting is enacted in California law. This rating reflects legal codification, not harmonization or proven effectiveness. Voluntary and mandatory systems still use different taxonomies, thresholds, recipients, and disclosure rules, which the OECD framework seeks to make more comparable.

Sources: s2, s3, s4

Limits and open questions

Incident counts cannot be read as prevalence without knowing coverage, reporting incentives, duplication, and selection effects. Legal analysis must use the current official text for the relevant system, actor, place, and date. Incident reporting is also distinct from vulnerability disclosure, whistleblowing, continuous monitoring, and an internal postmortem. Reports may contain personal, proprietary, security-sensitive, or legally privileged information requiring controlled handling.

Sources: s1, s2, s3, s4

Related terms

References

Last updated: 2026-09-07

In the Skills Atlas

This term is also covered in the Skills Atlas as ai risk management skill.