AI Providers as ICT Third-Party Providers under DORA

DORA treats AI providers as ICT third-party providers under Art. 28. It covers the duties involved and where AI Act deadlines start to matter.

Why AI providers fall under DORA at all

When a financial entity uses an AI system or a GPAI model from an external provider – for credit scoring, fraud detection, customer-service chatbots or internal text analysis, say – this counts as an ICT service within the meaning of DORA. The provider thereby becomes an ICT third-party provider. That applies regardless of whether the AI provider is itself a financial entity, and regardless of whether it is a high-risk system under the AI Act. The only decisive factor for classification as an ICT third-party provider is that a contractual arrangement exists for the use of an ICT service (Art. 28(1) DORA).

This means: any bank, insurer, payment service provider or other DORA-obligated entity that buys in AI services remains, under Art. 28(1)(a) DORA, “at all times fully responsible” for compliance with DORA obligations. Outsourcing to an AI provider does not relieve that responsibility.

The core duties under Art. 28 before signing a contract

Before entering into a contractual arrangement with an AI provider, Art. 28(4) DORA requires specific assessment steps:

  • Criticality assessment (point (a)): Does the AI service support a critical or important function? This is often the case with credit-decision or fraud-prevention systems.
  • Regulatory permissibility (point (b)): Are the conditions for outsourcing met?
  • Risk identification (point (c)), including whether the use contributes to ICT concentration risk under Art. 29 – a real issue with dominant GPAI providers.
  • Due diligence on the provider (point (d)).
  • Conflict-of-interest assessment (point (e)).

Under Art. 28(5) DORA, contracts may only be concluded with providers that maintain appropriate information security standards; for critical or important functions, the most up-to-date and highest quality standards must be taken into account. An AI provider that cannot give robust information on information security, training-data provenance or model robustness typically fails to meet this requirement.

Register of information and reporting duties

Art. 28(3) DORA requires financial entities to maintain and update a register of information on all contractual arrangements with ICT third-party providers – distinguishing whether a critical or important function is affected. Any planned arrangement supporting such a function must be reported to the competent authority in good time; the same applies where a previously non-critical function becomes critical. In addition, at least annual reporting is required on the number and type of new arrangements and the categories of providers involved.

In practice, this means: every AI provider under contract must appear in the register – including its classification as critical/important or not. A separate shadow inventory of “AI tools bought by the business unit” is not compatible with Art. 28(3).

The interface with AI Act deadlines

The due diligence obligation under Art. 28(4)(d) DORA – assessing whether the AI provider is suitable – cannot be evaluated without regard to the AI provider’s own, parallel obligations under the AI Act. From 02.08.2026, the transparency obligations under Art. 50 AI Act apply (with a grace period until 02.12.2026 for systems already placed on the market beforehand). An AI provider that fails to meet its transparency obligations from that date – for instance, labelling AI-generated content or informing users – sends a signal that should feed into the due diligence and risk assessment under Art. 28(4) DORA. Missing or unclear information from the provider about its own AI Act obligations is an indicator of inadequate governance, and this should be documented during the selection process.

Common gaps in practice

A frequent pattern: AI tools are procured by business units without involving ICT risk management or compliance, because they are perceived as “software-as-a-service” rather than classic outsourcing. The result is missing criticality assessments under Art. 28(4)(a), incomplete registers of information under Art. 28(3), and contracts lacking evidence of appropriate information security standards under Art. 28(5). Particularly with GPAI providers, where only a handful of dominant players exist, the concentration-risk assessment under Art. 28(4)(c) is also often incomplete.

Conclusion

From a DORA perspective, AI providers are ICT third-party providers just like any other software or cloud provider – subject to the same duties of due diligence, registration and risk assessment before a contract is signed. Anyone who does not know which AI services are already in use across the organisation, and whether these support critical functions, has a gap in their ICT risk management under Art. 28 DORA. Use the free risk check at /einstufung to get an initial assessment of where your organisation stands on AI use and regulatory obligations.

Factual orientation, not legal advice. Citations refer to the named legal acts and were checked against the official EUR-Lex texts.