AI Assurance Institute Logo AI Assurance Institute

The Role of Post-Market Monitoring Systems in Managing Risk under the EU AI Act

Article 72 of the EU AI Act mandates that providers of high-risk AI systems establish, implement, document, and maintain a post-market monitoring system (PMMS) as part of their overall Quality Management System (Article 17). The PMMS is a proactive, continuous risk-management mechanism that collects and analyses real-world data after deployment to detect emerging risks, performance degradation, new misuse patterns, or unforeseen harms to health, safety, or fundamental rights. It closes the lifecycle loop between pre-market risk assessment (Article 9) and ongoing safety assurance. This article articulates the role of post-market monitoring systems in managing risk under the AI Act from regulatory, operational, practical, and strategic perspectives, detailing their requirements, application, achievements, examples, edge cases, and implications for high-risk AI providers.

Regulatory Foundation: The Mandatory Role of Post-Market Monitoring

Article 72 requires providers to establish a PMMS that is proportionate to the nature, intended purpose, and risks of the high-risk AI system. It must be integrated with the risk management system (Article 9) and the broader QMS (Article 17), ensuring that real-world evidence continuously feeds back into risk evaluation and mitigation. Key regulatory purposes include:

The PMMS is not optional post-deployment surveillance; it is a core risk-management instrument that extends the preventive logic of Article 9 into the operational phase - achieving sustained protection of health, safety, and fundamental rights long after market placement.

Structural Requirements: How the PMMS Must Be Established and Operated

Article 72(1)-(3) and related implementing provisions require the PMMS to be documented, systematic, and proportionate. EN 18286 (typically Clause 8 on post-market processes and Clause 9 on performance evaluation) embeds these requirements within the QMS framework:

Practical example: A high-risk AI system for automated hiring decisions monitors demographic parity and adverse impact ratios monthly via anonymised user logs. When parity falls below the pre-market threshold, the PMMS triggers a risk re-evaluation, corrective dataset rebalancing, and deployer notification - preventing ongoing discrimination.

Operational-Level Application: How PMMS Manages Risk in Practice

The PMMS operates as a continuous feedback loop within the QMS:

Edge case: Continuously learning systems require near-real-time PMMS capabilities - automated monitoring of adaptation behaviour, predefined drift thresholds, and rapid escalation to risk re-assessment when boundaries are breached, ensuring uncontrolled evolution does not introduce new risks.

Integration, Nuances, and Strategic Implications

The PMMS integrates deeply with the QMS (post-market monitoring as a core element in EN 18286), RMS (real-world data feeds risk re-evaluation), and technical documentation (updates to Annex IV). For sectoral overlaps (e.g., medical devices under MDR), leverage existing vigilance/post-market surveillance systems with AI-specific additions (bias/performance drift monitoring). Nuances: Proportionality for SMEs (focus on highest-impact risks); deployers share monitoring duties (Article 29) and must feed data back to providers.

Strategic achievements: Beyond compliance, a robust PMMS enables data-driven improvement, early detection of liabilities, enhanced trust from deployers/regulators/users, and competitive advantage through sustained performance. Challenges: Data privacy constraints (GDPR compliance), resource demands for real-time analysis, and uncertainty during transition (EN 18286 citation delay). Best practice: Define clear monitoring KPIs aligned with quality objectives, automate where possible (dashboards, alerts), conduct regular PMMS effectiveness reviews, and align with EN 18286 draft for future presumption.

In summary, the post-market monitoring system required under the EU AI Act plays a pivotal role in managing risk by extending preventive risk controls into the real-world operational phase - continuously detecting, evaluating, and mitigating emerging threats to health, safety, and fundamental rights, thereby ensuring that high-risk AI remains safe, effective, and compliant throughout its entire lifecycle.

Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 9, 17, 72 & 73, and the EN 18286 draft standard. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions become fully applicable on 2 August 2026.