Financial organisations do not need private AI for everything. They need it for the workloads where the data is sensitive and the dependency is documented, and those are a subset.
Consider a firm of thirty people. Its realistic AI work is internal document search, questions about its own policies, drafts of client communications, contract analysis, reporting, research and administrative automation. Several of those touch material that should not leave the building casually.
What the regulation actually puts on you
DORA does not forbid cloud AI. It insists on ownership of the risk. Article 28(1)(a) requires that financial entities using ICT services “shall, at all times, remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation and applicable financial services law”.
Article 30(2)(b) then requires the contract to name “the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location”, plus advance notice if the provider intends to change them.
Article 28(1)(b) makes the effort proportionate to “the nature, scale, complexity and importance of ICT-related dependencies”. A small firm is not expected to run a large institution's programme. It is expected to know what it depends on.
Where the local option genuinely helps
For workloads that stay internal, a local system lets staff work with the firm's own material without sending each document to an external inference endpoint. The register row is short, the location does not move with a console setting, and the exit question is simpler because there is no service to exit.
It does not make the firm compliant. Article 28(1)(a) is explicit that the responsibility does not transfer, to a cloud provider or to an appliance supplier.
The first workflow
Start with an internal policy and procedure assistant. The AI reads approved internal documents and answers staff questions about them.
It is a good first choice for four reasons. The documents are already internal. The answers are checkable against a source. Nobody outside the firm is affected by a wrong answer. And the value is immediate, because the questions are asked every week already.
Then expand deliberately: document summarisation, drafting, internal research, and only later anything that touches a customer outcome.
The register entry for an AI workflow should be written before the workflow goes live, not after somebody asks for it.
The question worth asking
Not "can AI replace part of the team?" but: which repetitive knowledge work can AI accelerate without exposing anything that should not be exposed, and can we evidence that answer?
That question has a short list of answers in most small financial firms, and the list is enough to justify a first deployment.
With Bastion
What Bastion changes
Bastion is a private AI system delivered as one sealed appliance that runs inside your building. One monthly fee covers the hardware, the model, the hardened operating system and support, and nothing your team types leaves the building.
For the DORA register, a Bastion node gives a one-line answer to Article 30(2)(b): the service is provided and the data processed at the customer's own premises, with no subcontracted processing location and no outbound connectivity required.
Criticality, recovery objectives, access control and exit strategy stay with the entity. Article 28(1)(a) does not allow a supplier to take them, and we do not claim to.
Questions this article answers
- Where should a small financial firm start with AI?
- With one internal workflow, usually a policy and procedure assistant that answers staff questions from approved internal documents. The documents are already internal, the answers are checkable against a source, and no customer is affected by a wrong answer.
- Does a local AI system make a financial firm DORA compliant?
- No. Article 28(1)(a) states that the entity remains fully responsible at all times. A local system shortens the register row for the processing location; criticality, recovery objectives, access control and exit strategy stay with the entity.
- How much DORA work does a small firm have to do?
- Article 28(1)(b) makes the effort proportionate to the nature, scale, complexity and importance of the ICT dependencies. A small firm is not expected to run a large institution's programme, but it is expected to know what it depends on.
On the record
- 1
- 2
Read next
- DORA and AI: an assistant is an ICT dependency, not an experimentWhat Article 28 puts on the financial entity, what Article 30 requires in the contract, which questions an AI supplier has to answer in writing, and where a local appliance changes the dependency without removing the duty.Read the article
- How to evaluate an AI deployment: the checklist for a 5 to 100 person organisationTen questions about your own work, then four lists to put to any supplier: the technical specification, the data flow, the security architecture and the commercial terms. If a supplier cannot answer them, that is the answer.Read the article