DORA
Regulation (EU) 2022/2554 · applicable since 17 Jan 2025
RequiresDigital operational resilience and ICT third-party risk management: the AI provider is part of your operational risk, with audit and exit-strategy obligations.
HelmcodeAn auditable EU provider, dedicated or on-premise deployment, and a standard OpenAI-compatible API: your exit strategy is changing a URL, not rewriting the integration.