1. Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred.
2. The report referred to in paragraph 1 shall be made immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link, and, in any event, not later than 15 days after the provider or, where applicable, the deployer, becomes aware of the serious incident.
The period for the reporting referred to in the first subparagraph shall take account of the severity of the serious incident.
3. Notwithstanding paragraph 2 of this Article, in the event of a widespread infringement or a serious incident as defined in Article 3, point (49)(b), the report referred to in paragraph 1 of this Article shall be provided immediately, and not later than two days after the provider or, where applicable, the deployer becomes aware of that incident.
4. Notwithstanding paragraph 2, in the event of the death of a person, the report shall be provided immediately after the provider or the deployer has established, or as soon as it suspects, a causal relationship between the high-risk AI system and the serious incident, but not later than 10 days after the date on which the provider or, where applicable, the deployer becomes aware of the serious incident.
5. Where necessary to ensure timely reporting, the provider or, where applicable, the deployer, may submit an initial report that is incomplete, followed by a complete report.
6. Following the reporting of a serious incident pursuant to paragraph 1, the provider shall, without delay, perform the necessary investigations in relation to the serious incident and the AI system concerned. This shall include a risk assessment of the incident, and corrective action.
The provider shall cooperate with the competent authorities, and where relevant with the notified body concerned, during the investigations referred to in the first subparagraph, and shall not perform any investigation which involves altering the AI system concerned in a way which may affect any subsequent evaluation of the causes of the incident, prior to informing the competent authorities of such action.






Organisaation olisi laadittava ja dokumentoitava menettely, jolla hallitaan ja raportoidaan vakavista vaaratilanteista, jotka liittyvät sen suuren riskin tekoälyjärjestelmiin. Menettelyllä olisi varmistettava oikea-aikainen viestintä markkinavalvontaviranomaisten kanssa.
Menettelyyn olisi sisällyttävä






Organisaation olisi pidettävä kirjaa kaikista vakavista vaaratilanteista, jotka liittyvät sen suuren riskin tekoälyjärjestelmiin. Tässä rekisterissä olisi dokumentoitava vaaratilanteen yksityiskohdat, suoritettu tutkinta, viranomaisille toimitetut raportit ja korjaavat toimet, jotka on toteutettu ongelman ratkaisemiseksi ja tulevien tapausten estämiseksi.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)