WHAT THE ARTICLE IS ABOUT
Compliance does not end at launch — it continues throughout the product lifecycle
Article 72 establishes post-market monitoring as a mandatory ongoing obligation for high-risk AI providers. It shifts compliance from a one-time pre-market exercise to a continuous process — requiring providers to actively track how their systems perform in the real world and respond to what they find. This is the AI Act’s equivalent of pharmacovigilance in the medical devices world.
WHAT IT SAYS
Active monitoring, documented plan, integration with existing systems
- Providers of high-risk AI systems must establish and document a post-market monitoring system
- The monitoring system must actively and systematically collect, document and analyse relevant data on the performance of the AI system throughout its lifetime
- Data may come from deployers, users, or other sources — including incident reports, performance logs, and feedback
- Monitoring must enable the provider to evaluate continuous compliance with the Section 2 technical requirements
- The monitoring system must be based on a post-market monitoring plan, which forms part of the technical documentation under Annex IV
- The Commission will adopt an implementing act with a template for the monitoring plan
- Where a post-market monitoring system already exists under other EU legislation (medical devices, financial services), providers may integrate AI Act requirements into that system rather than creating a separate one
- The monitoring obligation does not apply to sensitive operational data from law enforcement deployers
WHO IS AFFECTED
All providers of high-risk AI systems after market placement
- All providers of high-risk AI systems — monitoring is mandatory from the moment of market placement
- Deployers who share performance data with providers in fulfilment of Article 26 obligations
- The Commission which will publish the monitoring plan template
- Market surveillance authorities who may request monitoring records during investigations
WHAT IT MEANS FOR SMES
Build monitoring into your product from day one — not as an afterthought
- Post-market monitoring cannot be bolted on after launch — the data collection infrastructure needs to be designed into your product before it goes to market
- Define your monitoring metrics before launch: what performance indicators will tell you whether your system continues to meet its technical requirements? These become the basis of your monitoring plan
- Engage your deployers: they are a critical data source under Article 72, but they will only share performance data if you have a clear, contractual mechanism for them to do so — build this into your deployer agreements
- The Commission template will help structure your monitoring plan — wait for it before finalising your approach, but start designing your data collection architecture now
- If you already have monitoring obligations under GDPR, financial regulation or sector-specific law, integrate your AI Act monitoring into those existing systems rather than creating separate compliance processes
- Monitoring records are a core part of your technical documentation — store them securely and with sufficient retention to cover the system’s expected lifetime
Related Articles
- Article 20 — Corrective actions (what to do when monitoring identifies problems)
- Article 73 — Reporting of serious incidents (the escalation obligation when monitoring finds serious issues)
- Article 26 — Deployer obligations (deployers must provide monitoring data to providers)
- Article 18 — Documentation keeping (monitoring records form part of technical documentation)
