← The journal
Strategy

DORA and AI Vendors: Exit Plans, Concentration Risk and Contract Clauses

How EU financial entities should treat AI vendors under DORA: exit plans, concentration risk and contract clauses.

Swfte Journal / Strategy

If you are a bank, insurer, investment firm or payment institution in the EU, your LLM provider is an ICT third-party service provider under the Digital Operational Resilience Act. That means the questions your supervisor asks about a core banking vendor now apply to the model API behind your support assistant or credit-memo drafting agent: where does it run, who else is in the chain, and how do you leave?

This post walks through the parts of DORA that matter most when you buy model, inference and agent services: the register, exit plans, concentration risk and contract terms. Last verified 2026-10-06.

What DORA asks of you as the buyer

DORA has applied since 17 January 2025 to financial entities and governs ICT third-party risk. The core of it for vendor management sits in Chapter V of the Regulation:

  • Article 28 sets the general principles, including the register of information on contractual arrangements and exit strategies for ICT services that support critical or important functions.
  • Article 29 requires a preliminary assessment of ICT concentration risk, including the sub-outsourcing chains behind a provider.
  • Article 30 lists the key contractual provisions, with a longer list for services supporting critical or important functions.
  • Articles 31 to 44 create the oversight regime for critical ICT third-party providers (CTPPs).

DORA does not mention large language models by name. It does not need to. A hosted model API is an ICT service, and the question is whether it supports a function your firm has classified as critical or important. An internal memo drafter probably does not; an agent triaging payment alerts might. Your own function classification decides how heavy the obligations are, so settle that first. For the AI-specific reading, see DORA for AI.

The register of information: what to record for an AI service

A register line that says "OpenAI-compatible API, EU region" is not enough. For each AI service, capture at least:

  • Every entity that processes your data: model developer, inference host, cloud provider, observability or evaluation vendor, embedding or retrieval provider.
  • The functions supported, and whether any is critical or important.
  • Where prompts, retrieved context, outputs, logs and backups are processed and stored, and who can administer them.
  • Which other model could do the job, and what it would take to switch.

That last point feeds the exit plan. If you cannot name a fallback model, you do not yet have an exit strategy, only a hope.

What a model-provider exit plan looks like in practice

Article 28 requires exit strategies for ICT services supporting critical or important functions, and Article 30 points to a mandatory transition period in the contract for those functions. The legal text sets the frame; the engineering decides whether the plan works. A usable exit plan for an LLM service has six parts.

1. Model portability through a gateway

Applications that call a provider's SDK directly carry its request format and tool-calling conventions into every codebase. Put a model gateway between your applications and providers so that a model is a configuration value, not a code dependency, and "switch the primary model for this workload" becomes a change you can rehearse. Our model exit cost audit framework and the broader guide to avoiding AI vendor lock-in cover how to price that dependency.

2. Prompt and evaluation portability

Prompts tuned to one model often degrade on another. Keep prompts, few-shot examples and tool schemas in version control, plus an evaluation set that scores the workload on accuracy, refusal behavior, latency and output validity. Without it you cannot say whether a fallback model is acceptable.

3. Data return

Define what leaves with you: fine-tuning datasets, stored conversations, evaluation logs, embeddings and any vendor-side thread state. Article 30 expects the contract to cover access, recovery and return of data on insolvency or termination. List the specific data categories and export format, not just "customer data".

4. Retrieval index rebuild

A retrieval index depends on its embedding model, so changing provider means re-embedding the corpus. Record how long that takes, what it costs, and whether you keep the source documents and chunking configuration yourself. An index you can rebuild from your own sources is portable; one only the vendor can reproduce is lock-in.

5. A tested fallback model

A fallback that has never served traffic is an assumption. Pick a secondary model, preferably from a different provider and hosting chain, route a small share of non-critical traffic to it, and run the evaluation set on a schedule.

6. A transition period

Agree how long the provider keeps serving you, and at what price, while you migrate. Compare that with your own migration estimate: if your rebuild takes ten weeks and the contract gives you four, the gap is a finding.

Concentration risk: the questions to ask

Article 29 asks you to assess concentration risk before entering an arrangement, including where the provider relies on sub-outsourced ICT services. AI stacks concentrate in ways that are easy to miss because the dependencies are layered. Ask:

  • Single model vendor. Do all critical workloads depend on one model family? What happens if it is deprecated, repriced or withdrawn from your region?
  • Single cloud region. If the inference host and your retrieval store sit in one region of one cloud, a regional outage takes down the whole capability.
  • Shared GPU supplier. Apparently different AI vendors may run on the same hyperscaler or GPU provider. Ask each to disclose its infrastructure chain, then look for overlap.
  • Hidden sub-processors. Evaluation, moderation, logging and vector-store services often sit outside the headline contract.

None of this forbids concentration. Know where it is, decide whether it is acceptable for the function, and document the decision.

Where CTPP designation fits, and where it does not

Under Articles 31 to 44, the European Supervisory Authorities can designate providers as critical. According to Morgan Lewis and PwC Germany, the first list of 19 designated CTPPs was published on 18 November 2025. Check the current list yourself.

Two cautions. Designation does not discharge your own duties: the register, exit plans and concentration assessment remain yours. And a provider's absence from the list says nothing about whether the service supports a critical function for you. Swfte is not a designated CTPP.

Contract clause checklist for AI vendors

A starting point for the Article 30 conversation, not a drafting template.

AreaWhat to ask for in an AI services contractWhy it matters
Service descriptionNamed models, versions, endpoints and the support commitments for eachSilent model swaps change behavior
LocationsWhere prompts, context, outputs, logs and backups are processed and stored, and notice of changesFeeds the register and your data-protection analysis
Sub-outsourcingDisclosed chain, advance notice of changes, right to objectArticle 29 concentration assessment
Data protection and integritySecurity measures, encryption, deletion on instruction, no training on your data unless agreedConfidentiality and availability duties
Return of dataExport formats and timelines for fine-tunes, logs, embeddings and stored state, including on insolvencyExit and recovery
Service levelsAvailability, latency and incident response targets, with precise definitionsResilience of critical functions
Incident assistanceNotification timing, cooperation with your incident reportingMajor ICT incident reporting is also part of DORA
Authority cooperationCooperation with your supervisors and resolution authoritiesArticle 30 provision
TestingParticipation in your resilience testing for critical or important functionsArticle 30 provision for those functions
Termination rightsTermination triggers and a defined transition period with continued serviceExit strategy
DeprecationMinimum notice before a model is retiredPrevents forced migrations

Check the exact list in Article 30 against your template and have counsel adapt it.

The Data Act as a second lever

DORA tells you what to ask. The Data Act, which the Commission's fact page says has applied since 12 September 2025, adds statutory switching rights for data processing services in Chapter VI. According to Faegre Drinker, customers can switch with a maximum of two months' notice, the transition period is at most 30 calendar days, and the data retrieval period is at least 30 days.

On cost, the Commission's fact page says only costs directly linked to switching can be charged until 12 January 2027, and from that date there are no switching charges, including egress fees. For a financial entity this is negotiating leverage and a backstop if a contract is silent. Whether a given model API counts as a data processing service under the Act depends on its terms, so confirm with counsel. See Data Act and AI for how the pieces fit. Treat it as a complement to DORA contract terms, not a replacement.

For architecture that keeps this tractable in regulated environments, see our piece on the EU sovereign AI stack for banks and the public sector.

How Swfte supports this

Swfte is a Sovereign Intelligence Platform built for Europe, and it is designed to let you treat the model as a replaceable component. Its BuildX model gateway fronts 50+ LLMs, the technical basis for the portability and fallback steps above. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements, such as a Trust Profile that records approved models, data residency and audit settings per AI system; the exact posture depends on use case, jurisdiction, deployment and configuration. Customer data is stored in AWS eu-west-1 (Ireland) today, and private, dedicated and in-region deployment options are designed to let you set the EU data boundary and administrative access you need, scoped through a dedicated deployment engagement. Swfte is not a designated CTPP; see the trust page for current security status. Start with the EU hub, then see governance, sovereignty and the Trust Profile.

This is not legal advice. Confirm your obligations with qualified counsel.

Keep the conversation practical.

Turn an idea into a working next step.

Discuss your use case
0
0
0
0

Enjoyed this article?

Get more insights on AI and enterprise automation delivered to your inbox.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.