What Art. 72 requires
Art. 72 AI Act obliges providers of high-risk AI systems to establish and document a post-market monitoring system, proportionate to the AI technology and the risks of the system (Art. 72(1)). This is not a one-off check but an obligation spanning the entire lifetime of the system: performance data made available by providers or deployers, or collectable from other sources, must be actively and systematically collected, documented and analysed (Art. 72(2)). The aim is for the provider to continuously assess whether the requirements set out in Chapter III, Section 2 of the AI Act continue to be met — not merely at the point of conformity assessment, but throughout ongoing operation.
Where relevant, this also includes analysing interaction with other AI systems. An exception applies to sensitive operational data of deployers that are law enforcement authorities — this data need not feed into the monitoring system.
The monitoring plan
The monitoring system must not arise on an ad hoc basis; it must rest on a documented plan that forms part of the technical documentation under Annex IV (Art. 72(3)). The Commission was expected to adopt, by 2 February 2026, an implementing act providing a template for this plan together with the list of elements to be included. As things stand today (11 August 2026), that deadline has already passed — check the current status of the implementing act before finalising your plan, as the detailed requirements for the template may still be refined.
In practice, this means a monitoring plan without clearly defined responsibilities, data sources, evaluation intervals and escalation routes is not sufficient. The plan must be specific enough that an auditor can trace which data is evaluated, when, and by whom, and how deviations from expected performance translate into corrective measures.
When the obligation actually applies
Art. 72 forms part of the high-risk obligations under Chapter III, Section 2. The Digital Omnibus on AI has shifted the application dates for these obligations: for high-risk AI systems under Annex III (for example in the areas of employment, creditworthiness and law enforcement), the obligation now applies only from 2 December 2027, rather than from 2 August 2026 as originally envisaged. For high-risk AI systems covered by Annex I product legislation, the deadline shifts to 2 August 2028. The date of 2 August 2026 itself does not concern Art. 72 but the transparency obligations under Art. 50 — the two dates should not be confused in your planning.
Those who leave the additional time unused are wasting it: a functioning monitoring system cannot be conjured up at short notice, since it requires data pipelines, allocated responsibilities and evaluation routines that only mature once embedded in live operation.
Integration rather than duplication
Art. 72(4) allows providers already subject to sector-specific market surveillance under Annex I, Section A, to use their existing monitoring systems and plans rather than building parallel structures — provided the existing system achieves an equivalent level of protection and the elements required under Art. 72(1) to (3) are integrated using the Commission template. The same applies to high-risk AI systems under Annex III, point 5, placed on the market by financial institutions that are already subject to governance requirements under financial services law. This is particularly relevant for organisations that already run, for instance, DORA reporting processes or product safety surveillance — here it is worth conducting a gap analysis rather than maintaining two separate systems in parallel.
Common gaps in practice
Advisory work repeatedly reveals the same weaknesses: monitoring systems exist only on paper, without operational data actually flowing back into them. Deployer feedback is not captured in a structured way, so the provider only notices performance deviations once it is too late. And the monitoring plan is drawn up as a one-off document for conformity assessment rather than maintained as a living management tool. Those who start now defining data flows and responsibilities for post-market monitoring will, by the relevant application date — 2 December 2027 or 2 August 2028 — have a robust process rather than a hastily assembled document.
Whether, and in which category, your AI system qualifies as high-risk, and which deadlines specifically apply to you, can be clarified in a few minutes using our free risk assessment at /einstufung.