Post-Market Monitoring Is Required. It Is Not Continuous

Article 72 of the EU AI Act requires deployers of high-risk AI systems to implement post-market monitoring. Most organizations have interpreted this as establishing a monitoring program.

RCDr. Richard Chingombe · Founder, Verisq·7 min read·Practitioner perspective, not legal advice

The gap is between a monitoring program that exists and one that is continuous, meaningful, and connected to governance response.

Why This Matters Now

Post-market monitoring for high-risk AI systems is a specific EU AI Act requirement that extends the governance obligation beyond deployment. Unlike traditional software governance, AI Act post-market monitoring is specifically designed to detect AI-specific risks that emerge after deployment: behavioral drift, bias patterns, safety issues, and emerging risks that pre-deployment assessment did not anticipate.

The implementation challenge is that effective post-market monitoring requires continuous operational capability that most organizations have not built specifically for AI systems. Monitoring that checks AI system performance during scheduled review cycles does not meet the continuous monitoring standard the regulation envisions.

Post-market monitoring as a reporting exercise and post-market monitoring as a continuous operational capability are different things. The regulation requires the second. Most programs have built the first.

The Governance Problem Beneath the Surface

Development teams build rigorous pre-deployment assessment processes. Operations teams maintain availability and performance infrastructure. Post-market monitoring as defined by the AI Act requires a third discipline that sits between these two: continuous behavioral assessment in production governed by the same rigor as pre-deployment testing.

This third discipline has no natural home in most organizational structures. Development hands off to operations. Operations monitors availability. Post-market monitoring falls in the governance gap between them.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

What This Actually Means in Enterprise Practice

Monitoring Cadence Does Not Match Risk Emergence Cadence

AI system risks can emerge, intensify, and cause harm between monitoring cycles. A bias pattern that develops gradually over three months will not be detected by a quarterly review until it has already affected a significant population.

Risk emergence is continuous. Monitoring designed around reporting cycles is periodic. The gap between them is the window during which emerging risks are undetected.

Monitoring Scope Does Not Cover AI-Specific Risk Signals

Operational monitoring tracks availability, latency, error rates, and throughput. These are right metrics for service reliability. They are not the metrics that detect AI-specific risks: output distribution shifts, demographic disparity changes, confidence calibration drift, and behavioral changes in specific input segments.

AI post-market monitoring requires different instrumentation from operational monitoring. Organizations that extended operational monitoring to AI systems have addressed availability. They have not addressed behavioral governance.

Monitoring Findings Are Not Connected to Response

Even where ongoing monitoring produces findings, the connection to governance response is frequently absent or informal. A drift signal in model output distribution may be observed by the data science team and attributed to normal variation without triggering a formal governance review.

Serious Incident Detection Does Not Meet the Regulation's Standard

The EU AI Act requires not just monitoring for serious incidents but the capability to detect them with sufficient sensitivity. Monitoring programs that rely on customer complaints to identify serious incidents do not meet this detection capability standard.

How Different Teams See This: Where They All Miss

AI GovernanceDefining monitoring requirements. Not typically responsible for the continuous technical infrastructure that implements them.
OperationsManaging production infrastructure monitoring. Not typically instrumenting AI-specific behavioral signals.
Data ScienceObserving model performance through ad hoc analysis. Not formally connected to governance reporting obligations.
Legal and ComplianceDocumenting post-market monitoring as a compliance artifact. Not typically assessing whether the monitoring meets the regulation's continuous standard.

Post-market monitoring as a continuous operational capability requires defined ownership, specific instrumentation, governance-connected response workflows, and a monitoring architecture that covers AI-specific risk signals.

Framework Control Reference

The specific control obligations most relevant to this topic. Use in governance discussions, vendor assessments, and audit responses.

EU AI Act | Article 72Deployers of high-risk AI systems must implement post-market monitoring to collect and review data on system performance after placing in service.
EU AI Act | Article 26(5)Deployers must monitor AI system operation and report serious incidents. Effective detection capability is required, not just incident reporting infrastructure.
EU AI Act | Article 73Serious incidents involving high-risk AI systems must be reported without undue delay. Detection capability enabling timely reporting is required.
NIST AI RMF | Manage 4.1 / Measure 2.6Organizations must monitor AI system performance over time and document performance changes. Continuous operational monitoring is the intended standard.
ISO 42001 | Clause 9.1Organizations must monitor, measure, analyze, and evaluate AI system performance on an ongoing basis.
Financial Services SR 11-7 | Ongoing Performance MonitoringModel risk management requires ongoing performance monitoring with defined triggers for escalation.

These controls share a common requirement: the obligation is active, not declarative. Documenting alignment is not the same as demonstrating it.

The Enterprise Reality Gap

The enterprise post-market monitoring reality gap is between the monitoring documentation organizations produce and the continuous monitoring capability the regulation requires. The documentation captures scheduled review results. The regulation requires a capability that can detect emerging risks between those reviews.

Post-market monitoring that catches issues when they become serious has not satisfied the early detection requirement. Monitoring that detects behavioral changes before they become serious is the standard the regulation is designed to produce.

Enterprise Scenario

The setupA healthcare organization uses an AI triage prioritization system. A retrospective clinical audit identifies a pattern suggesting patients from specific zip codes receive systematically lower priority scores.
The investigationThe team discovers that operational logs capture patient IDs, timestamps, and priority outputs but not the feature values input to the model, the model version active during the period, or the intermediate computations that produced the priority scores.

The investigation cannot determine which features drove the disparity or whether a specific model update introduced it. The evidence required to understand the failure does not exist because the traceability infrastructure was never built.

Industry Signal

The AI Office established under the EU AI Act has signaled that post-market monitoring will be a primary examination area in supervisory activity. Early guidance emphasizes that monitoring must include specific capability for detecting the AI-specific failure modes relevant to the system's use case. Organizations that present quarterly review documentation as their monitoring program will face questions about continuous detection capability that quarterly reviews do not address.

Regulators will ask what the monitoring would detect, how quickly, and what governance response it would trigger. Quarterly review documentation answers the first question partially. It does not address the second and third.

Enabling Capabilities

  • AI behavioral monitoring platforms: Continuous monitoring of model output distributions and behavioral signals with automated alerting for anomalous patterns.
  • Drift detection tooling: Statistical frameworks for detecting distributional shifts in model inputs and outputs that indicate emerging behavioral change.
  • Bias monitoring dashboards: Ongoing tracking of demographic disparity metrics with trend visualization and alert thresholds.
  • Serious incident detection frameworks: Defined criteria for what constitutes a serious incident under Article 73 with monitoring infrastructure designed to detect those criteria.

A Practical Starting Point

For each high-risk AI system, define what continuous monitoring looks like in practice. Not the quarterly review schedule, but the signals monitored continuously, the thresholds that trigger alerts, the response workflows those alerts activate, and the serious incident criteria that trigger regulatory notification.

Continuous monitoring is defined by what it detects and how quickly, not by the reports it produces at scheduled intervals.

Questions Leaders Should Be Asking

  • For each high-risk AI system, what behavioral signals are monitored continuously between scheduled governance reviews?
  • What thresholds trigger an alert in our post-market monitoring program, and what is the response workflow those alerts activate?
  • What constitutes a serious incident under EU AI Act Article 73 for each of our high-risk AI deployments?
  • How would our monitoring program detect a gradual behavioral drift that does not appear in aggregate performance metrics?

What to Require From Vendors

Ask directly:

"What behavioral monitoring capabilities does your platform provide between scheduled reviews, specifically including drift detection, demographic disparity trending, and serious incident detection?"

Expect as evidence:
  • Specific description of continuously monitored signals with alert thresholds
  • Drift detection capabilities with documentation of what types of drift are detectable
  • Serious incident detection criteria and notification workflow

A vendor who describes post-market monitoring as periodic performance review has described a governance artifact. Ask specifically about the continuous detection capability between those reviews.

Demonstrating Diligence

  • Documentation: Continuous monitoring architecture documentation; serious incident criteria with detection methodology; alert threshold and response workflow documentation.
  • Process: Defined ownership for continuous monitoring; governance response workflow for monitoring alerts; serious incident notification process with timeline requirements.
  • Technical evidence: Continuous monitoring output records; alert history with response documentation.

Article 72 diligence requires demonstrating continuous monitoring capability, not just periodic review documentation.

Closing Perspective

Post-market monitoring is one of the EU AI Act requirements that reveals most clearly the difference between AI governance as documentation and AI governance as operational discipline. The documentation requirement is satisfiable with periodic reviews. The operational requirement is a continuous capability that requires specific investment in monitoring infrastructure, governance response architecture, and organizational accountability.

The organizations that build this capability before regulatory examination are better positioned than those that discover the gap during it.

Post-market monitoring is not a compliance event. It is an operational discipline that continues for the life of the system.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.