EU DORA Regulation Tightens Cryptographic Key Protection Amid AI-Driven Cyber Threats
The EU's Digital Operational Resilience Act (DORA) now obliges financial institutions, insurers, investment firms and their ICT service providers to safeguard cryptographic keys throughout their lifecycle and to implement strong authentication as part of a unified ICT risk‑management framework. Non‑compliance can attract penalties of up to 2 % of global annual turnover for firms or €5 million for critical third‑party providers.
At the same time, the EU’s broader cyber‑security regime, including GDPR and NIS2, is moving toward heavier fines and personal liability for corporate executives. Experts warn that AI tools such as Claude Mythos are able to uncover long‑standing vulnerabilities in widely used software, raising the risk of sophisticated attacks and automated phishing. The convergence of tighter regulation and AI‑enhanced threat vectors is reshaping how companies must approach data protection and operational resilience.
Entities: Anthropic · Claude Mythos · Digital Operational Resilience Act · European Union