Chapter 20 of 25
Registration, Monitoring and Market Surveillance
After market entry, the Act relies on information flows: database records, monitoring plans, incident reports and supervisory access. Articles 71–78 show how those flows support sectoral surveillance while protecting rights, confidential information and cybersecurity.
The Information Flow After Market Entry
A connected oversight loop
Articles 71-78 create an information flow after market entry: registration, monitoring, incident reporting, supervisory investigation and confidentiality safeguards.
Read legal duties precisely
For every rule, identify who acts, when the rule is triggered, what must be done, and which limits or exceptions apply.
The four stations
Visualise a database form, monitoring dashboard, incident-alert channel and secure evidence room. Article 78 protects information across all four.
Article 71: The EU Database for Annex III High-Risk AI Systems
Database establishment
Article 71(1): "The Commission shall, in collaboration with the Member States, set up and maintain an EU database" for the specified registered AI systems.
Consultation duties
When setting functional specifications, the Commission shall consult relevant experts. When updating them, it shall consult the Board.
Who enters which data?
Sections A and B of Annex VIII are entered by the provider or, where applicable, authorised representative. Section C is entered by a qualifying public-sector deployer.
Public versus restricted information
Article 49 registrations are publicly available in a user-friendly manner, subject to stated exceptions. Article 60 registrations are restricted unless consent supports public access.
Article 71 in Practice: Access, Personal Data and Control
Role allocation matters
A provider or authorised representative enters Annex VIII Sections A and B. A qualifying public-sector deployer enters Section C under Article 49(3) and (4).
Personal data are not unlimited
"The EU database shall contain personal data only in so far as necessary" for collecting and processing information under the Regulation.
Named registration contacts
Necessary information includes names and contact details of natural persons responsible for registration and legally authorised to represent the provider or deployer.
Controller and support
"The Commission shall be the controller of the EU database." It shall provide adequate technical and administrative support, and the database shall meet applicable accessibility requirements.
Article 72: Post-Market Monitoring as a Lifecycle System
A mandatory system, scaled to risk
"Providers shall establish and document a post-market monitoring system" proportionate to the AI technologies' nature and the high-risk system's risks.
What the system shall do
It shall actively and systematically collect, document and analyse relevant lifetime performance data so the provider can evaluate continuous Chapter III, Section 2 compliance.
Two important qualifiers
Where relevant, monitoring shall analyse interaction with other AI systems. It shall not cover sensitive operational data of deployers that are law-enforcement authorities.
Plan and technical documentation
The monitoring system shall be based on a plan, and that plan shall be part of Annex IV technical documentation. Article 72(3) set a Commission implementing-act deadline of 2 February 2026.
Quiz: Monitoring System Boundaries
Apply Article 72 precisely
A provider says: "Because our high-risk system has low observed error rates, we will conduct a voluntary annual review instead of maintaining a documented monitoring system. We will also collect every item of operational data from police deployers just in case it is useful."
Which answer best reflects Article 72?
Which statement is correct?
- The provider may replace the system with a voluntary annual review, but may collect all police operational data.
- The provider shall establish and document a proportionate monitoring system, but the obligation shall not cover sensitive operational data of deployers that are law-enforcement authorities.
- The provider has no monitoring obligations until a serious incident occurs.
- The provider must collect all data from every deployer, regardless of relevance.
Show Answer
Answer: B) The provider shall establish and document a proportionate monitoring system, but the obligation shall not cover sensitive operational data of deployers that are law-enforcement authorities.
Article 72(1) uses "shall" for establishing and documenting a proportionate post-market monitoring system. Article 72(2) requires active and systematic collection, documentation and analysis of relevant data, but expressly states that the obligation shall not cover sensitive operational data of deployers that are law-enforcement authorities.
Article 73: Serious Incidents and the Three Reporting Clocks
The reporting destination
Providers of high-risk AI systems placed on the Union market shall report any serious incident to market surveillance authorities in the Member States where it occurred.
Ordinary clock: 15 days
Report immediately once a causal link, or reasonable likelihood, is established; in any event, "not later than 15 days" after awareness of the serious incident.
Fast clock: 2 days
For a widespread infringement or an Article 3, point (49)(b) serious incident, report immediately and "not later than two days" after awareness.
Death: suspicion can trigger immediacy
For a death, report immediately after establishing or suspecting a causal relationship, with an outer limit of "not later than 10 days" after awareness.
After the report
The provider shall investigate without delay, assess risk and take corrective action. It shall not make cause-affecting alterations before informing competent authorities.
Article 73 Worked Timeline: From Detection to Authority Action
Match the facts to the clock
Ordinary incidents use the Article 73(2) rule; widespread infringements and Article 3, point (49)(b) incidents use two days; deaths use the 10-day outer limit.
Incomplete does not mean late
Where necessary for timely reporting, Article 73(5) permits an incomplete initial report followed by a complete one.
Authority response
Article 73(8): the market surveillance authority shall take appropriate Article 19 measures within seven days of receiving the notification.
Sectoral reporting qualifications
Articles 73(9) and (10) limit certain notifications to Article 3, point (49)(c) incidents, under their stated conditions.
Article 74: Who Supervises, and What Can They Access?
The framework rule
"Regulation (EU) 2019/1020 shall apply to AI systems covered by this Regulation." Its product and economic-operator references are adapted for AI systems and Article 2(1) operators.
Annual reporting beyond compliance
Authorities shall annually report competition-relevant information to the Commission and relevant national competition authorities, plus prohibited practices and measures taken.
Sectoral authority allocation
For Annex I Section A product-related systems, the relevant sectoral authority is the market surveillance authority, subject to a coordinated national derogation.
Documentation, data and remote access
Providers shall grant full access to documentation and relevant development data where necessary. APIs or other remote tools may be used, subject to security safeguards.
Source code is exceptional
A reasoned request is not enough alone: source-code access also requires necessity and exhaustion or insufficiency of data- and documentation-based review.
Articles 74-76: Special Supervisors, AI Office Cooperation and Real-World Testing
Financial-sector supervision
For directly connected financial-services uses, the relevant national financial supervisor shall be market surveillance authority, subject to Article 74(7)'s coordinated derogation.
Data protection and judicial independence
Specified Annex III areas require designated data-protection authorities or similarly designated authorities. Surveillance shall not affect judicial independence or judicial activity.
When the AI Office enters
The AI Office supervises a system and its general-purpose model when both were developed by the same provider. It can supply relevant information within 30 days after a qualified request.
Testing in real-world conditions
Authorities may suspend or terminate non-compliant testing, or require changes. A decision or objection shall give grounds and explain how it may be challenged.
Article 77: Fundamental-Rights Authorities Can Obtain Evidence
A targeted access power
Fundamental-rights authorities may obtain documentation only when access is necessary to fulfil their mandate and remains within their jurisdiction.
Accessible language and format
They "shall have the power to request and access any documentation created or maintained under this Regulation in accessible language and format."
Member State list
By 2 November 2024, each Member State shall identify the relevant bodies, publish a list, notify it to the Commission and other Member States, and keep it updated.
Testing when documents are insufficient
The authority may make a reasoned request for technical testing. The market surveillance authority shall organise it with close involvement within a reasonable time.
Quiz: Documentation, Testing and Source Code
Distinguish three different powers
A national body responsible for enforcing non-discrimination obligations examines an Annex III high-risk AI system. The documentation does not let it determine whether a fundamental-rights infringement occurred. Which action does Article 77(3) describe?
What may the fundamental-rights authority do under Article 77(3)?
- It may automatically publish all documentation and source code.
- It may make a reasoned request to the market surveillance authority to organise technical testing of the high-risk AI system.
- It must itself alter the AI system to test it.
- It may require source-code access without any conditions.
Show Answer
Answer: B) It may make a reasoned request to the market surveillance authority to organise technical testing of the high-risk AI system.
Where documentation is insufficient, Article 77(3) says the authority or body may make a reasoned request to the market surveillance authority to organise testing through technical means. The authority shall organise testing with the requesting body closely involved within a reasonable time. Source-code access instead has the distinct, cumulative conditions in Article 74(13).
Article 78: Confidentiality, Strict Necessity and Cybersecurity
Confidentiality covers more than trade secrets
Article 78 protects IP, confidential business information and trade secrets, including source code, plus investigations, security interests, proceedings and classified information.
Strict necessity
Authorities "shall request only data that is strictly necessary" for risk assessment and exercising their powers under this Regulation and Regulation (EU) 2019/1020.
Cybersecurity and deletion
Authorities shall use adequate and effective cybersecurity measures and shall delete collected data as soon as it is no longer needed for its original purpose.
Sensitive operational settings
Special rules restrict disclosure and exclude sensitive operational data in specified law-enforcement, border-control, immigration and asylum contexts.
Secure access is still access
Where the named authorities are providers, technical documentation stays on their premises, but qualified surveillance staff can immediately access it or a copy upon request.
Flashcards: Exact Rules to Recall
Review the key actors, deadlines and safeguards
Flip each card, then try to explain the rule with its trigger and qualifier.
- Who shall set up and maintain the EU database?
- Article 71(1): "The Commission shall, in collaboration with the Member States, set up and maintain an EU database."
- Who enters Annex VIII Sections A and B data?
- The provider or, where applicable, the authorised representative.
- What is the ordinary outer reporting deadline for a serious incident?
- Not later than 15 days after the provider or, where applicable, deployer becomes aware of the serious incident.
- What deadline applies to a widespread infringement or Article 3, point (49)(b) incident?
- Immediately, and not later than two days after the provider or, where applicable, deployer becomes aware of that incident.
- What is the death-related outer deadline?
- Not later than 10 days after the date on which the provider or, where applicable, deployer becomes aware of the serious incident.
- When may source code be accessed under Article 74(13)?
- Only upon a reasoned request, where access is necessary for conformity assessment and data/documentation-based testing, auditing and verification have been exhausted or proved insufficient.
- What data may authorities request under Article 78(2)?
- Only data that is strictly necessary for assessing AI-system risk and exercising their powers.
Key Terms
- AI Office
- The body with specified monitoring, supervision and information-access functions for general-purpose AI systems under Article 75.
- EU database
- The database that the Commission shall set up and maintain with Member States under Article 71 for the specified registered AI systems.
- reasoned request
- A request that must give reasons; it is required, for example, for Article 74(13) source-code access and Article 77(3) technical testing.
- serious incident
- An incident for which Article 73 establishes reporting, investigation and authority-response rules; special deadlines apply in specified cases.
- strict necessity
- Article 78(2)'s limit that authorities shall request only data strictly necessary for risk assessment and exercising their powers.
- authorised representative
- The actor that, where applicable, enters Annex VIII Sections A and B data in the EU database instead of the provider under Article 71(2).
- post-market monitoring plan
- The plan on which the monitoring system shall be based; it shall be part of Annex IV technical documentation.
- market surveillance authority
- The authority assigned supervisory functions under Article 74, with sector-specific allocations and powers.
- post-market monitoring system
- The documented provider system that Article 72 requires to be proportionate to the AI technologies' nature and the high-risk AI system's risks.
- fundamental-rights authority or body
- A national public authority or body supervising or enforcing Union-law fundamental-rights obligations in relation to Annex III high-risk AI systems under Article 77.
- confidential business information or trade secrets
- Protected information under Article 78(1), including source code, alongside other protected interests and subject to the provision's stated exception.