How should AI risks be managed under DORA?

Published on

06/07/2026

Updated on

10/07/2026

Reading time

2 min

On December 18, 2025, the Federal Financial Supervisory Authority (BaFin) published a guidance document for regulated financial companies, meant to provide support for using Artificial Intelligence (AI). The document isn’t mandatory but is supposed to make the regulatory requirements for using AI more understandable in light of the Digital Operational Resilience Act (DORA). This article gives an overview of BaFin’s AI guidance.

How does the EU AI regulation define the term ‘AI system’?

According to Art. 3 No. 1 of the EU AI Regulation, an AI system is a “machine-based system designed for varying degrees of autonomous operation, which can be adaptable after it starts operating, and which derives from the inputs it receives how outputs such as predictions, content, recommendations, or decisions are created for explicit or implicit goals that can affect physical or virtual environments.”
The EU AI Regulation, like DORA, is the overarching framework within which BaFin fulfills its supervisory duties.

Programming with AI Tools

Programming with AI tools is explicitly mentioned in BaFin’s AI guidance. The ‘Code generation with AI assistants’ even gets its own section and makes it clear that the regulatory requirements apply no matter who wrote the code. Anyone developing software with AI needs to have the proper knowledge and skills to evaluate and test the results. For example, it has to be checked to what extent the generated code calls external, AI-based functions (like through APIs) without it being intended.

Conclusion for financial companies

DORA already provides the necessary framework to operate AI safely, but a strict application of ICT risk management principles to the specific characteristics of AI is required. In summary, these key points can be taken from the guidance:
No start without governance: Before any technical implementations start, suitable governance and organizational structures need to be in place. The ICT risk management framework according to DORA is enough to cover AI systems as well, but it has to be applied consistently.
Same standards for everyone: It doesn’t matter whether an AI system was developed in-house or bought from third parties (like standard software). The same high standards apply for analysis, testing, and security.
Focus on data and cloud: Since AI systems are usually based on cloud infrastructures and sensitive data, the focus shifts heavily to ICT third-party risk management and data classification (data security).
Holistic strategy for assistants: Especially for the widely used AI assistants (GenAI/LLMs), purely technical safeguards aren’t enough; a holistic security strategy is needed here, combining technical, organizational, and regulatory measures.
A short summary as a video is available on YouTube: Managing AI Risks in Finance based on Guidance Document from German BaFin

Suchen Sie nach einer Lösung für den elektronischen Zahlungsverkehr?