Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
EUDEEP coverage

EU Digital Operational Resilience Act (DORA): AI Compliance Requirements

EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entities and their ICT service providers. It mandates a harmonized ICT risk management framework covering AI tools, mandatory third-party ICT risk assessment contracts (including AI vendors), regular resilience testing, and major ICT incident reporting. Financial entities using AI tools must include them in their ICT risk management and third-party oversight programs.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 17, 2025

Maximum Penalty

No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance.

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

ICT Risk Management Framework

Critical

Implement a documented ICT risk management framework covering all ICT assets including AI tools and services. Must include risk identification, protection measures, detection capabilities, response protocols, and recovery procedures. Board-level oversight of ICT risk is required.

Deadline: January 17, 2025

DORA Art. 5-16

Third-Party ICT Risk Assessment (AI Vendors)

Critical

Assess and document ICT risks from all third-party ICT service providers, including AI tool vendors (OpenAI, Microsoft Copilot, etc.). Contracts with ICT service providers must include mandatory clauses: security requirements, audit rights, exit strategies, and incident notification obligations.

Deadline: January 17, 2025

DORA Art. 28-30

Mandatory Contract Clauses for AI Vendors

Critical

Any AI software vendor contracted by an EU financial institution must ensure their contracts include DORA-mandatory clauses: (1) security SLAs aligned with client's ICT risk management standards; (2) audit rights for the financial entity and regulatory authorities; (3) incident notification obligations (within defined timelines); (4) exit planning and data portability; (5) subcontracting disclosure and controls.

Deadline: January 17, 2025

DORA Art. 30

Major ICT Incident Reporting

High Priority

Establish incident management processes to detect, classify, and report major ICT-related incidents to the relevant national competent authority. Includes incidents caused by or involving AI systems. Initial report within 4 hours of classification; intermediate report within 72 hours; final report within one month.

Deadline: January 17, 2025

DORA Art. 17-23

Digital Operational Resilience Testing

Medium Priority

Conduct annual resilience testing of ICT systems including AI tools (vulnerability assessments, penetration testing). Significant institutions must conduct Threat-Led Penetration Testing (TLPT) every 3 years.

Deadline: January 17, 2026

DORA Art. 24-27

Who Does This Apply To?

DORA applies to 20 categories of EU financial entities: credit institutions (banks), payment institutions, e-money institutions, investment firms, crypto-asset service providers (MiCA), insurance undertakings, asset management companies, trading venues, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers, and others. It also applies to their ICT third-party service providers (including AI software vendors, cloud AI APIs, and AI-powered security tools). "Critical ICT third-party providers" may be directly supervised by European Supervisory Authorities (ESAs). An AI vendor selling to EU-regulated financial institutions is an "ICT third-party service provider" and must comply with DORA contractual requirements.

Recent Regulatory Guidance

rulemaking2025-01-17

ESA Joint Guidelines on DORA Third-Party ICT Risk Assessment

Joint EBA/ESMA/EIOPA guidelines confirm that AI APIs and cloud AI services constitute "ICT third-party services" under DORA and must be included in financial institutions' third-party ICT risk programs. Guidelines specify that: (1) AI model documentation must be provided to financial entity upon request; (2) AI vendor must notify financial entity within 4 hours of major AI system incident affecting financial entity's operations; (3) financial entity must maintain exit plan for each critical AI dependency.

Source
guidance2025-11-18

Critical ICT Third-Party Provider (CTPP) Oversight — First Designations (19 providers)

ESAs published the first list of 19 Critical ICT Third-Party Providers (CTPPs) subject to direct EU supervisory oversight under DORA Art. 31-35, spanning hyperscale cloud, data-center, infrastructure/network, and financial-sector-specific technology providers — including AWS, Microsoft, Google Cloud, Deutsche Telekom, Oracle, and SAP. Designation triggers direct Lead-Overseer oversight: annual risk analyses, comprehensive reporting, on-site inspections, and Joint Examination Team (JET) supervision. The list is updated and republished annually.

Source
guidance2026-01-01

2026 — Supervisory Posture Shifts From Readiness Checks to Active Enforcement

Multiple 2026 compliance trackers (Legiscope, regulation-dora.eu) report that, roughly a year into DORA's application, national competent authorities and the ESAs shifted from readiness assessments to active enforcement in 2026 — examining firms for compliance EVIDENCE rather than remediation plans. As of this cycle, first formal fines under national Art. 50 penalty regimes are anticipated in the second half of 2026 but had not yet been independently confirmed/named; left unset rather than guessed.

Source

Quarterly Enforcement Digest

Q3 2026: DORA fully in application since January 17, 2025; 2026 marks the shift from readiness checks to active enforcement, with first formal national-law fines anticipated in H2 2026 (not yet independently confirmed as of this cycle). The first Critical ICT Third-Party Provider list — 19 providers, spanning cloud, data-center, network, and financial-tech categories (AWS, Microsoft, Google Cloud, Deutsche Telekom, Oracle, SAP) — was published 2025-11-18, not September 2025 as previously stated; it is republished annually. Penalty exposure differs sharply by role: financial entities face NATIONAL, Member-State-set penalties under Art. 50 (no single EU-wide percentage — a >50x spread exists between the lowest and highest national ceilings found), while only the 19 designated Critical ICT providers face the EU-level Art. 35 periodic penalty (up to 1% of average daily worldwide turnover, for up to 6 months). AI vendors selling to EU financial institutions must ensure contracts include all DORA Art. 30 mandatory clauses.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering EU Digital Operational Resilience Act (DORA)

These industry playbooks include jurisdiction-specific checklist items and guidance for EU Digital Operational Resilience Act (DORA).

Frequently Asked Questions

Does EU Digital Operational Resilience Act (DORA) apply to my business?

EU DORA (Regulation 2022/2554, in application January 17, 2025) applies to 20 categories of EU-regulated financial entities and their ICT service providers. It mandates a harmonized ICT risk management framework covering AI tools, mandatory… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under EU Digital Operational Resilience Act (DORA) is: No single EU-wide penalty amount for financial entities — DORA Art. 50 delegates administrative-penalty amounts to each Member State's own national law, with wide divergence (e.g., Finland caps individual penalties at €100,000; Germany at €5,000,000). For DESIGNATED CRITICAL ICT third-party providers only, the EU-level Lead Overseer may impose a periodic penalty payment under Art. 35 of up to 1% of average daily worldwide turnover, charged daily for a maximum of 6 months, until compliance.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with EU Digital Operational Resilience Act (DORA)?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/digital-operational-resilience-act-dora

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan