DORA (Digital Operational Resilience Act)
The EU regulation on digital operational resilience for financial entities — extends to ICT third-party risk management, which catches LLM and AI vendor concentration risk.
What DORA (Digital Operational Resilience Act) means in practice
The Digital Operational Resilience Act is the EU regulation on digital operational resilience for financial entities — banks, insurers, investment firms, payment service providers. The provisions matter for AI in two ways. First, ICT third-party risk management explicitly catches AI and LLM vendor relationships: financial entities must assess vendor concentration risk, contractual undertakings, and recovery posture. Second, the operational-resilience testing regime includes scenario testing against major vendor failures — a category that includes cloud LLM provider disruption. DORA is one of the regulatory drivers behind the CRO framing shift toward vendor concentration risk and the operational requirement to maintain a multi-model architecture with at least one self-hosted open-weights model as the recovery path.
Related terms
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
EU AI Act →
The European Union's AI Act — risk-tiered regulation of AI systems, with high-risk-system requirements that effectively mandate auditability, human oversight and conformity assessment.
Open-weights model →
An LLM whose model weights are publicly downloadable under a permissive licence, allowing on-premise inference, fine-tuning, and full audit of the model artefact.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.