DORA (Digital Operational Resilience Act)
Binding EU regulation on digital operational resilience for financial entities, in full application since 17 January 2025. Covers ICT risk management, incident reporting, resilience testing, and — most consequentially here — a dedicated regime for ICT third-party service providers, including an oversight framework for those designated critical. Financial entities completed their first mandatory Register of Information submissions to national competent authorities in Q1 2026, consolidating to the European Supervisory Authorities by 31 March 2026. Threat-led penetration testing cycles run to a January 2028 milestone for designated entities.
Why it matters for autonomous finance
Every other instrument in this register is voluntary. DORA is law, it is already enforced, and it reaches further than most AI vendors realize. The ICT third-party provider regime does not care whether you call yourself an AI company: if a financial entity depends on your service for a critical function, you are inside the contractual and oversight requirements, and your customer is obliged to register you. An agent platform selling into EU financial services is an ICT third-party provider whether or not anyone has said so out loud.
What it does not cover
DORA is about operational resilience, not model behavior. It will tell you that your agent platform must be recoverable, contractually bound, exit-planned and reportable when it fails. It says nothing about whether the agent should have been permitted to take the action in the first place. Resilience and authority are different questions, and satisfying DORA answers only the first.
No treatment of delegated authority, agent identity, drift, or what an autonomous system may commit. A perfectly DORA-compliant agent can still be ungoverned. Every entry in this register carries this section. A standard read past its scope is worse than no standard, because it produces confidence without coverage.