Short answer. DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), is the EU law that requires banks, insurers, and other financial entities to withstand, respond to, and recover from technology disruptions. It has applied since 17 January 2025. DORA treats artificial intelligence as information and communication technology (ICT), so an AI model or an external AI vendor falls under the same risk management, testing, and oversight rules as any other critical system. It does not set up a separate AI regime, it folds AI into one accountable resilience framework that the management body owns.
For an AI system, each DORA obligation turns into a concrete requirement. A credit-scoring model is ICT, so it needs monitoring, access controls, and a tested recovery plan. An AI vendor that hosts a model is an ICT third-party provider, so its contract needs the same audit and exit clauses as a core banking platform. If a model fails in a way that disrupts a critical function, the outage can cross the threshold for a reportable incident and start the clock on the notification deadline.
The penalties give the rules weight. Competent authorities can impose periodic penalties, fine critical third-party providers up to 1% of average daily worldwide turnover per day, suspend specific ICT services, and ban senior managers from their functions until a firm complies.
DORA stands on five pillars. ICT risk management requires a documented framework to identify, protect, detect, and recover, with the management body legally accountable (Articles 5 to 16). Incident management requires major ICT-related incidents to be classified and reported to the competent authority on a fixed timeline, with the initial notification due within hours of detection. Digital operational resilience testing includes threat-led penetration testing for the largest entities. Third-party risk requires contracts with ICT providers to specify audit rights, exit strategies, and service levels. The fifth pillar is information sharing on cyber threats between financial entities.
DORA has applied since 17 January 2025 and treats AI as ICT, with no separate AI regime.
Yes. An AI vendor that hosts or serves a model is an ICT third-party provider under DORA, including providers based outside the EU. Its contract needs the same audit rights, exit strategy, and service levels as a core banking system, and the European Supervisory Authorities now directly oversee providers designated as critical. A model accessed through an external API, a hosted vector database, and a managed inference service each count as a separate arrangement, so an insurer running generative AI through a cloud provider has to govern that dependency, not just the model.
DORA asks for an artifact that many AI programs never produce: a complete inventory. Every financial entity has to maintain a Register of Information that lists each ICT third-party arrangement supporting an important function, and submit it to its supervisor. An insurer that runs three generative AI use cases through one cloud provider has to record that dependency, name the function it supports, and hold an exit plan for it. A bank that cannot say which AI services touch a critical function is already behind the rule.
The two operate together for AI in finance. The AI Act governs how an AI system is built and what it is allowed to decide, classifying credit scoring and life and health insurance pricing as high-risk. DORA governs whether that system stays available and accountable when something breaks. A bank that deploys an AI underwriting model has to satisfy both: the AI Act for human oversight and documentation, DORA for operational resilience and third-party control. Running them as one program, rather than two separate compliance projects, is what keeps the cost contained and the timeline realistic.
DORA applies to 20 categories of financial entity, from banks and insurers to investment firms and crypto-asset service providers, and it reaches any ICT provider that serves them. For financial services and insurance in Slovakia, the Czech Republic, and Austria, this closes the gap between an AI pilot and a production system. A model that runs in a demo carries no resilience obligation. The same model wired into loan approvals or claims handling becomes part of a critical function, and DORA expects it to be tested, logged, and recoverable. Accountability sits with the management body, not the data science team, so a board that approves an AI use case now owns its resilience in the eyes of the supervisor.
Begin with the inventory, because every other obligation depends on it. List each AI service in use, name the function it supports, and mark which functions are critical or important. From that list, build the Register of Information, then check each critical arrangement for the contract clauses DORA requires: audit rights, an exit strategy, and service levels. Next, confirm the incident process can classify and report a major ICT event inside the notification window, and that someone on the management body owns the framework. A firm that can produce its register, its contracts, and its incident playbook on request is most of the way to compliant, because those three artifacts are what a supervisor asks for first.
The hard part of DORA is not writing the policy, it is proving that an AI system behaves the way the policy claims. Ableneo builds that proof into delivery for regulated clients across Central Europe, including ČSOB, Erste, and UNIQA, where every model ships with monitoring, logged decisions, and a recovery path from the first release. About 80% of Ableneo projects reach production, against an industry pattern of pilots that stall before they meet a control, and that rate comes from designing for audit and resilience before the first model goes live. Our work on AI transformation treats people, data, governance, and the model as one system, because a resilient AI system depends on the structure that surrounds it.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.