Post-market monitoring
Ongoing tracking and review of how an AI system performs in the real world after it has been released, to catch problems early.
The Simple Version
Ongoing tracking and review of how an AI system performs in the real world after it has been released, to catch problems early.
Detailed Explanation
Article 72 requires providers to establish, document, and implement a post-market monitoring plan as part of their quality management system. The plan must specify metrics, data collection mechanisms, and review cadences. For systems that collect user interaction data, providers must analyse this data for accuracy drift, emerging harms, or unanticipated use patterns. Where serious incidents or malfunctions are identified, providers must notify national competent authorities without undue delay and, for a serious incident, within defined timeframes. Post-market monitoring integrates with the EU AI Act's incident management provisions.
Key Characteristics
- Mandatory for all high-risk AI system providers under Article 72
- Must be documented in the post-market monitoring plan within technical documentation
- Triggers incident-reporting obligations when serious incidents are detected
- Should feed system updates and, where necessary, trigger new conformity assessments
Why It Matters
Product operations and AI governance teams must build post-market monitoring into production MLOps pipelines, including automated data collection, drift detection, and escalation workflows.
Real-World Analogy
Like the pharmacovigilance system pharmaceutical companies run after a drug is approved, continuously tracking adverse events, updating safety labels, and reporting to health authorities.
Common Misconceptions
- Post-market monitoring is optional best practice, it is a mandatory legal requirement for high-risk AI system providers.
- Periodic internal reviews satisfy the requirement, providers must actively collect real-world performance data, not only review internally generated reports.