The regulatory trilemma of AI-driven cybersecurity in the European Union: reconciling the AI Act, DORA, and fundamental rights
Abstract
: The European Union has enacted two landmark frameworks that impose partially divergent obligations on financial entities deploying artificial intelligence (AI) in cybersecurity. The AI Act (Regulation (EU) 2024/1689) establishes a risk-based classification system subjecting AI systems to graduated transparency, explainability, and human-oversight duties. The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) requires financial entities to maintain robust Information and Communication Technology (ICT) risk-management capabilities, including rapid, automation-capable threat detection and incident response. This article argues that, for systemically significant financial actors, the combined operation of these two regimes together with the EU Charter of Fundamental Rights produces what it terms a regulatory trilemma: a three-cornered tension