AI Act Documents:
Recital 155
(155) In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring systempost-market monitoring systemmeans all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actionsArticle 3(25) in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational datasensitive operational datameans operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedingsArticle 3(38) of deployers which are law enforcementlaw enforcementmeans activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public securityArticle 3(46) authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructurecritical infrastructuremeans critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557Article 3(62), infringements of obligations under Union law intended to protect fundamental rightsfundamental rightsIncludes human dignity, right to life, prohibition of torture, protection of personal datapersonal dataAny information relating to an identified or identifiable natural person ('data subjectsubjectfor the purpose of real-world testing, means a natural person who participates in testing in real-world conditionsArticle 3(58)data subjectsubjectfor the purpose of real-world testing, means a natural person who participates in testing in real-world conditionsArticle 3(58)An identified or identifiable natural person to whom personal data relateGDPR Art. 4(1)'). Includes name, ID number, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural or social identityGDPR Art. 4(1), freedom of expression, non-discrimination, equality between women and men, rights of the child, right to an effective remedy and fair trialCharter of Fundamental Rights Art. 1–54 or serious damage to property or the environment.