Three forces are reshaping European financial services at once, and they are not independent. Artificial intelligence is in day-to-day use at more than 85% of the banks under European banking supervision. The operational resilience rulebook governing how it is run has applied since January 2025. And the providers underneath both are a short list of firms supervisors have now named. This article takes them in that order: what the technology changed, what the regulation requires, and what a bank or insurer should be deciding this year.
Technology and regulation as the twin engines of industry transformation
No single force is doing the reshaping. Technology and regulation are advancing together, and the interaction between them is where the difficulty sits. A bank that deploys AI without understanding its regulatory position has not innovated; it has taken on an unpriced liability.
Adoption is no longer the interesting question. Patrick Montagner of the ECB Supervisory Board put it flatly in February 2026: “Over 85% of the banks we supervise are using AI.” The deployment pattern across European institutions is consistent, and none of it is exotic:
- credit scoring and creditworthiness assessment
- payment and card fraud detection
- anti-money-laundering monitoring and alert triage
- customer onboarding and document processing
- internal IT operations and code assistance
What changed is the speed and scale of decisions, which is precisely what older control frameworks were not built to audit. In our banking software work the constraint is rarely the model. It is that the institution cannot yet evidence how the model behaves.
Sequencing is what makes that affordable. We moved a bank off legacy internet banking onto microservices with 1.5M+ users migrated in six months and no disruption, and the order of the work – what moves first, what keeps running, what has to be provable at each step – was the design, not a project-management detail.
Regulation moved to meet that, and it moved before the technology settled. DORA (Regulation (EU) 2022/
Artificial intelligence: capability, risk and the governance gap
The promise is well covered. The governance gap that opens the moment a model moves from pilot to production is not.
When an AI model contributes to a credit decision that turns out to be wrong or discriminatory, the accountable party under EU law is the institution, not the vendor. Annex III point 5(b) of the AI Act classifies creditworthiness assessment as high-risk, expressly excepting systems used to detect financial fraud, and Article 27 requires the deployer of a credit scoring system to run a fundamental rights impact assessment before first use. Article 25(1) goes further: put your own name on a bought high-risk system, or modify it substantially, and you become its provider with the full set of provider obligations.
Pedro Machado, the ECB representative to the Supervisory Board, framed the operational test in February 2026: “If a bank cannot explain why an AI model behaves the way it does, in terms that are meaningful for decision-making, then it cannot truly control that model.”
That is a statement about control rather than paperwork, and it points at the second exposure: generative systems come from a small number of providers and rest on a small number of clouds. Machado named the consequences in the same speech: concentration risk, vendor lock-in, data confidentiality, operational resilience and exit strategies.
Evaluating a platform to build the next decade on?
Our free vendor-neutral scorecard rates any mini-app or super app platform on seven criteria, including SDK openness, runtime portability, FINMA and DORA fit, exit terms and total cost, with the exact question to put to each vendor.
Regulatory pressure and the new definition of operational readiness
Regulators have always set minimum standards. What is different now is that the standards name mechanisms, not just outcomes.
DORA is the clearest case. Article 19 requires a three-stage report on a major ICT incident, and Commission Delegated Regulation (EU) 2025/
Then the supervisors named the concentration. The first DORA designation of critical ICT third-party providers, made by the European Supervisory Authorities on 18 November 2025, covered 19 firms, Amazon Web Services and Microsoft among them. The EBA had already reported that important services are often outsourced to a few large providers, with rising reliance across the banking system. The failure mode is not theoretical either: the AWS us-east-1 disruption of 20 October 2025 ran for roughly 16 hours, and press reporting at the time listed several European banking services among those affected.
Old definition of readiness | What DORA now asks for | |
|---|---|---|
Incident reporting | Escalate when it becomes serious | 4 hours from classification, 72 hours, one month |
Third-party contracts | Commercial terms | Documented in the Article 28(3) register |
Exit planning | A drafted plan | A plan that has been tested |
Testing | Annual audit sign-off | Resilience testing of critical systems |
Accountability | The vendor's failure | The institution's, regardless of who ran the system |
Richard Cook observed in “How Complex Systems Fail”, written in 1998 for clinicians rather than bankers, that complex systems run in a degraded mode as a normal condition, and that catastrophe requires several failures to line up. The current rulebook has adopted that assumption. Readiness now means evidence that the plan has been exercised.
Strategic priorities for financial institutions navigating structural change
Naming the forces is the easy half. Sequencing the response is where institutions separate.
- Treat compliance as an operational discipline rather than a legal one. Retrofitting governance onto a live AI system costs an order of magnitude more than designing it in, because the evidence has to be reconstructed rather than recorded.
- Map critical technology dependencies and hold a tested alternative. DORA Article 29 asks for the assessment before contracting, and the designation of critical providers in November 2025 means supervisors already know where your concentration sits.
- Keep the ability to explain and audit automated decisions in-house. It cannot be outsourced to the vendor, because Article 25(1) of the AI Act can make you the provider anyway.
- Use the deferral, do not bank on it. Regulation (EU) 2026/
1744 pushed the Annex III high-risk obligations from 2 August 2026 to 2 December 2027, but the Article 50 transparency duties still start on 2 August 2026 and GDPR Article 22 never moved.
The institutions that define the next decade will not be the ones with the most advanced technology. They will be the ones that can show, on a Tuesday afternoon, why a system decided what it decided.
Platform work behind those decisions
Rebuilding for what the rulebook now expects?
WislaCode builds regulated banking software where architecture and compliance are the same conversation: integration, audit trails, resilience and the evidence a supervisor asks for.
What are the biggest factors shaping the future of the financial services industry right now?
AI adoption, operational resilience regulation, and the concentration of critical technology in a few providers. They are connected: AI deepens dependence on third-party platforms, that dependence amplifies concentration risk, and concentration risk is what DORA now supervises. Treating them as three separate programmes is how institutions manage each one badly.
How is artificial intelligence changing the way banks operate?
It is accelerating decisions across credit, fraud, compliance monitoring and customer service, and creating accountability gaps that EU law is closing. Under the AI Act the institution remains responsible for the outcome of an automated decision, even when a third-party system produced it. More than 85% of banks under European banking supervision now use AI in some form.
What does operational resilience mean in practice under DORA?
That a firm can keep delivering critical services through disruption and can prove it with tested plans. DORA requires an initial incident report within four hours of classifying an incident as major, exit plans that are “comprehensive, documented and sufficiently tested”, and a register of every ICT arrangement. A plan that has never been exercised does not meet the standard, however well it reads.
Why is technology concentration risk a growing concern?
Because the same handful of providers now sit under most critical operations. On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers under DORA, among them Amazon Web Services, Microsoft and Google Cloud. The AWS disruption of 20 October 2025, around 16 hours long, showed how far a single regional failure travels.
How does DORA affect technology procurement decisions?
It turns them into compliance decisions. Before contracting for an ICT service supporting a critical or important function, a firm must assess concentration risk under Article 29 and hold a tested exit plan under Article 28(8). Reaching go-live without a rehearsed transition route is a potential breach of a specific obligation, not just a risk-management gap.
Have the EU AI Act obligations for financial services been delayed?
Partly. Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July, moved the Annex III high-risk obligations, including credit scoring, from 2 August 2026 to 2 December 2027. The Article 50 transparency obligations still apply from 2 August 2026, and GDPR Article 22 has governed automated credit decisions throughout.




