AIPolicyTracker
Legal requirement Post-market monitoring European Union Partially applicable

Deployers must monitor high-risk AI, suspend use on risk and report serious incidents

Context fileUnder EU AI Act, Article 26(5)

Source-linked Open official source

What does it require?

Deployers must monitor a high-risk AI system's operation against the provider's instructions and feed observations to the provider under Article 72. If they have reason to think the system as used may present a risk to health, safety or fundamental rights, they must inform the provider or distributor and the market surveillance authority without undue delay and suspend use. On a serious incident, they must immediately inform the provider, then the importer or distributor and the authorities. Financial institutions meet this through their internal governance rules.

Practical action

Give each high-risk system an operational owner with a kill-switch authority and a written escalation route to the provider and the authority.

Who does it apply to?

Deployers of high-risk AI systems; the incident-reporting leg is aligned with Article 73.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessIncident coordinator · continuous
    AI incident management and regulatory reporting

    Serves 14 recorded duties · evidence: AI incident response playbook, AI incident record, Incident report to an authority

    Suspension decision and notifications to provider and authority.

  • satisfiesTechnical measureAI system owner · continuous
    Post-deployment monitoring and drift detection

    Serves 10 recorded duties · evidence: Post-market monitoring plan, Monitoring dashboard or periodic monitoring report, Monitoring review decision

    Deployer-side monitoring with feedback to the provider.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Operational monitoring logrecord
Suspension and escalation proceduredocument

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 9.1; Annex A.6.2.6, A.8.4Operation and monitoring; communication of incidents.high
NIST AI RMF 1.0MANAGE 2.4, MANAGE 4.1, MANAGE 4.3Deactivation mechanisms, post-deployment monitoring and incident response.high

Cite this record

AIPolicyTracker (2026). “Deployers must monitor high-risk AI, suspend use on risk and report serious incidents (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-5-deployer-monitoring-and-suspension (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.