White paper WP-020
DORA-Compliant AI Governance with Zero-Knowledge Audit Records
Five overlapping EU regimes, one proof pipeline your ICT auditor can actually verify.
At a glance
- Paper
- WP-020
- Topic
- DORA-Compliant AI Governance with Zero-Knowledge Audit Records
- Format
- PDF + web summary
- Signatures
- ML-DSA-65 post-quantum (NIST FIPS 204)
- Sandbox
- Reproducible at affix-io.com/sandbox
- Company
- AffixIO, Wales, UK
DORA-Compliant AI Governance with Zero-Knowledge Audit Records is an AffixIO technical paper. Five overlapping EU regimes, one proof pipeline your ICT auditor can actually verify.
Financial firms now run AI inside DORA's ICT perimeter, MiCA's crypto rules, and the EU AI Act at once. Mutable logs satisfy none of them under scrutiny. We show how zero-knowledge proof records give BaFin-ready audit trails without storing customer prompts or model outputs.
Summary
Financial firms now run AI inside DORA's ICT perimeter, MiCA's crypto rules, and the EU AI Act at once. Mutable logs satisfy none of them under scrutiny. We show how zero-knowledge proof records give BaFin-ready audit trails without storing customer prompts or model outputs.
Download the full PDF for technical detail, diagrams, and reproduction steps. Public sandbox: affix-io.com/sandbox.
Related reading
Frequently asked questions
Does DORA apply to LLMs?
BaFin's January 2026 guidance treats generative AI and LLM deployments as in-scope ICT systems requiring governance and audit evidence.
Can ZK proofs replace traditional ICT logs?
They complement logs by providing tamper-evident, independently verifiable records of AI policy evaluation without retaining sensitive transaction data.
How does this relate to MiCA?
Crypto-asset service providers using AI for risk scoring or customer communication need the same verifiable governance artefacts as traditional banks.