What is DORA and who does it apply to?

DORA is Regulation (EU) 2022/2554, the Digital Operational Resilience Act. It has applied since 17 January 2025 and covers 21 categories of financial entity — banks, insurers, investment firms, payment institutions, crypto-asset service providers and others — together with the ICT providers that serve them.

Its scope is deliberately broad. Rather than prescribing technologies, DORA sets requirements across five areas: ICT risk management, incident reporting and classification, digital operational resilience testing, ICT third-party risk management, and an EU-level oversight regime for providers designated as critical to the sector.

Why is an AI vendor treated as ICT third-party risk?

Because that is what it is. DORA's definition of ICT services covers digital and data services provided on an ongoing basis through ICT systems. An AI assistant that indexes your documents and answers questions about them plainly qualifies. The consequence is that AI procurement moves out of innovation budgets and into the third-party risk framework.

For most institutions this is the single largest practical change. AI pilots that were previously assessed on capability and cost now have to clear the same contractual bar as a core systems supplier — before deployment, not after.

What Articles 28–30 require of an ICT contract
Requirement areaWhat the contract must address
Service descriptionA clear and complete description of functions and services, including whether subcontracting of critical or important functions is permitted.
Data locationThe locations where data is processed and stored, and notice requirements if those change.
Availability and integrityProvisions ensuring availability, authenticity, integrity, and confidentiality of data, including personal data.
Access and audit rightsFull access, inspection, and audit rights for the financial entity and its competent authorities.
Incident handlingAssistance obligations when an ICT incident occurs, at no additional cost or at a pre-agreed cost.
Termination and exitTermination rights and transition periods that allow the entity to move without operational disruption.

What is the register of information and what goes in it?

The register of information is a structured inventory of every contractual arrangement with an ICT third-party provider, maintained at entity, sub-consolidated and consolidated level, and reported to competent authorities. The reporting templates are set by Commission Implementing Regulation (EU) 2024/2956.

In practice this is where informal AI adoption becomes visible. A departmental subscription to an AI tool, expensed on a card and never routed through procurement, is still an ICT arrangement. If it is not in the register, the register is incomplete — and completeness is exactly what supervisors examine.

  • Identify every AI service currently in use, including departmental and trial subscriptions.
  • Determine for each whether it supports a critical or important function.
  • Capture the provider's identity, the service description, and the data processing and storage locations.
  • Record the contractual terms against the Article 30 requirements and note the gaps.
  • Establish who owns the entry and how it is kept current as the service changes.

What changes when AI supports a critical or important function?

The requirements tighten substantially. Arrangements supporting critical or important functions attract enhanced contractual terms, closer supervisory attention, and a documented exit strategy that lets you move provider without operational disruption. Concentration risk also has to be assessed and managed.

Exit strategy is the requirement that most directly shapes AI architecture. To exit an AI platform you need your index or the ability to rebuild it, your configuration, your evaluation baselines, and your audit history — in formats you can take elsewhere. A platform that cannot export those artefacts makes a compliant exit strategy difficult to write honestly.

How does DORA interact with the EU AI Act?

They are separate regimes on separate timelines, and a financial entity deploying AI is generally subject to both. DORA governs operational resilience and third-party risk. The AI Act, Regulation (EU) 2024/1689, governs the AI system itself — its risk classification, transparency, and, for high-risk uses, conformity obligations.

EU AI Act application dates as they now stand
DateWhat applies
2 February 2025Prohibited practices and AI literacy obligations.
2 August 2025General-purpose AI model obligations; national competent authorities and EU governance structures.
2 August 2026Article 50 transparency obligations, including disclosure that content is AI-generated. Penalties for breach reach €15 million or 3% of worldwide annual turnover, whichever is higher.
2 December 2026End of the transitional period for marking and detection obligations on generative AI systems already on the market.
2 December 2027Annex III high-risk obligations, deferred from 2 August 2026 by the Digital Omnibus agreement reached in May 2026.
2 August 2028Annex I high-risk obligations for AI embedded in regulated products, deferred from 2 August 2027.

What should a financial entity do about AI under DORA?

Treat AI procurement as ICT third-party procurement from the beginning. The work divides into an inventory exercise you can start immediately and a contractual exercise that has to happen before anything new is deployed.

Inventory what exists

Find every AI service in use across the organisation, including the ones that never went through procurement. Expense data and network logs usually reveal more than a survey does.

Classify by function

Determine which arrangements support critical or important functions. This decides which contractual and exit requirements apply.

Assess contracts against Article 30

Audit rights, data location, subcontracting, incident assistance, and termination are the clauses most often missing from AI vendor agreements written for a different market.

Write the exit strategy

Specify what you would need to move provider and confirm the vendor can actually supply it. Test the export rather than trusting the clause.

Fold AI into resilience testing

Include AI-supported processes in your testing programme and in incident classification, so a degradation is detected and reported like any other ICT incident.