# Post-Market Monitoring for AI Systems — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/post-market-monitoring-ai
> Sources are cited per item. Verify against the official texts before relying on them.

Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and critical component that warrants its own topic.

## Overview

## Legal Framework

Post-market monitoring for AI systems is primarily governed by Article 72 of the AI Act, which requires providers of high-risk AI systems to establish and document a post-market monitoring plan. This plan must be proportional to the nature of the AI system and the risks it presents, and must serve to collect, document, and analyze data on the system's performance and compliance throughout its lifecycle. The monitoring obligation is designed to ensure that risks emerging during real-world deployment—risks that may not have been identifiable during pre-market conformity assessment—are detected and addressed.

Article 20 of the AI Act complements this by imposing corrective action and notification duties. When a provider identifies that a high-risk AI system does not comply with the Act's requirements, it must immediately take necessary corrective actions, which may include withdrawal, recall, or disabling of the system. Providers must also inform relevant national competent authorities and, where applicable, their authorized representatives, of any non-compliance and the corrective measures taken.

The enforcement architecture rests on independent supervisory authorities whose powers must be established in national law. The requirement for supervisory independence is anchored in Article 16(3) of the relevant framework, as well as Article 16(2) TFEU and Article 39 TEU. National legislation must equip these authorities with the power to refer violations to judicial authorities and initiate judicial proceedings—a power whose necessity was affirmed by the Court of Justice in *Schrems* (CJEU, 6 October 2015, C-362/14).

## Key Developments

The Court of Justice's ruling in *Schrems* established that supervisory authorities must possess effective judicial enforcement tools, including the ability to bring proceedings before courts when violations are identified. This principle, originally developed under the 1995 Privacy Directive, carries forward into the AI Act enforcement ecosystem: national authorities overseeing post-market compliance must have teeth, not merely advisory mandates.

The independence guarantee for supervisory authorities has been treated by the Court of Justice as essential to ensuring the effectiveness and reliability of compliance oversight. This means that providers subject to Article 72 monitoring obligations should expect enforcement from authorities that are structurally insulated from external influence—political or commercial—and that can escalate non-compliance to judicial proceedings when corrective actions under Article 20 are deemed insufficient.

## Practical Guidance

- **Draft a documented post-market monitoring plan before market placement.** Article 72 requires this plan to be proportional to the AI system's risk profile. Tailor data collection methods, analysis frequency, and escalation triggers to the specific use case and risk categorization of the system.

- **Establish internal triggers for Article 20 corrective action.** Define clear thresholds within the monitoring plan that, when breached, automatically initiate the corrective action workflow—including withdrawal, recall, or disabling—and set timelines for notifying competent authorities.

- **Map your notification chain in advance.** Identify the relevant national competent authorities and authorized representatives for each jurisdiction where the AI system is deployed, so that Article 20 notification obligations can be discharged immediately upon identification of non-compliance.

- **Ensure monitoring captures real-world drift, not just technical performance.** The rationale behind Article 72 is that pre-market assessment cannot anticipate all deployment risks. Monitoring must therefore track contextual factors—input data shifts, user behavior changes, and emerging harms—not merely system accuracy metrics.

- **Anticipate judicial escalation.** Given that supervisory authorities must be empowered to refer violations to judicial authorities, treat post-market monitoring findings as potentially litigation-relevant records. Maintain audit-ready documentation of all monitoring activities, identified risks, and corrective actions taken.

## Legislation (full text of key provisions)

### Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

*Source: AI Act, aiact-art-72-en, 2024-06-12 — https://overview.legal/posts/93175*

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Corrective actions and duty of information

*Source: AI Act, aiact-art-20-en, 2024-06-12 — https://overview.legal/posts/92298*

### Recital 155 — high-risk AI post-market monitoring systems

*Source: AI Act, aiact-rec-155-en, 2024-06-12 — https://overview.legal/posts/93992*

In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.

### Recital 81 — provider quality management system

*Source: AI Act, aiact-rec-81-en, 2024-06-12 — https://overview.legal/posts/93844*

The provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

### Recital 156 — market surveillance and compliance enforcement framework

*Source: AI Act, aiact-rec-156-en, 2024-06-12 — https://overview.legal/posts/93994*

In order to ensure an appropriate and effective enforcement of the requirements and obligations set out by this Regulation, which is Union harmonisation legislation, the system of market surveillance and compliance of products established by Regulation (EU) 2019/1020 should apply in its entirety. Market surveillance authorities designated pursuant to this Regulation should have all enforcement powers laid down in this Regulation and in Regulation (EU) 2019/1020 and should exercise their powers and carry out their duties independently, impartially and without bias. Although the majority of AI systems are not subject to specific requirements and obligations under this Regulation, market surveillance authorities may take measures in relation to all AI systems when they present a risk in accordance with this Regulation. Due to the specific nature of Union institutions, agencies and bodies falling within the scope of this Regulation, it is appropriate to designate the European Data Protection Supervisor as a competent market surveillance authority for them. This should be without prejudice to the designation of national competent authorities by the Member States. Market surveillance activities should not affect the ability of the supervised entities to carry out their tasks independently, when such independence is required by Union law.

### Recital 141 — real world testing conditions without sandbox

*Source: AI Act, aiact-rec-141-en, 2024-06-12 — https://overview.legal/posts/93964*

In order to accelerate the process of development and the placing on the market of the high-risk AI systems listed in an annex to this Regulation, it is important that providers or prospective providers of such systems may also benefit from a specific regime for testing those systems in real world conditions, without participating in an AI regulatory sandbox. However, in such cases, taking into account the possible consequences of such testing on individuals, it should be ensured that appropriate and sufficient guarantees and conditions are introduced by this Regulation for providers or prospective providers. Such guarantees should include, inter alia, requesting informed consent of natural persons to participate in testing in real world conditions, with the exception of law enforcement where the seeking of informed consent would prevent the AI system from being tested. Consent of subjects to participate in such testing under this Regulation is distinct from, and without prejudice to, consent of data subjects for the processing of their personal data under the relevant data protection law. It is also important to minimise the risks and enable oversight by competent authorities and therefore require prospective providers to have a real-world testing plan submitted to competent market surveillance authority, register the testing in dedicated sections in the EU database subject to some limited exceptions, set limitations on the period for which the testing can be done and require additional safeguards for persons belonging to certain vulnerable groups, as well as a written agreement defining the roles and responsibilities of prospective providers and deployers and effective oversight by competent personnel involved in the real world testing. Furthermore, it is appropriate to envisage additional safeguards to ensure that the predictions, recommendations or decisions of the AI system can be effectively reversed and disregarded and that personal data is protected and is deleted when the subjects have withdrawn their consent to participate in the testing without prejudice to their rights as data subjects under the Union data protection law. As regards transfer of data, it is also appropriate to envisage that data collected and processed for the purpose of testing in real-world conditions should be transferred to third countries only where appropriate and applicable safeguards under Union law are implemented, in particular in accordance with bases for transfer of personal data under Union law on data protection, while for non-personal data appropriate safeguards are put in place in accordance with Union law, such as Regulations (EU) 2022/868 (42) and (EU) 2023/2854 (43) of the European Parliament and of the Council.

### Recital 36 — biometric system use notification and reporting

*Source: AI Act, aiact-rec-36-en, 2024-06-12 — https://overview.legal/posts/93754*

In order to carry out their tasks in accordance with the requirements set out in this Regulation as well as in national rules, the relevant market surveillance authority and the national data protection authority should be notified of each use of the real-time biometric identification system. Market surveillance authorities and the national data protection authorities that have been notified should submit to the Commission an annual report on the use of real-time biometric identification systems.

### Recital 114 — systemic risk AI model obligations

*Source: AI Act, aiact-rec-114-en, 2024-06-12 — https://overview.legal/posts/93910*

The providers of general-purpose AI models presenting systemic risks should be subject, in addition to the obligations provided for providers of general-purpose AI models, to obligations aimed at identifying and mitigating those risks and ensuring an adequate level of cybersecurity protection, regardless of whether it is provided as a standalone model or embedded in an AI system or a product. To achieve those objectives, this Regulation should require providers to perform the necessary model evaluations, in particular prior to its first placing on the market, including conducting and documenting adversarial testing of models, also, as appropriate, through internal or independent external testing. In addition, providers of general-purpose AI models with systemic risks should continuously assess and mitigate systemic risks, including for example by putting in place risk-management policies, such as accountability and governance processes, implementing post-market monitoring, taking appropriate measures along the entire model’s lifecycle and cooperating with relevant actors along the AI value chain.

## Guidance

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

## Literature

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

### From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

*Source: Accounting and Auditing, 2026-07-15 — https://overview.legal/posts/132365 — original: https://doi.org/10.3390/accountaudit2030012*

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring.

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### Regulatory Responses to Data Breaches: Evaluating the Effectiveness of GDPR and CCPA in Consumer Protection

*Source: International Journal of Social Sciences and Public Administration, 2025-01-23 — https://overview.legal/posts/132539 — original: https://doi.org/10.62051/ijsspa.v6n1.22*

In the digital age, data breaches have become a significant threat to consumer privacy, prompting the implementation of stringent data protection regulations worldwide. This paper evaluates the effectiveness of two prominent regulatory frameworks, the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States, in safeguarding consumer data and responding to data breaches. Through a comparative analysis of their key provisio

## Related topics

- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Market Surveillance and Control of AI Systems** — https://overview.legal/topics/market-surveillance-control-ai
  This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems
- **AI Incident Notification** — https://overview.legal/topics/serious-incident-notification-ai
  The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated cov
- **Authority Access Rights to AI Systems and Documentation** — https://overview.legal/topics/authority-access-rights-ai-systems
  This new topic would specifically address the rights and procedures for competent authorities to access AI systems, facilities, documentation, and data during o
- **Interim Measures under AI Act** — https://overview.legal/topics/interim-measures-ai-act
  This new topic is needed to specifically address interim measures provisions in the AI Act, which allow authorities to take temporary protective actions against
- **Conformity Body Notification** — https://overview.legal/topics/conformity-assessment-body-notification
  This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Ac

---
Generated by overview.legal · https://overview.legal/topics/post-market-monitoring-ai · 2026-08-22
