Financial firms have lived under DORA, the Digital Operational Resilience Act, since 17 January 2025. Most of the coverage focused on incident reporting and resilience testing. The part that matters most for AI is quieter and more structural: DORA is openly worried that European finance has become dependent on a handful of cloud providers, and it has built machinery to do something about it.
The concentration-risk problem, stated plainly
DORA created an oversight regime for what it calls critical ICT third-party providers. In November 2025 the European Supervisory Authorities named the first batch, and the list read exactly as you would guess: AWS, Microsoft Azure, Google Cloud, Oracle, IBM and others, as the supervisors confirmed. Regulators pointed out that a large majority of EU financial entities rely on at least two of the big three cloud platforms for critical functions.
Think about what that means as a systemic matter. If most of the continent's banks and insurers run their critical workloads on the same three American companies, then those three companies are single points of failure for the whole financial system. An outage, a compromise or a geopolitical rupture at one of them is not one firm's problem. It is everyone's problem at once. That is precisely the risk DORA was written to manage.
What DORA asks firms to do
DORA rests on several pillars, but the ones that touch AI directly are ICT risk management and third-party risk. In practice a financial entity has to keep a register of its ICT third parties, assess concentration risk, ensure it has exit strategies, and be able to keep operating if a provider fails. If your AI runs on a cloud model, that provider goes in the register, and you have to be able to answer the awkward question: what happens to this capability if this provider is unavailable, and can we actually move?
The uncomfortable maths for a lot of firms. Their AI, their productivity suite and their core infrastructure often sit with the same one or two hyperscalers. That is not diversification. It is concentration wearing a diversified costume, and DORA is designed to make supervisors ask about it.
Where on-premise changes the answer
Running an AI system on your own hardware does not make DORA go away. You still have resilience obligations, you still test, you still report incidents. But it changes the third-party risk picture in a specific, favourable way. A model that runs inside your own data centre is not another critical dependency on an externally overseen hyperscaler. It shortens the chain. Your exit strategy for that workload is trivial, because there is nothing to exit. And the concentration-risk question a supervisor might ask about your AI has a clean answer: this one does not add to our exposure, because we own it.
For the ICT third-party register, fewer external suppliers means less to document, monitor and stress-test. For concentration risk, keeping a critical workload in-house is the opposite of piling more load onto a designated critical provider. None of this is a silver bullet, and a badly run on-premise system can be less resilient than a well-run cloud one. But the structural point holds: the shorter your supply chain, the easier DORA's third-party questions are to answer.
This briefing is general information and not legal or regulatory advice. DORA is detailed and enforced by sector supervisors, so work through your specific obligations with your compliance function and, where relevant, Finansinspektionen guidance.