Post-deployment monitoring and drift detection
Watches a live AI system for falling performance, shifting data, emerging bias and unexpected use, and turns what it sees into corrective action, incident reports and documentation updates.
- Duties satisfied
- 3
- done properly, does the work
- Duties supported
- 7
- contributes; the duty needs more
- Jurisdictions
- 4
- Evidence items
- 3
How is it implemented?
Each deployed system has a monitoring plan that names the indicators to be tracked, the thresholds that trigger review, the feedback channels open to users and deployers, and who looks at the results and how often. Telemetry from logs, sampled human review of outputs, complaint data and periodic re-testing feed a dashboard or report. When an indicator breaches its threshold the owner opens a ticket, decides whether retraining, rollback, extra oversight or an incident report is needed and records the outcome. Monitoring findings are reviewed at governance meetings and feed the annual refresh of the risk and impact assessments.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
European Union 6 duties
-
satisfies Legal requirement confidence highOperate a post-market monitoring system
EU AI Act · Article 72 · applies from 2 Aug 2026
Documented monitoring plan with indicators, feedback channels and review cadence.
-
satisfies Legal requirement confidence highDeployers must monitor high-risk AI, suspend use on risk and report serious incidents
EU AI Act · Article 26(5) · applies from 2 Aug 2026
Deployer-side monitoring with feedback to the provider.
-
supports Legal requirementEstablish a risk management system for high-risk AI
EU AI Act · Article 9 · applies from 2 Aug 2026
Post-market data feeds risk re-evaluation.
-
supports Legal requirementAchieve appropriate accuracy, robustness and cybersecurity
EU AI Act · Article 15 · applies from 2 Aug 2026
Consistent performance over the lifecycle is confirmed in operation.
-
supports Legal requirementUse high-risk AI as instructed, monitor it and inform affected people
EU AI Act · Article 26 · applies from 2 Aug 2026
Monitoring operation and informing the provider of risks.
-
supports Legal requirementDeployers must ensure input data they control is relevant and representative
EU AI Act · Article 26(4) · applies from 2 Aug 2026
Detects input drift away from the intended population.
Singapore 1 duty
-
satisfies VoluntaryManage data quality, model development and monitoring across the lifecycle
Singapore Model AI Governance Framework · Second edition, Part on operations management
Active monitoring and regular tuning after deployment.
Colorado (United States) 2 duties
-
supports Legal requirementDeployers must complete impact assessments for high-risk AI
Colorado AI Act · C.R.S. 6-1-1703(3) · applies from 30 Jun 2026
Post-deployment monitoring described in the assessment.
-
supports Legal requirementDevelopers must notify the Attorney General and deployers of discovered algorithmic discrimination
Colorado AI Act · C.R.S. 6-1-1702(5) · applies from 30 Jun 2026
Ongoing testing is one of the discovery routes the statute names.
United States 1 duty
-
supports Voluntary confidence highMeasure and test trustworthiness characteristics (Measure)
NIST AI RMF · MEASURE function
Tracking metrics over time.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| Post-market monitoring plan | Procedure or standard operating process | Indicators, thresholds, feedback channels, review cadence and responsibilities for one system. |
| Monitoring dashboard or periodic monitoring report | Monitoring record | |
| Monitoring review decision | Approval or sign-off record | Recorded decision on retraining, rollback or escalation after a threshold breach. |
Owner: AI system owner. Frequency: continuous.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 7.3 Lack of capability or robustness AI system safety, failures, & limitations305 incidents · 126 risk entries
- 1.3 Unequal performance across groups Discrimination & Toxicity34 incidents · 17 risk entries
- 5.1 Overreliance and unsafe use Human-Computer Interaction38 incidents · 60 risk entries
- 6.5 Governance failure Socioeconomic & Environmental3 incidents · 61 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Clause 9.1; Annex A.6.2.6 | high | |
| NIST AI RMF | MEASURE 3.1, 3.3; MANAGE 4.1 | high | |
| ISO/IEC 23894 | Clause 6.6 | Monitoring and review of AI risks. | medium |
Cite this record
AIPolicyTracker (2026). “Post-deployment monitoring and drift detection”. https://aipolicytracker.org/controls/post-market-monitoring-and-drift-detection (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "Post-deployment monitoring and drift detection" satisfy?
- It is recorded as satisfying 3 and supporting 7 duties across European Union, Singapore, Colorado (United States) and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- Post-market monitoring plan, Monitoring dashboard or periodic monitoring report and Monitoring review decision. Owner: AI system owner. Frequency: continuous.