• ENEN
    • IT IT
    • ES ES
PARTNER LOGIN
  • ENEN
    • IT IT
    • ES ES

Auriga

  • COMPANY

    • About Us

    • Auriga History

    • Group

    • Our Values

    • Our Network

      • Partnerships

      • Certifications

      • Suppliers

    • CSR (ethical code)

      • CSR – Corporate Social Responsibility

  • BANKING

    • Overview

    • Needs

      • Channel Integration

      • Monitoring network

      • Marketing & Customer Relations

      • Accessibility of banking service

      • Corporate Banking

      • Banking Data Analysis

      • Branch of the Future

      • ATM network security

    • Products and Solutions

      • Shared Services

        • WinWebServer Architecture

        • Proactive Network Monitoring

        • One to One Marketing

      • ATM / Kiosks

        • WWS ATM

      • Internet / PC

        • WWS Digital Banking

      • Mobile Banking and Payments

        • WWS Mobile

      • Electronic payments

        • MyBank

      • Bank Marketing & Digital Signage

        • WWS One to One OMNIA

        • WWS Signage

        • WWS Perfect

        • WWS Simply Feed

      • Network Monitoring & Fraud Management

        • WWS Proactive Monitoring OMNIA

        • WWS Fraud Management System

        • WWS Simply Check

      • Call Centre

        • WWS Help Desk

      • Cash Handling

        • WWS Cash Handling

        • WWS Cash Management

      • Digital Invoicing and Document Management

        • WWS e-Invoicing

      • Branch

        • WWS Fill4Me and Bank4Me

        • WWS Greæter

        • WWS Customer Management

      • Business Analytics

        • WWS Business Analytics Management

        • WWS Asset Management

      • Cyber Security Platform

        • Lookwise Device Manager

  • NEWS & MEDIA

    • News

    • Press Release

    • Press Review

    • Blog

    • Videos

    • Infographics

  • RESOURCES

    • White Papers

    • Customer stories

    • Research

    • Brochures

  • CONTACT

    • Contact us

  • CAREERS

    • Work for Us

    • Online application

    • Job vacancies

Blog

  • Home
  • News & Media
  • Blog
  • EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY
EU AI Act and DORA compliance requirements for banks in 2026

EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY

29 July 2026 / Blog

Summary

2 August 2026 marks the next major compliance milestone of the EU AI Act. Financial institutions should identify where AI is used, classify systems according to risk, implement appropriate governance controls, and align AI management with existing DORA operational resilience requirements.

KEY TAKEAWAYS

  • From 2 August 2026, major AI Act obligations apply to many AI systems used by financial institutions.
  • Banks must identify where AI is used and determine whether systems qualify as high-risk.
  • AI governance should be integrated with existing DORA operational resilience programmes.
  • AI systems must be traceable, secure and subject to human oversight.
  • Compliance requires evidence – not only policies.

IN SUMMARY: 2 August 2026 marks the next major compliance milestone of the EU AI Act. Financial institutions should identify where AI is used, classify systems according to risk, implement appropriate governance controls, and align AI management with existing DORA operational resilience requirements.

WHAT DOES THE EU AI ACT MEAN FOR BANKS?

The EU AI Act does not prohibit banks from using artificial intelligence. Instead, it introduces a risk-based framework requiring appropriate governance, documentation, human oversight and cybersecurity controls for certain AI systems, particularly those classified as high risk.

Examples of potentially high-risk AI systems include:

  • AI used for creditworthiness assessment
  • Credit scoring models
  • AI supporting loan approval decisions
  • AI used to verify customer identity
  • AI integrated into critical compliance workflows

This Sunday, 2 August 2026, marks an important milestone in the European regulatory calendar for artificial intelligence. Not because AI regulation begins on that date, but because it marks a significant expansion in the implementation of the European Union’s AI Act.

The first provisions of the AI Act came into force in August 2024 and have been introduced gradually ever since. The ban on prohibited AI practices and AI literacy obligations took effect in February 2025, followed by requirements relating to general-purpose AI models, governance and enforcement in August 2025.

From 2 August 2026, most of the remaining provisions will begin to apply, including transparency requirements and much of the regulatory framework governing high-risk AI systems. However, the implementation timeline does not end there. Certain obligations for high-risk systems will continue to be phased in through 2027 and, in some cases, into 2028. For banks across the European market, this timeline should not simply be viewed as a legal compliance deadline. It is an opportunity to prepare. AI is no longer an isolated innovation initiative; it is becoming part of a bank’s regulatory, technological and operational landscape.

The question is no longer whether a bank uses AI. The real question is whether it knows where AI is being used, which processes it influences, what decisions it affects, what data it depends on, who is accountable for it, and what happens when it fails or produces inaccurate results.

AI IS ALREADY EMBEDDED IN BANKING

AI is already embedded across most core banking functions, including fraud detection, credit assessment, anti-money laundering, customer service and internal operations. However, not every AI application presents the same level of regulatory or operational risk.

A system that summarises internal documentation presents very different risks from one that influences lending decisions. Likewise, an AI tool that helps prioritise fraud alerts is fundamentally different from one that automatically takes action on a customer’s account, transaction or financial products.

Banks therefore need to distinguish between three levels of AI use:

  • AI that informs
  • AI that recommends
  • AI that acts

AI can accelerate analysis, identify unusual patterns, reduce operational workload and support better decision-making. The risks emerge when AI outputs begin influencing important business processes without sufficient traceability, oversight or the ability for human review.

NOT EVERY SENSITIVE USE CASE IS PROHIBITED

The AI Act does not prohibit banks from using AI in sensitive processes. Instead, it classifies AI systems according to risk and requires governance controls appropriate to that level of risk.

Which banking AI systems are considered high risk?

For example, AI used for assessing creditworthiness or credit scoring for individuals may be classified as high-risk. This does not mean these applications are prohibited. Rather, they must comply with strict requirements covering risk management, documentation, traceability, human oversight, robustness and cybersecurity.

Fraud detection is also a critical banking function, although it is treated differently from credit scoring under the regulation. AI models can help detect suspicious behaviour, prioritise alerts and support fraud and security teams. The key is ensuring that high-impact decisions remain subject to appropriate controls, review processes, traceability and escalation mechanisms.

The objective is not to slow AI adoption, but to prevent AI from becoming an uncontrolled “black box” within processes that affect customers, regulated activities or other critical banking functions.

AI AS A CYBER-CRITICAL ASSET

An AI system is far more than a model. It is a combination of code, data, decision logic, prompts, APIs, connectors, credentials, logs, pipelines, internal tools, external suppliers and configuration decisions. Every one of these layers introduces potential risk. For example:

  • A model can be manipulated through compromised training data.
  • A prompt can expose sensitive information.
  • An API may grant excessive permissions.
  • An AI agent may gain uncontrolled access to internal systems.
  • A third-party supplier may create technology dependency. Inadequate logging may make it impossible to reconstruct what happened during a security incident.

One of the clearest examples is data poisoning. If a fraud detection or anti-money laundering model is trained or fine-tuned using manipulated data, it may learn incorrect patterns. As a result, suspicious behaviour could appear legitimate, while legitimate customer activity could be incorrectly flagged as fraudulent.

Within banking, this is far more than a technical issue. It creates operational, regulatory, financial and, perhaps most importantly, reputational risk.

HOW DOES THE AI ACT INTERACT WITH DORA?

The AI Act and the Digital Operational Resilience Act (DORA) should be considered together within the banking sector, although they address different areas and should not be confused.

DORA does not regulate artificial intelligence itself. Instead, it focuses on the digital operational resilience of financial institutions, covering ICT risk management, incident reporting, resilience testing, business continuity, recovery and third-party technology risk.

The AI Act, by contrast, focuses on trustworthy, risk-based AI, introducing requirements around governance, transparency, record-keeping, human oversight, robustness, cybersecurity and lifecycle management.

The intersection between these two frameworks is particularly important for banks. An AI system used by a financial institution may simultaneously be subject to AI governance obligations while also qualifying as an ICT asset supporting an important or critical banking function.

For this reason, critical AI should not be managed solely by innovation, analytics or business teams. It should form part of the organisation’s technology inventory, operational risk framework, cybersecurity programme, third-party risk management, incident response procedures and resilience testing.

FROM POLICIES TO EVIDENCE

Regulatory compliance will not be achieved simply by drafting policies. The real challenge will be demonstrating that the bank remains in control of the AI systems it deploys. Banks should be able to provide clear evidence whenever required, including:

  • A comprehensive inventory of AI systems
  • Risk classifications
  • Clearly assigned ownership and accountability
  • Technical and functional documentation
  • Decision traceability
  • Access controls
  • Robustness testing
  • Continuous monitoring
  • Business continuity and contingency plans
  • Incident management processes
  • Third-party supplier assessments

Every financial institution should be asking one fundamental question: If an AI system fails, produces an incorrect recommendation, behaves unexpectedly or is compromised, can the bank reconstruct exactly what happened and respond quickly enough to correct it? If the answer is not documented, tested and supported by evidence, then the system is not truly under control.

HOW SHOULD BANKS GOVERN AI SYSTEMS?

2 August 2026 should be seen as a maturity milestone for European banking. It marks the point at which AI becomes part of the same strategic conversation that already surrounds cybersecurity, operational resilience and third-party technology risk.

The competitive advantage for banks will not come from being the first to adopt AI. It will come from adopting it more effectively than others. This includes implementing strong security, full traceability and the ability to respond rapidly to failures, hallucinations in critical systems or false positives.

In banking, trust cannot simply be claimed; it must be demonstrated, both to regulators and to customers. The AI Act, DORA and the broader wave of digital operational resilience regulation are all designed to ensure that artificial intelligence earns and maintains that trust.

FAQ

  1. What does the EU AI Act mean for banks?

    The EU AI Act introduces a risk-based framework for AI. Banks must identify where AI is used and apply appropriate governance, documentation, oversight and cybersecurity controls.

  2. Does the EU AI Act prohibit AI in banking?

    No. Banks can continue using AI, including for fraud detection, credit assessment, anti-money laundering and customer service, provided that the relevant requirements are met.

  3. Which banking AI systems may be high-risk?

    AI used to assess an individual’s creditworthiness or credit score may be classified as high-risk and subject to stricter controls.

  4. How does the AI Act interact with DORA?

    The AI Act governs the responsible use of AI, while DORA focuses on ICT and operational resilience. Banks should align both frameworks when AI supports critical functions.

  5. Should AI be managed as a critical ICT asset?

    Yes, when it supports important banking processes. AI systems should be included in technology inventories, risk management, monitoring, incident response and resilience testing.

  6. What are the main AI cybersecurity risks for banks?

    Key risks include data poisoning, sensitive data exposure, excessive API permissions, weak access controls, third-party dependency and insufficient logging.

  7. What should banks do to prepare?

    Banks should inventory their AI systems, classify risks, assign ownership, implement human oversight and strengthen monitoring, documentation and incident response.

  8. What evidence should banks maintain?

    Banks should retain risk classifications, technical documentation, decision logs, access controls, testing records, monitoring evidence and third-party assessments.

    
  • Tweet
  • News
  • Press Release
  • Press Review
  • Blog
  • Videos
  • Infographics

DO YOU WANT INSIGHTS FROM THE WORLD’S BANKING INDUSTRY?

JOIN THE AURIGA COMMUNITY TO BE ALWAYS UPDATED ON:

News on software solutions

Invitations to industry events

Customer stories

Reports

Market research

...and much more!

LET'S CONNECT

CONTACT

HEADQUARTER - BARI
Via Don Luigi Guanella, 17
70124 Bari - Italy

TEL: +39.080.5692111

info@aurigaspa.com

Milan office
Rome office
Brussels office
London office
Madrid office
Mexico City office

BUSINESS CONTACTS

Niccolo Garzelli - Auriga - Footer

Niccolò Garzelli Milan office
niccolo.garzelli@aurigaspa.com

brendan-thorpe-contacts

BRENDAN THORPE London office
brendan.thorpe@aurigaspa.com

Stefano Cipollone Milan office
stefano.cipollone@aurigaspa.com

MARTIN ESPINELMexico City office
martin.espinel@aurigaspa.com

lukasz-feluch

ŁUKASZ FELUCHVarsaw office
lukasz.feluch@aurigaspa.com

RUDY DE WOLFBrussels office
rudolf.dewolf@aurigaspa.com

angel arenillas

ÁNGEL ARENILLAS YUSTEMadrid office
angel.arenillas@aurigaspa.com

Kelum-Dissanayake-Auriga-Footer

Kelum Dissanayakekelum.dissanayake@aurigaspa.com

EXPLORE

  • About Us
  • WinWebServer
  • Blog
  • White Papers
  • Research

LATEST NEWS

  • Hybrid banking model integrating branches, ATMs, self-service and remote human assistance

    BEYOND BRANCHES: WHY THE FUTURE OF BANKING IS ACCESS-BASED, HYBRID AND HUMAN-CENTRIC

    30/06/2026
  • Accessible omnichannel banking across digital, branch and ATM services in the UK.

    Looking Beyond Branch Doors

    21/05/2026
  • Auriga-to-Attend-ATMIA-Europe-Emerging-Markets

    Auriga to Attend ATMIA Europe & Emerging Markets 2026 Roadshow in Madrid

    18/05/2026

Connect with us

SUBSCRIBE TO THE NEWSLETTER

Join the Auriga community

Let's connect

Auriga Spa - Copyright © 2026 - All rights reserved | Legal Notice | Privacy Policy | Cookie Policy | Whistleblowing Policy | Social Media Policy
P.I. 05566820725 - Capital € 1.196.055 i.v. - R.E.A. 426675

TOP
Gestisci Consenso

We, and third party websites you may interact with via our site, use cookies to collect site usage data and improve your experience, this includes permanent and profiling cookies. By clicking ‘Accept’ you agree to allow cookies, however you can disable this through your browser settings at anytime. If you opt to totally or partial disable cookies, this might compromise some features on the website. For more information on our cookie policy, go to the Legal Notice page.

Functional Always active
L'archiviazione tecnica o l'accesso sono strettamente necessari al fine legittimo di consentire l'uso di un servizio specifico esplicitamente richiesto dall'abbonato o dall'utente, o al solo scopo di effettuare la trasmissione di una comunicazione su una rete di comunicazione elettronica.
Preferenze
L'archiviazione tecnica o l'accesso sono necessari per lo scopo legittimo di memorizzare le preferenze che non sono richieste dall'abbonato o dall'utente.
Statistiche
L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici. L'archiviazione tecnica o l'accesso che viene utilizzato esclusivamente per scopi statistici anonimi. Senza un mandato di comparizione, una conformità volontaria da parte del vostro Fornitore di Servizi Internet, o ulteriori registrazioni da parte di terzi, le informazioni memorizzate o recuperate per questo scopo da sole non possono di solito essere utilizzate per l'identificazione.
Marketing
L'archiviazione tecnica o l'accesso sono necessari per creare profili di utenti per inviare pubblicità, o per tracciare l'utente su un sito web o su diversi siti web per scopi di marketing simili.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}