Direct answer
How do we monitor our AI system after it goes live?
This falls under Article 72: post-market monitoring. That obligation applies today. The provision itself applies then, but it only acquires an object once a high-risk AI system exists; through Annex III that is from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- The plan may be proportionate to the nature of the system and align with existing sectoral monitoring regimes.
First step: Draw up a post-market monitoring plan.
You describe: Your high-risk system runs in production. You must keep tracking how it behaves in practice and act as soon as that behaviour deviates from what you established at assessment time. Likely role: provider (you place the system on the market).
This applies now
- Article 72: post-market monitoringApplicable
- Article 73: serious incident reportingApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
- Article 12: logging and traceabilityfrom 2 December 2027
- Article 17: quality management systemfrom 2 December 2027
Depends on your situation
- Article 61: informed consent of test subjects for testing in real world conditionsArticle 60(4), point (i), with Article 61(1)
These provisions only apply once the stated fact is established. The locator says which provision settles it.
Post-market monitoring and incident reporting belong together: the Article 72 monitoring system is how you discover what Article 73 requires you to report. The logs from Article 12 provide the evidence to reconstruct afterwards what happened.
Your first actions
- Draw up a post-market monitoring plan. Systematically collect and analyse real-world data on the system’s performance and compliance throughout its lifetime.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Set up an incident process with reporting routes. Define what a serious incident is, assign the reporting route to the supervisor and rehearse the process.
Record this
- Monitoring plan and reports
- Article 49(2) registration record for the system assessed as not high-risk
- Incident register and reports
education
Proctoring during exams: which real-world data the institution reports back
A vendor offers proctoring software that flags possible cheating during exams. Several universities of applied sciences use the system, each with its own assessment formats and its own student populations. The vendor wants to know which real-world data it must keep collecting after roll-out, and from whom.
Provenance: Article 72(1) requires providers to establish and document a post-market monitoring system, proportionate to the nature of the AI technologies and the risks of the system. Article 72(2) provides that this system actively and systematically collects, documents and analyses relevant data which may be provided by deployers or collected through other sources on the performance of high-risk AI systems throughout their lifetime, and which allow the provider to evaluate the continuous compliance of those systems with the requirements set out in Chapter III, Section 2. Where relevant, monitoring includes an analysis of the interaction with other AI systems. Article 72(3) provides that the system is based on a plan forming part of the technical documentation referred to in Annex IV.
The duty sits with the provider, but the useful signals arise in education itself: unfounded suspicions, student complaints, differences between programmes and assessment formats. Our reading is that paragraph 2 allows deployers to supply that data while leaving the duty to collect and analyse it with the provider. What the article does not settle is the route by which the data reaches you, or whether the institutions are bound to supply it; that is something you have to arrange with them and cannot read out of Article 72. We would therefore fix that route before the system goes live, and would also set out in the plan how you break performance down by assessment format and by group, since an average across all schools hides precisely the pattern you are looking for.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Article 72(1)-(3)
education
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
education
Application file handling at an educational institution
An educational institution uses AI for application file handling: indexing, searching, text and speech processing, translation of documents submitted with applications, and extracting, transforming and organising the collected data into a usable format.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Indexing, searching, translating and reorganising application files remains preparatory work, as long as the system leaves the substantive judgment on the application entirely to the institution.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
education
Customs risk assessment of goods at the external border
An AI system is used by customs authorities to assess the risk that goods entering the EU do not comply with legislation applicable at the border, based on information about the economic operators concerned, such as container number, description of goods, routing, transport and payment method.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Determine what your risk model actually targets, because if it concerns consignments and goods flows rather than personal aspects of individuals, there is no profiling to block the exemption.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
High-risk does not mean prohibited, and not high-risk does not mean permitted
The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)
Split and agentic architectures are assessed as a whole
The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.
Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90
EN 18286:2026: quality management system for EU AI Act regulatory purposes
EN 18286:2026 (Artificial intelligence: Quality management system for EU AI Act regulatory purposes) was drafted by CEN/CLC/JTC 21 under standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. It is the first JTC 21 deliverable to reach publication. According to a published coverage statement accompanying the standard, not yet confirmed by a second independent source, it addresses Article 17(1) points (a) to (m) and Article 11(1) first sentence, and expressly not Article 17(2) to (4) or Article 72. The standard is NOT currently cited in the Official Journal. The Article 40 presumption of conformity only attaches after that citation.
EN ISO/IEC 42001: artificial intelligence management system
ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system, published on 18 December 2023 and structured on the plan-do-check-act cycle. The text was adopted unchanged as EN ISO/IEC 42001:2026, approved by CEN on 13 March 2026, with national implementation by the member standards bodies. This adoption is not a deliverable under standardisation request M/613: the standard is not cited in the Official Journal and therefore confers no presumption of conformity under Article 40. For Article 17, the designated deliverable under M/613 is EN 18286:2026; that standard is likewise not cited in the Official Journal.
prEN 18229-1: AI trustworthiness framework part 1, logging
prEN 18229-1 (AI trustworthiness framework, Part 1: Logging) is the JTC 21 deliverable under M/613 for Article 12 of the AI Act: high-risk AI systems must technically allow for the automatic recording of events over their lifetime. As at June 2026 the deliverable was at the Enquiry stage. It has not yet been published as an EN and is not cited in the Official Journal.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation