AI_ACTArt. 73voice-validated
AI_ACT Art73: Art. 73
AI_ACT
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Providers of high-risk AI systems placed on the Union market shall report any serious incident to the market surveillance authorities of the Member States where that incident occurred. Such reports shall be made immediately after the provider has established a causal link between the AI system and the serious incident or the reasonable likelihood of such a link, and in any event not later than 15 days.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 0
| Mitigation | What it does | Confidence |
|---|
Underlying weaknesses · 6
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-20 | 1. Insufficient input validation for AI models or systems can lead to adversarial attacks or compromise, causing serious incidents under Art. 73. | 90% |
| CWE-287 | 1. Flaws in authentication mechanisms allow unauthorized users to access and manipulate high-risk AI systems, leading to serious incidents per Art. 73. | 85% |
| CWE-306 | 1. Critical AI system functions lacking authentication can be exploited, directly causing serious incidents reportable under Art. 73. | 85% |
| CWE-327 | 1. Weak cryptographic algorithms expose sensitive AI training data or model parameters, risking unauthorized disclosure and serious incidents under Art. 73. | 80% |
| CWE-434 | 1. Unrestricted file uploads to an AI system can introduce malicious code or models, enabling attacks that cause serious incidents under Art. 73. | 85% |
| CWE-502 | 1. Deserializing untrusted data in AI system components can lead to remote code execution and system compromise, causing serious incidents under Art. 73. | 85% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0171 compute · voice-rubric self-validated