Chapter IX · Post-market monitoring, information sharing and market surveillance
Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
Official text
Each paragraph records where its wording comes from. Only text reproduced unchanged from the Official Journal is authentic; consolidated text is editorial and has no legal value. Paragraphs, subparagraphs and points each have their own link.
Providers shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.
Authentic — as published in the Official Journal
The post-market monitoring system shall actively and systematically collect, document and analyse relevant data which may be provided by deployers or which may be collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of AI systems with the requirements set out in Chapter III, Section 2. Where relevant, post-market monitoring shall include an analysis of the interaction with other AI systems. This obligation shall not cover sensitive operational data of deployers which are law-enforcement authorities.
Authentic — as published in the Official Journal
The post-market monitoring system shall be based on a post-market monitoring plan. The post-market monitoring plan shall be part of the technical documentation referred to in Annex IV. The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027.
Consolidated text — no legal value · amended by Regulation (EU) 2026/1744
For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, where a post-market monitoring system and plan are already established under that legislation, in order to ensure consistency, avoid duplications and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary elements described in paragraphs 1, 2 and 3 using the template referred in paragraph 3 into systems and plans already existing under that legislation, provided that it achieves an equivalent level of protection.
The first subparagraph of this paragraph shall also apply to high-risk AI systems referred to in point 5 of Annex III placed on the market or put into service by financial institutions that are subject to requirements under Union financial services law regarding their internal governance, arrangements or processes.
Authentic — as published in the Official Journal
The formal analysis of Article 72
Article 6 is formalised first. The remaining articles follow.
Article 72 is formalised node by node: each rule as a deontic position with its operator, each exception with its rank, each predicate resolved against the definitions in Article 3.
What members get, per article
- the rule logic: every norm as a formal position, with the defeater chain that decides which exception wins
- the competency questions and their answers, every unanswered one marked as a gap and named
- the ontology: predicates bound to AISV (AI Standardisation Vocabulary) and to the definitions they depend on, exportable as JSON-LD and OWL
- the documentation: the Article 6(4) assessment record generated from a fact set, with its derivation and the version of the law it was decided against
Built for providers claiming the 6(3) derogation, for the counsel who has to defend that claim, and for the auditor who reads it afterwards.
Access is invite-only and opening in stages. Article 6 is formalised first; the remaining articles follow.
No mail client? Write to hello@signatu.com
Already a member? Sign in
What the article requiresUnder review
- 01Establish and document a post-market monitoring system proportionate to the nature of the AI technology and to the risks of the system.
- 02Actively and systematically collect, document and analyse relevant data on the performance of the system throughout its lifetime — from deployers, or collected by the provider itself.
- 03Cover, where relevant, interaction with other AI systems.
- 04Use the data to evaluate continuous compliance with the requirements of Chapter III, Section 2.
- 05Base the system on a post-market monitoring plan that is part of the technical documentation under Annex IV and follows the Commission's template.
- 06Feed findings back into the risk management system under Article 9 and into corrective action under Article 20.
- 07Where a serious incident is identified, report it under Article 73.
- 08Where the provider is already subject to post-market monitoring under other Union harmonisation legislation, integrate the two to avoid duplication.
In practiceUnder review
Post-market monitoring is the article most often written as a promise rather than a system. It needs named data sources, a cadence, thresholds that trigger review, and a traceable link from an observation to a change in the risk file. EN 18286 pulls it into the quality management system, which is where it stays alive.
Standards addressing this articleUnder review
- EN 18286Quality management system for EU AI Act regulatory purposesPublished on 22 July 2026. Not yet cited in the Official Journal. · 15 modelled requirements
- prEN 18228AI risk managementRejected at public enquiry (closed 30 July 2026) by a majority of national standards bodies. The Commission's preliminary assessment found it a valid candidate for harmonisation.