AI System Monitoring Under the EU AI Act: Post-Market Monitoring Under Article 72
Article 72 of the EU AI Act requires providers of high-risk AI systems to establish a post-market monitoring system. We support you in implementation: from systematic data collection and automatic logging to timely incident reporting to the market surveillance authority.
- ✓Post-market monitoring plan under Art. 72 for your high-risk AI systems
- ✓Automatic logging under Art. 12 with minimum 6-month retention
- ✓Reporting processes for serious incidents within the 15-day deadline under Art. 73
- ✓Human oversight under Art. 14 integrated into the monitoring process
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










Post-Market Monitoring Under Article 72 of the EU AI Act
Why ADVISORI for AI Monitoring
- Practical experience with post-market monitoring in regulated industries (financial sector, healthcare)
- Technical expertise in monitoring architectures on AWS, Azure and on-premise
- Understanding of interfaces with GDPR, MaRisk and DORA
- Support from concept through to regulatory examination
Deadline: August 2026
From 2 December 2027, the requirements for post-market monitoring of high-risk AI systems apply in full. A documented monitoring plan under Art. 72(3) must form part of the technical documentation. Missing systems can result in fines of up to EUR 15 million or 3% of annual turnover.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We implement post-market monitoring systems in five phases, tailored to the complexity of your AI landscape and the specific requirements of your risk level.
Our Approach:
Stocktaking: inventory AI systems, determine risk classes, derive Art. 72 requirements
Create monitoring plan: define data sources, metrics, thresholds and escalation paths
Technical implementation: deploy logging, dashboards and alerting systems
Reporting processes: set up incident reporting under Art. 73, escalation matrix and authority communication
Training and operation: empower the team, establish monitoring cycles, continuous improvement

Asan Stefanski
Head of Digital Transformation
Expertise & Experience:
11+ years of experience, Applied Computer Science degree, Strategic planning and management of AI projects, Cyber Security, Secure Software Development, AI
Our Services
We offer you tailored solutions for your digital transformation
Compliance Monitoring & Alerting
Automated monitoring of EU AI Act compliance with immediate notifications in the event of deviations.
- Real-time Compliance Status Monitoring
- Automated alert systems for violations
- Compliance dashboard and reporting
- Regulatory update integration
AI Performance & Bias Monitoring
Continuous monitoring of AI system performance and detection of bias and discrimination.
- Automated Model Performance Tracking
- Bias Detection and Fairness Monitoring
- Data Drift and Model Degradation Detection
- Explainability and Transparency Metrics
Our Competencies
Choose the area that fits your requirements
The EU AI Act compliance requirements define concrete obligations for various AI systems. We support you in the complete implementation of all necessary measures to comply with the new European AI regulation.
The EU AI Act imposes extensive documentation requirements on AI systems. We support you in systematically fulfilling all documentation obligations for legally compliant AI development and use.
Our AI risk assessment supports you in the systematic analysis and classification of your AI systems in accordance with EU AI Act Article 9. From AI inventory through risk analysis to a continuous risk management system across the entire lifecycle.
Our expertise in the systematic classification of AI systems under the EU AI Act enables precise compliance strategies. From initial categorization to continuous reassessment — for secure and compliant AI innovation.
Frequently Asked Questions about EU AI Act Monitoring Systems
What does Article 72 of the EU AI Act require from providers?
Article 72 requires providers of high-risk AI systems to establish a post-market monitoring system. This system must actively and systematically collect, document and analyse data on the performance of the AI system throughout its entire lifecycle. It must be proportionate to the nature of the AI system and its risk level. A documented monitoring plan forms part of the technical documentation under Annex IV.
What logging obligations apply under Article 12 of the EU AI Act?
High-risk AI systems must have automatic logging capabilities. The following must be recorded: periods of use, input data leading to matches, reference databases used, and the identity of verifying persons. Deployers must retain these logs for at least six months. The logs serve traceability and form the basis for regulatory inspections.
How must serious incidents be reported under Article 73?
Serious incidents (events causing death, health damage or significant fundamental rights violations) must be reported to the competent market surveillance authority within 15 days of becoming aware. The deadline is shortened in cases of imminent danger. Providers must establish a clear escalation process to ensure timely reporting.
What is the difference between post-market monitoring and human oversight?
Post-market monitoring under Art. 72 is the systematic collection and analysis of data after placing on the market, an obligation of the provider. Human oversight under Art. 14 means that natural persons can effectively oversee the AI system during operation and intervene when necessary, an obligation of the deployer. The two concepts complement each other: monitoring provides the data, human oversight enables the response.
How does AI monitoring relate to GDPR and DORA?
AI monitoring and GDPR overlap significantly: Data Protection Impact Assessments under Art. 35 GDPR complement AI risk assessments, and monitoring data may contain personal data. For financial institutions, DORA adds ICT risk management and incident reporting requirements. An integrated monitoring strategy covering the AI Act, GDPR and DORA avoids duplication and gaps.
Who is responsible for monitoring, the provider or the deployer?
The obligations are shared. Providers must establish the post-market monitoring system, document the monitoring plan and report serious incidents. Deployers must ensure ongoing operational monitoring, retain logs and report notable risks to providers and authorities. In practice, this requires clear contractual arrangements between provider and deployer.
What standards and norms support the implementation of AI monitoring?
ISO/IEC 42001 provides an AI management system framework as a foundation. The final draft ISO/IEC FDIS 24970 (as of May 2026) standardises AI system logging under Article 12. The European Commission is developing harmonised standards specifically for post-market monitoring. Existing IT monitoring frameworks such as ITIL and ISO 27001 can serve as a starting point and be extended with AI-specific requirements.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance

Sovereign AI · ADVISORI
Frontier AI on European infrastructure
Frontier performance, entirely in Europe and under European law: as local language models in your infrastructure or orchestrated through Synthara AI Studio.
- EU inference: no CLOUD Act, no kill switch
- GDPR-compliant on European hardware
- Live in a few weeks, no vendor lock-in