Regulation
DORA AI compliance
What the Digital Operational Resilience Act actually requires of AI systems in financial services — and how Svalv maps every obligation to a concrete evidence artifact.
What DORA actually requires of AI systems
DORA (Regulation (EU) 2022/2554) has been binding on EU financial entities since 17 January 2025. It establishes a comprehensive ICT risk management framework that applies to any technology supporting critical or important functions — including AI and LLM systems.
Article 28: ICT third-party register
Financial entities must maintain a register of all ICT third-party service providers, including AI vendors. The register must document the services provided, data processing locations, subcontracting chains, and exit strategies. For on-premise AI, the register entry is simpler — but it still must exist.
Incident reporting
Major ICT-related incidents must be reported to competent authorities within prescribed timeframes. AI system failures, model misbehaviour, and data integrity incidents all qualify. Your infrastructure needs immutable logs that prove what happened, when, and what was affected.
Resilience testing and TLPT
DORA requires regular resilience testing, and for significant entities, threat-led penetration testing (TLPT). AI systems supporting critical functions must be included. This means your LLM infrastructure needs documented test procedures, results, and remediation evidence.
The gap generic AI vendors leave
Most private-AI vendors stop at deployment: they'll host a model for you, maybe in an EU data centre. But DORA doesn't ask “is the model running?” It asks: “where is the register entry? Show me the incident response log. Prove the resilience test. Document the exit strategy.”
Cloud-based AI APIs add complexity: foreign jurisdiction, opaque subcontracting chains, and concentration risk that DORA specifically warns against. Self-hosted AI eliminates these concerns — but only if you generate the evidence.
DORA requirement → Svalv evidence artifact
| DORA requirement | Svalv evidence artifact |
|---|---|
| Art. 28 ICT third-party register | Auto-generated register entries with data processing locations, model provenance, and version history |
| Incident reporting | Immutable audit trail with timestamped inference logs, error records, and anomaly detection alerts |
| Resilience testing | Automated resilience test reports: model degradation checks, failover verification, load testing results |
| TLPT (threat-led penetration testing) | Infrastructure hardening documentation, attack surface analysis, penetration test-ready architecture |
| Exit strategy | Documented model portability: open-source models on standard hardware, no proprietary lock-in |
| Subcontracting chains | Complete dependency map: no hidden subprocessors, all components auditable |
| EU AI Act Annex IV (when applicable) | Technical documentation: training data provenance, model architecture, risk assessment, monitoring measures |
Key dates
17 January 2025
binding
DORA (Regulation (EU) 2022/2554) applies to EU financial entities and ICT third-party service providers.
2 August 2026
statutory
EU AI Act high-risk obligations (Annex III) — including AI in credit scoring and insurance — statutory effective date.
2 December 2027
proposed deferral
Digital Omnibus package proposes deferring high-risk AI obligations to this date. Provisionally agreed; not yet final. Check EUR-Lex for current status.
Dates verified July 2026. The EU AI Act timeline is in flux; this page is updated quarterly. Last review: July 2026.
Frequently asked questions
Bring sovereign AI inside your walls.
Book a call or join the pilot. We'll map your infrastructure and models to DORA and EU AI Act requirements — and the evidence to prove it.