AI Governance, Risk & Red Teaming
Strategic · M10 · lesson 10 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Article 73 Serious-Incident Reporting Tabletop Drill, 15-Day Clock Live-Fire
📖
now learning

Article 73 Serious-Incident Reporting Tabletop Drill, 15-Day Clock Live-Fire

15 min

On a Monday morning in May 2026, the AI Governance Committee chair at Acme Inc opens the quarterly meeting with a slide that has one sentence on it: "We have an Article 73 obligation to report a serious incident within 15 days of awareness, 2 days if widespread. Can we prove we can execute under pressure? Show me the After-Action Report." The room is quiet for a moment. The CRO looks at the CAIO. The CAIO looks at the CISO. The Red Team Lead looks at the General Counsel. The honest answer comes back from the Trust & Safety lead: "We haven't drilled it. We have the policy from lesson 088. We have the runbook. We have not run a tabletop where someone started a clock and forced the team to file a mock report." The chair closes the laptop. "Then we have a project. We are running the drill in 30 days. I want the AAR on the next agenda." This lesson is the project plan. It is the L4 leadership-tier artifact, the five-stage tabletop drill design, the five sample scenarios, the participant roster, the fifteen-decision inventory, the After-Action Report template, the common failure catalogue, and the cadence, that turns Article 73 readiness from a paragraph in a policy into a live-fire exercise the AIGC can sign and the ISO 42001 Stage 2 surveillance auditor can verify.

Why a Tabletop Drill in 2026 - Three Reasons the Real Test Cannot Be the First Test

Every Article 73-readiness program at Acme-class scale already has the policy (the lesson 087 artifact) and the runbook (the lesson 088 artifact). Most programs stop there. The argument for why the tabletop drill is not optional has three parts in 2026, and each is regulator-defensible on its own.

First, Article 73 mandates serious-incident reporting within 15 days of provider awareness, 2 days if widespread per Article 3(50), and the clock does not wait for the AI Governance Committee to schedule its first incident review meeting. The clock starts the moment the provider becomes aware of the causal link between the AI system and the harm under Article 3(49)(a)-(d). In a first-incident environment with no drill history, the first ninety minutes of the clock are typically consumed by people asking each other "is this an Article 73 incident, who decides, and who notifies the Member State market surveillance authority?", and those ninety minutes are unrecoverable. A program that has drilled the workflow knows within thirty minutes who declares, who notifies the AIGC chair, and who starts drafting. A program that has not drilled finds out at the worst possible moment that the Communications lead is not in the escalation tree, that the General Counsel is on vacation, that the MSA portal credentials are with a person who left the company in March, and that nobody is sure whether Article 3(49)(a) "serious harm to health" includes the hospitalization of a single customer.

Second, ISO 42001 Stage 2 surveillance audit explicitly expects tabletop evidence under control A.6.2.7 (incident management) and clause 9 (performance evaluation). The Stage 1 readiness review verified the policy existed; the Stage 2 surveillance audit verifies the policy is operating. Auditors ask for the After-Action Report from the most recent tabletop, the corrective-action register from gaps identified, and evidence that corrective actions were closed before the next drill. A program with no AAR fails this control. A program with an AAR but no corrective-action follow-through fails it more visibly. The pattern is consistent across ISO 42001 audit reports issued in Q1 2026: the surveillance auditors do not ask whether a tabletop happened; they ask for the dated AAR and the closed corrective actions.

Third, EU AI Act competent authority readiness drills are a 2026 reality. The European AI Office and several national market surveillance authorities (BSI in Germany, AGID in Italy, ACPR-coordinated AI authorities in France) have announced that they will run market-surveillance readiness exercises with selected high-risk providers. The notice period for such an exercise is short, days, not weeks. A provider that has not run its own tabletop has no way to predict how it will perform under a real regulator-driven exercise. The cost-benefit calculus is settled: an internal tabletop costs €15-50k in opportunity time; a failed regulator drill costs reputation, additional scrutiny, and, if the provider misses the real Article 73 clock during or after the exercise, Article 99(3) penalty exposure at €15M / 3% of global turnover.

The conclusion the AIGC chair reaches is straightforward: the tabletop drill is the only defensible way to prove the organization can execute Article 73 under pressure. The next sections describe how to design it.

Five-Stage Drill Design - From Pre-Drill Setup to After-Action Report

A defensible tabletop drill is not a meeting. It is a five-stage exercise that runs from T-30 days to T+14 days, with a compressed live-execution window inside it. The five stages are non-negotiable; skipping any one of them produces a drill the surveillance auditor will not credit.

Stage 1 - Pre-Drill Setup (T-30 to T-1 days)

Pre-drill setup is the planning phase. The AIGC chair or designated drill director chooses the scenario from the library (see next section); the participant list is locked; the date and time window are notified to participants without disclosing the scenario; observers from internal audit and (for surveillance-audit-readiness drills) the ISO 42001 lead auditor are invited; success criteria are defined and signed by the AIGC chair. Success criteria typically include: Article 3(49) determination within four hours of injection; AIGC chair notification within thirty minutes of determination; mock report drafted and submitted (to a controlled inbox, not the real MSA) within the applicable clock; fifteen-decision inventory captured with timestamps. Pre-drill setup ends with a signed drill charter retained in the AAR dossier.

Stage 2 - Scenario Injection (T-0)

Scenario injection is the moment the clock starts. Injection happens via a simulated channel matched to the scenario: a mock email to the AIGC chair from the Trust & Safety lead reporting an anomaly, a mock phone call to the red team lead reporting an attacker disclosure, a fake user-complaint volume spike rendered into the actual complaint dashboard, or a mock vendor advisory rendered into the actual security intake queue. The injection is unannounced to the participants; the observers know it is the start. The clock is started on a public timer visible to the observers but not (yet) to the participants. The injection artifact (the email, the call transcript, the dashboard snapshot) is captured in the AAR dossier as evidence the drill happened.

Stage 3 - Live Execution (T+0 to T+4 hours compressed; representing T+0 to T+15 days real)

Live execution is the heart of the drill. Participants execute the lesson 088 runbook: detection, triage, containment, Article 3(49) determination, AIGC chair notification, CRO notification, mock report drafting, fifteen-decision inventory. Observers shadow each role and capture timestamps, decisions made, decisions deferred, and gaps surfaced. Real-time compression is the design choice: a four-hour live window represents the fifteen-day clock, with the observer announcing checkpoints ("we are now at T+24 hours real time," "we are now at T+72 hours," "we are now at T+10 days," "we are now at T+15 days, clock about to expire"). At each checkpoint, the participants must declare what they have done, what they will do next, and what they would have done by the real clock. The mock report is filed to the controlled inbox at the equivalent real-time clock point. Live execution ends at T+4 hours drill time with the mock report filed.

Stage 4 - Hot-Wash (T+4 to T+6 hours)

Hot-wash is the immediate retrospective. While memory is fresh, the observers walk the participants through the timeline they captured. Three questions structure the hot-wash: what worked, what didn't, what surprised. Hot-wash captures candor that the formal AAR will lose; participants who would not write "I didn't know who to call" in a formal document will say it in the hot-wash room. The hot-wash is recorded (audio, with consent) for the AAR drafter. Hot-wash ends with each participant naming one gap they personally observed and one corrective action they personally commit to drive.

Stage 5 - After-Action Report (within 14 days)

The After-Action Report is the formal artifact. It is drafted within 14 days by the drill director, reviewed by the AIGC, signed by the AIGC chair, and retained per Article 18 (typically 10 years). The AAR uses the eight-section template described later in this lesson. Corrective actions are entered into the program's corrective-action register with named owners and dated commitments. The AAR is the ISO 42001 A.6.2.7 evidence artifact and the EU AI Act Article 72 + 73 readiness evidence artifact. A program that runs Stages 1-4 but never formalizes the AAR has done a workshop, not a drill.

Five Sample Tabletop Scenarios - One per Article 3(49) Sub-Criterion Plus a Widespread Case

A program that drills the same scenario every year produces the same lessons every year. A program that rotates across Article 3(49) sub-criteria builds breadth. The five scenarios below are the canonical 2026 rotation; the first four map one-to-one to Article 3(49)(a)-(d), the fifth covers the Article 3(50) widespread case with the 2-day clock.

Scenario 1 - Healthcare-Adjacent Hallucination (Article 3(49)(a))

The injection: a Trust & Safety lead receives 47 customer complaints over a 72-hour window indicating that Acme.ServiceAssist (the customer-facing GenAI assistant) provided incorrect medication-interaction information. One customer, an 82-year-old with a chronic condition, was hospitalized after acting on an Acme.ServiceAssist response that recommended doubling a dose. The hospital has issued a preliminary statement linking the hospitalization to the AI-provided guidance. The scenario forces Article 3(49)(a) "serious harm to health" determination, Article 26(4) deployer-side coordination if the provider is upstream, GDPR Article 33 health-data implications, and a public-disclosure decision. The clock per Article 73 is 15 days; per the Commission draft template, where death is involved or imminent, the 10-day clock may apply. The drill tests whether the team can determine within four hours that Article 3(49)(a) is in play and that the 15-day clock has started running.

Scenario 2 - Critical-Infrastructure Prompt Injection (Article 3(49)(b))

The injection: an agent operating in the energy-sector deployer environment (Acme is the provider; the deployer is a regional grid operator) has been compromised via indirect prompt injection embedded in a vendor-supplied document fed into the agent's RAG context. The compromised agent issued an incorrect automated rebalancing instruction at 03:47 UTC; the deployer's safety interlocks caught it before grid impact occurred, but the deployer has notified Acme under Article 26(4) and characterized the event as a near-miss-but-reportable due to the criticality of the infrastructure. The scenario forces Article 3(49)(b) "serious and irreversible disruption of critical infrastructure" determination against the safety-interlock save, NIS2 Article 23 cyber-incident overlap analysis, the 2-day clock if widespread, and coordination with the deployer's CSIRT. The drill tests the team's analysis of "the harm was averted by the safety control, is this still an Article 73 incident?" (Conservative answer: report it; a regulator-favorable posture is over-report not under-report.)

Scenario 3 - Fundamental-Rights Breach via Fairness Disparity (Article 3(49)(c))

The injection: a third-party fairness researcher publishes an analysis showing that the Acme credit-scoring agent (Annex III §5(b) high-risk credit-worthiness system) systematically denies loans to a protected class at 2.4× the rate of the reference class, controlling for income, employment, and credit history. The researcher emailed the AIGC chair and the DPO simultaneously, gave Acme 14 days before publication, and is now publishing. The deployer is a major retail bank in three Member States. The scenario forces Article 3(49)(c) "infringement of obligations under Union law intended to protect fundamental rights" determination, Charter and Race Equality Directive analysis, GDPR Article 9 special-categories analysis, Annex III §5(b) substantial-modification analysis (does the model fix itself constitute a substantial modification triggering Article 43(4)?), and an FRIA refresh under Article 27. The Article 73 clock is 2 days if the disparity is "widespread" per Article 3(50) and 15 days otherwise. The drill tests the team's determination of widespread vs single-instance and the speed of FRIA refresh.

Scenario 4 - Property Damage via Agent Tool Misuse (Article 3(49)(d))

The injection: the autonomous procurement-agent deployed in the Acme Finance organization (an internal agentic system with tool-allowlist for ERP vendor lookup and purchase-order issuance) executed €4.2 million in unauthorized vendor purchases over a 48-hour window before the budget-tripwire fired. Root cause is preliminarily an LLM06 over-reliance failure combined with an ASI04 unbounded-resource-consumption failure: the agent interpreted an ambiguous internal instruction as authorization for end-of-quarter purchases and executed against a vendor list it had partial allowlist authority for. The scenario forces Article 3(49)(d) "serious harm to property" determination, Article 26 deployer obligation, internal financial-reporting implications (SOX Section 302 disclosure controls), Article 17 quality-management-system review, and external counsel engagement. The Article 73 clock is 15 days. The drill tests whether the team frames this as "internal financial loss" (and therefore non-reportable) or "serious harm to property" within Article 3(49)(d) scope (and therefore reportable). The defensible answer in 2026: report it; document the property-damage analysis; do not rely on an "internal only" carve-out the Article does not provide.

Scenario 5 - Widespread Incident, Foundation-Model Upstream Change (Article 3(50) Widespread + 2-Day Clock)

The injection: the foundation-model provider pushed a Tuesday-night model update that cascaded through 1,200 enterprise deployers simultaneously, materially degrading the safety-filter performance on a class of inputs. Acme is one of the 1,200 deployers; the foundation-model provider issued an Article 25(2) upstream-provider notice at 08:14 UTC; the deployer-side first-detection at Acme was 07:51 UTC (twenty-three minutes earlier) through internal red-team monitoring. The scenario forces Article 3(50) "widespread" determination, the 2-day clock, Article 25(2) upstream-provider coordination, Article 86 affected-party notification analysis, Annex XII deployer notification analysis, and coordination of public-statement timing with the foundation-model provider's own disclosures. The drill tests two distinct things: (a) can the team determine "widespread" under Article 3(50) within four hours; (b) can the team coordinate a multi-deployer disclosure without saying something inconsistent with the foundation-model provider's own statement. The 2-day clock makes both questions urgent.

Drill Participants and the Fifteen-Decision Inventory

A defensible drill has both the right people in the room and a structured way to capture what they decide. The participant roster and the fifteen-decision inventory together turn a workshop into a measurable exercise.

Participants by Role

The minimum participant roster for a tier-1 system drill is: AIGC chair (drill convener); CRO (risk-tolerance owner); CAIO (technical owner); CISO (cyber-incident overlap owner); Red Team Lead (technical analysis owner); DPO (GDPR / Charter / fundamental-rights advisor); General Counsel (Article 73 reporting decision owner with the CAIO); Communications lead (public-statement readiness owner); the system owner for the in-scope AI system; the AI Risk Office liaison (3LoD coordination); and, for tier-1 drills involving regulators, External Counsel pre-engaged on retainer. For Stage 2 surveillance-audit-readiness drills, the ISO 42001 lead auditor is invited as observer (not participant); for high-risk-system drills where the notified body has surveillance responsibility, the notified-body relationship manager is informed in advance. Observers from internal audit (3LoD) shadow the drill and produce an independent observation report appended to the AAR.

Fifteen-Decision Inventory - What Observers Capture with Timestamps

The fifteen decisions below are the structured capture set. Every observer carries the inventory; every decision is timestamped; the inventory becomes the spine of the AAR.

  1. Article 3(49) yes/no determination within four hours of injection. Who decides, what evidence, what sub-criterion (a/b/c/d).
  2. AIGC chair notification timestamp. Goal: within 30 minutes of determination.
  3. CRO notification timestamp. Goal: within 30 minutes of AIGC notification.
  4. Containment-action selection. What containment is invoked, rollback, tool disable, RAG isolation, traffic shedding, account freeze, and on what authority.
  5. Article 73 report drafting start timestamp. Goal: within 2 hours of determination.
  6. Annex XII deployer notification yes/no. For provider-side incidents where deployers must be informed.
  7. Article 25(2) upstream-provider notification yes/no. For incidents where the GPAI upstream is implicated.
  8. Article 86 affected-party notification yes/no. For incidents where individual affected parties have a right to explanation under Article 86.
  9. External counsel engagement decision. Was it engaged, when, on what authority, what mandate.
  10. Public-statement decision. Issue, hold, or coordinate with deployer / upstream; if issue, what content.
  11. Regulator pre-call decision. Was a pre-call with the MSA initiated before formal report submission.
  12. Report submission timestamp vs the applicable clock. Did the mock report hit the 2-day / 15-day window.
  13. Follow-up investigation plan within 90 days. Was a 90-day follow-up plan committed and assigned.
  14. Board AI subcommittee notification. Was the board AI subcommittee chair notified, and when.
  15. AIRA breach assessment. Was the AI Risk Appetite breach analysis performed, what KRI crossed, what tolerance band, and is a board-level breach-disclosure required.

Observers capture each decision's actor, timestamp, evidence, and any deferrals or open questions. A drill that captures all fifteen with timestamps produces an AAR with concrete data; a drill that captures "discussion happened" produces an AAR the surveillance auditor will discount.

AAR Template, Common 2026 Failures, and Drill Cadence

The After-Action Report and the failure catalogue are the two artifacts the AIGC and the auditor read most carefully. Both deserve template-level discipline.

After-Action Report - Eight-Section Template

  1. Scenario summary. Which scenario from the library, key facts injected, design intent.
  2. Timeline. T-0 injection through T+4h hot-wash end, with each fifteen-decision-inventory timestamp.
  3. Decisions captured. All fifteen decisions with actor, timestamp, evidence, deferrals.
  4. Gaps identified. Specific, named gaps, not "Communications was slow" but "Communications lead was not in the on-call rotation tree on the drill date and learned of the drill 47 minutes after injection."
  5. Corrective actions. Each gap mapped to a corrective action with named owner, dated commitment, success criterion, and verification mechanism. Entered into the program's corrective-action register.
  6. Recommendations. Forward-looking program changes: policy edits, runbook edits, training requests, tool requests, vendor escalations.
  7. AIGC sign-off. Dated signature of the AIGC chair confirming the drill happened, the gaps are accepted, the corrective actions are agreed.
  8. Re-drill schedule. Date of the next drill, which scenario, named gaps the next drill must verify closed.

Common 2026 Tabletop Drill Failures

Eight failure modes recur in 2026 AAR reviews and ISO 42001 surveillance findings.

  • Treating the drill as a check-the-box exercise. Participants attend, talk through scenarios in the abstract, do not actually exercise the runbook. AAR is glossy. Auditor sees no decisions, no timestamps, no gaps closed.
  • Participants gaming the scenario. The senior leaders in the room steer the discussion toward favorable narratives ("we would have determined Article 3(49) immediately, we have great processes"). Observer's report shows the actual analysis took ninety minutes longer than claimed. The AAR must be the observers' AAR, not the participants' self-assessment.
  • No AAR formalization. Hot-wash happens, notes go into a shared doc, nothing is ever signed. The control fails the next surveillance audit.
  • No follow-up corrective actions tracked. Gaps are listed in the AAR, no owner, no date, no verification. Next drill repeats the same gaps.
  • No public-statement coordination. The drill focuses on the report to the MSA and ignores the equally hard problem of what the company says publicly. Lesson 090 (the next lesson) is the public-disclosure runbook; the drill must exercise its activation.
  • Article 3(49) determination skipped or rushed. Teams assume "yes, it's serious" without working through which sub-criterion and which clock. AAR shows determination but cannot defend the sub-criterion choice.
  • Clock not actually started. The observer says "the clock is running" but the drill participants never look at the clock visibly. Participants finish the drill not knowing whether they hit the window. AAR has to reconstruct from timestamps after the fact.
  • No integration with cyber tabletop drills. The AI tabletop and the cyber tabletop are run on different days with different participants and different scenarios; in reality, AI incidents and cyber incidents overlap (Scenario 2 is the canonical example). The integrated drill, AI + cyber, with the CISO and CAIO both leading, is the 2026 best-practice pattern.

Drill Cadence and the Surveillance-Audit-Readiness Drill

The 2026 cadence pattern that is regulator-defensible and that ISO 42001 surveillance auditors credit:

  • Tier-1 systems (Annex III high-risk, GPAI deployers, foundation-model providers): annual drill minimum, plus a post-substantial-modification drill after any Article 43(4) re-conformity event.
  • Tier-2 systems: biennial drill (every two years).
  • Cross-functional all-company exercise: quarterly mini-exercise (a 60-90 minute exercise on a single scenario with reduced participant set; the AAR is lighter but the cadence is maintained).
  • Surveillance-audit-readiness drill: 6-12 months before the ISO 42001 Stage 2 surveillance audit, with the ISO 42001 lead auditor invited as observer. This drill specifically targets the A.6.2.7 evidence and is sometimes called the "audit dress rehearsal."
  • Integrated AI + cyber drill: at least once per year; co-led by CISO and CAIO; tests the overlap analysis between NIS2 Article 23 cyber-incident reporting and AI Act Article 73 AI-incident reporting.

Worked Example - Acme Q2 2026 Healthcare-Adjacent Hallucination Drill, Cross-Walks, and Penalty Exposure

The narrative below is the abbreviated AAR of Acme Inc's Q2 2026 tier-1 drill, Scenario 1 (healthcare-adjacent hallucination, Article 3(49)(a)). It is the model for how to read a real AAR.

Scenario. Acme.ServiceAssist provided incorrect medication-interaction guidance to 47 customers in a 72-hour window; one was hospitalized; the hospital issued a preliminary causal statement. Drill date: 2026-04-22, 09:00-13:00 CET.

Timeline. T-0 (injection) 09:00: Trust & Safety lead receives the mock complaint cluster + hospital statement in the actual complaint dashboard. T+04m: Trust & Safety opens incident ticket. T+19m: CAIO informed. T+27m: AIGC chair notified (within 30-minute goal). T+34m: CRO notified. T+58m: red team begins replay analysis of the implicated conversations. T+1h47m: Article 3(49)(a) "yes" determination signed by CAIO + General Counsel; 15-day clock declared started. T+2h04m: mock Article 73 report drafting started. T+3h12m: containment complete (the medication-interaction skill disabled in production; rollback to v3.7.2 base). T+3h41m: external counsel engaged (the firm Acme has on AI-incident retainer). T+9d8h equivalent: mock report submitted to controlled inbox; within 15-day window. T+4h drill time: live execution ends; hot-wash begins.

Decisions captured. All fifteen captured with timestamps. Article 3(49) determination ✓. AIGC chair notification ✓ (27m, beat 30m goal). CRO notification ✓ (34m). Containment ✓. Drafting start ✓. Annex XII deployer notification N/A (Acme is the deployer; no downstream deployers). Article 25(2) upstream notification ✓ (foundation-model vendor notified at T+2h11m). Article 86 affected-party notification ✓ (47 customers identified; notifications drafted by hour 6 of drill). External counsel ✓. Public statement decision: hold until report filed, then issue (decision at T+2h33m). Regulator pre-call: scheduled but not executed in drill scope. Report submission timestamp: T+9d8h equivalent. 90-day follow-up plan: drafted and committed. Board AI subcommittee notification: chair notified at T+1h12m drill time. AIRA breach assessment: KRI "customer-harm events" breached green threshold (1 hospitalization > 0 events), amber tolerance entered, board AI subcommittee informed.

Six gaps identified. (1) Communications lead was not in the on-call escalation tree on the drill date and learned of the drill 47 minutes after injection, gap closed by 2026-05-01 with on-call rotation update. (2) The MSA portal credentials were held by a single individual who was on PTO; access took 41 minutes to re-establish, gap closed by 2026-05-15 with dual-custody credential reset. (3) The Annex III §5(b) FRIA refresh template was last updated in 2025 and did not reference the May 2026 EDPB-EU AI Office joint guidance, template refreshed 2026-05-08. (4) The hospital statement causal analysis was performed sequentially with the technical RCA; running them in parallel saves 90 minutes of clock, runbook updated to require parallel paths. (5) External counsel's retainer scope did not explicitly cover Article 73 first-call advice, retainer scope amended 2026-05-12. (6) The AIRA breach disclosure to the board AI subcommittee chair used Slack, which is not the documented disclosure channel, channel documentation updated; future breaches use the documented incident-channel.

AIGC sign-off. Chair signed AAR on 2026-05-02, ten days after drill, within the 14-day commitment. Corrective actions all dated; verification at the Q3 2026 cross-functional mini-exercise.

Regulator Cross-Walks - Where the AAR Maps

The AAR is named evidence for multiple frameworks. The cross-walk below is the minimum mapping every AIGC artifact should carry.

  • EU AI Act: Articles 3(49), 3(50), 9 (risk management), 17 (quality management), 25(2) (upstream-provider obligations), 26 + 26(5) (deployer obligations), 27 (FRIA), 50 (transparency), 71 (database registration), 72 (post-market monitoring), 73 (serious-incident reporting), 86 (right to explanation), 89 (post-market monitoring plan), 99 (penalties); Annex IV §9 (post-market monitoring documentation); Annex XII (deployer information).
  • NIST AI RMF: Manage 1.3 (incident response), Manage 4.1 (continuous improvement), Measure 2.7 (security and resilience), Measure 4.1 (post-deployment monitoring).
  • ISO/IEC 42001: A.6.2.7 (incident management, named tabletop AAR evidence), A.9 (operation), A.10 (performance evaluation).
  • ISO/IEC 27035: incident management lifecycle alignment.
  • NIS2: Article 23 cyber-incident reporting overlap.
  • SR 11-7: incident-response pillar of the model risk management framework (for financial-services deployers).
  • PRA SS1/23: principle 5 on incident management (for UK PRA-regulated firms).

Penalty Exposure - Why the Drill Pays for Itself

Article 99(3) imposes administrative fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher, for non-compliance with Article 73 (among others). Article 99(5) imposes administrative fines up to €7.5 million or 1% for the supply of incorrect, incomplete, or misleading information to authorities. A program that misses the Article 73 clock, or that files a report so incomplete it triggers an Article 99(5) finding, faces penalty exposure that dwarfs the €15-50k cost of an annual drill by three to four orders of magnitude. The economic case for the drill is settled before the first hour of analysis.

Key Takeaways

  • Article 73 mandates serious-incident reporting within 15 days of provider awareness, 2 days if widespread under Article 3(50), and the only defensible way to prove the organization can execute under pressure is to drill it before an incident happens; ISO 42001 Stage 2 surveillance audit and 2026 competent-authority readiness exercises both expect the AAR.
  • A defensible drill is a five-stage exercise: Pre-Drill Setup (T-30 days), Scenario Injection (T-0), Live Execution (T+0 to T+4h compressed), Hot-Wash (T+4 to T+6h), and the formal After-Action Report (within 14 days, AIGC chair-signed).
  • Rotate across five scenarios mapped to Article 3(49)(a)-(d) and Article 3(50): healthcare-adjacent hallucination; critical-infrastructure prompt injection; fundamental-rights fairness disparity; property damage via agent tool misuse; widespread foundation-model upstream change.
  • Capture fifteen decisions per drill with timestamps: from Article 3(49) determination at T+4h, through AIGC chair notification, containment selection, report drafting, Annex XII / Article 25(2) / Article 86 notifications, external counsel, public statement, regulator pre-call, submission vs clock, 90-day follow-up, board AI subcommittee, AIRA breach assessment.
  • The AAR uses the eight-section template, scenario, timeline, decisions, gaps, corrective actions, recommendations, AIGC sign-off, re-drill schedule, and the corrective-action register is what the ISO 42001 surveillance auditor verifies.
  • Eight common 2026 drill failures: check-the-box mode, participant gaming, no AAR formalization, no corrective-action tracking, no public-statement coordination, Article 3(49) determination rushed, clock not actually started, no integration with cyber tabletop drills.
  • Cadence: tier-1 annual + post-substantial-modification; tier-2 biennial; quarterly all-company mini-exercise; surveillance-audit-readiness drill 6-12 months before Stage 2; integrated AI + cyber drill at least once per year.
  • Penalty exposure under Article 99(3) (€15M / 3% for Article 73 failures) and Article 99(5) (€7.5M / 1% for misleading information to authorities) dwarfs the €15-50k annual cost of the drill by three to four orders of magnitude; the AAR is named ISO 42001 A.6.2.7 evidence and EU AI Act Article 72 + 73 readiness evidence.