Article 72: post-market monitoring
Conformity assessment proves the system was compliant on the day it shipped. Article 72 is how you demonstrate it still is. It is the obligation that converts compliance from a project into an operating process, and the one most likely to be discovered late, because nothing forces it until something goes wrong.
What the system has to do
Establish and document a post-market monitoring system proportionate to the nature of the AI technologies and the risks. It must actively and systematically collect, document and analyse relevant data on performance throughout the system’s lifetime, data provided by deployers or collected through other sources, allowing you to evaluate continuous compliance with the Chapter III Section 2 requirements. Where relevant, it includes analysis of interaction with other AI systems.
Three words that set the bar
Actively: waiting for complaints is not monitoring. Systematically: ad hoc review does not qualify. Continuous compliance: the object of measurement is not user satisfaction or uptime, it is whether Articles 9 to 15 are still satisfied.
The monitoring plan
The system must be based on a post-market monitoring plan, and that plan is part of the Annex IV technical documentation: heading 9. Two consequences:
- It is examined during conformity assessment, before the system ships. You write the plan before you have any data.
- Changing how you monitor is a change to the technical file, not a private operational decision.
The Commission was to adopt an implementing act establishing a template for the plan and the list of elements to be included, by 2 February 2026. Check the current position before drafting from scratch — if the template exists, use it.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What to actually measure
Practical recommendation, not a legal requirement. The Regulation states the outcome; these are the measures that make “continuous compliance” demonstrable article by article.
| Against | Live measure |
|---|---|
| Art. 15 accuracy | The same declared metric, computed on production data, tracked against the figure in the instructions for use. |
| Art. 10 data | Input distribution drift against the training distribution; proportion of inputs outside the specified input-data envelope. |
| Art. 14 oversight | Override rate, time per review, escalation volume. A rate collapsing toward zero is a signal. Article 14 → |
| Art. 9 risk | Realised occurrences of risks in the register; new risks not previously identified. |
| Art. 15 feedback loops | Evidence that outputs are not degrading the inputs to future operations. |
| Art. 73 incidents | Near misses as well as reportable incidents. Near misses are where the monitoring earns its cost. |
The loop back to Article 9
Article 9(2)(c) requires the risk management system to evaluate risks emerging from post-market monitoring data. Article 72 exists to produce it. These are not two programmes; they are one cycle with two article numbers, and the evidence that the cycle turns, dated risk-file updates triggered by monitoring findings, is what distinguishes a live system from a documented intention.
Deployers are inside the loop too: Article 26(5) requires them to monitor operation per the instructions for use and inform the provider where they have reason to consider the system may present a risk.
Status labels on this page
Verified fact: The Art. 72 requirements, the plan's place in Annex IV, the Commission implementing act and its 2 February 2026 date, and the Art. 9(2)(c) linkage.
Expert analysis: The measurement table, which is our practice rather than a prescribed list.
Unsettled: The final content of the Commission template. Confirm current status before drafting.
Monitoring is a process, not a document
The plan is written once and examined at conformity assessment. The process runs for the life of the system, and the evidence it produces is what a market surveillance authority will ask for first.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
What is post-market monitoring under the EU AI Act?
Article 72 requires providers of high-risk AI systems to establish and document a post-market monitoring system proportionate to the nature of the AI technologies and the risks. The system must actively and systematically collect, document and analyse relevant data on the performance of high-risk AI systems throughout their lifetime, provided by deployers or collected through other sources, allowing the provider to evaluate continuous compliance with the Chapter III Section 2 requirements. Where relevant it includes analysis of interaction with other AI systems.
What is the post-market monitoring plan?
Article 72 requires the post-market monitoring system to be based on a post-market monitoring plan, which forms part of the technical documentation referred to in Annex IV. The European Commission was to adopt an implementing act laying down detailed provisions establishing a template for the plan and the list of elements to be included in it, by 2 February 2026.
Is post-market monitoring a provider or deployer obligation?
Article 72 is a provider obligation. Deployers have related but separate duties: Article 26(5) requires deployers to monitor the operation of the system on the basis of the instructions for use and to inform the provider where they have reason to consider the system may present a risk, and Article 26(6) requires them to keep logs under their control for at least six months.
How does post-market monitoring relate to the risk management system?
They are a loop. Article 9(2)(c) requires the risk management system to evaluate risks that may emerge based on data gathered from the post-market monitoring system. Article 72 exists to generate that data. A risk file that contains no post-market input is incomplete for any system that has been live for a meaningful period.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →