Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter IX Section 1 · Article 72

Article 72: post-market monitoring

Conformity assessment proves the system was compliant on the day it shipped. Article 72 is how you demonstrate it still is. It is the obligation that converts compliance from a project into an operating process, and the one most likely to be discovered late, because nothing forces it until something goes wrong.

Art. 72Annex IV heading 9Art. 9(2)(c) loop
When this applies. This is a Chapter III obligation on providers of high-risk AI systems. Following Regulation (EU) 2026/1744 it applies from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for high-risk AI embedded in Annex I regulated products. Full timeline →

What the system has to do

Establish and document a post-market monitoring system proportionate to the nature of the AI technologies and the risks. It must actively and systematically collect, document and analyse relevant data on performance throughout the system’s lifetime, data provided by deployers or collected through other sources, allowing you to evaluate continuous compliance with the Chapter III Section 2 requirements. Where relevant, it includes analysis of interaction with other AI systems.

Three words that set the bar

Actively: waiting for complaints is not monitoring. Systematically: ad hoc review does not qualify. Continuous compliance: the object of measurement is not user satisfaction or uptime, it is whether Articles 9 to 15 are still satisfied.

The monitoring plan

The system must be based on a post-market monitoring plan, and that plan is part of the Annex IV technical documentation: heading 9. Two consequences:

  • It is examined during conformity assessment, before the system ships. You write the plan before you have any data.
  • Changing how you monitor is a change to the technical file, not a private operational decision.

The Commission was to adopt an implementing act establishing a template for the plan and the list of elements to be included, by 2 February 2026. Check the current position before drafting from scratch — if the template exists, use it.

Art. 72Annex IV point 9

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

What to actually measure

Practical recommendation, not a legal requirement. The Regulation states the outcome; these are the measures that make “continuous compliance” demonstrable article by article.

AgainstLive measure
Art. 15 accuracyThe same declared metric, computed on production data, tracked against the figure in the instructions for use.
Art. 10 dataInput distribution drift against the training distribution; proportion of inputs outside the specified input-data envelope.
Art. 14 oversightOverride rate, time per review, escalation volume. A rate collapsing toward zero is a signal. Article 14 →
Art. 9 riskRealised occurrences of risks in the register; new risks not previously identified.
Art. 15 feedback loopsEvidence that outputs are not degrading the inputs to future operations.
Art. 73 incidentsNear misses as well as reportable incidents. Near misses are where the monitoring earns its cost.

The loop back to Article 9

Article 9(2)(c) requires the risk management system to evaluate risks emerging from post-market monitoring data. Article 72 exists to produce it. These are not two programmes; they are one cycle with two article numbers, and the evidence that the cycle turns, dated risk-file updates triggered by monitoring findings, is what distinguishes a live system from a documented intention.

Deployers are inside the loop too: Article 26(5) requires them to monitor operation per the instructions for use and inform the provider where they have reason to consider the system may present a risk.

Status labels on this page

Verified fact: The Art. 72 requirements, the plan's place in Annex IV, the Commission implementing act and its 2 February 2026 date, and the Art. 9(2)(c) linkage.

Expert analysis: The measurement table, which is our practice rather than a prescribed list.

Unsettled: The final content of the Commission template. Confirm current status before drafting.

Next step

Monitoring is a process, not a document

The plan is written once and examined at conformity assessment. The process runs for the life of the system, and the evidence it produces is what a market surveillance authority will ask for first.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Questions

What is post-market monitoring under the EU AI Act?

Article 72 requires providers of high-risk AI systems to establish and document a post-market monitoring system proportionate to the nature of the AI technologies and the risks. The system must actively and systematically collect, document and analyse relevant data on the performance of high-risk AI systems throughout their lifetime, provided by deployers or collected through other sources, allowing the provider to evaluate continuous compliance with the Chapter III Section 2 requirements. Where relevant it includes analysis of interaction with other AI systems.

What is the post-market monitoring plan?

Article 72 requires the post-market monitoring system to be based on a post-market monitoring plan, which forms part of the technical documentation referred to in Annex IV. The European Commission was to adopt an implementing act laying down detailed provisions establishing a template for the plan and the list of elements to be included in it, by 2 February 2026.

Is post-market monitoring a provider or deployer obligation?

Article 72 is a provider obligation. Deployers have related but separate duties: Article 26(5) requires deployers to monitor the operation of the system on the basis of the instructions for use and to inform the provider where they have reason to consider the system may present a risk, and Article 26(6) requires them to keep logs under their control for at least six months.

How does post-market monitoring relate to the risk management system?

They are a loop. Article 9(2)(c) requires the risk management system to evaluate risks that may emerge based on data gathered from the post-market monitoring system. Article 72 exists to generate that data. A risk file that contains no post-market input is incomplete for any system that has been live for a meaningful period.