Skip to content

The regulatory trilemma of AI-driven cybersecurity in the European Union: reconciling the AI Act, DORA, and fundamental rights

Jul 2026 · Law, Ethics & Technology · pp. 1-15 · 0 citations · 15 references

TL;DR

For systemically significant financial actors, the combined operation of these two regimes together with the EU Charter of Fundamental Rights produces what it terms a regulatory trilemma: a three-cornered tension.

Abstract

: The European Union has enacted two landmark frameworks that impose partially divergent obligations on financial entities deploying artificial intelligence (AI) in cybersecurity. The AI Act (Regulation (EU) 2024/1689) establishes a risk-based classification system subjecting AI systems to graduated transparency, explainability, and human-oversight duties. The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) requires financial entities to maintain robust Information and Communication Technology (ICT) risk-management capabilities, including rapid, automation-capable threat detection and incident response. This article argues that, for systemically significant financial actors, the combined operation of these two regimes together with the EU Charter of Fundamental Rights produces what it terms a regulatory trilemma: a three-cornered tension

View source

Similar papers

Conference Sep 2026

Balancing Transparency, Cybersecurity, and Innovation: Technical and Legal Challenges of AI Regulation in the European Union

This research presents an analysis of a fundamental problem in contemporary digital regulation, namely the need to ensure the transparency of algorithmic systems, maintain a high level of user cybersecurity, and foster technological innovation. The research focuses on the implementation of the EU Artificial Intelligenc...

Vaidas Jurkevičius, M. Pleskach, Romanas Tumasonis · 0 citations
Review Open access Oct 2026

Operationalising AI Governance in Public Administration: An Integrated Regulatory and Risk Management Framework

Public organisations are increasingly using Artificial Intelligence (AI) and Algorithmic Decision-making Systems (ADSs), but the rules and governance requirements that apply to them remain spread across different legal and risk-management frameworks. This study analyses the European Union (EU) AI Act, the General Data...

Nikolaos Levantis, Aggeliki Sgora, Athanasios Tsipis et al. · 0 citations
Open access Sep 2026

From obligation to enforcement: mapping EU AI act and CRA cybersecurity requirements to technical controls for LLM-based autonomous agents

Large language model (LLM) agents (systems that couple a language model with tools, memory, and orchestration so that they can plan and act with limited supervision) are entering production just as the European Union’s Artificial Intelligence Act (AI Act) and Cyber Resilience Act (CRA) begin to apply. Both instruments...

Abayomi Ogayemi · 0 citations
Review Open access Sep 2026

Governing Agentic AI in the Administrative State: Human Oversight, Cybersecurity Accountability, and Risk in Autonomous Digital Systems

Agentic artificial intelligence (AI) shifts digital government from systems that generate recommendations toward networked systems that perceive, plan, communicate, invoke tools, initiate actions, and adapt with limited direct supervision. This article examines agentic AI as an intelligent cybersecurity governance prob...

Haris Alibašić · 0 citations
Open access 2026

No borders for compliance: EU AI act obligations for non-EU digital agencies and tech companies

This paper addresses the critical problem of non-EU digital agencies and tech companies that service the EU market but remain largely unaware of or unprepared for their compliance obligations. The enforcement of the European Union Artificial Intelligence Act (EU AI Act) on August 2, 2026, introduces a comprehensive reg...

Ivana Denčić, S. Stanisavljev · 0 citations
#explainable ai Review Open access Oct 2026

Toward an integrative theoretical model of AI-supported cybersecurity governance and organizational resilience

Artificial intelligence (AI) increasingly supports cybersecurity work through risk scoring, anomaly detection, alert triage, vulnerability prioritization, threat-intelligence enrichment, and incident-response assistance. Existing research explains important aspects of technical performance, responsible AI, cybersecurit...

Irlenys Josefina Tersek Rodríguez · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.