Market Surveillance and Control of AI Systems
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems under the AI Act, which is a distinct regulatory domain not fully captured by existing topics.
Overview
9 sources · Jul 23, 2026Legal Framework
Market surveillance of AI systems under the AI Act operates through three interlocking provisions. Article 72 imposes a continuous obligation on providers of high-risk AI systems to actively monitor their products' performance after deployment. Providers must establish and maintain a documented post-market monitoring plan that is proportionate to the nature and risks of the AI system. This plan must be kept up to date and serve as the provider's primary mechanism for identifying corrective actions, including recalls or updates. The rationale is that AI systems evolve through learning and environmental interaction, making ex-ante conformity assessment insufficient on its own.
Article 85 establishes a complaints channel: any natural or legal person who believes an AI Act infringement has occurred may lodge a complaint with the relevant market surveillance authority. These complaints must be processed under the procedural framework of Regulation (EU) 2019/1020, meaning national market surveillance authorities are obligated to take them into account when planning and conducting surveillance activities. This creates a direct civic enforcement lever alongside institutional monitoring.
Article 76 governs the supervision of testing in real-world conditions. Market surveillance authorities are empowered to oversee such testing, ensuring that providers and deployers conducting real-world trials comply with the conditions and safeguards set out in the AI Act. This provision bridges the gap between pre-market testing and post-market deployment, giving authorities supervisory reach over the developmental phase itself.
Key Developments
Because the AI Act entered into force recently, no enforcement decisions or court rulings have yet crystallized interpretive thresholds under Articles 72, 76, or 85. However, the integration with Regulation (EU) 2019/1020 means that established market surveillance practices under that framework — including risk-based prioritization, cross-border cooperation through the Single Market Surveillance Portal, and the Union Product Compliance Network — will shape how AI-specific complaints and monitoring obligations are operationalized. Authorities are expected to apply graduated enforcement responses, beginning with information requests and escalating to product withdrawal where post-market monitoring reveals systemic safety failures.
Practical Guidance
- Implement a living post-market monitoring plan under Article 72 that defines data collection methods, incident thresholds, feedback channels from deployers, and triggers for corrective action — and update it whenever the system's intended purpose or operating environment changes.
- Establish an internal complaint-handling interface that can receive and triage complaints, since Article 85 complaints may arrive through market surveillance authorities and require timely, documented responses.
- Designate a compliance owner responsible for the post-market monitoring plan's execution and for liaising with market surveillance authorities during real-world testing supervision under Article 76.
- Document all real-world testing conditions — including participant consent, safeguards, and termination criteria — so that authorities conducting supervision under Article 76 can verify compliance on request.
- Integrate monitoring findings into the conformity assessment lifecycle, using post-market data to inform whether system updates require renewed conformity assessment or notification to the relevant authority.