AI_ACTArt. 73voice-validated

AI_ACT Art73: Art. 73

AI_ACT

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred. Such reports shall be made immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link, and in any event not later than 15 days.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-201. Insufficient input validation for AI models or systems can lead to adversarial attacks or compromise, causing serious incidents under Art. 73.
90%
CWE-2871. Flaws in authentication mechanisms allow unauthorized users to access and manipulate high-risk AI systems, leading to serious incidents per Art. 73.
85%
CWE-3061. Critical AI system functions lacking authentication can be exploited, directly causing serious incidents reportable under Art. 73.
85%
CWE-3271. Weak cryptographic algorithms expose sensitive AI training data or model parameters, risking unauthorized disclosure and serious incidents under Art. 73.
80%
CWE-4341. Unrestricted file uploads to an AI system can introduce malicious code or models, enabling attacks that cause serious incidents under Art. 73.
85%
CWE-5021. Deserializing untrusted data in AI system components can lead to remote code execution and system compromise, causing serious incidents under Art. 73.
85%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0171 compute · voice-rubric self-validated