AI Center › Post-Market Monitoring & Logging
Global · The AI Lifecycle — Stage 11 of 14
Post-Market Monitoring & Logging
Stage 11 of 14 in The AI Lifecycle. Once a high-risk AI system is placed on the market, Regulation (EU) 2024/1689 requires the provider to run a documented post-market monitoring system, high-risk systems to record events automatically, providers and deployers to retain those logs, and market-surveillance authorities to act on any system found to present a risk.
This stage sets out what the EU AI Act (Regulation (EU) 2024/1689) requires for surveillance of a fielded high-risk AI system: post-market monitoring under Article 72, automatic logging under Article 12, log retention under Articles 19 and 26, the deployer monitoring duty under Article 26, and the market-surveillance procedures of Articles 74 and 79. It also records the serious-incident tracking that Article 55 places on providers of general-purpose AI models with systemic risk, and the operation, maintenance and continuous-validation processes described in ISO/IEC 5338:2023. Each requirement is stated as the named authority sets it out; applicability dates are given as they stand under Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which was published in the Official Journal on 24 July 2026 and is in force from 27 July 2026.
What post-market monitoring must a provider carry out under Article 72?
Article 72 requires the provider of a high-risk AI system to establish and document a post-market monitoring system proportionate to the AI technologies and the system's risks, and to use it to collect and analyse performance data across the system's lifetime.
Under EU AI Act Article 72(1), the provider of a high-risk AI system 'shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system.' Article 72(2) requires that system to 'actively and systematically collect, document and analyse relevant data' on the performance of the system throughout its lifetime, whether provided by deployers or drawn from other sources, so that the provider can evaluate the system's continuous compliance with the requirements in Chapter III, Section 2 (risk management, data governance, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity). Where relevant, the monitoring must include an analysis of the system's interaction with other AI systems. The same paragraph excludes sensitive operational data of deployers that are law-enforcement authorities. Article 3(25) frames the post-market monitoring system as all activities carried out by providers to collect and review experience gained from use, for the purpose of identifying any need to apply corrective or preventive actions. This surveillance runs continuously across the fielded lifetime, distinct from the pre-market conformity assessment carried out before the system is placed on the market.
Source: EU AI Act, Art. 72(1)-(2) — Regulation (EU) 2024/1689 ↗
What is the post-market monitoring plan, and has the Commission adopted the implementing act for it?
Article 72(3) requires the monitoring system to be based on a post-market monitoring plan that forms part of the Annex IV technical documentation, and directs the Commission to establish that plan's standardised form by an implementing act by 2 February 2026. As verified on 12 July 2026, that implementing act had not been published in the Official Journal.
Article 72(3) states that the post-market monitoring system 'shall be based on a post-market monitoring plan,' and that this plan 'shall be part of the technical documentation referred to in Annex IV.' The same paragraph directs the Commission to adopt an implementing act, under the examination procedure in Article 98(2), 'establishing a template for the post-market monitoring plan and the list of elements to be included in the plan by 2 February 2026.' As verified on 12 July 2026, no such implementing act had been published in the Official Journal; the European Commission (Shaping Europe's digital future) has indicated that, in the course of 2026, it will issue guidelines including 'a voluntary template for the post-market monitoring of high-risk AI systems.' Article 72(4) allows providers of systems already covered by the Union harmonisation legislation in Annex I, Section A, and financial institutions covered by point 5 of Annex III, to integrate the Article 72(1)-(3) elements into monitoring systems and plans that already exist under that legislation, provided an equivalent level of protection is achieved. The plan therefore sits inside the Annex IV documentation that a provider maintains while the system is on the market.
What automatic logging must a high-risk AI system provide under Article 12?
Article 12 requires that high-risk AI systems be technically able to record events (logs) automatically over their lifetime, with logging that supports risk identification, post-market monitoring and operation monitoring, and a specified minimum set of logs for remote biometric identification systems.
Article 12(1) requires that high-risk AI systems 'shall technically allow for the automatic recording of events (logs) over the lifetime of the system.' Article 12(2) ties this to traceability: the logging capabilities must enable the recording of events relevant for (a) identifying situations that may result in the system presenting a risk within the meaning of Article 79(1) or in a substantial modification, (b) facilitating the post-market monitoring referred to in Article 72, and (c) monitoring the operation of the system referred to in Article 26(5). Logging is thus the technical substrate that feeds both post-market monitoring and market surveillance. Article 12(3) sets a minimum for the remote biometric identification systems in point 1(a) of Annex III: the logs must at least record the period of each use (start and end date and time), the reference database against which input data was checked, the input data for which the search led to a match, and the identification of the natural persons involved in verifying the results under Article 14(5). Article 13 separately requires the instructions for use to describe the system's logging capabilities.
Who keeps the automatically generated logs, and for how long?
Both providers and deployers keep the automatically generated logs that are under their control for a period appropriate to the intended purpose and, in any event, of at least six months, unless other Union or national law provides otherwise. Financial institutions keep them within their existing regulatory documentation.
| Who retains | Logs covered | Retention period | Authority |
|---|---|---|---|
| Provider | Logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent under their control | A period appropriate to the intended purpose, of at least six months, unless other Union or national law provides otherwise | EU AI Act, Art. 19(1) — Regulation (EU) 2024/1689 |
| Deployer | Logs automatically generated by the high-risk AI system, to the extent under their control | A period appropriate to the intended purpose, of at least six months, unless other Union or national law provides otherwise | EU AI Act, Art. 26(6) — Regulation (EU) 2024/1689 |
| Provider that is a financial institution | The same automatically generated logs | Maintained as part of the documentation kept under Union financial services law | EU AI Act, Art. 19(2) — Regulation (EU) 2024/1689 |
| Deployer that is a financial institution | The same automatically generated logs | Maintained as part of the documentation kept under Union financial services law | EU AI Act, Art. 26(6), second subparagraph — Regulation (EU) 2024/1689 |
What monitoring must a deployer of a high-risk AI system carry out?
Article 26(5) requires deployers to monitor the operation of the system on the basis of the instructions for use, to inform the provider where relevant under Article 72, and to suspend use and notify authorities where they find the system presents a risk or a serious incident has occurred.
Article 26(5) requires deployers to 'monitor the operation of the high-risk AI system on the basis of the instructions for use' and, where relevant, to inform the provider in accordance with Article 72. If a deployer has reason to consider that using the system in line with the instructions may result in the system presenting a risk within the meaning of Article 79(1), the deployer must, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and suspend use of the system. Where a deployer identifies a serious incident, it must immediately inform first the provider, then the importer or distributor and the relevant market surveillance authorities; if the provider cannot be reached, Article 73 applies mutatis mutandis. As with the provider's system, this obligation does not cover sensitive operational data of deployers that are law-enforcement authorities. For deployers that are financial institutions, the monitoring obligation is treated as fulfilled by complying with internal-governance rules under Union financial services law. The deployer's monitoring and the provider's post-market monitoring system are linked: deployer observations are an explicit data source that Article 72(2) contemplates.
What market-surveillance powers apply to AI systems once they are on the market?
Article 74 makes Regulation (EU) 2019/1020 applicable to AI systems and gives designated market-surveillance authorities access to documentation and to training, validation and testing data, and to source code on a reasoned request under stated conditions.
Article 74(1) makes Regulation (EU) 2019/1020 on market surveillance applicable to AI systems, with references to an 'economic operator' read as covering all operators identified in Article 2(1) of the AI Act and references to a 'product' read as covering AI systems in scope. For high-risk systems tied to products under the Annex I, Section A legislation, the market surveillance authority is the one designated under those acts (Article 74(3)); for systems used by regulated financial institutions, it is the relevant financial-supervision authority (Article 74(6)); and for certain Annex III systems used in law enforcement, border management, justice and democracy, Member States designate data-protection or equivalent authorities (Article 74(8)). Article 74(12) grants these authorities, where relevant and necessary, full access to the documentation and to the training, validation and testing data sets used to develop a high-risk system, including through application programming interfaces or other remote means. Article 74(13) allows access to the source code only on a reasoned request and only where access is necessary to assess conformity with the Chapter III, Section 2 requirements and testing, auditing and verification based on the provider's data and documentation have been exhausted or proved insufficient. Information obtained is subject to the confidentiality obligations in Article 78.
What happens when a market-surveillance authority finds an AI system presents a risk?
Article 79 sets a national-level procedure: the authority evaluates the system, requires the operator to bring it into compliance, withdraw it or recall it within a set period, and, if the operator does not act, takes provisional measures and notifies the Commission and other Member States.
Article 79(1) provides that an 'AI system presenting a risk' is understood as a 'product presenting a risk' as defined in Article 3, point 19 of Regulation (EU) 2019/1020, in so far as it presents risks to the health or safety, or to fundamental rights, of persons. Under Article 79(2), where a market surveillance authority has sufficient reason to consider that a system presents such a risk, it evaluates the system's compliance with all requirements and obligations in the Regulation, cooperating with the fundamental-rights authorities in Article 77(1) where relevant. If the system is found non-compliant, the authority requires the operator, without undue delay, to bring it into compliance, withdraw it, or recall it within a prescribed period, and in any event within the shorter of 15 working days or the period set by relevant Union harmonisation legislation. Article 79(5) provides that if the operator fails to take adequate corrective action within that period, the authority takes 'all appropriate provisional measures' to prohibit or restrict the system, withdraw it, or recall it, and notifies the Commission and the other Member States. Under Article 79(8), a provisional measure not objected to within three months is deemed justified, reduced to 30 days for the prohibited practices in Article 5.
How does ISO/IEC 5338 frame operation and maintenance after deployment?
ISO/IEC 5338:2023 describes AI system life cycle processes, placing an operation process at Clause 6.4.15 and a maintenance process at Clause 6.4.16 within its technical processes, which cover running a fielded system and sustaining its capability.
ISO/IEC 5338:2023 (Information technology — Artificial intelligence — AI system life cycle processes) adapts the general system life cycle processes of ISO/IEC/IEEE 12207 to AI systems, organising them into agreement, organizational project-enabling, technical management and technical process groups. Within the technical processes at Clause 6.4, the standard describes an operation process (Clause 6.4.15) and a maintenance process (Clause 6.4.16) that apply once a system is in use. In paraphrase: the operation process covers running the system in its intended operational environment and monitoring how it performs there, while the maintenance process covers sustaining and restoring the system's capability, including addressing faults and degradations identified during operation. The standard notes AI-specific particularities for these processes, reflecting that a model's behaviour can change with new data and use rather than remaining fixed after release. Read against the AI Act, these process descriptions sit alongside the Article 72 monitoring and Article 12 logging duties: the standard frames operation and maintenance as engineering processes, while the Regulation states the corresponding legal obligations. ISO/IEC and IEEE wording is under copyright and is summarised here in fresh wording; the clauses are consulted through the ISO Online Browsing Platform.
How does post-market monitoring connect to continuous validation?
ISO/IEC 5338:2023 defines a continuous validation process at Clause 6.4.14 that, in the standard's own note, applies even where a model does not learn continuously, for example to detect data drift, concept drift or technical malfunctions. This is the engineering counterpart to the AI Act's continuous-compliance duty under Article 72(2).
ISO/IEC 5338:2023 places a continuous validation process at Clause 6.4.14, separate from the one-time validation process at Clause 6.4.13. The standard notes that, unlike the example life cycle model in ISO/IEC 22989:2022, its continuous validation stage is not marked as applying only in the case of continuous learning: in paraphrase, the standard states that continuous validation is also relevant where a model does not learn continuously, for example to detect data drift, concept drift, or technical malfunctions. This mirrors the AI Act's post-market surveillance duties: Article 72(2) requires the provider to evaluate a system's continuous compliance with the Chapter III, Section 2 requirements throughout its lifetime, and Article 12(2)(a) requires logs that help identify situations in which the system may come to present a risk or undergo a substantial modification. Drift or malfunction detected in operation can feed the post-market monitoring system and, where a threshold in Article 79(1) is reached, the market-surveillance procedure. Stage 5 covers validation and continuous validation in detail; this stage records how those processes are carried forward once the system is on the market. ISO wording is paraphrased in fresh wording; the clauses are consulted through the ISO Online Browsing Platform.
When do the post-market monitoring, logging and surveillance obligations apply?
Under Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, the Chapter IX Articles covered here (72, 74 and 79) apply from 2 August 2026, while Articles 12, 19 and 26 apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I ones; the Chapter V obligations, including Article 55, have applied since 2 August 2025.
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and, under the second paragraph of Article 113, applies from 2 August 2026, with staged exceptions set out in the third paragraph. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and is in force from 27 July 2026; it amends that third paragraph. The obligations discussed here that sit in Chapter IX — Articles 72, 74 and 79 — apply from 2 August 2026. The logging and log-retention obligations that sit in Chapter III, Sections 2 and 3 — Articles 12, 19 and 26 — apply from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. Article 6(5), on Commission guidelines, is carved out of that deferral and applies from 2 August 2026, as does Chapter III, Section 5 (Articles 40 to 49) on standards, conformity assessment, certificates and registration. The general-purpose AI model obligations in Chapter V, including Article 55, have applied since 2 August 2025 under Article 113(b). Under Article 111(2), high-risk systems intended for use by public authorities that were placed on the market before 2 August 2026 must be brought into compliance by 2 August 2030.
Terms defined at this stage
- Post-market monitoring plan
- The plan on which a provider's post-market monitoring system must be based under Article 72(3); it forms part of the technical documentation referred to in Annex IV, and the Commission is directed to establish, by implementing act by 2 February 2026, a standardised form for it and the list of elements it must contain. ↗
- AI system presenting a risk
- Under Article 79(1), an AI system understood as a 'product presenting a risk' as defined in Article 3, point 19 of Regulation (EU) 2019/1020, in so far as it presents risks to the health or safety, or to fundamental rights, of persons. ↗
Cite this page
1BusinessWorld AI Center, "Post-Market Monitoring & Logging — The AI Lifecycle." https://1businessworld.com/ai-center/post-market-monitoring-and-logging/ Version as of July 26, 2026.
The AI Center is informational only. It is provided by 1BusinessWorld strictly for general informational and educational purposes. Nothing in the AI Center constitutes, or should be construed as, legal, regulatory, compliance, technical, engineering, security, investment, financial, or other professional advice, or a recommendation, endorsement, solicitation, or offer regarding any technology, product, model, provider, framework, or course of action. 1BusinessWorld is not a law firm, regulatory authority, standards body, conformity-assessment or certification body, or investment adviser, and nothing in the AI Center creates any advisory, fiduciary, attorney-client, or other professional relationship with 1BusinessWorld. Although the AI Center references official materials published by legislatures, regulators, standards bodies, research organizations, and other named authorities, 1BusinessWorld makes no representation or warranty, express or implied, as to the accuracy, completeness, timeliness, or fitness for any purpose of any content, and, to the fullest extent permitted by law, disclaims all liability for any loss or damage of any kind arising directly or indirectly from the use of, or reliance on, any information presented. Laws, regulations, standards, technical practices, and AI capabilities change frequently and differ by jurisdiction; readers must verify all information against the current official text or source and consult qualified legal, compliance, technical, and other professional advisors before acting. Any decision relating to the development, deployment, procurement, or governance of AI systems is made solely at the reader's own risk. Last reviewed: July 26, 2026.
