Hochleistungs-KI als IKT-Risikotreiber unter DORA
Read More

Frontier AI as an ICT Risk Driver under DORA

Frontier AI is changing the cyber risk landscape for financial entities – and with it the requirements for appropriate ICT risk management under DORA. A new statement by the European Supervisory Authorities explains how existing DORA requirements should be applied in light of faster, more scalable and more complex AI-enabled attacks. This article examines the supervisory expectations and identifies where financial entities should review their existing processes and controls.
Read More
9. MaRisk-Novelle und DORA: Digitale Resilienz wird Chefsache 9th MaRisk Amendment and DORA: Digital Resilience Becomes a Board-Level Responsibility
Read More

9th MaRisk Amendment and DORA: Digital Resilience Becomes a Board-Level Responsibility

The draft of the 9th MaRisk amendment systematically integrates the requirements of DORA into the existing MaRisk governance framework without creating a separate national regime. As a result, digital operational resilience is becoming a core management responsibility: ICT risks are no longer viewed solely as an IT security issue but as part of overall bank management, risk strategy, and institution-wide governance.
Read More
IT-Anforderungen an Finanzunternehmen in Deutschland – ein Überblick über den regulatorischen Rahmen IT Requirements for Financial Institutions in Germany – an overview of the regulatory framework
Read More

IT Requirements for Financial Institutions in Germany – an overview of the regulatory framework

IT regulation in the financial sector is becoming increasingly complex. With DORA, the FinmadiG, the NIS 2 Implementation Act, GDPR, the Cyber Resilience Act, the Data Act and the AI Act, financial institutions face far-reaching requirements regarding digital resilience, third-party risk management and governance. This article provides a structured overview of the current regulatory framework in Germany and at EU level.
Read More
KI-Regulierung in der Praxis: Was die Aufsicht zu KI im Finanzsektor wirklich sehen will | ALLES LEGAL #126 AI Regulation in Practice
Read More

AI Regulation in Practice: What Supervisors Really Expect to See from AI in the Financial Sector | ALLES LEGAL #126

Annerton partner Josefine Spengler explains how supervisory authorities assess AI systems in the financial sector in practice. AI is not treated as a regulatory special case but as an ICT system embedded within existing frameworks, particularly DORA. The focus lies on governance, accountability, traceability and ongoing monitoring. The interaction between DORA and the EU AI Act adds further complexity. The key takeaway: AI is not merely an IT issue – it is a management responsibility.
Read More