AI concentration is an operating problem before it becomes a systemic one
EIOPA's September 16 analysis says AI is moving from experimentation toward established use across financial services. Its 2025 survey covered 347 insurers in 25 EEA countries: 65% reported already using generative AI and another 23% planned to. The operational warning is not simply that many firms use AI. It is that they may depend on the same small group of model, cloud, and infrastructure providers while deploying AI into claims, fraud, customer service, data analysis, and other important services.
EIOPA's recommendation is concrete: make material dependencies visible, test provider or model failures, verify that exit plans work, retain human expertise and fallback capacity, and preserve provider diversity. It also makes an important policy judgment: another broad layer of AI regulation is not the immediate answer. Rigorous implementation of existing DORA and AI Act controls, coordinated monitoring, and targeted supervisory action matter more.
The same concern appears outside EU insurance. The Bank of Canada's 2026 Financial System Survey found almost all respondents were using AI, usually at limited or moderate levels, and planned further use in investment work, operations, back-office processes, financial-crime prevention, and customer service. Respondents pointed to concentration among AI/cloud providers, weak backup plans, talent constraints, and the ability to maintain critical functions during outages or disruption.
DORA supplies a demanding benchmark for in-scope EU financial entities. For ICT services supporting critical or important functions, exit strategies must address provider failure, degraded service, disruption, material risk, and contract termination. Plans must be comprehensive, documented, sufficiently tested, periodically reviewed, and capable of preserving business activity, regulatory compliance, and service continuity.
This page uses that tested-exit discipline as an operating model. It is not legal advice, and not every AI tool or organization falls into the same regulatory scope. Legal and compliance owners must determine which service and entity obligations apply.