Skip to content
Topic Contested in court

Monitoring Actions under AI Act

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses 'Monitoring actions' as a distinct topic under the AI Act, which encompasses systematic oversight procedures, compliance verification, and market surveillance activities that are not fully captured by existing more general monitoring topics.

16 linked items 7 Laws2 Guidance1 News6 Literature

Overview

11 sources · Sep 25, 2026

Legal Framework

Monitoring obligations under the AI Act are primarily governed by Article 72, which mandates that providers of high-risk AI systems establish a post-market monitoring system, and Article 20, which imposes corrective action and information duties when non-conformity or risk is identified. Recital 155 supplies the rationale: providers must be able to take corrective action in a timely manner, particularly where AI systems continue to "learn" after deployment.

Article 72(1) requires that the monitoring system be "proportionate to the nature of the AI technologies and the risks of the high-risk AI system." Article 72(2) specifies the operational core — providers must "actively and systematically collect, document and analyse relevant data" throughout the system's lifetime to evaluate continuous compliance with Chapter III, Section 2 requirements. The monitoring plan must be integrated into the technical documentation per Annex IV, with a Commission template due by 2 February 2026.

Article 20 creates a two-tier obligation. First, where a provider "consider[s] or ha[s] reason to consider" non-conformity, it must immediately take corrective actions — bringing the system into conformity, withdrawing it, disabling it, or recalling it — and inform distributors, deployers, authorised representatives, and importers. Second, where the system presents a risk under Article 79(1), the provider must investigate causes, collaborate with the reporting deployer, and inform market surveillance authorities and, where applicable, the notified body.

"all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software."
— AI Act Recital 155

Key Developments

The AI Act's monitoring architecture draws on established market surveillance principles from Union harmonisation legislation. Article 72(4) explicitly accommodates high-risk AI systems already subject to post-market monitoring under sectoral legislation, requiring consistency and avoidance of duplication. This integration approach mirrors the enforcement coordination challenges the EDPB has flagged in adjacent digital regulation contexts.

The doctrinal backdrop reinforces that effective monitoring requires independent supervisory authorities with judicial referral capacity — a principle the Court of Justice established in Schrems (C-362/14) under the prior data protection framework. Member states must ensure national law equips competent authorities to bring infringements before judicial bodies. This structural requirement now extends to AI system oversight.

For general-purpose AI models, Recital 108 delineates a narrower monitoring scope: the AI Office assesses whether providers have implemented a copyright compliance policy, but does not conduct work-by-work training data verification. This creates a distinct, lighter-touch monitoring regime compared to the systematic obligations imposed on high-risk system providers.

Status of the Debate

This topic is developing. No dominant doctrinal pattern has yet emerged, largely because the AI Act's monitoring provisions are not yet operational — the Commission's implementing act on the post-market monitoring plan template is due by February 2026, and national implementing legislation is still being formulated across member states.

The open questions are practical: how will market surveillance authorities coordinate with data protection authorities when high-risk AI systems process personal data, and what threshold triggers the Article 20 duty to investigate? The relationship between AI Act monitoring and GDPR accountability obligations remains unresolved. Resolution will likely come through the first enforcement actions and any EDPB-AI Office cooperation framework.

Practical Guidance

  • Establish a proportionate post-market monitoring system now under Article 72(1), calibrated to the risk profile and technological characteristics of each high-risk AI system you provide.
  • Build the monitoring plan into technical documentation per Article 72(3), anticipating the Commission template expected by February 2026 to avoid later restructuring.
  • Define internal triggers for Article 20 corrective actions, including clear escalation procedures for when staff "consider or have reason to consider" non-conformity, ensuring immediate notification to distributors, deployers, and authorities.
  • Exclude sensitive operational data of law-enforcement deployers from monitoring data collection, as required by Article 72(2), and document the boundary to demonstrate compliance.
  • Map overlaps with existing sectoral post-market monitoring obligations under Annex I legislation to leverage Article 72(4)'s consistency and anti-duplication provisions.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section