Skip to content
Topic Developing

Monitoring Actions under AI Act

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses 'Monitoring actions' as a distinct topic under the AI Act, which encompasses systematic oversight procedures, compliance verification, and market surveillance activities that are not fully captured by existing more general monitoring topics.

15 linked items 7 Laws1 Guidance1 News6 Literature

Overview

13 sources · Jul 23, 2026

Legal Framework

Monitoring actions under the AI Act are governed by three interlocking provisions. Article 89 AI Act establishes the core monitoring framework, empowering authorities to conduct systematic oversight of AI systems on the market. Article 20 AI Act addresses corrective actions and the duty of information, requiring providers to take remedial measures when non-compliance is identified and to inform competent authorities accordingly. Article 72 AI Act imposes post-market monitoring obligations specifically on providers of high-risk AI systems, mandating a documented post-market monitoring plan that tracks system performance throughout its lifecycle.

The doctrinal commentary underscores that Article 16(3) requires an independent authority to oversee compliance—a requirement anchored in Article 16(2) TFEU and Article 39 TEU. The independence guarantee ensures the effectiveness and reliability of supervisory oversight over AI systems. Member States must also provide in national law for the supervisory authority's power to bring infringements before judicial authorities and initiate judicial proceedings. This obligation is not novel: the CJEU confirmed in Schrems (C-362/14, 6 October 2015) that such a power existed even under the Privacy Directive 1995, and it carries forward into the AI Act's enforcement architecture.

Key Developments

The Schrems ruling established a critical enforcement principle: supervisory authorities must possess genuine judicial referral powers, not merely administrative sanctioning authority. National implementations that fail to grant this competence are deficient. The Dutch experience illustrates the gap—the data protection authority historically lacked explicit judicial referral authority under the Wbp, prompting legislative amendment to align with the Schrems standard.

The CJEU's settled case law on institutional independence sets a demanding threshold: monitoring authorities must be structurally insulated from external influence, whether political, economic, or operational. This means that national authorities designated under the AI Act cannot be subordinate to government ministries or industry stakeholders in their decision-making on compliance. The independence requirement directly shapes how Member States must configure their AI market surveillance authorities when transposing the regulation.

Practical Guidance

  • Establish a post-market monitoring plan for every high-risk AI system before market placement, as required by Article 72, documenting performance metrics, incident detection mechanisms, and corrective action triggers throughout the system's lifecycle.
  • Implement corrective action procedures consistent with Article 20, including defined timelines for remediation and a clear duty-of-information protocol specifying which authorities must be notified when non-compliance is identified.
  • Verify that the designated national authority possesses judicial referral powers in national implementing legislation—relying solely on administrative enforcement risks falling short of the standard articulated in Schrems.
  • Ensure the monitoring authority's structural independence by confirming that appointments, budget, and decision-making processes are insulated from external interference, as required by Article 16(3) and CJEU jurisprudence on supervisory independence.
  • Document compliance verification processes to a standard that withstands judicial scrutiny, maintaining records that demonstrate both technical conformity and fundamental rights impact assessment, given that monitoring actions may ultimately be adjudicated before national courts.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 7
Art. 3(25) ‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI… AI Act Art. 9(2)(c) the evaluation of other risks possibly arising, based on the analysis of data gathered from the post-market monitoring system referred to in Article 7… AI Act Art. 12(2)(b) facilitating the post-market monitoring referred to in Article 72; and AI Act Art. 16(j) take the necessary corrective actions and provide information as required in Article 20; AI Act rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024 art 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems AI Act Jun 2024 rec 108 Recital 108 — AI Office copyright compliance monitoring AI Act Jun 2024 art 20 Corrective actions and duty of information AI Act Jun 2024 art 89 Monitoring actions AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 114 Recital 114 — systemic risk AI model obligations AI Act Jun 2024
Guidance 1
§16 See articles 35 - 36 DSA. 4 Adopted to formally consult or to cooperate with the EDPB or its members . This poses a risk for conflicting guidance or e… Statement on the Digital Services Package and Data Strategy on the digital services package and data Statement on the Digital Services Package and Data Strategy EDPB Nov 2021
News 1
White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022
Literature 6
Accounting and Auditing From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence Accounting and Auditing Jul 2026 Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 AI and Ethics Eu regulatory ecosystem for ethical AI AI and Ethics Jun 2025 International Journal of Computer Applications A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance International Journal of Computer Applications Sep 2024 International Journal of Social Sciences and Public Administration Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection International Journal of Social Sciences and Public Administration Jan 2025 International Journal of Law and Societal Studies Balancing Security and Privacy: Analyzing the Effectiveness of EU Digital Surveillance Laws in Criminal Proceedings International Journal of Law and Societal Studies Sep 2025