Post-Market Monitoring for AI Systems
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and critical component that warrants its own topic.
Overview
13 sources · Jul 23, 2026Legal Framework
Post-market monitoring for AI systems is primarily governed by Article 72 of the AI Act, which requires providers of high-risk AI systems to establish and document a post-market monitoring plan. This plan must be proportional to the nature of the AI system and the risks it presents, and must serve to collect, document, and analyze data on the system's performance and compliance throughout its lifecycle. The monitoring obligation is designed to ensure that risks emerging during real-world deployment—risks that may not have been identifiable during pre-market conformity assessment—are detected and addressed.
Article 20 of the AI Act complements this by imposing corrective action and notification duties. When a provider identifies that a high-risk AI system does not comply with the Act's requirements, it must immediately take necessary corrective actions, which may include withdrawal, recall, or disabling of the system. Providers must also inform relevant national competent authorities and, where applicable, their authorized representatives, of any non-compliance and the corrective measures taken.
The enforcement architecture rests on independent supervisory authorities whose powers must be established in national law. The requirement for supervisory independence is anchored in Article 16(3) of the relevant framework, as well as Article 16(2) TFEU and Article 39 TEU. National legislation must equip these authorities with the power to refer violations to judicial authorities and initiate judicial proceedings—a power whose necessity was affirmed by the Court of Justice in Schrems (CJEU, 6 October 2015, C-362/14).
Key Developments
The Court of Justice's ruling in Schrems established that supervisory authorities must possess effective judicial enforcement tools, including the ability to bring proceedings before courts when violations are identified. This principle, originally developed under the 1995 Privacy Directive, carries forward into the AI Act enforcement ecosystem: national authorities overseeing post-market compliance must have teeth, not merely advisory mandates.
The independence guarantee for supervisory authorities has been treated by the Court of Justice as essential to ensuring the effectiveness and reliability of compliance oversight. This means that providers subject to Article 72 monitoring obligations should expect enforcement from authorities that are structurally insulated from external influence—political or commercial—and that can escalate non-compliance to judicial proceedings when corrective actions under Article 20 are deemed insufficient.
Practical Guidance
Draft a documented post-market monitoring plan before market placement. Article 72 requires this plan to be proportional to the AI system's risk profile. Tailor data collection methods, analysis frequency, and escalation triggers to the specific use case and risk categorization of the system.
Establish internal triggers for Article 20 corrective action. Define clear thresholds within the monitoring plan that, when breached, automatically initiate the corrective action workflow—including withdrawal, recall, or disabling—and set timelines for notifying competent authorities.
Map your notification chain in advance. Identify the relevant national competent authorities and authorized representatives for each jurisdiction where the AI system is deployed, so that Article 20 notification obligations can be discharged immediately upon identification of non-compliance.
Ensure monitoring captures real-world drift, not just technical performance. The rationale behind Article 72 is that pre-market assessment cannot anticipate all deployment risks. Monitoring must therefore track contextual factors—input data shifts, user behavior changes, and emerging harms—not merely system accuracy metrics.
Anticipate judicial escalation. Given that supervisory authorities must be empowered to refer violations to judicial authorities, treat post-market monitoring findings as potentially litigation-relevant records. Maintain audit-ready documentation of all monitoring activities, identified risks, and corrective actions taken.