← Back to Perspectives

The Central Bank of the UAE has published a Guidance Note on the responsible adoption and use of AI and machine learning by every licensed financial institution in the country. It now sits in the official CBUAE Rulebook - not a discussion paper, not a consultation. A supervisory expectation.

Most of the coverage treated this as a banking story. It isn't. It's a template. And in a region where regulators watch each other closely, we expect insurance authorities, telecoms regulators, and free zone supervisors across the GCC to reach for the same structure within eighteen months.


Why this note is different from what came before

The UAE already has an ethical AI audit regime for public sector procurement, and a broader compliance framework that applies across sectors. Both are worth reading. Neither is what this is.

A central bank guidance note operates through the supervisory relationship, not a tender document. It doesn't wait for you to bid on a government contract. It applies continuously, to every model you already have in production, and it is enforced by the same body that sets your capital requirements and reviews your risk appetite. That changes the incentives entirely.

What it actually asks for

None of this is exotic. It is, in substance, what mature model risk functions in London and Singapore have run for a decade. What's new is that it is now explicit, written down, and specific to the Gulf's supervisory context.


Who this actually catches

Licensed financial institutions, obviously. But also every consultancy, systems integrator, and AI vendor selling into them. If you are delivering a fraud model, a credit scoring engine, or a customer-facing chatbot with any transactional authority into a UAE bank, your delivery artefacts now need to answer questions your statement of work probably didn't anticipate: who validated this model, what's the monitoring cadence, and what happens when it drifts.

We have seen this pattern before, just not this explicit. A regional bank we worked with had already built a capable fraud detection model. What it hadn't built was a documented ownership structure or a monitoring dashboard anyone outside the data science team could read. The model was good. The governance evidence didn't exist. Under this note, that gap is now a supervisory finding waiting to happen, not a nice-to-have.


What to do before your next examination

  1. Inventory every AI/ML model currently in production, including the ones bolted onto a vendor platform you didn't build
  2. Assign a named owner and a documented validation record to each one
  3. Build the monitoring evidence now, before a supervisor asks for it retrospectively
  4. Extend your third-party risk assessment template to cover AI-specific vendor questions

The bottom line

This is not a banking compliance footnote. It is the clearest signal yet of how GCC regulators intend to govern AI in systemically important sectors: through the supervisor, continuously, with board accountability attached. Firms delivering AI programmes into regulated Gulf industries should assume this pattern arrives in their sector next, and start building the governance evidence before it's mandatory rather than after.