The three previous articles in this series are cleanly ruled out for the deploying company: it doesn't build, it doesn't have what needs to be kept and Annex IV doesn't even impose anything.
With post-market monitoring the split stops being clean, and it's worth saying that up front: here the easy conclusion doesn't hold. Article 72 belongs to the provider, yes. But the deploying company has related duties, they sit in another article, and one of them is among the most demanding in the whole Regulation.
What Article 72 requires, and of whom
"Providers shall establish and document a post-market monitoring system in a manner that is proportionate to the nature of the AI technologies and the risks of the high-risk AI system."
Paragraph 2 describes what that system does: it collects, documents and analyses data on the system's performance "actively and systematically" throughout its lifetime, so that the provider can assess whether it continues to meet the requirements.
And that's where the piece that decides the split shows up. The data that system analyses is, in the words of the text, "relevant data which may be provided by deployers or which may be collected through other sources".
The deploying company doesn't build the monitoring system: it's one of its sources. And that position isn't decorative, because the Regulation imposes it elsewhere.
What Article 26(5) does require of you
Paragraph 5 of Article 26 is short and contains three distinct duties. It deserves a full read before ruling anything out.
First, monitor. "Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72."
Note the cross-reference: your duty to inform is defined by reference to the provider's system. These aren't two separate worlds — you are the designated informant of the mechanism the provider is required to maintain.
Second, warn and suspend. Where you have reason to consider that using the system in accordance with its instructions may result in it presenting a risk within the meaning of Article 79(1), you must inform the provider or distributor and the market surveillance authority "without undue delay", and suspend use.
That last obligation rarely makes it onto any task list, and it's the toughest one in the paragraph: it isn't informing and waiting for instructions. It's stopping using it.
Third, escalate serious incidents. If you identify a serious incident, you must inform "immediately" — and the article fixes the order: first the provider, then the importer or distributor and the market surveillance authority.
Why the easy reading is dangerous here
In the three previous articles, "this belongs to the provider" settled the matter. Not here, and getting that confused has real consequences.
A company that concludes "post-market monitoring isn't mine" and files it away will have got the subject of Article 72 right and got everything else wrong: it will still have the duty to monitor operation, to inform, to notify the authority, and to suspend use in the face of a risk.
The difference between "this obligation isn't mine" and "I have no related obligation" is exactly where compliance plans fall apart. And it's an error you won't catch by reading Article 72 alone: you have to go to Article 26.
What it takes to be able to comply with Article 26(5)
Three things, and none of them is a new document.
Know who monitors each system. "Monitoring operation on the basis of the instructions for use" needs a specific person to do it and to know it's theirs to do. Without a name, the duty isn't assigned — it's just stated.
Have the instructions for use on hand. The paragraph anchors monitoring to them. If nobody knows where they are, the reference has nothing to point to.
Know who to notify, and in what order. Provider first. Then the importer or distributor, and the market surveillance authority. Working out those contacts on the day of the incident wastes the hours the Regulation itself treats as critical — and we'll see the underlying reason when we cover Article 73, where the notification deadlines start counting from the moment you become aware of the incident.
What this case teaches about the others
This block has been ruling out provider articles one by one, each for a different substantive reason. Article 72 is the one that shows the limit of the method: ruling out the subject of an article doesn't rule out the matter.
And it's a good reminder of why the real work isn't reading the Regulation — it's having written down, system by system and dated, who monitors it, where its instructions are, and who gets called if something goes wrong. That isn't something you improvise on the day it's needed, which is precisely the only day it's needed.
Content in accordance with Articles 26 and 72 of Regulation (EU) 2024/1689.
This article is for informational purposes only and does not constitute legal advice.