Compliance 13 min read

Post-Market Monitoring Under the AI Act: Building Your Surveillance System

Conformity assessment gets most of the attention, but Article 72's post-market monitoring obligations are equally demanding. Here's how to build a surveillance system that keeps your AI systems compliant after they go live.

By Dr. Katharina Berger, Regulatory Affairs · Published

Compliance Doesn't End at Market Placement

Many organizations treat AI Act compliance as a one-time project: complete the conformity assessment, get the CE marking, register in the EU database, and declare victory. This approach is fundamentally wrong — and dangerous.

The EU AI Act builds a full lifecycle compliance model. Under Article 72, providers of high-risk AI systems must implement post-market monitoring systems that actively track their systems' performance in real-world conditions throughout the product's life. For deployers, Article 26(5) adds a parallel obligation to monitor how the system operates and report issues to providers.

What Article 72 Actually Requires

Article 72 mandates that providers of high-risk AI systems actively collect, document, and analyze data on system performance after market placement. The monitoring system must cover:

1. Ongoing Performance Tracking

Providers must monitor their AI systems' performance against the metrics defined in their technical documentation. This means tracking accuracy over time across different deployment contexts, monitoring for performance degradation (data drift, concept drift, distribution shift), comparing real-world outcomes against pre-market testing results, and identifying any systematic failures or unexpected behaviours.

2. User and Deployer Feedback Collection

Providers must have mechanisms to collect feedback from deployers and, where appropriate, from users and affected persons — including structured feedback channels, mechanisms for deployers to report cases where the AI output was overridden, and feedback about whether instructions for use were sufficient.

3. Documentation Updates

Post-market monitoring findings must flow back into the technical documentation. If monitoring reveals performance characteristics that differ from pre-market testing, the documentation must be updated. This creates a living documentation system — not a static document produced once for conformity assessment.

Serious Incident Reporting: The Critical Obligation

Article 73 of the AI Act establishes mandatory incident reporting for providers of high-risk AI systems with tight deadlines:

Incident Type Reporting Deadline
Death or serious health impact15 days from awareness
Serious disruption or harm15 days from awareness
Other serious incidents3 months from awareness
Near-misses (systemic risk GPAI)2 weeks from awareness

Building Your Post-Market Monitoring System

A robust post-market monitoring system has five interconnected components:

Component 1: Performance Monitoring Infrastructure

Build automated monitoring pipelines that capture model inputs and outputs, calculate performance metrics against pre-defined thresholds, detect statistical drift in input data distributions, trigger alerts when performance degrades below acceptable levels, and maintain audit logs of model operation.

Component 2: Human Review Processes

Establish regular model review cadences, cross-functional review committees, clear criteria for escalation, and defined decision-making authority for corrective actions including system suspension.

Component 3: Incident Management

Build an AI-specific incident management system that captures reports from deployers and affected parties, classifies incidents by severity using the AI Act's definitions, triggers the appropriate reporting timeline, and documents corrective measures.

Component 4: Deployer Communication

Providers need structured deployer feedback channels, training for deployers on what constitutes a reportable incident, contractual obligations for deployers to report issues, and regular updates about monitoring findings and system changes.

Component 5: Documentation and Regulatory Interface

Every finding, assessment, and corrective action must be documented. Maintain a monitoring log, update technical documentation when monitoring reveals material changes, and keep records of all incidents and reports to authorities.

Corrective Actions and Market Withdrawal

When post-market monitoring reveals that a system poses unanticipated risks, providers must take corrective action. The AI Act's hierarchy of responses runs from issuing updated instructions or warnings, to software patches and model updates, to mandatory retraining, to market withdrawal or recall. Authorities can also mandate corrective actions — including ordering market withdrawal if monitoring reveals serious risks.

Need help designing your post-market monitoring framework? Browse our directory of AI compliance consultants who specialize in AI governance infrastructure.