DORA & AI Tools: What Financial Firms Must Do (2026)
DORA is technology-neutral, so it never names AI. But a consumer AI tool is an external ICT service, and staff pasting client data into it is exactly the risk the regulation expects firms to control.
AIovert Security & Compliance Team
GDPR, EU AI Act & DORA practitioners writing on AI data protection for EU businesses.
Published 4 July 2026 · Last updated 4 July 2026
The short answer
The Digital Operational Resilience Act (DORA) applies to EU financial entities and requires them to manage ICT risk across all systems and third-party providers. When employees use AI tools, DORA is relevant because those tools are ICT services that introduce data-leakage and third-party risk. DORA has applied since 17 January 2025, so in-scope firms must already account for AI-tool usage within their ICT risk-management and third-party frameworks.
Who does DORA apply to?
DORA (Regulation (EU) 2022/2554) covers a broad range of EU financial entities: banks, payment institutions, investment firms, insurers, and crypto-asset service providers, plus certain critical ICT third-party providers. If you are in scope, ICT risk from AI tools is part of your remit, and the obligation has been live since 17 January 2025.
Are AI tools covered by DORA?
Yes. Consumer AI tools are external ICT services, so staff pasting client or transaction data into them creates data-leakage and concentration risk that DORA expects firms to identify, monitor, and mitigate under their ICT risk-management framework (Articles 5–16). The exposure is measurable: according to Cyberhaven, 11% of the data employees paste into ChatGPT is confidential, the kind of uncontrolled flow to an external provider DORA is designed to surface.
Which controls support DORA for AI tools?
A browser-level control that prevents sensitive data from reaching external AI tools, logs events for audit, and enforces policy supports the operational-resilience and third-party-risk expectations under DORA, while keeping data on the device. AIovert is an EU-based, on-device browser DLP tool that classifies and blocks sensitive data before it is entered into consumer AI tools such as ChatGPT, Claude and Gemini. See the residency angle in EU data residency and AI compliance, the deployment model in on-device vs proxy AI data protection, the financial-services playbook, and the pillar, the best GDPR DLP and AI data security tools.
Frequently asked questions
Does DORA specifically mention AI?
DORA is technology-neutral and does not single out AI, but AI tools are ICT services and therefore fall within its ICT risk-management and third-party-risk requirements. Firms must treat AI usage like any other ICT risk.
Since when has DORA applied?
DORA has applied to in-scope EU financial entities since 17 January 2025. Firms are expected to have ICT risk-management, incident-reporting, and third-party-risk arrangements in place, which should account for AI-tool usage.
How does a data control help with DORA?
By preventing uncontrolled data flows to external AI providers, producing audit logs, and enforcing policy, it supports the ICT risk-management and third-party-oversight obligations DORA imposes.
Primary sources
- DORA: Regulation (EU) 2022/2554 (eur-lex.europa.eu)
- DORA Articles 5–16: ICT risk management framework (eur-lex.europa.eu)
- European Supervisory Authorities: DORA materials (eiopa.europa.eu)
- Cyberhaven: 11% of data pasted into ChatGPT is confidential (cyberhaven.com)
Regulatory dates and requirements can change. Verify against the official EU sources above before relying on them. This page is informational and not legal advice.
See AIovert live
ICT-risk control for AI tools: block client and transaction data from reaching external AI, log every event, keep data on-device. Set up in ~15 minutes.