Skip to content
Topic Contested in court

Post-Market Monitoring for AI Systems

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and critical component that warrants its own topic.

21 linked items 15 Laws2 Guidance4 Literature

Overview

13 sources · Jul 23, 2026

Legal Framework

Post-market monitoring for AI systems is primarily governed by Article 72 of the AI Act, which requires providers of high-risk AI systems to establish and document a post-market monitoring plan. This plan must be proportional to the nature of the AI system and the risks it presents, and must serve to collect, document, and analyze data on the system's performance and compliance throughout its lifecycle. The monitoring obligation is designed to ensure that risks emerging during real-world deployment—risks that may not have been identifiable during pre-market conformity assessment—are detected and addressed.

Article 20 of the AI Act complements this by imposing corrective action and notification duties. When a provider identifies that a high-risk AI system does not comply with the Act's requirements, it must immediately take necessary corrective actions, which may include withdrawal, recall, or disabling of the system. Providers must also inform relevant national competent authorities and, where applicable, their authorized representatives, of any non-compliance and the corrective measures taken.

The enforcement architecture rests on independent supervisory authorities whose powers must be established in national law. The requirement for supervisory independence is anchored in Article 16(3) of the relevant framework, as well as Article 16(2) TFEU and Article 39 TEU. National legislation must equip these authorities with the power to refer violations to judicial authorities and initiate judicial proceedings—a power whose necessity was affirmed by the Court of Justice in Schrems (CJEU, 6 October 2015, C-362/14).

Key Developments

The Court of Justice's ruling in Schrems established that supervisory authorities must possess effective judicial enforcement tools, including the ability to bring proceedings before courts when violations are identified. This principle, originally developed under the 1995 Privacy Directive, carries forward into the AI Act enforcement ecosystem: national authorities overseeing post-market compliance must have teeth, not merely advisory mandates.

The independence guarantee for supervisory authorities has been treated by the Court of Justice as essential to ensuring the effectiveness and reliability of compliance oversight. This means that providers subject to Article 72 monitoring obligations should expect enforcement from authorities that are structurally insulated from external influence—political or commercial—and that can escalate non-compliance to judicial proceedings when corrective actions under Article 20 are deemed insufficient.

Practical Guidance

  • Draft a documented post-market monitoring plan before market placement. Article 72 requires this plan to be proportional to the AI system's risk profile. Tailor data collection methods, analysis frequency, and escalation triggers to the specific use case and risk categorization of the system.

  • Establish internal triggers for Article 20 corrective action. Define clear thresholds within the monitoring plan that, when breached, automatically initiate the corrective action workflow—including withdrawal, recall, or disabling—and set timelines for notifying competent authorities.

  • Map your notification chain in advance. Identify the relevant national competent authorities and authorized representatives for each jurisdiction where the AI system is deployed, so that Article 20 notification obligations can be discharged immediately upon identification of non-compliance.

  • Ensure monitoring captures real-world drift, not just technical performance. The rationale behind Article 72 is that pre-market assessment cannot anticipate all deployment risks. Monitoring must therefore track contextual factors—input data shifts, user behavior changes, and emerging harms—not merely system accuracy metrics.

  • Anticipate judicial escalation. Given that supervisory authorities must be empowered to refer violations to judicial authorities, treat post-market monitoring findings as potentially litigation-relevant records. Maintain audit-ready documentation of all monitoring activities, identified risks, and corrective actions taken.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 15
Art. 3(25) ‘post-market monitoring system’ means all activities carried out by providers of AI systems to collect and review experience gained from the use of AI… AI Act Art. 3(26) ‘market surveillance authority’ means the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020… AI Act Art. 3(48) ‘national competent authority’ means a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union… AI Act Art. 5(4) Without prejudice to paragraph 3, each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for law enforcement p… AI Act art 72 Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems AI Act Jun 2024 rec 155 Recital 155 — high-risk AI post-market monitoring systems AI Act Jun 2024 art 85 Right to lodge a complaint with a market surveillance authority AI Act Jun 2024 art 20 Corrective actions and duty of information AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 159 Recital 159 — biometric AI surveillance authority powers AI Act Jun 2024 rec 156 Recital 156 — market surveillance and compliance enforcement framework AI Act Jun 2024 rec 130 Recital 130 — rapid deployment of innovative AI systems AI Act Jun 2024 rec 36 Recital 36 — biometric system use notification and reporting AI Act Jun 2024 rec 114 Recital 114 — systemic risk AI model obligations AI Act Jun 2024 rec 170 Recital 170 — complaint rights for AI regulation infringement AI Act Jun 2024 rec 161 Recital 161 — Union and national supervision responsibilities for general-purpose AI AI Act Jun 2024 rec 141 Recital 141 — real world testing conditions without sandbox AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024 rec 153 Recital 153 — national competent authorities designation AI Act Jun 2024
Guidance 2
edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 32024 on data protection authorities role in the Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework EDPB Jul 2024
Literature 4
Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 Accounting and Auditing From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence Accounting and Auditing Jul 2026 Zeszyt Prawniczy UAM Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act Zeszyt Prawniczy UAM Dec 2025 International Journal of Social Sciences and Public Administration Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection International Journal of Social Sciences and Public Administration Jan 2025