The provider's Article 72 system must actively and systematically collect, document, and analyse relevant data about high-risk AI system performance throughout the system lifetime. The data may come from deployers or other sources and must allow the provider to evaluate continuous compliance with the Chapter III, Section 2 high-risk requirements.
The monitoring plan is part of Annex IV technical documentation, so it should be versioned with the system description, intended purpose, risk management file, testing evidence, change history, instructions for use, and EU declaration of conformity. Treat deployer feedback, support tickets, operational logs, drift metrics, bias or discrimination signals, cybersecurity signals, near misses, and complaints as inputs to a monitored compliance file, not only as customer-success data.
Regulation (EU) 2026/1744 removes the power to impose one harmonised plan template. Instead, the Commission must publish guidance, including a voluntary post-market monitoring plan template, by 2 September 2027. Providers remain responsible for a plan that fits the system and organisation; waiting for the voluntary template does not replace system-specific preparation.