Integrating AI into the regulatory environment of the financial sector

10 September 2024 | Knowledge, News, The Right Focus

Artificial intelligence is increasingly making its presence felt in the financial sector, opening up new opportunities for automation, data analysis and the personalisation of services. However, as the use of AI grows, so do the challenges of integrating it with existing regulations. Key aspects of this integration include compliance with the Digital Operational Resilience Act (DORA). From the perspective of Polish entities and the specificities of the Polish financial sector, the Polish Financial Supervision Authority’s (KNF) guidelines on the use of cloud computing are also relevant.

We look at how the implementation of AI-based solutions fits into current financial sector regulations, and what changes are necessary to allow the financial sector to fully benefit from the potential of artificial intelligence.

AI in the age of DORA

The DORA, which aims to increase the digital resilience of the financial sector, places particular emphasis on managing the risks associated with information and communication technology (ICT) services.

Services provided using artificial intelligence systems, which are in principle considered software under the AI Act, will include a number of types of services that DORA considers to be ICT services. This means that banks and other financial institutions need to ensure their compliance with this regulation.

AI can help improve digital resilience by, among other things:

  • Early detection of cyber threats
  • Automating system monitoring
  • Optimising decision making

However, in order for financial institutions to realise the full potential of AI in line with DORA, they must ensure the transparency of the implemented technologies. This can be achieved by:

  • Ensuring data security
  • Carrying out a risk assessment
  • Applying appropriate security measures
  • Developing incident reporting procedures

Integrating AI with DORA requirements also requires the implementation of appropriate mechanisms for controlling and monitoring services.

A mandatory digital resilience testing programme includes software analysis or source code review, which in practice means ensuring that the algorithms used are designed and implemented in a way that minimises risk.

DORA also requires consideration of the potential impact of the solutions used on service continuity and availability. To minimise risk, banks should possess redundancy via alternative solutions and mechanisms for manual intervention, for example when algorithms fail or do not perform as expected.

Financial institutions should note the similarities between DORA and the AI Act. A streamlined approach to implementing each of these regulations could result in lower costs and improved risk and resilience management.

Establishing a single, well-documented framework that clearly identifies risks arising from the use of artificial intelligence systems, including any cyber threats, and identifying measures to address those risks, can help ensure compliance with legislation such as DORA and the AI Act.

In developing such a framework, the risks arising from the processing of personal data should not be overlooked.

AI and Cloud Communication

The relationship between the cloud and artificial intelligence is inextricable.

The cloud is a natural environment for the development of AI, as it allows for the easy creation and subsequent management of AI-powered applications, as well as the processing of massive amounts of data, which is critical to the efficiency of algorithms. However, such implementation presents additional challenges for financial institutions, such as ensuring compliance with cloud usage guidelines.

The Cloud Communication, a set of guidelines for supervised entities, imposes a number of obligations on these entities in relation to data security.

As AI technologies are largely cloud-based, the financial sector will routinely need to consider the requirements of the Communication when implementing artificial intelligence systems, which will involve, among other things, the need to:

  • Ensure adequate staff competence
  • Develop an information processing plan
  • Monitor the processing environment
  • Regularly document the activities carried out

GDPR and other regulations

When discussing the implementation of AI-based solutions, it is important to consider the appropriate protection of personal data in accordance with applicable legislation, most notably the GDPR.

Notwithstanding data protection regulations, banks and financial institutions interested in implementing solutions from third-party AI providers should consider the regulations applicable to their business that set out the requirements for regulated outsourcing (e.g. banking, insurance or payments), as well as other recommendations of the supervisory authority, including Recommendation D.

In summary, integrating AI into the financial sector is no small challenge. However, above all it is a tremendous opportunity to improve process efficiency and operational security, and thus to deliver services more efficiently.

The increasing use of AI in banking will bring greater convenience to customers and competitive advantage to banks.

And to achieve this, it is particularly important to synergise the solutions implemented with the regulatory environment in order to fully exploit the potential of AI for financial actors.

Any questions? Contact us

Maciej Kuranc

Mikołaj Kuterek

Latest Knowledge

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.

Record fines and the upcoming 21st sanctions package – what should businesses expect?

The past year has brought a series of enforcement actions that clearly signal a tightening approach by the Polish customs and revenue authorities towards breaches of the sanctions regime. Importantly, businesses should already be preparing for further changes, as the European Union has announced its 21st sanctions package and updated the list of designated persons and entities. We examine the key developments and offer guidance on how to minimise the risk of non-compliance.

A sea change in the rules governing board members’ liability for a company’s tax arrears

The bill amending the General Tax Code (No. UC138) fundamentally overhauls the rules governing the tax liability of third parties for capital companies’ tax arrears.  It comes in response to recent CJEU judgments, the Ombudsman’s February statement and the post-audit report of the Supreme Chamber of Audit (NIK) of December 2025. We examine what’s changing, who will be affected by the new rules and what steps are worth taking right now.

Partner in name, but only if male: the linguistic trap in Polish corporate law

One of the structures available under Polish law is the ‘spółka partnerska’ (professional partnership), modelled on the Anglo-Saxon Limited Liability Partnership. As defined in the Polish Commercial Companies Code, this is a vehicle for individuals practising liberal professions, such as doctors, architects and accountants. And yet, the provisions governing professional partnerships make no mention of their applicability to women. We therefore examine whether there is no room for female partners, feminine-gendered forms, or simply linguistic empathy.

Can you sue over words aimed at an entire community?

A damaging public statement does not necessarily refer to a specific individual. Sometimes, the author attributes negative characteristics to a whole group of people, portrays them as a threat or uses language that could be seen as demeaning. Statements of this kind frequently concern LGBTQ+ people. This raises the question: can a member of the targeted community bring a lawsuit seeking compensation or an apology, even if they were not named directly? We decided to look into this.

Banking sector overview | Banking today and tomorrow | June 2026

According to a statement published by GPW Benchmark, the reference rate administrator, and the Polish Financial Supervision Authority (KNF), which oversees the administrator, 31 December 2036 will be the last day on which the WIBID and WIBOR rates will be provided for all key fixing periods: 1 month (1M), 3 months (3M) and 6 months (6M).

How to correctly calculate length of service from 1 May 2026

New rules for calculating length of service have applied to private sector employers since the beginning of May 2026. With companies continuing to express concerns about the new framework, the Ministry of Family, Labour and Social Policy has addressed the most common questions. We look at the issues that are (still) troubling employers and how we can help.

Contact us:

Monika Maćkowska-Morytz

Monika Maćkowska-Morytz

Advocate / Partner / Head of the Personal Data Protection and Cyber Security Practice

+48 660 765 918

m.mackowska-morytz@kochanski.pl