# Market Surveillance and Control of AI Systems — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/market-surveillance-control-ai
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems under the AI Act, which is a distinct regulatory domain not fully captured by existing topics.

## Overview

## Legal Framework

Market surveillance of AI systems under the AI Act operates through three interlocking provisions. Article 72 imposes a continuous obligation on providers of high-risk AI systems to actively monitor their products' performance after deployment. Providers must establish and maintain a documented post-market monitoring plan that is proportionate to the nature and risks of the AI system. This plan must be kept up to date and serve as the provider's primary mechanism for identifying corrective actions, including recalls or updates. The rationale is that AI systems evolve through learning and environmental interaction, making ex-ante conformity assessment insufficient on its own.

Article 85 establishes a complaints channel: any natural or legal person who believes an AI Act infringement has occurred may lodge a complaint with the relevant market surveillance authority. These complaints must be processed under the procedural framework of Regulation (EU) 2019/1020, meaning national market surveillance authorities are obligated to take them into account when planning and conducting surveillance activities. This creates a direct civic enforcement lever alongside institutional monitoring.

Article 76 governs the supervision of testing in real-world conditions. Market surveillance authorities are empowered to oversee such testing, ensuring that providers and deployers conducting real-world trials comply with the conditions and safeguards set out in the AI Act. This provision bridges the gap between pre-market testing and post-market deployment, giving authorities supervisory reach over the developmental phase itself.

## Key Developments

Because the AI Act entered into force recently, no enforcement decisions or court rulings have yet crystallized interpretive thresholds under Articles 72, 76, or 85. However, the integration with Regulation (EU) 2019/1020 means that established market surveillance practices under that framework — including risk-based prioritization, cross-border cooperation through the Single Market Surveillance Portal, and the Union Product Compliance Network — will shape how AI-specific complaints and monitoring obligations are operationalized. Authorities are expected to apply graduated enforcement responses, beginning with information requests and escalating to product withdrawal where post-market monitoring reveals systemic safety failures.

## Practical Guidance

- **Implement a living post-market monitoring plan** under Article 72 that defines data collection methods, incident thresholds, feedback channels from deployers, and triggers for corrective action — and update it whenever the system's intended purpose or operating environment changes.
- **Establish an internal complaint-handling interface** that can receive and triage complaints, since Article 85 complaints may arrive through market surveillance authorities and require timely, documented responses.
- **Designate a compliance owner** responsible for the post-market monitoring plan's execution and for liaising with market surveillance authorities during real-world testing supervision under Article 76.
- **Document all real-world testing conditions** — including participant consent, safeguards, and termination criteria — so that authorities conducting supervision under Article 76 can verify compliance on request.
- **Integrate monitoring findings into the conformity assessment lifecycle**, using post-market data to inform whether system updates require renewed conformity assessment or notification to the relevant authority.

## Legislation (full text of key provisions)

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Supervision of testing in real world conditions by market surveillance authorities

*Source: AI Act, aiact-art-76-en, 2024-06-12 — https://overview.legal/posts/93261*

### Recital 155 — high-risk AI post-market monitoring systems

*Source: AI Act, aiact-rec-155-en, 2024-06-12 — https://overview.legal/posts/93992*

In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.

### Recital 161 — Union and national supervision responsibilities for general-purpose AI

*Source: AI Act, aiact-rec-161-en, 2024-06-12 — https://overview.legal/posts/94004*

It is necessary to clarify the responsibilities and competences at Union and national level as regards AI systems that are built on general-purpose AI models. To avoid overlapping competences, where an AI system is based on a general-purpose AI model and the model and system are provided by the same provider, the supervision should take place at Union level through the AI Office, which should have the powers of a market surveillance authority within the meaning of Regulation (EU) 2019/1020 for this purpose. In all other cases, national market surveillance authorities remain responsible for the supervision of AI systems. However, for general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk, market surveillance authorities should cooperate with the AI Office to carry out evaluations of compliance and inform the Board and other market surveillance authorities accordingly. Furthermore, market surveillance authorities should be able to request assistance from the AI Office where the market surveillance authority is unable to conclude an investigation on a high-risk AI system because of its inability to access certain information related to the general-purpose AI model on which the high-risk AI system is built. In such cases, the procedure regarding mutual assistance in cross-border cases in Chapter VI of Regulation (EU) 2019/1020 should apply mutatis mutandis.

### Recital 156 — market surveillance and compliance enforcement framework

*Source: AI Act, aiact-rec-156-en, 2024-06-12 — https://overview.legal/posts/93994*

In order to ensure an appropriate and effective enforcement of the requirements and obligations set out by this Regulation, which is Union harmonisation legislation, the system of market surveillance and compliance of products established by Regulation (EU) 2019/1020 should apply in its entirety. Market surveillance authorities designated pursuant to this Regulation should have all enforcement powers laid down in this Regulation and in Regulation (EU) 2019/1020 and should exercise their powers and carry out their duties independently, impartially and without bias. Although the majority of AI systems are not subject to specific requirements and obligations under this Regulation, market surveillance authorities may take measures in relation to all AI systems when they present a risk in accordance with this Regulation. Due to the specific nature of Union institutions, agencies and bodies falling within the scope of this Regulation, it is appropriate to designate the European Data Protection Supervisor as a competent market surveillance authority for them. This should be without prejudice to the designation of national competent authorities by the Member States. Market surveillance activities should not affect the ability of the supervised entities to carry out their tasks independently, when such independence is required by Union law.

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

### Recital 36 — biometric system use notification and reporting

*Source: AI Act, aiact-rec-36-en, 2024-06-12 — https://overview.legal/posts/93754*

In order to carry out their tasks in accordance with the requirements set out in this Regulation as well as in national rules, the relevant market surveillance authority and the national data protection authority should be notified of each use of the real-time biometric identification system. Market surveillance authorities and the national data protection authorities that have been notified should submit to the Commission an annual report on the use of real-time biometric identification systems.

### Recital 114 — systemic risk AI model obligations

*Source: AI Act, aiact-rec-114-en, 2024-06-12 — https://overview.legal/posts/93910*

The providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.

### Recital 130 — rapid deployment of innovative AI systems

*Source: AI Act, aiact-rec-130-en, 2024-06-12 — https://overview.legal/posts/93942*

Under certain conditions, rapid availability of innovative technologies may be crucial for health and safety of persons, the protection of the environment and climate change and for society as a whole. It is thus appropriate that under exceptional reasons of public security or protection of life and health of natural persons, environmental protection and the protection of key industrial and infrastructural assets, market surveillance authorities could authorise the placing on the market or the putting into service of AI systems which have not undergone a conformity assessment. In duly justified situations, as provided for in this Regulation, law enforcement authorities or civil protection authorities may put a specific high-risk AI system into service without the authorisation of the market surveillance authority, provided that such authorisation is requested during or after the use without undue delay.

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

## Literature

### From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

*Source: Accounting and Auditing, 2026-07-15 — https://overview.legal/posts/132365 — original: https://doi.org/10.3390/accountaudit2030012*

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring.

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### Eu regulatory ecosystem for ethical AI

*Source: AI and Ethics, 2025-06-02 — https://overview.legal/posts/53866 — original: https://doi.org/10.1007/s43681-025-00749-x*

Abstract AI applications raise complex ethical, legal, and security challenges that demand comprehensive and coordinated governance at multiple levels. In this paper, we examine how key European Union (EU) regulatory frameworks, such as the AI Act, GDPR, and NIS2, interact to set standards for AI security, functionality, and ethical performance. By comparing the objectives and requirements outlined in these regulatory instruments, we identify points of convergence that encourage a holistic appro

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Post-Market Monitoring for AI Systems** — https://overview.legal/topics/post-market-monitoring-ai
  Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and
- **AI Incident Notification** — https://overview.legal/topics/serious-incident-notification-ai
  The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated cov
- **Interim Measures under AI Act** — https://overview.legal/topics/interim-measures-ai-act
  This new topic is needed to specifically address interim measures provisions in the AI Act, which allow authorities to take temporary protective actions against
- **Authority Access Rights to AI Systems and Documentation** — https://overview.legal/topics/authority-access-rights-ai-systems
  This new topic would specifically address the rights and procedures for competent authorities to access AI systems, facilities, documentation, and data during o
- **Conformity Body Notification** — https://overview.legal/topics/conformity-assessment-body-notification
  This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Ac

---
Generated by overview.legal · https://overview.legal/topics/market-surveillance-control-ai · 2026-08-22
