Integrating AI into the regulatory environment of the financial sector

10 September 2024 | Knowledge, News, The Right Focus

Artificial intelligence is increasingly making its presence felt in the financial sector, opening up new opportunities for automation, data analysis and the personalisation of services. However, as the use of AI grows, so do the challenges of integrating it with existing regulations. Key aspects of this integration include compliance with the Digital Operational Resilience Act (DORA). From the perspective of Polish entities and the specificities of the Polish financial sector, the Polish Financial Supervision Authority’s (KNF) guidelines on the use of cloud computing are also relevant.

We look at how the implementation of AI-based solutions fits into current financial sector regulations, and what changes are necessary to allow the financial sector to fully benefit from the potential of artificial intelligence.

AI in the age of DORA

The DORA, which aims to increase the digital resilience of the financial sector, places particular emphasis on managing the risks associated with information and communication technology (ICT) services.

Services provided using artificial intelligence systems, which are in principle considered software under the AI Act, will include a number of types of services that DORA considers to be ICT services. This means that banks and other financial institutions need to ensure their compliance with this regulation.

AI can help improve digital resilience by, among other things:

  • Early detection of cyber threats
  • Automating system monitoring
  • Optimising decision making

However, in order for financial institutions to realise the full potential of AI in line with DORA, they must ensure the transparency of the implemented technologies. This can be achieved by:

  • Ensuring data security
  • Carrying out a risk assessment
  • Applying appropriate security measures
  • Developing incident reporting procedures

Integrating AI with DORA requirements also requires the implementation of appropriate mechanisms for controlling and monitoring services.

A mandatory digital resilience testing programme includes software analysis or source code review, which in practice means ensuring that the algorithms used are designed and implemented in a way that minimises risk.

DORA also requires consideration of the potential impact of the solutions used on service continuity and availability. To minimise risk, banks should possess redundancy via alternative solutions and mechanisms for manual intervention, for example when algorithms fail or do not perform as expected.

Financial institutions should note the similarities between DORA and the AI Act. A streamlined approach to implementing each of these regulations could result in lower costs and improved risk and resilience management.

Establishing a single, well-documented framework that clearly identifies risks arising from the use of artificial intelligence systems, including any cyber threats, and identifying measures to address those risks, can help ensure compliance with legislation such as DORA and the AI Act.

In developing such a framework, the risks arising from the processing of personal data should not be overlooked.

AI and Cloud Communication

The relationship between the cloud and artificial intelligence is inextricable.

The cloud is a natural environment for the development of AI, as it allows for the easy creation and subsequent management of AI-powered applications, as well as the processing of massive amounts of data, which is critical to the efficiency of algorithms. However, such implementation presents additional challenges for financial institutions, such as ensuring compliance with cloud usage guidelines.

The Cloud Communication, a set of guidelines for supervised entities, imposes a number of obligations on these entities in relation to data security.

As AI technologies are largely cloud-based, the financial sector will routinely need to consider the requirements of the Communication when implementing artificial intelligence systems, which will involve, among other things, the need to:

  • Ensure adequate staff competence
  • Develop an information processing plan
  • Monitor the processing environment
  • Regularly document the activities carried out

GDPR and other regulations

When discussing the implementation of AI-based solutions, it is important to consider the appropriate protection of personal data in accordance with applicable legislation, most notably the GDPR.

Notwithstanding data protection regulations, banks and financial institutions interested in implementing solutions from third-party AI providers should consider the regulations applicable to their business that set out the requirements for regulated outsourcing (e.g. banking, insurance or payments), as well as other recommendations of the supervisory authority, including Recommendation D.

In summary, integrating AI into the financial sector is no small challenge. However, above all it is a tremendous opportunity to improve process efficiency and operational security, and thus to deliver services more efficiently.

The increasing use of AI in banking will bring greater convenience to customers and competitive advantage to banks.

And to achieve this, it is particularly important to synergise the solutions implemented with the regulatory environment in order to fully exploit the potential of AI for financial actors.

Any questions? Contact us

Maciej Kuranc

Mikołaj Kuterek

Latest Knowledge

Length of service now includes periods of self-employment

The length of service no longer depends solely on work carried out under a contract of employment. The amendment to the Labour Code introduces significant changes, as work carried out under civil law contracts or as part of business activity will now also be included when calculating service, which affects employees’ rights. What will this mean for employees and employers?

Banking sector overview | Banking today and tomorrow | February 2026

The Polish banking sector is undergoing intense reshuffling on a scale not seen for years. Large banks are changing owners, foreign players are shifting their strategies and new investors are entering the market. The question is whether these are just temporary shifts in capital or the beginning of lasting change in the industry’s balance of power.

31 January. Don’t forget about the DAC7 Directive

The deadline for meeting the obligations under the DAC7 directive and the Polish regulations implementing it is fast approaching. Online platform operators must fulfil their reporting obligations by 31 January 2026 at the latest with regard to 2025 data. For many, this is the final opportunity not only to prepare the required information, but also to verify whether DAC7 obligations apply to them and, if so, to what extent.

The New Consumer Credit Act – extensive regulation with a broad market impact

In 2025, the Polish financial market entered another phase of adjustments to EU legislation. The draft new Consumer Credit Act implementing the CCD2 Directive, alongside the regulations on distance financial services, represents one of the most comprehensive attempts to standardise the rules for providing finance to consumers. The changes are so extensive that they cover all stages, from advertising and customer acquisition to the assessment of creditworthiness, the structure of agreements, the scope of the lender’s liability, withdrawal rules and the detailed organisation of remote sales.

Energy Radar 2026: Your roadmap to energy transition

Energy is no longer the exclusive domain of engineers and politicians; it is becoming the foundation of the business strategy of any company that wants to remain competitive. And 2026 will see a multitude of legislative changes that will fundamentally alter the current approach to the rules for grid connection, energy trading and reporting obligations.

Banking sector overview | Banking today and tomorrow | January 2026

On 1 January, new regulations came into force that increased the income tax rate paid by banks. The rate will be 30% in 2026. However, entities starting their business, credit and savings unions (SKOKs), small entities, and banks undergoing restructuring will pay less.

2025 in the banking sector: legal and tax changes, and strategic challenges

The Polish banking sector underwent profound reforms and new regulatory obligations in 2025. Despite achieving record financial results, banks were faced with mounting tax pressures and changes in benchmarks, as well as the implementation of EU regulations concerning operational security, anti-money laundering, digital payments, the use of artificial intelligence, environmental issues, ESG reporting and green transformation. Against this backdrop, we also observed market consolidation, partly driven by growing competition from new banks. In this article, we explore how these factors have transformed the Polish financial institution market.

Contact us:

Monika Maćkowska-Morytz

Monika Maćkowska-Morytz

Advocate / Partner / Head of the Personal Data Protection and Cyber Security Practice

+48 660 765 918

m.mackowska-morytz@kochanski.pl