AI Assurance Institute Logo AI Assurance Institute

The Role of Post-Market Monitoring Systems

in Managing Risk under the EU AI Act

Article 72 of the EU AI Act mandates that providers of high-risk AI systems establish, implement, document, and maintain a post-market monitoring system (PMMS) as part of their overall Quality Management System (Article 17). The PMMS is a proactive, continuous risk-management mechanism that collects and analyses real-world data after deployment to detect emerging risks, performance degradation, new misuse patterns, or unforeseen harms to health, safety, or fundamental rights. It closes the lifecycle loop between pre-market risk assessment (Article 9) and ongoing safety assurance.

Regulatory Foundation: The Mandatory Role of Post-Market Monitoring

Article 72 requires providers to establish a PMMS that is proportionate to the nature, intended purpose, and risks of the high-risk AI system. It must be integrated with the risk management system (Article 9) and the broader QMS (Article 17), ensuring that real-world evidence continuously feeds back into risk evaluation and mitigation. Key regulatory purposes include:

Structural Requirements: How the PMMS Must Be Established and Operated

Article 72(1)-(3) and related implementing provisions require the PMMS to be documented, systematic, and proportionate. prEN 18286 (typically Clause 8 on post-market processes and Clause 9 on performance evaluation) embeds these requirements within the QMS framework:

  1. Defined Monitoring Plan: A documented plan specifying data sources (user feedback, logs, performance metrics), collection frequency, analysis methods, and thresholds for action.
  2. Data Collection & Analysis: Collect relevant real-world data (anonymised where possible); analyse for deviations from pre-market assumptions (e.g., accuracy drop, bias emergence).
  3. Risk Re-Evaluation: Feed findings back into the risk management system; assess whether new/emerging risks require mitigation or re-classification.
  4. Reporting & Action Triggers: Link to serious incident reporting (Article 73); trigger corrective actions, updates to technical documentation, or communication to deployers/authorities.
  5. Documentation & Traceability: Maintain version-controlled records of monitoring results, analyses, and actions taken - auditable for conformity assessment and market surveillance.

Operational-Level Application: How PMMS Manages Risk in Practice

The PMMS operates as a continuous feedback loop within the QMS:

Edge case

Continuously learning systems require near-real-time PMMS capabilities - automated monitoring of adaptation behaviour, predefined drift thresholds, and rapid escalation to risk re-assessment when boundaries are breached, ensuring uncontrolled evolution does not introduce new risks.

Integration, Nuances, and Strategic Implications

The PMMS integrates deeply with the QMS (post-market monitoring as a core element in prEN 18286), RMS (real-world data feeds risk re-evaluation), and technical documentation (updates to Annex IV). For sectoral overlaps (e.g., medical devices under MDR), leverage existing vigilance/post-market surveillance systems with AI-specific additions (bias/performance drift monitoring). Nuances: Proportionality for SMEs (focus on highest-impact risks); deployers share monitoring duties (Article 29) and must feed data back to providers.

Strategic achievements: Beyond compliance, a robust PMMS enables data-driven improvement, early detection of liabilities, enhanced trust from deployers/regulators/users, and competitive advantage through sustained performance. Challenges: Data privacy constraints (GDPR compliance), resource demands for real-time analysis, and uncertainty during transition (prEN 18286 citation delay). Best practice: Define clear monitoring KPIs aligned with quality objectives, automate where possible (dashboards, alerts), conduct regular PMMS effectiveness reviews, and align with prEN 18286 draft for future presumption.

In summary

The post-market monitoring system required under the EU AI Act plays a pivotal role in managing risk by extending preventive risk controls into the real-world operational phase - continuously detecting, evaluating, and mitigating emerging threats to health, safety, and fundamental rights, thereby ensuring that high-risk AI remains safe, effective, and compliant throughout its entire lifecycle.

Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 9, 17, 72 & 73, and the prEN 18286 draft standard. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions become fully applicable on 2 August 2026.