SkarpSkarp

Chapter 20 of 25

Registration, Monitoring and Market Surveillance

After market entry, the Act relies on information flows: database records, monitoring plans, incident reports and supervisory access. Articles 71–78 show how those flows support sectoral surveillance while protecting rights, confidential information and cybersecurity.

24 min readen

The Information Flow After Market Entry

A connected oversight loop

Articles 71-78 create an information flow after market entry: registration, monitoring, incident reporting, supervisory investigation and confidentiality safeguards.

Read legal duties precisely

For every rule, identify who acts, when the rule is triggered, what must be done, and which limits or exceptions apply.

The four stations

Visualise a database form, monitoring dashboard, incident-alert channel and secure evidence room. Article 78 protects information across all four.

Article 71: The EU Database for Annex III High-Risk AI Systems

Database establishment

Article 71(1): "The Commission shall, in collaboration with the Member States, set up and maintain an EU database" for the specified registered AI systems.

Consultation duties

When setting functional specifications, the Commission shall consult relevant experts. When updating them, it shall consult the Board.

Who enters which data?

Sections A and B of Annex VIII are entered by the provider or, where applicable, authorised representative. Section C is entered by a qualifying public-sector deployer.

Public versus restricted information

Article 49 registrations are publicly available in a user-friendly manner, subject to stated exceptions. Article 60 registrations are restricted unless consent supports public access.

Article 71 in Practice: Access, Personal Data and Control

Role allocation matters

A provider or authorised representative enters Annex VIII Sections A and B. A qualifying public-sector deployer enters Section C under Article 49(3) and (4).

Personal data are not unlimited

"The EU database shall contain personal data only in so far as necessary" for collecting and processing information under the Regulation.

Named registration contacts

Necessary information includes names and contact details of natural persons responsible for registration and legally authorised to represent the provider or deployer.

Controller and support

"The Commission shall be the controller of the EU database." It shall provide adequate technical and administrative support, and the database shall meet applicable accessibility requirements.

Article 72: Post-Market Monitoring as a Lifecycle System

A mandatory system, scaled to risk

"Providers shall establish and document a post-market monitoring system" proportionate to the AI technologies' nature and the high-risk system's risks.

What the system shall do

It shall actively and systematically collect, document and analyse relevant lifetime performance data so the provider can evaluate continuous Chapter III, Section 2 compliance.

Two important qualifiers

Where relevant, monitoring shall analyse interaction with other AI systems. It shall not cover sensitive operational data of deployers that are law-enforcement authorities.

Plan and technical documentation

The monitoring system shall be based on a plan, and that plan shall be part of Annex IV technical documentation. Article 72(3) set a Commission implementing-act deadline of 2 February 2026.

Quiz: Monitoring System Boundaries

Apply Article 72 precisely

A provider says: "Because our high-risk system has low observed error rates, we will conduct a voluntary annual review instead of maintaining a documented monitoring system. We will also collect every item of operational data from police deployers just in case it is useful."

Which answer best reflects Article 72?

Which statement is correct?

  1. The provider may replace the system with a voluntary annual review, but may collect all police operational data.
  2. The provider shall establish and document a proportionate monitoring system, but the obligation shall not cover sensitive operational data of deployers that are law-enforcement authorities.
  3. The provider has no monitoring obligations until a serious incident occurs.
  4. The provider must collect all data from every deployer, regardless of relevance.
Show Answer

Answer: B) The provider shall establish and document a proportionate monitoring system, but the obligation shall not cover sensitive operational data of deployers that are law-enforcement authorities.

Article 72(1) uses "shall" for establishing and documenting a proportionate post-market monitoring system. Article 72(2) requires active and systematic collection, documentation and analysis of relevant data, but expressly states that the obligation shall not cover sensitive operational data of deployers that are law-enforcement authorities.

Article 73: Serious Incidents and the Three Reporting Clocks

The reporting destination

Providers of high-risk AI systems placed on the Union market shall report any serious incident to market surveillance authorities in the Member States where it occurred.

Ordinary clock: 15 days

Report immediately once a causal link, or reasonable likelihood, is established; in any event, "not later than 15 days" after awareness of the serious incident.

Fast clock: 2 days

For a widespread infringement or an Article 3, point (49)(b) serious incident, report immediately and "not later than two days" after awareness.

Death: suspicion can trigger immediacy

For a death, report immediately after establishing or suspecting a causal relationship, with an outer limit of "not later than 10 days" after awareness.

After the report

The provider shall investigate without delay, assess risk and take corrective action. It shall not make cause-affecting alterations before informing competent authorities.

Article 73 Worked Timeline: From Detection to Authority Action

Match the facts to the clock

Ordinary incidents use the Article 73(2) rule; widespread infringements and Article 3, point (49)(b) incidents use two days; deaths use the 10-day outer limit.

Incomplete does not mean late

Where necessary for timely reporting, Article 73(5) permits an incomplete initial report followed by a complete one.

Authority response

Article 73(8): the market surveillance authority shall take appropriate Article 19 measures within seven days of receiving the notification.

Sectoral reporting qualifications

Articles 73(9) and (10) limit certain notifications to Article 3, point (49)(c) incidents, under their stated conditions.

Article 74: Who Supervises, and What Can They Access?

The framework rule

"Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation." Its product and economic-operator references are adapted for AI systems and Article 2(1) operators.

Annual reporting beyond compliance

Authorities shall annually report competition-relevant information to the Commission and relevant national competition authorities, plus prohibited practices and measures taken.

Sectoral authority allocation

For Annex I Section A product-related systems, the relevant sectoral authority is the market surveillance authority, subject to a coordinated national derogation.

Documentation, data and remote access

Providers shall grant full access to documentation and relevant development data where necessary. APIs or other remote tools may be used, subject to security safeguards.

Source code is exceptional

A reasoned request is not enough alone: source-code access also requires necessity and exhaustion or insufficiency of data- and documentation-based review.

Articles 74-76: Special Supervisors, AI Office Cooperation and Real-World Testing

Financial-sector supervision

For directly connected financial-services uses, the relevant national financial supervisor shall be market surveillance authority, subject to Article 74(7)'s coordinated derogation.

Data protection and judicial independence

Specified Annex III areas require designated data-protection authorities or similarly designated authorities. Surveillance shall not affect judicial independence or judicial activity.

When the AI Office enters

The AI Office supervises a system and its general-purpose model when both were developed by the same provider. It can supply relevant information within 30 days after a qualified request.

Testing in real-world conditions

Authorities may suspend or terminate non-compliant testing, or require changes. A decision or objection shall give grounds and explain how it may be challenged.

Article 77: Fundamental-Rights Authorities Can Obtain Evidence

A targeted access power

Fundamental-rights authorities may obtain documentation only when access is necessary to fulfil their mandate and remains within their jurisdiction.

Accessible language and format

They "shall have the power to request and access any documentation created or maintained under this Regulation in accessible language and format."

Member State list

By 2 November 2024, each Member State shall identify the relevant bodies, publish a list, notify it to the Commission and other Member States, and keep it updated.

Testing when documents are insufficient

The authority may make a reasoned request for technical testing. The market surveillance authority shall organise it with close involvement within a reasonable time.

Quiz: Documentation, Testing and Source Code

Distinguish three different powers

A national body responsible for enforcing non-discrimination obligations examines an Annex III high-risk AI system. The documentation does not let it determine whether a fundamental-rights infringement occurred. Which action does Article 77(3) describe?

What may the fundamental-rights authority do under Article 77(3)?

  1. It may automatically publish all documentation and source code.
  2. It may make a reasoned request to the market surveillance authority to organise technical testing of the high-risk AI system.
  3. It must itself alter the AI system to test it.
  4. It may require source-code access without any conditions.
Show Answer

Answer: B) It may make a reasoned request to the market surveillance authority to organise technical testing of the high-risk AI system.

Where documentation is insufficient, Article 77(3) says the authority or body may make a reasoned request to the market surveillance authority to organise testing through technical means. The authority shall organise testing with the requesting body closely involved within a reasonable time. Source-code access instead has the distinct, cumulative conditions in Article 74(13).

Article 78: Confidentiality, Strict Necessity and Cybersecurity

Confidentiality covers more than trade secrets

Article 78 protects IP, confidential business information and trade secrets, including source code, plus investigations, security interests, proceedings and classified information.

Strict necessity

Authorities "shall request only data that is strictly necessary" for risk assessment and exercising their powers under this Regulation and Regulation (EU) 2019/1020.

Cybersecurity and deletion

Authorities shall use adequate and effective cybersecurity measures and shall delete collected data as soon as it is no longer needed for its original purpose.

Sensitive operational settings

Special rules restrict disclosure and exclude sensitive operational data in specified law-enforcement, border-control, immigration and asylum contexts.

Secure access is still access

Where the named authorities are providers, technical documentation stays on their premises, but qualified surveillance staff can immediately access it or a copy upon request.

Flashcards: Exact Rules to Recall

Review the key actors, deadlines and safeguards

Flip each card, then try to explain the rule with its trigger and qualifier.

Who shall set up and maintain the EU database?
Article 71(1): "The Commission shall, in collaboration with the Member States, set up and maintain an EU database."
Who enters Annex VIII Sections A and B data?
The provider or, where applicable, the authorised representative.
What is the ordinary outer reporting deadline for a serious incident?
Not later than 15 days after the provider or, where applicable, deployer becomes aware of the serious incident.
What deadline applies to a widespread infringement or Article 3, point (49)(b) incident?
Immediately, and not later than two days after the provider or, where applicable, deployer becomes aware of that incident.
What is the death-related outer deadline?
Not later than 10 days after the date on which the provider or, where applicable, deployer becomes aware of the serious incident.
When may source code be accessed under Article 74(13)?
Only upon a reasoned request, where access is necessary for conformity assessment and data/documentation-based testing, auditing and verification have been exhausted or proved insufficient.
What data may authorities request under Article 78(2)?
Only data that is strictly necessary for assessing AI-system risk and exercising their powers.

Key Terms

AI Office
The body with specified monitoring, supervision and information-access functions for general-purpose AI systems under Article 75.
EU database
The database that the Commission shall set up and maintain with Member States under Article 71 for the specified registered AI systems.
reasoned request
A request that must give reasons; it is required, for example, for Article 74(13) source-code access and Article 77(3) technical testing.
serious incident
An incident for which Article 73 establishes reporting, investigation and authority-response rules; special deadlines apply in specified cases.
strict necessity
Article 78(2)'s limit that authorities shall request only data strictly necessary for risk assessment and exercising their powers.
authorised representative
The actor that, where applicable, enters Annex VIII Sections A and B data in the EU database instead of the provider under Article 71(2).
post-market monitoring plan
The plan on which the monitoring system shall be based; it shall be part of Annex IV technical documentation.
market surveillance authority
The authority assigned supervisory functions under Article 74, with sector-specific allocations and powers.
post-market monitoring system
The documented provider system that Article 72 requires to be proportionate to the AI technologies' nature and the high-risk AI system's risks.
fundamental-rights authority or body
A national public authority or body supervising or enforcing Union-law fundamental-rights obligations in relation to Annex III high-risk AI systems under Article 77.
confidential business information or trade secrets
Protected information under Article 78(1), including source code, alongside other protected interests and subject to the provision's stated exception.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself