Jump to

Post-Market Monitoring (AI Act)

What is post-market monitoring under the AI Act?

Post-market monitoring is the system that providers of high-risk AI systems must establish under Article 72: a documented, proportionate process for actively and systematically collecting and analysing data on the system’s performance in real use, throughout its lifetime, in order to verify continuous compliance. It runs on a post-market monitoring plan that forms part of the technical documentation and follows a Commission template. The premise is plain: conformity is not a certificate won once, but a state that must keep being demonstrated after release.

What the monitoring system feeds

  • Corrective action: drift, degraded accuracy or new misuse patterns must trigger fixes, warnings or withdrawal of the system;
  • Incident reporting: monitoring is how you detect a serious incident within the reporting clock;
  • Deployer feedback: Article 26 duties make deployers your sensors in the field — contracts should oblige structured feedback and access to logs.

The legal dimension: observability with a paper trail

For ML teams this is familiar model-observability work — drift dashboards, evaluation suites, logging. The legal delta is documentation: a written plan, defined thresholds, and a traceable line from each detection to the action taken. That record is what a market surveillance authority or a conformity assessment will ask for. Systems on the December 2027 runway should design monitoring in now rather than bolt it on at assessment time.

Turkish context

Türkiye has no equivalent obligation in force — KVKK and general product-safety rules govern domestically — but Turkish providers selling high-risk systems into the EU carry Article 72 in full. In practice the requirement arrives through customers: EU deployers ask for the monitoring plan during procurement. Building the plan alongside the model is far cheaper than reconstructing the evidence afterwards.

Do: write the monitoring plan together with engineering — thresholds, owners, escalation paths — and version it with each release. Don’t: let monitoring live only in dashboards; findings that never reach a documented decision do not exist for compliance purposes.

Sources. Regulation (EU) 2024/1689 (AI Act).