From AI risk to resilience: getting ready for DORA and the EU AI Act.
The most advanced AI models can dangerously identify and exploit software vulnerabilities, and regulators are responding. DORA already applies, and the EU AI Act is phasing in: transparency and staff training since August 2026, high-risk obligations from December 2027. We help you build a single framework that satisfies both, implement it, and run it with you.
The risk is accelerating, and regulators know it.
AI becomes a serious cybersecurity risk
Anthropic’s Mythos model uncovered thousands of critical vulnerabilities. The European Central Bank summoned risk officers from euro-area banks, and Belgium’s FSMA warned that the cost of attacking any regulated entity has fallen sharply.
DORA today, the AI Act tomorrow
DORA already treats AI as part of a firm’s ICT estate and register of information. The AI Act adds inventory, classification, human oversight and accountability obligations on top.
Four pillars, one team, strategic partners.
We advise, we implement, we can operate, and we transfer the skills to your own teams.
Business & regulatory advisory
Technology advisory
Managed services
AI solutions
The framework we deliver aligns with the AI Act and DORA.
- AI inventory and risk classification
- Governance, operating model and roles
- AI policy and human oversight
- Risk and controls framework
- Architecture and data flows
- Agent identities, access and permissions
- Model, RAG and agent security
- Attack surface and patching
- Third-party and concentration risk
- Register of information
- Resilience, recovery and testing
- Evidence, audit and reporting
AI-specific risks we cover.
Our method
Ready to build your AI resilience framework?
Let’s talk about your DORA roadmap, the EU AI Act, and what needs to ship first.