{"id":80437,"date":"2026-07-29T14:55:11","date_gmt":"2026-07-29T13:55:11","guid":{"rendered":"https:\/\/www.aurigaspa.com\/?p=80437"},"modified":"2026-07-29T14:57:08","modified_gmt":"2026-07-29T13:57:08","slug":"eu-ai-act-for-banks-dora-compliance","status":"publish","type":"post","link":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/","title":{"rendered":"EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY"},"content":{"rendered":"<h2><strong>KEY TAKEAWAYS<\/strong><\/h2>\n<ul>\n<li><strong>From 2 August 2026, major AI Act obligations apply to many AI systems used by financial institutions. <\/strong><\/li>\n<li><strong>Banks must identify where AI is used and determine whether systems qualify as high-risk. <\/strong><\/li>\n<li><strong>AI governance should be integrated with existing DORA operational resilience programmes. <\/strong><\/li>\n<li><strong>AI systems must be traceable, secure and subject to human oversight. <\/strong><\/li>\n<li><strong>Compliance requires evidence &#8211; not only policies.<\/strong><\/li>\n<\/ul>\n<p><strong>IN SUMMARY:<\/strong> 2 August 2026 marks the next major compliance milestone of the EU AI Act. Financial institutions should identify where AI is used, classify systems according to risk, implement appropriate governance controls, and align AI management with existing DORA operational resilience requirements.<\/p>\n<h2><strong>WHAT DOES THE EU AI ACT MEAN FOR BANKS?<\/strong><\/h2>\n<p>The EU AI Act does not prohibit banks from using artificial intelligence. Instead, it introduces a risk-based framework requiring appropriate governance, documentation, human oversight and cybersecurity controls for certain AI systems, particularly those classified as high risk.<\/p>\n<p>Examples of potentially high-risk AI systems include:<\/p>\n<ul>\n<li>AI used for creditworthiness assessment<\/li>\n<li>Credit scoring models<\/li>\n<li>AI supporting loan approval decisions<\/li>\n<li>AI used to verify customer identity<\/li>\n<li>AI integrated into critical compliance workflows<\/li>\n<\/ul>\n<p><strong>This Sunday, 2 August 2026,<\/strong> marks an important milestone in the European regulatory calendar for artificial intelligence. Not because AI regulation begins on that date, but because it marks a significant expansion in the implementation of the European Union&#8217;s AI Act.<\/p>\n<p>The first provisions of the AI Act came into force in August 2024 and have been introduced gradually ever since. The ban on prohibited AI practices and AI literacy obligations took effect in February 2025, followed by requirements relating to general-purpose AI models, governance and enforcement in August 2025.<\/p>\n<p>From 2 August 2026, most of the remaining provisions will begin to apply, including transparency requirements and much of the regulatory framework governing high-risk AI systems. However, the implementation timeline does not end there. Certain obligations for high-risk systems will continue to be phased in through 2027 and, in some cases, into 2028. For banks across the European market, this timeline should not simply be viewed as a legal compliance deadline. It is an opportunity to prepare. AI is no longer an isolated innovation initiative; it is becoming part of a bank&#8217;s regulatory, technological and operational landscape.<\/p>\n<p>The question is no longer whether a bank uses AI. The real question is whether it knows where AI is being used, which processes it influences, what decisions it affects, what data it depends on, who is accountable for it, and what happens when it fails or produces inaccurate results.<\/p>\n<h2><strong>AI IS ALREADY EMBEDDED IN BANKING<\/strong><\/h2>\n<p>AI is already embedded across most core banking functions, including fraud detection, credit assessment, anti-money laundering, customer service and internal operations<strong>.<\/strong> However, not every AI application presents the same level of regulatory or operational risk.<\/p>\n<p>A system that summarises internal documentation presents very different risks from one that influences lending decisions. Likewise, an AI tool that helps prioritise fraud alerts is fundamentally different from one that automatically takes action on a customer&#8217;s account, transaction or financial products.<\/p>\n<p>Banks therefore need to distinguish between three levels of AI use:<\/p>\n<ul>\n<li>AI that informs<\/li>\n<li>AI that recommends<\/li>\n<li>AI that acts<\/li>\n<\/ul>\n<p>AI can accelerate analysis, identify unusual patterns, reduce operational workload and support better decision-making. The risks emerge when AI outputs begin influencing important business processes without sufficient traceability, oversight or the ability for human review.<\/p>\n<h2><strong>NOT EVERY SENSITIVE USE CASE IS PROHIBITED<\/strong><\/h2>\n<p>The AI Act does not prohibit banks from using AI in sensitive processes. Instead, it classifies AI systems according to risk and requires governance controls appropriate to that level of risk.<\/p>\n<h3><strong>Which banking AI systems are considered high risk?<\/strong><\/h3>\n<p>For example, AI used for assessing creditworthiness or credit scoring for individuals may be classified as high-risk. This does not mean these applications are prohibited. Rather, they must comply with strict requirements covering risk management, documentation, traceability, human oversight, robustness and cybersecurity.<\/p>\n<p>Fraud detection is also a critical banking function, although it is treated differently from credit scoring under the regulation. AI models can help detect suspicious behaviour, prioritise alerts and support fraud and security teams. The key is ensuring that high-impact decisions remain subject to appropriate controls, review processes, traceability and escalation mechanisms.<\/p>\n<p>The objective is not to slow AI adoption, but to prevent AI from becoming an uncontrolled &#8220;black box&#8221; within processes that affect customers, regulated activities or other critical banking functions.<\/p>\n<h2><strong>AI AS A CYBER-CRITICAL ASSET<\/strong><\/h2>\n<p>An AI system is far more than a model. It is a combination of code, data, decision logic, prompts, APIs, connectors, credentials, logs, pipelines, internal tools, external suppliers and configuration decisions. Every one of these layers introduces potential risk. For example:<\/p>\n<ul>\n<li>A model can be manipulated through compromised training data.<\/li>\n<li>A prompt can expose sensitive information.<\/li>\n<li>An API may grant excessive permissions.<\/li>\n<li>An AI agent may gain uncontrolled access to internal systems.<\/li>\n<li>A third-party supplier may create technology dependency. Inadequate logging may make it impossible to reconstruct what happened during a security incident.<\/li>\n<\/ul>\n<p>One of the clearest examples is data poisoning. If a fraud detection or anti-money laundering model is trained or fine-tuned using manipulated data, it may learn incorrect patterns. As a result, suspicious behaviour could appear legitimate, while legitimate customer activity could be incorrectly flagged as fraudulent.<\/p>\n<p>Within banking, this is far more than a technical issue. It creates operational, regulatory, financial and, perhaps most importantly, reputational risk.<\/p>\n<h2><strong>HOW DOES THE AI ACT INTERACT WITH DORA?<\/strong><\/h2>\n<p>The AI Act and the Digital Operational Resilience Act (<a href=\"https:\/\/www.eiopa.europa.eu\/digital-operational-resilience-act-dora_en\" target=\"_blank\" rel=\"noopener\">DORA<\/a>) should be considered together within the banking sector, although they address different areas and should not be confused.<\/p>\n<p>DORA does not regulate artificial intelligence itself. Instead, it focuses on the digital operational resilience of financial institutions, covering ICT risk management, incident reporting, resilience testing, business continuity, recovery and third-party technology risk.<\/p>\n<p>The AI Act, by contrast, focuses on trustworthy, risk-based AI, introducing requirements around governance, transparency, record-keeping, human oversight, robustness, cybersecurity and lifecycle management.<\/p>\n<p>The intersection between these two frameworks is particularly important for banks. An AI system used by a financial institution may simultaneously be subject to AI governance obligations while also qualifying as an ICT asset supporting an important or critical banking function.<\/p>\n<p>For this reason, critical AI should not be managed solely by innovation, analytics or business teams. It should form part of the organisation&#8217;s technology inventory, operational risk framework, cybersecurity programme, third-party risk management, incident response procedures and resilience testing.<\/p>\n<p><strong>FROM POLICIES TO EVIDENCE <\/strong><\/p>\n<p>Regulatory compliance will not be achieved simply by drafting policies. The real challenge will be demonstrating that the bank remains in control of the AI systems it deploys. Banks should be able to provide clear evidence whenever required, including:<\/p>\n<ul>\n<li>A comprehensive inventory of AI systems<\/li>\n<li>Risk classifications<\/li>\n<li>Clearly assigned ownership and accountability<\/li>\n<li>Technical and functional documentation<\/li>\n<li>Decision traceability<\/li>\n<li>Access controls<\/li>\n<li>Robustness testing<\/li>\n<li>Continuous monitoring<\/li>\n<li>Business continuity and contingency plans<\/li>\n<li>Incident management processes<\/li>\n<li>Third-party supplier assessments<\/li>\n<\/ul>\n<p>Every financial institution should be asking one fundamental question: If an AI system fails, produces an incorrect recommendation, behaves unexpectedly or is compromised, can the bank reconstruct exactly what happened and respond quickly enough to correct it? If the answer is not documented, tested and supported by evidence, then the system is not truly under control.<\/p>\n<h2><strong>HOW SHOULD BANKS GOVERN AI SYSTEMS?<\/strong><\/h2>\n<p>2 August 2026 should be seen as a maturity milestone for European banking. It marks the point at which AI becomes part of the same strategic conversation that already surrounds cybersecurity, operational resilience and third-party technology risk.<\/p>\n<p>The competitive advantage for banks will not come from being the first to adopt AI. It will come from adopting it more effectively than others. This includes implementing strong security, full traceability and the ability to respond rapidly to failures, hallucinations in critical systems or false positives.<\/p>\n<p>In banking, trust cannot simply be claimed; it must be demonstrated, both to regulators and to customers. The AI Act, DORA and the broader wave of digital operational resilience regulation are all designed to ensure that artificial intelligence earns and maintains that trust.<\/p>\n<h2><strong>FAQ<\/strong><\/h2>\n<ol>\n<li>\n<h3>What does the EU AI Act mean for banks?<\/h3>\n<p>The EU AI Act introduces a risk-based framework for AI. Banks must identify where AI is used and apply appropriate governance, documentation, oversight and cybersecurity controls.<\/li>\n<li>\n<h3>Does the EU AI Act prohibit AI in banking?<\/h3>\n<p>No. Banks can continue using AI, including for fraud detection, credit assessment, anti-money laundering and customer service, provided that the relevant requirements are met.<\/li>\n<li>\n<h3>Which banking AI systems may be high-risk?<\/h3>\n<p>AI used to assess an individual\u2019s creditworthiness or credit score may be classified as high-risk and subject to stricter controls.<\/li>\n<li>\n<h3>How does the AI Act interact with DORA?<\/h3>\n<p>The AI Act governs the responsible use of AI, while DORA focuses on ICT and operational resilience. Banks should align both frameworks when AI supports critical functions.<\/li>\n<li>\n<h3>Should AI be managed as a critical ICT asset?<\/h3>\n<p>Yes, when it supports important banking processes. AI systems should be included in technology inventories, risk management, monitoring, incident response and resilience testing.<\/li>\n<li>\n<h3>What are the main AI cybersecurity risks for banks?<\/h3>\n<p>Key risks include data poisoning, sensitive data exposure, excessive API permissions, weak access controls, third-party dependency and insufficient logging.<\/li>\n<li>\n<h3>What should banks do to prepare?<\/h3>\n<p>Banks should inventory their AI systems, classify risks, assign ownership, implement human oversight and strengthen monitoring, documentation and incident response.<\/li>\n<li>\n<h3>What evidence should banks maintain?<\/h3>\n<p>Banks should retain risk classifications, technical documentation, decision logs, access controls, testing records, monitoring evidence and third-party assessments.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>KEY TAKEAWAYS From 2 August 2026, major AI Act obligations apply to many AI systems used by financial institutions. Banks must identify where AI is used and determine whether systems qualify as high-risk. AI governance should be integrated with existing DORA operational resilience programmes. AI systems must be traceable, secure and subject to human oversight.<\/p>\n","protected":false},"author":1,"featured_media":80438,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[81],"tags":[],"class_list":["post-80437","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-eng"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.1 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>EU AI Act for Banks: DORA, Risk and Compliance 2026<\/title>\n<meta name=\"description\" content=\"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"EU AI Act for Banks: DORA, Risk and Compliance 2026\" \/>\n<meta property=\"og:description\" content=\"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"Auriga\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/aurigaspa\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-29T13:55:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-29T13:57:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/eu-ai-act-for-banks-dora-compliance-2026-auriga-social.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Roberto\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"EU AI Act for Banks: DORA, Risk and Compliance 2026\" \/>\n<meta name=\"twitter:description\" content=\"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Roberto\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/\"},\"author\":{\"name\":\"Roberto\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#\\\/schema\\\/person\\\/8b3ed77214b1f6af4b421d4cf1c8dced\"},\"headline\":\"EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY\",\"datePublished\":\"2026-07-29T13:55:11+00:00\",\"dateModified\":\"2026-07-29T13:57:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/\"},\"wordCount\":1573,\"publisher\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.aurigaspa.com\\\/wp-content\\\/uploads\\\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png\",\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/\",\"url\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/\",\"name\":\"EU AI Act for Banks: DORA, Risk and Compliance 2026\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.aurigaspa.com\\\/wp-content\\\/uploads\\\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png\",\"datePublished\":\"2026-07-29T13:55:11+00:00\",\"dateModified\":\"2026-07-29T13:57:08+00:00\",\"description\":\"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.aurigaspa.com\\\/wp-content\\\/uploads\\\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png\",\"contentUrl\":\"https:\\\/\\\/www.aurigaspa.com\\\/wp-content\\\/uploads\\\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png\",\"width\":850,\"height\":390,\"caption\":\"EU AI Act and DORA compliance requirements for banks in 2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/news-and-media\\\/blog-eng\\\/eu-ai-act-for-banks-dora-compliance\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/\",\"name\":\"Auriga\",\"description\":\"The banking evolution\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#organization\",\"name\":\"Auriga\",\"url\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.aurigaspa.com\\\/wp-content\\\/uploads\\\/marchio_auriga_nopayoff_web.png\",\"contentUrl\":\"https:\\\/\\\/www.aurigaspa.com\\\/wp-content\\\/uploads\\\/marchio_auriga_nopayoff_web.png\",\"width\":660,\"height\":360,\"caption\":\"Auriga\"},\"image\":{\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/aurigaspa\",\"https:\\\/\\\/www.instagram.com\\\/auriga_the_banking_evolution\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/auriga-spa\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/aurigaspacom\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.aurigaspa.com\\\/en\\\/#\\\/schema\\\/person\\\/8b3ed77214b1f6af4b421d4cf1c8dced\",\"name\":\"Roberto\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a60dc2ae898eaddf9dc429fcf2a75cb42a37382c1fa0db640d0a6f6edd0b6fec?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a60dc2ae898eaddf9dc429fcf2a75cb42a37382c1fa0db640d0a6f6edd0b6fec?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a60dc2ae898eaddf9dc429fcf2a75cb42a37382c1fa0db640d0a6f6edd0b6fec?s=96&d=mm&r=g\",\"caption\":\"Roberto\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"EU AI Act for Banks: DORA, Risk and Compliance 2026","description":"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/","og_locale":"en_US","og_type":"article","og_title":"EU AI Act for Banks: DORA, Risk and Compliance 2026","og_description":"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.","og_url":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/","og_site_name":"Auriga","article_publisher":"https:\/\/www.facebook.com\/aurigaspa","article_published_time":"2026-07-29T13:55:11+00:00","article_modified_time":"2026-07-29T13:57:08+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/eu-ai-act-for-banks-dora-compliance-2026-auriga-social.png","type":"image\/jpeg"}],"author":"Roberto","twitter_card":"summary_large_image","twitter_title":"EU AI Act for Banks: DORA, Risk and Compliance 2026","twitter_description":"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.","twitter_misc":{"Written by":"Roberto","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#article","isPartOf":{"@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/"},"author":{"name":"Roberto","@id":"https:\/\/www.aurigaspa.com\/en\/#\/schema\/person\/8b3ed77214b1f6af4b421d4cf1c8dced"},"headline":"EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY","datePublished":"2026-07-29T13:55:11+00:00","dateModified":"2026-07-29T13:57:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/"},"wordCount":1573,"publisher":{"@id":"https:\/\/www.aurigaspa.com\/en\/#organization"},"image":{"@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png","articleSection":["Blog"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/","url":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/","name":"EU AI Act for Banks: DORA, Risk and Compliance 2026","isPartOf":{"@id":"https:\/\/www.aurigaspa.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#primaryimage"},"image":{"@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png","datePublished":"2026-07-29T13:55:11+00:00","dateModified":"2026-07-29T13:57:08+00:00","description":"From 2 August 2026, banks face expanded EU AI Act duties. Learn how to classify AI risk, align with DORA and demonstrate compliance.","breadcrumb":{"@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#primaryimage","url":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png","contentUrl":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/eu-ai-act-for-banks-dora-compliance-2026-auriga.png","width":850,"height":390,"caption":"EU AI Act and DORA compliance requirements for banks in 2026"},{"@type":"BreadcrumbList","@id":"https:\/\/www.aurigaspa.com\/en\/news-and-media\/blog-eng\/eu-ai-act-for-banks-dora-compliance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.aurigaspa.com\/en\/"},{"@type":"ListItem","position":2,"name":"EU AI ACT 2026: WHAT BANKS NEED TO KNOW ABOUT AI GOVERNANCE, DORA, AND CYBERSECURITY"}]},{"@type":"WebSite","@id":"https:\/\/www.aurigaspa.com\/en\/#website","url":"https:\/\/www.aurigaspa.com\/en\/","name":"Auriga","description":"The banking evolution","publisher":{"@id":"https:\/\/www.aurigaspa.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.aurigaspa.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.aurigaspa.com\/en\/#organization","name":"Auriga","url":"https:\/\/www.aurigaspa.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.aurigaspa.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/marchio_auriga_nopayoff_web.png","contentUrl":"https:\/\/www.aurigaspa.com\/wp-content\/uploads\/marchio_auriga_nopayoff_web.png","width":660,"height":360,"caption":"Auriga"},"image":{"@id":"https:\/\/www.aurigaspa.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/aurigaspa","https:\/\/www.instagram.com\/auriga_the_banking_evolution\/","https:\/\/www.linkedin.com\/company\/auriga-spa","https:\/\/www.youtube.com\/user\/aurigaspacom"]},{"@type":"Person","@id":"https:\/\/www.aurigaspa.com\/en\/#\/schema\/person\/8b3ed77214b1f6af4b421d4cf1c8dced","name":"Roberto","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a60dc2ae898eaddf9dc429fcf2a75cb42a37382c1fa0db640d0a6f6edd0b6fec?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a60dc2ae898eaddf9dc429fcf2a75cb42a37382c1fa0db640d0a6f6edd0b6fec?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a60dc2ae898eaddf9dc429fcf2a75cb42a37382c1fa0db640d0a6f6edd0b6fec?s=96&d=mm&r=g","caption":"Roberto"}}]}},"_links":{"self":[{"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/posts\/80437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/comments?post=80437"}],"version-history":[{"count":1,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/posts\/80437\/revisions"}],"predecessor-version":[{"id":80442,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/posts\/80437\/revisions\/80442"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/media\/80438"}],"wp:attachment":[{"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/media?parent=80437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/categories?post=80437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aurigaspa.com\/en\/wp-json\/wp\/v2\/tags?post=80437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}