The Gap AI Automation Who we work with Approach Fintech Garden Blog Start a conversation

DORA and the EU AI Act: One Framework, Not Two

2026-09-15 Operational Compliance

Two regulations, one operations team

If you run compliance or operations at a payment institution or EMI, you are currently tracking two clocks. DORA has been in force since January 17, 2025, and applies directly to payment institutions, e-money institutions, and their ICT providers. The EU AI Act is a different animal. Some obligations already bite, prohibited practices since February 2025 and general-purpose AI rules since August 2025, while the big one for lenders and scoring engines, the Annex III high-risk regime, was pushed back. The Digital Omnibus that entered into force in July 2026 moved the Annex III deadline from August 2, 2026 to December 2, 2027. That is real breathing room, but it is not a reason to stop building.

I ran operations at Solaris Bank long enough to know what happens when two regulatory tracks get treated as two separate projects. You end up with two risk registers, two sets of third-party questionnaires, two audit trails, and a team quietly resenting both. The smarter move, and the one we push clients toward at Novafin, is to treat DORA and the AI Act as inputs into one control framework, because operationally they ask for almost the same things.

What DORA actually requires today

DORA is built on five pillars: ICT risk management and governance, incident classification and reporting, resilience testing, third-party risk management, and information sharing. The third-party piece is the one catching institutions off guard. Every regulated entity has to maintain a Register of Information covering every ICT contract, and the ESAs used that data to name the first list of critical ICT third-party providers in November 2025, nineteen firms whose failure would ripple across the sector. If a critical provider under that oversight regime does not comply, the ESAs can fine it up to 1% of average daily worldwide turnover per day, for up to six months. That is not a rounding error in anyone's budget.

For a payment institution, the practical output of DORA is a living inventory: which systems are critical, which vendors sit behind them, how incidents get classified and reported within the regulatory windows, and how often resilience actually gets tested rather than assumed.

What the AI Act adds

Here is where it gets relevant fast for anyone using models in underwriting, fraud scoring, or onboarding. Annex III of the AI Act classifies AI systems used to assess a natural person's creditworthiness or credit score as high-risk. Fraud detection is carved out, but scoring is not. High-risk classification triggers logging obligations under Article 12, transparency under Article 13, human oversight under Article 14, and a fundamental rights impact assessment for deployers under Article 27. Even with the Annex III deadline now sitting at December 2027, the prohibited-practices rules and general-purpose AI obligations are already live, and building the documentation, logging, and oversight muscle now is cheaper than doing it under deadline pressure. Penalties for high-risk breaches top out at 15 million euros or 3% of global turnover, whichever is higher, putting it in the same weight class as DORA's third-party fines.

Where the two rules overlap

Read the requirements side by side and the overlap is obvious. Both demand a registered inventory of critical systems and providers. Both demand incident logging with defined severity and reporting timelines. Both demand human oversight and accountability for automated decisions. Both demand evidence, not intentions, when a supervisor asks. If your compliance function builds two separate programs to satisfy each law, you are paying twice for the same evidence base.

The practical move

Start with one inventory that tags every system by two attributes: is it a critical ICT function under DORA, and does it touch a high-risk AI use case under Annex III. That single tag structure tells you which controls stack and which teams need to sign off. Automate the logging and incident classification once, then map the outputs to both regimes' reporting formats instead of running parallel processes.

Novafin builds this kind of shared compliance and operations infrastructure for regulated payment institutions and EMIs, so your team spends its time on the business, not on reconciling two audit trails that should have been one. If you want a straight read on where your current setup stands against DORA and the AI Act, get in touch.