Skip to content
AIAC AI ASSURANCE COUNCIL

EU AI Act

Article 72 — Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems

Article 72 requires a provider to establish, document and run a system that actively collects and analyses field data across a high-risk system’s lifetime — for one specific purpose: evaluating whether it still complies. It is a conformity-monitoring duty, not a product-performance one, and that distinction decides most assessments.

§ 1 — Who it binds

Whose duty this is, and what it excludes

Provider

Providers of high-risk AI systems under either gateway. Deployers feed the system but carry no Article 72 duty of their own. Annex I Section B systems are outside it entirely under the amended scope provision — which now includes machinery, moved there by the Digital Omnibus, where equivalent monitoring is intended to be reinstated through the sectoral instrument instead.

§ 2 — In practice

Monitoring conformity, not performance

The operative words are that the monitoring must allow the provider to evaluate the continuous compliance of the system with the Chapter III Section 2 requirements. That is a narrower and harder target than what most organisations mean by AI monitoring. Uptime, latency, drift and complaint volumes measure product health. This article asks whether the declared accuracy figures still hold on the deployment population, whether representativeness survives as that population moves, and whether the oversight designed under Article 14 is still functioning as designed.

The Digital Omnibus changed how the plan is governed and, in one respect, strengthened it. The original text required the Commission to adopt an implementing act with a mandatory template; that empowerment was removed and replaced with guidance including a voluntary template, due considerably later. Two things did not change: the plan remains mandatory, and it is now expressly part of the Annex IV technical documentation. Providers who deferred building one while waiting for the template have been waiting for an artefact the obligation never depended on.

That relocation also creates the enforcement route worth knowing, because Article 72 is not enumerated in the penalty provision and — unlike most Section 2 requirements — is not reachable through the provider obligations either. The chain that will actually be used runs the other way: the plan is an Annex IV element, Annex IV is the technical documentation requirement, and that requirement sits in Section 2. So a missing plan is a fineable documentation defect at Union level, while a plan that exists and is never operated leaves only national exposure. That asymmetry is not stated anywhere in the practitioner literature and is worth an assessor’s attention. The same seam appears from the other side in Article 9, where the risk process must draw on post-market data — one loop, written into the Regulation twice, and commonly built as two systems that never meet.

§ 3 — When it applies

Already in force

  1. 2 August 2026

    The general application date. Chapter IX is not among the exceptions in Article 113, and the Digital Omnibus deferred only Chapter III Sections 1 to 3 — so this provision was not moved with the high-risk requirements it monitors.

§ 4 — What discharges it

What the monitoring has to produce

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    The plan itself, inside the technical documentation

    Not a standalone policy. The Annex IV file is where it belongs, and an assessor looking for it looks there first. Its absence is the one failure under this article with a clear route to a Union-level fine.

  2. 02

    A signal-to-requirement map

    Each monitored signal tied to the Section 2 requirement it bears on, with the threshold at which it becomes a compliance question rather than an engineering one. This is what separates conformity monitoring from product monitoring.

  3. 03

    A finding that came out of the monitoring, and what it changed

    Field data that never alters a risk rating or a declared figure indicates a system running alongside the compliance process rather than inside it. One traced example is worth more than the dashboard.

  4. 04

    Where integration is relied on, the equivalence argument

    A documented case that the existing sectoral or financial-services arrangement achieves an equivalent level of protection, addressing the elements this article requires rather than asserting general coverage.

§ 5 — Worked example

Worked example — good monitoring, wrong target

A provider of a high-risk recruitment system operates a mature monitoring stack: model drift alerting, weekly performance dashboards, a customer complaints queue and quarterly retraining. Two years of history, nothing missed. There is no document called a post-market monitoring plan, and none of the monitoring output has ever been mapped to a requirement of the Regulation.

Where does this leave the provider?

Exposed on the artefact and probably short on the substance. The plan is mandatory and is an element of the technical documentation, so its absence is a documentation defect reachable at Union level regardless of how good the monitoring is. On substance the question is what the monitoring is monitoring: drift alerting tells you the input distribution moved, and the article asks whether the declared accuracy still holds for the population the system is now being used on — related, not the same. The fix is mostly mapping rather than building. Take the signals that already exist, state which Section 2 requirement each one bears on, name the threshold at which a signal becomes a compliance question, and write down where that question goes. Most of the work is done; none of it is currently pointed at the Regulation.

§ 6 — What a weak answer looks like

MLOps offered as compliance

An MLOps stack offered as post-market monitoring. Drift detection, alert thresholds, dashboards and a retraining cadence — genuinely good engineering, pointed at model behaviour rather than at continued conformity. The tell is that no signal has a requirement behind it, so nothing the monitoring observes can ever become a compliance finding. The remedy is usually mapping rather than building, which is why this is among the cheaper findings to close and among the more common to leave open.

§ 7 — Exposure

Exposure — indirect, and easy to misjudge

No direct ceiling; exposure runs through the technical documentation

Article 72 is not enumerated in Article 99 and, unlike most Chapter III Section 2 requirements, is not reachable through the provider obligations in Article 16 either. Direct exposure is under Article 99(1) — the penalties each Member State lays down, which must be effective, proportionate and dissuasive but vary by jurisdiction. The Union-level route is indirect: the monitoring plan is an Annex IV element, so its absence is a technical-documentation defect reachable at €15 million or 3% under Article 99(4)(a). Market surveillance measures, including withdrawal, are frequently the more consequential outcome.

§ 8 — Elsewhere

The same requirement elsewhere

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • NIST AI RMF

    MANAGE 4.1 addresses implemented post-deployment monitoring plans, including capture of user input, appeal and override, incident response and change management. It is the closest single subcategory correspondence to this article.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 9 — provenance

The provision itself

This page sets out what the instrument requires and what discharges it. The official text is the authority — these go straight to it.

Certification

Assessed on the same standard of evidence

Every Council credential is examined on applied judgement against a published anchor, set out the way the obligations on this page are. The free AI Literacy Certificate is open to any adult today, and the register lists what is open for enrolment.