Skip to contentThe Observability LayerSearch

Flagship compendium · Section 21 of 24

Crosswalk: Incident & Loss-of-Control Reporting

Cohort: the four instruments that impose (or operationalize) a duty to report AI harms, from frontier loss-of-model-control and deceptive-subversion incidents down to consequential-decision harms, compared on what fires a report, who reports, to whom, how fast, who's in scope, and what bites. Cell convention: concise treatment + [key]. = source is silent / does not address that dimension.

Column keys: [IL] Illinois SB 315 (AI Safety Measures Act) · [EU-GPAI] EU GPAI Code of Practice, Safety & Security chapter · [CO] Colorado SB 26-189 (ADMT Act) · [EU-AIA] EU AI Act, Art. 73 (serious-incident reporting) / Art. 55

Evidence table: Dimension, 🟦 Illinois SB 315 [IL], 🟨 EU GPAI Code [EU-GPAI], 🟩 Colorado ADMT [CO], 🟪 EU AI Act Art. 73/55 [EU-AIA]
Dimension🟦 Illinois SB 315 [IL]🟨 EU GPAI Code [EU-GPAI]🟩 Colorado ADMT [CO]🟪 EU AI Act Art. 73/55 [EU-AIA]
What triggers a report"Critical safety incident": loss of model control causing bodily injury, materialization of a catastrophic risk, unauthorized model-weights access causing injury, or a model using deceptive techniques to subvert developer controls [IL]Serious incident arising from a GPAI model with systemic risk (incl. loss-of-control / autonomy pathways): track, document, report [EU-GPAI]No incident-reporting trigger. Obligation is a post-adverse-decision notice to the consumer when ADMT materially influenced an unfavorable consequential decision [CO]Serious incident under Art. 73 (high-risk systems); serious-incident reporting is one of the four Art. 55 systemic-risk duties for GPAI [EU-AIA]
Loss-of-control / deception explicitly namedUniquely explicit: both "loss of model control" and "deceptive techniques against the developer to subvert controls" are named triggers [IL]Implied: loss-of-control / autonomy sits inside systemic-risk for the largest models [EU-GPAI]: (regime is about consequential-decision fairness, not model control) [CO]Implied: autonomy / loss-of-control is a systemic-risk category, not a separate statutory trigger [EU-AIA]
Who must reportThe frontier developer (a large frontier developer is the covered entity) [IL]Provider of the GPAI model with systemic risk [EU-GPAI]Deployer (notice runs to the consumer, not a regulator) [CO]Provider / deployer of the high-risk system; GPAI provider for Art. 55 [EU-AIA]
To whomNot separately quoted in the source excerpt; enforcement vests in the Attorney General [IL]The EU AI Office and national authorities [EU-GPAI]The consumer (individual affected); enforcement to the Colorado AG [CO]National market-surveillance authority (Art. 73); AI Office + national authorities for GPAI (Art. 55) [EU-AIA]
Timeline72 hours of the developer learning facts sufficient for reasonable belief [IL]"Strict deadlines" per severity (Code-level detail; not quoted verbatim) [EU-GPAI]No deadline framed as hours/days; notice is "post-adverse-decision" [CO]Art. 73 staged windows (up to 15 days, shorter for death/widescale) [EU-AIA]
Covered-entity thresholdLarge frontier developer: >$500M prior-year gross revenue AND model trained at >10^26 FLOP [IL]GPAI with systemic risk: >10^25 FLOP or Commission designation (~5–15 providers) [EU-GPAI]ADMT that materially influences a consequential decision in enumerated domains (no compute/revenue gate) [CO]High-risk (Annex III) for Art. 73; GPAI systemic-risk >10^25 FLOP for Art. 55 [EU-AIA]
PenaltiesCivil: ≤$1M first violation, ≤$3M subsequent [IL]Code is voluntary; teeth come from the underlying AI Act fines [EU-GPAI]Deceptive trade practice under the Colorado Consumer Protection Act [CO]AI Act fines up to €35M / 7% turnover (top tier) [EU-AIA]
Enforcement modelAG only, no private right of action [IL]Commission / AI Office (from 2 Aug 2026); presumption-of-conformity for signatories [EU-GPAI]AG exclusive, no private right of action; 60-day cure (sunsets 1 Jan 2030) [CO]National market-surveillance authorities + Commission (GPAI) [EU-AIA]
In-force vs pendingPending: passed both houses 5/29/2026, awaiting Pritzker's signature; effective 1 Jan 2027 if signed [IL]In effect; GPAI obligations applied 2 Aug 2025, enforcement from 2 Aug 2026 [EU-GPAI]Signed 14 May 2026; effective 1 Jan 2027 [CO]In force (2024); Art. 73 / most rules + enforcement powers from 2 Aug 2026 [EU-AIA]
Evidence limitsProvisional; engrossed bill, not enactedSummary only; exact deadlines require primary textSigned statuteArticle wording not quoted

How to read this

  • Only Illinois names loss-of-control and deception as report triggers. SB 315's "critical safety incident" is the single instrument here that explicitly fires on a model losing control or using deceptive techniques to subvert its developer's controls [IL]. The EU treats those as sub-cases of "systemic risk / serious incident" [EU-GPAI] [EU-AIA]; Colorado does not address model control at all [CO].
  • Two of these aren't really incident-reporting regimes. Colorado's "report" is a post-adverse-decision notice to the affected consumer about a consequential decision [CO]: a fairness/transparency duty, not a safety-incident pipeline. The EU GPAI Code [EU-GPAI] is the operational elaboration of the EU AI Act's statutory duty [EU-AIA], so they are one regime at two altitudes, not two peers.
  • Timeline is where the cohort splits hardest: Illinois demands 72 hours [IL]; the EU AI Act's Art. 73 allows staged windows up to 15 days [EU-AIA]. Illinois is by far the tightest clock among binding instruments.
  • Scope gates run on opposite logic. Illinois and the EU systemic-risk tier gate on compute + (IL) revenue (10^26 FLOP / $500M; 10^25 FLOP) [IL] [EU-GPAI], capturing only a handful of frontier labs. Colorado gates on function, any ADMT that materially influences a consequential decision [CO], sweeping in far more deployers but for a narrower harm.
  • All three US/EU enforcement models converge on the regulator, not the plaintiff. Both US instruments are AG-only with no private right of action [IL] [CO]; the EU routes through the AI Office / market-surveillance authorities [EU-GPAI] [EU-AIA]. And status matters: Illinois is the only one not yet enacted, cite it as pending.

Related-but-voluntary international regimes, the OECD Hiroshima AI Process (HAIP) reporting framework and the G7 Hiroshima Code of Conduct, invite frontier developers to disclose incidents and vulnerabilities, but carry no binding trigger, deadline, or penalty and so sit outside this matrix.

Sources