Skip to content

DORA

The ESAs just told you what DORA expects about AI-driven attacks

The article-by-article series ended with the point that DORA is a chain, and that everything downstream inherits the quality of your asset and function map. On 31 July 2026 the three ESAs published a joint statement that tests exactly that claim. It is about frontier AI models being used to find and exploit vulnerabilities faster than your patch cycle can close them, and it says the rulebook you already have is the rulebook you are expected to use.

DORA oversight, and the whole regulation on one page

This is the finale of the article-by-article series. Chapter V, section II, Articles 31 onward, is the part of DORA that reaches past individual firms and up to the providers everyone depends on: the critical ICT third-party providers, supervised directly at EU level. Then, as promised at the start, DORA on one page.

DORA Article 16: the simplified regime is lighter, not optional

So far this series has walked the full ICT risk management framework, Articles 5 to 15. Article 16 is for the entities that do not have to do all of that. It is proportionality written into the regulation. It is also widely misread as an exemption, which it is not. Today, who qualifies for the simplified framework, and what they still have to do.

DORA Articles 13 and 14: the quiet articles that decide if you improve

Most of DORA is about preventing and surviving incidents. Articles 13 and 14 are about what happens afterwards: do you learn, and do you communicate. They are easy to skim past because they do not come with hard thresholds. They are also, in my experience, where the difference between a mature function and a box-ticking one actually shows. Today, learning and communication.

The document list BaFin walks in with

Most DORA readiness work starts from the regulation and tries to guess what a supervisor will ask for. You do not have to guess. BaFin published the list.

The awkward part is what happens when you lay your existing policy stack next to it.

DORA Articles 11 and 12: what "recover" has to actually mean

Detection tells you something broke. Articles 11 and 12 are about getting back up. This is the part of DORA that auditors love, because continuity and backup are testable in a way that policies are not: either you restored within your stated objective or you did not. Today, business continuity and backup, and the RTS that says testing them once is not enough.