Regulation

DORA AI compliance

What the Digital Operational Resilience Act actually requires of AI systems in financial services — and how Svalv maps every obligation to a concrete evidence artifact.

What DORA actually requires of AI systems

DORA (Regulation (EU) 2022/2554) has been binding on EU financial entities since 17 January 2025. It establishes a comprehensive ICT risk management framework that applies to any technology supporting critical or important functions — including AI and LLM systems.

Article 28: ICT third-party register

Financial entities must maintain a register of all ICT third-party service providers, including AI vendors. The register must document the services provided, data processing locations, subcontracting chains, and exit strategies. For on-premise AI, the register entry is simpler — but it still must exist.

Incident reporting

Major ICT-related incidents must be reported to competent authorities within prescribed timeframes. AI system failures, model misbehaviour, and data integrity incidents all qualify. Your infrastructure needs immutable logs that prove what happened, when, and what was affected.

Resilience testing and TLPT

DORA requires regular resilience testing, and for significant entities, threat-led penetration testing (TLPT). AI systems supporting critical functions must be included. This means your LLM infrastructure needs documented test procedures, results, and remediation evidence.

The gap generic AI vendors leave

Most private-AI vendors stop at deployment: they'll host a model for you, maybe in an EU data centre. But DORA doesn't ask “is the model running?” It asks: “where is the register entry? Show me the incident response log. Prove the resilience test. Document the exit strategy.”

Cloud-based AI APIs add complexity: foreign jurisdiction, opaque subcontracting chains, and concentration risk that DORA specifically warns against. Self-hosted AI eliminates these concerns — but only if you generate the evidence.

DORA requirement → Svalv evidence artifact

DORA requirementSvalv evidence artifact
Art. 28 ICT third-party registerAuto-generated register entries with data processing locations, model provenance, and version history
Incident reportingImmutable audit trail with timestamped inference logs, error records, and anomaly detection alerts
Resilience testingAutomated resilience test reports: model degradation checks, failover verification, load testing results
TLPT (threat-led penetration testing)Infrastructure hardening documentation, attack surface analysis, penetration test-ready architecture
Exit strategyDocumented model portability: open-source models on standard hardware, no proprietary lock-in
Subcontracting chainsComplete dependency map: no hidden subprocessors, all components auditable
EU AI Act Annex IV (when applicable)Technical documentation: training data provenance, model architecture, risk assessment, monitoring measures

Key dates

17 January 2025

binding

DORA (Regulation (EU) 2022/2554) applies to EU financial entities and ICT third-party service providers.

2 August 2026

statutory

EU AI Act high-risk obligations (Annex III) — including AI in credit scoring and insurance — statutory effective date.

2 December 2027

proposed deferral

Digital Omnibus package proposes deferring high-risk AI obligations to this date. Provisionally agreed; not yet final. Check EUR-Lex for current status.

Dates verified July 2026. The EU AI Act timeline is in flux; this page is updated quarterly. Last review: July 2026.

Frequently asked questions

Bring sovereign AI inside your walls.

Book a call or join the pilot. We'll map your infrastructure and models to DORA and EU AI Act requirements — and the evidence to prove it.