# Monitoring Actions under AI Act — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/monitoring-actions-ai-act
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses 'Monitoring actions' as a distinct topic under the AI Act, which encompasses systematic oversight procedures, compliance verification, and market surveillance activities that are not fully captured by existing more general monitoring topics.

## Overview

## Legal Framework

Monitoring actions under the AI Act are governed by three interlocking provisions. Article 89 AI Act establishes the core monitoring framework, empowering authorities to conduct systematic oversight of AI systems on the market. Article 20 AI Act addresses corrective actions and the duty of information, requiring providers to take remedial measures when non-compliance is identified and to inform competent authorities accordingly. Article 72 AI Act imposes post-market monitoring obligations specifically on providers of high-risk AI systems, mandating a documented post-market monitoring plan that tracks system performance throughout its lifecycle.

The doctrinal commentary underscores that Article 16(3) requires an independent authority to oversee compliance—a requirement anchored in Article 16(2) TFEU and Article 39 TEU. The independence guarantee ensures the effectiveness and reliability of supervisory oversight over AI systems. Member States must also provide in national law for the supervisory authority's power to bring infringements before judicial authorities and initiate judicial proceedings. This obligation is not novel: the CJEU confirmed in *Schrems* (C-362/14, 6 October 2015) that such a power existed even under the Privacy Directive 1995, and it carries forward into the AI Act's enforcement architecture.

## Key Developments

The *Schrems* ruling established a critical enforcement principle: supervisory authorities must possess genuine judicial referral powers, not merely administrative sanctioning authority. National implementations that fail to grant this competence are deficient. The Dutch experience illustrates the gap—the data protection authority historically lacked explicit judicial referral authority under the Wbp, prompting legislative amendment to align with the *Schrems* standard.

The CJEU's settled case law on institutional independence sets a demanding threshold: monitoring authorities must be structurally insulated from external influence, whether political, economic, or operational. This means that national authorities designated under the AI Act cannot be subordinate to government ministries or industry stakeholders in their decision-making on compliance. The independence requirement directly shapes how Member States must configure their AI market surveillance authorities when transposing the regulation.

## Practical Guidance

- **Establish a post-market monitoring plan** for every high-risk AI system before market placement, as required by Article 72, documenting performance metrics, incident detection mechanisms, and corrective action triggers throughout the system's lifecycle.
- **Implement corrective action procedures** consistent with Article 20, including defined timelines for remediation and a clear duty-of-information protocol specifying which authorities must be notified when non-compliance is identified.
- **Verify that the designated national authority possesses judicial referral powers** in national implementing legislation—relying solely on administrative enforcement risks falling short of the standard articulated in *Schrems*.
- **Ensure the monitoring authority's structural independence** by confirming that appointments, budget, and decision-making processes are insulated from external interference, as required by Article 16(3) and CJEU jurisprudence on supervisory independence.
- **Document compliance verification processes** to a standard that withstands judicial scrutiny, maintaining records that demonstrate both technical conformity and fundamental rights impact assessment, given that monitoring actions may ultimately be adjudicated before national courts.

## Legislation (full text of key provisions)

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Corrective actions and duty of information

*Source: AI Act, aiact-art-20-en, 2024-06-12 — https://overview.legal/posts/92298*

### Monitoring actions

*Source: AI Act, aiact-art-89-en, 2024-06-12 — https://overview.legal/posts/93407*

### Recital 155 — high-risk AI post-market monitoring systems

*Source: AI Act, aiact-rec-155-en, 2024-06-12 — https://overview.legal/posts/93992*

In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.

### Recital 108 — AI Office copyright compliance monitoring

*Source: AI Act, aiact-rec-108-en, 2024-06-12 — https://overview.legal/posts/93898*

With regard to the obligations imposed on providers of general-purpose AI models to put in place a policy to comply with Union copyright law and make publicly available a summary of the content used for the training, the AI Office should monitor whether the provider has fulfilled those obligations without verifying or proceeding to a work-by-work assessment of the training data in terms of copyright compliance. This Regulation does not affect the enforcement of copyright rules as provided for under Union law.

### Recital 81 — provider quality management system

*Source: AI Act, aiact-rec-81-en, 2024-06-12 — https://overview.legal/posts/93844*

The provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.

### Recital 114 — systemic risk AI model obligations

*Source: AI Act, aiact-rec-114-en, 2024-06-12 — https://overview.legal/posts/93910*

The providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.

## Guidance

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

## Recent developments

### Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer

*Source: White Label Consultancy, 2022-01-04 — https://overview.legal/posts/6311 — original: https://whitelabelconsultancy.com/2022/01/chief-privacy-officer-or-data-protection-officer/#entry-16*

> Do we need an Chief Privacy Officer, a Data Protection Officer, or do we need both?In the following article, I will examine the benefits of both roles, but I will also look at some of the challenges related to each of the roles and why these have impelled both Data Protection Officers and organisations to question what the ideal setup is for them.

## Literature

### From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

*Source: Accounting and Auditing, 2026-07-15 — https://overview.legal/posts/132365 — original: https://doi.org/10.3390/accountaudit2030012*

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring.

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

### Eu regulatory ecosystem for ethical AI

*Source: AI and Ethics, 2025-06-02 — https://overview.legal/posts/53866 — original: https://doi.org/10.1007/s43681-025-00749-x*

Abstract AI applications raise complex ethical, legal, and security challenges that demand comprehensive and coordinated governance at multiple levels. In this paper, we examine how key European Union (EU) regulatory frameworks, such as the AI Act, GDPR, and NIS2, interact to set standards for AI security, functionality, and ethical performance. By comparing the objectives and requirements outlined in these regulatory instruments, we identify points of convergence that encourage a holistic appro

### A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance

*Source: International Journal of Computer Applications, 2024-09-26 — https://overview.legal/posts/132613 — original: https://doi.org/10.5120/ijca2024923954*

International Journal of Computer Applications (0975 – 8887) Volume 186 – No. 38 , September 2024 23 A Comparative Analysis of the EU AI Act and the Colorado AI Act: Regulatory Approaches to Artificial Intelligence Governance Mayur Jariwala School of Computer and Information Sciences, University of the Cumberlands, Williamsburg, KY, USA ABSTRACT This comparative study examines the EU AI Act and the Colorado AI Act, focusing on their regulatory approaches to artificial intelligence. The EU AI Act provides a comprehensive framework with a risk - based classification, emphasizing transparency, accountability, and the protection of fundamental rights across diverse sectors. It aims to set a global benchmark for AI governance, influencing international standards. The Colorado AI Act targets high - risk AI systems, prioritizing consumer protection, fairness, and the prevention of algorithmic discrimination. It mandates detailed documentation, ri sk management, and transparency measures to ensure ethical AI deployment. This analysis explores the impacts of each act on innovation, industry practices, and consumer protection, as well as their potential global influence. The findings highlig

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

## Related topics

- **Post-Market Monitoring for AI Systems** — https://overview.legal/topics/post-market-monitoring-ai
  Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Risk Management System** — https://overview.legal/topics/risk-management-system
  This new topic is needed because risk management systems are a distinct and mandatory requirement under the AI Act, encompassing systematic processes for identi
- **AI Corrective Powers** — https://overview.legal/topics/authority-intervention-corrective-powers-ai
  This new topic is needed to specifically address the corrective and intervention powers that authorities possess to protect fundamental rights, including emerge
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **AI Corrective Actions** — https://overview.legal/topics/corrective-actions-ai
  This new topic is needed because corrective actions are a specific and distinct obligation under the AI Act that encompasses systematic procedures for addressin

---
Generated by overview.legal · https://overview.legal/topics/monitoring-actions-ai-act · 2026-08-22
