Financial regulation has always assumed its subjects were financial institutions — banks, insurers, payment providers, entities that hold a banking licence or sit under a regulator's existing remit. In November 2025, that assumption changed. The European Supervisory Authorities designated nineteen companies as 'critical' ICT third-party providers under DORA, a list that includes Amazon, Google, and IBM — none of which are financial institutions in any conventional sense, and all of which are now subject to direct oversight from EU financial regulators.
The logic behind this is systemic risk, not sectoral tidiness. A meaningful share of the EU's financial sector now runs its core operations — data storage, computing infrastructure, increasingly AI workloads — on a handful of hyperscale cloud platforms. If one of those platforms suffers a major outage or breach, the disruption does not stay contained to one bank's IT department; it potentially cascades across dozens of institutions that share the same underlying infrastructure. DORA's answer is to stop treating that infrastructure as an unregulated dependency and start regulating it directly, alongside the institutions that rely on it.
For the designated providers, this means a genuinely new form of exposure: EU financial supervisors can request security measures, remediation, and — for the first time — impose penalties directly on the technology company, not just on the bank that uses its services. For every other financial institution, the designation is also useful diagnostic information. If your cloud provider is on that list, you now know exactly which regulator is watching them, and can factor that oversight into your own third-party risk assessment rather than treating vendor resilience as something you have to verify entirely on your own.
It is a template worth watching beyond financial services. As critical infrastructure sectors realise how concentrated their cloud dependencies actually are, the DORA model — regulate the infrastructure provider directly, not just the regulated entity that depends on it — is a plausible direction for sector-specific EU cyber regulation more broadly.