See how Trussed maps to DORA in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    DORA and AI: Operational Resilience Overlap for Financial Services

    DORA does not name AI or AI agents, but its ICT risk management, incident reporting, and third-party oversight provisions apply structurally to AI systems: model providers count as ICT third-party providers, agent tool calls introduce sub-outsourcing-like dependency chains, and AI failures affecting critical functions must be assessed against DORA's incident classification thresholds.

    Direct answerDORA does not name AI or AI agents, but its ICT risk management, incident reporting, and third-party oversight provisions apply structurally to AI systems: model providers count as ICT third-party providers, agent tool calls introduce sub-outsourcing-like dependency chains, and AI failures affecting critical functions must be assessed against DORA's incident classification thresholds.

    Where DORA Meets AI Deployment

    Four existing DORA provisions carry the most direct weight for institutions running AI models and AI agents in production.

    ICT Risk Management

    AI systems supporting critical functions fall under DORA's identification, protection, detection, response, and recovery obligations.

    Third-Party Oversight

    AI model providers and hosting infrastructure delivered via API meet DORA's definition of ICT third-party services.

    Incident Classification

    Model drift or agent misbehavior can trigger DORA's major incident reporting thresholds if it disrupts a critical function.

    Resilience Testing

    DORA's testing programme, including TLPT for significant entities, extends interpretively to AI-dependent workflows.

    DORA as the Existing Regulatory Baseline

    Regulation (EU) 2022/2554, known as DORA, entered into force on 16 January 2023 and became applicable across EU financial entities on 17 January 2025. It establishes a binding ICT risk management framework, incident classification and reporting rules, third-party oversight requirements, and a digital operational resilience testing programme. DORA's text does not reference artificial intelligence, AI models, or AI agents as distinct categories. Financial entities deploying AI systems must therefore work from an existing regulatory baseline rather than an AI-specific rulebook, applying DORA's ICT provisions to AI insofar as AI constitutes an ICT system, an ICT service, or is delivered through an ICT third-party provider. This distinction matters for risk leaders: compliance obligations for AI systems are not new obligations layered on top of DORA, they are existing obligations that AI deployment brings into scope.

    Mapping DORA's ICT Risk Categories to AI-Specific Risk

    DORA requires an ICT risk management framework covering identification, protection, detection, response, and recovery, regardless of whether functions are performed in-house or outsourced. Applied to AI, this means model drift or performance degradation in production is not separately defined by DORA but can constitute an ICT-related incident if it disrupts a critical or important function. Agentic AI systems that autonomously initiate tool calls or transactions introduce dependency chains, spanning the foundation model provider, the orchestration layer, and downstream APIs, that map onto DORA's ICT third-party and sub-outsourcing provisions. Since DORA provides no AI-specific threshold, financial entities need to define internal criteria for what constitutes a reportable AI-driven disruption and document the rationale for how AI systems are classified within the existing framework.

    Third-Party AI Risk Under DORA's Oversight Framework

    DORA requires financial entities to maintain a Register of Information documenting all contractual arrangements with ICT third-party providers, including sub-outsourcing chains. AI models delivered via API or hosted infrastructure typically fall under this definition, triggering the same contractual and register obligations as other outsourced ICT functions. DORA also establishes an EU-level oversight framework allowing the European Supervisory Authorities to designate Critical ICT Third-Party Providers subject to direct oversight. Risk leaders should assess whether AI infrastructure or model hosting providers meet this criticality threshold. Sub-outsourcing by ICT third-party providers must be identified and assessed under DORA, which extends to cases where a model provider relies on downstream cloud infrastructure or a separate hosting layer. Financial entities remain fully accountable under DORA even when these services are outsourced.

    Incident Classification and Reporting for AI System Failures

    Articles 17 through 19 of DORA require financial entities to classify ICT-related incidents against defined materiality thresholds, such as client impact, data loss, and duration, and report major incidents to competent authorities within set timeframes. An AI system failure, whether a model outage, a drift-driven output error, or an unexpected agent tool call, must be evaluated against these same thresholds if it affects a critical or important function. Because DORA offers no AI-specific classification criteria, institutions are extending existing incident response runbooks to cover AI failure scenarios. This requires sufficient logging and traceability of AI agent tool calls to reconstruct incident timelines, a capability that is often not native to model deployment stacks built primarily for performance rather than auditability.

    Extending Resilience Testing to Agentic AI Workflows

    Articles 24 through 27 mandate a digital operational resilience testing programme, including basic testing for all in-scope entities and advanced Threat-Led Penetration Testing for entities identified as significant. This testing regime was designed around traditional ICT attack surfaces. Extending test scenarios to autonomous or tool-using AI agents is an interpretive application of DORA rather than an explicit requirement, but it follows the same logic as testing any other ICT-supported function. Institutions are including AI-driven and tool-calling workflows within resilience testing scope, particularly where those workflows support critical or important functions, and establishing fallback and recovery procedures for AI-dependent processes consistent with DORA's business continuity requirements.

    Governance and Accountability at the Board Level

    Board-level accountability under DORA for ICT risk extends to AI systems supporting critical or important functions, which requires documented oversight of AI vendor selection and deployment decisions. Exit strategies and substitutability assessments required under DORA's third-party provisions should explicitly address dependency on specific AI model providers, since switching providers for an embedded model can carry different operational risk than switching a traditional software vendor. For AI agents that execute tool calls autonomously, runtime controls that enforce least privilege on agent permissions and require approval for sensitive tool actions can help produce the audit logging that DORA's incident reporting and supervisory examination processes require. Trussed AI provides runtime governance and security controls, including agent identity, tool approval workflows, and audit logging, that support the auditability financial institutions need when demonstrating how AI-driven operations are monitored and controlled under an existing DORA framework.

    Governance Controls to Support DORA Compliance for AI Operations

    • Identify which AI vendors and model providers qualify as ICT third-party providers, and assess whether any meet criteria for critical provider designation.
    • Confirm incident classification criteria account for AI-specific failure modes, including model drift and unintended agent tool calls.
    • Include AI-dependent workflows within the scope of resilience testing and TLPT programmes where they support critical functions.
    • Maintain register-of-information data for AI infrastructure and model providers, including sub-outsourcing and exit terms.
    • Retain audit trails for AI agent decisions and tool calls sufficient to support incident reporting and supervisory examination.
    • Coordinate AI governance functions, such as model risk and data science, with existing DORA ICT risk management owners.

    Map Your AI Systems Against DORA's ICT Risk Framework

    Understand where AI model providers, agent tool calls, and third-party infrastructure intersect with DORA's incident reporting, testing, and oversight obligations.

    Talk to an Expert