DORA — Digital Operational Resilience Act applies
Financial entities must run an ICT risk-management framework, keep a register of ICT/AI third-party arrangements, report major ICT incidents and perform resilience testing.
The same obligation themes, side by side, from the catalogue that powers the rest of this site — 18 catalogued requirements across 16 themes. Expand any requirement to read it. Free, no login.
Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.
Every theme below appears in exactly one group, so these account for all 16 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.
EU AI Act · DORA
EU AI Actnot: DORA
DORAnot: EU AI Act
A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.
| Theme | EU AI Act | DORA |
|---|---|---|
| What is forbidden outright | ||
| Outright bans Are some uses forbidden regardless of safeguards? | Art. 5 Prohibited AI practices mustPractices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market. Read it in context → | — |
| What you must assess first | ||
| Risk management system Must you run a documented, continuous risk process? | Art. 9 Risk-management system mustEstablish, document and maintain a continuous risk-management system across the AI lifecycle. Read it in context → | DORA · ICT risk ICT risk-management framework mustOperate an ICT risk-management framework (management body accountable) that covers AI/ML systems and cloud dependencies. Read it in context → |
| Rights impact assessment Must you assess the impact on people before deploying? | Art. 27 Fundamental Rights Impact Assessment mustCertain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use. Read it in context → | — |
| What you owe the data | ||
| Data & training data Are there duties on the data the system learns from? | Art. 10 Data & data governance mustTraining, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness. Read it in context → | — |
| What you must build and prove | ||
| Accuracy, robustness & security Must you hit and evidence performance targets? | Art. 15 Accuracy, robustness & cybersecurity mustAchieve appropriate accuracy, robustness and cybersecurity, and declare metrics. Read it in context → | — |
| Technical documentation Must a technical file exist before deployment? | Art. 11 / Annex IV Technical documentation mustDraw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file). Read it in context → | — |
| Conformity assessment Must someone certify it before it goes to market? | Art. 43 Conformity assessment mustUndergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry. Read it in context → | — |
| Registration & public listing Must the system be registered or published somewhere? | Art. 49 EU database registration mustRegister the high-risk system in the EU database before placing it on the market. Read it in context → | — |
| What you must tell people | ||
| Transparency & explanation Must you explain how it works, and to whom? | Art. 13 Transparency & instructions for use mustProvide deployers with clear instructions: capabilities, limitations, and required human oversight. Read it in context → | — |
| Telling people AI was used Must people be told an AI was involved? | Art. 50 Transparency for certain systems mustInform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content. Read it in context → | — |
| Labelling AI-generated content Must generated output be marked or watermarked? | Art. 50(2) Marking of synthetic content mustMark AI-generated audio, image, video or text in a machine-readable, detectable way. Read it in context → | — |
| What you must do while it runs | ||
| Human oversight & override Must a person be able to intervene, review or stop it? | Art. 14 Human oversight mustDesign the system so humans can effectively oversee it, intervene, and stop it. Read it in context → | — |
| Logging & records Must the system keep records of what it did? | Art. 12 Record-keeping (logging) mustAutomatically record events (logs) over the system lifetime to ensure traceability. Read it in context → | — |
| Monitoring after deployment Must you keep watching it once it is live? | Art. 72 Post-market monitoring mustOperate a post-market monitoring system to collect and review performance data after deployment. Read it in context → | — |
| Incident reporting Must failures be reported, and to whom? | Art. 73 Serious-incident reporting mustReport serious incidents and malfunctioning to the competent market-surveillance authority. Read it in context → | DORA · Incidents Major ICT incident reporting & resilience testing mustClassify and report major ICT-related incidents and perform digital operational-resilience testing (incl. threat-led penetration testing for significant entities). Read it in context → |
| What the organisation must carry | ||
| Accountability & third parties Must accountability and supplier oversight be assigned? | — | DORA · Third-party ICT / AI third-party register & oversight mustMaintain a register of information on all ICT (incl. AI/cloud) third-party arrangements, manage concentration risk, and meet contractual requirements; critical providers face ESA oversight. Read it in context → |
Every dated obligation attached to these regulations, merged into one timeline.
Financial entities must run an ICT risk-management framework, keep a register of ICT/AI third-party arrangements, report major ICT incidents and perform resilience testing.
Eight unacceptable-risk practices (social scoring, manipulative AI, untargeted face-scraping, most real-time biometric ID) are banned.
The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.
GPAI providers owe transparency, technical documentation, copyright policy, and systemic-risk duties for capable models.
National competent authorities and fines (up to 7% of global turnover for prohibited use) become enforceable.
Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.
The Digital Omnibus adds a prohibition on AI systems for non-consensual intimate imagery/CSAM and ends the synthetic-content marking grace period for pre-existing systems.
Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).
Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.
High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.