In February 2026, the Central Bank of the UAE issued a guidance note that, quietly, marked one of the most consequential regulatory moments for the UAE's financial sector since the digital dirham launch. Generative AI usage among UAE financial institutions had surged 166% between 2024 and 2025, according to Dubai Financial Services Authority survey data. The Central Bank saw the same trajectory and acted. The guidance note on responsible AI sets out five principles — governance and accountability, fairness and non-discrimination, transparency and explainability, effective human oversight, and data management and privacy — and places full responsibility for outcomes, including outcomes produced by third-party AI vendors, squarely on the licensed financial institution.
What this means in practice is more complex than many banks have appreciated. This piece explains why, walks through each principle, and maps the strategic response every UAE financial institution should be building now.
The Context: A 166% Surge, and a Governance Gap
The scale of AI adoption in UAE financial services has moved from experimental to structural in under two years. The 166% surge in GenAI usage captured in DFSA survey data reflects banks deploying large language models for credit memos, fraud detection systems running machine learning on transaction flows, and customer service platforms resolving a significant proportion of queries through AI-driven chat. One Roland Berger analysis places 80% of GCC organisations as having embedded AI into their strategic plans as of early 2026, with 85% anticipating rising AI budgets through the year.
The problem is the execution gap. That same Roland Berger research found only 34% of GCC organisations have an enterprise-wide data foundation adequate to scale AI responsibly. Fewer than 30% have the operating model and formal governance structures to underpin that scaling. In financial services, where algorithmic decisions affect credit access, insurance pricing, fraud flags, and investment recommendations, this gap is not an internal IT challenge. It is a consumer protection risk.
That is precisely the lens through which CBUAE Governor H.E. Khaled Mohamed Balama framed the guidance: "The guidance note aims to establish a clear framework for the responsible use of artificial intelligence and machine learning in the financial sector, in a way that enhances consumer protection, reinforces governance and transparency principles, and emphasises the importance of human oversight and data protection requirements."
The Central Bank is not telling banks to slow down. It is telling them to build properly.
Principle 1: Governance and Accountability
The first principle requires licensed financial institutions to establish documented AI governance frameworks proportionate to their size, nature, and complexity. This is not a checkbox — it means a formal AI policy hierarchy: board-level ownership, clearly assigned second-line risk functions, and a maintained AI model inventory that captures every material AI system in production.
In practice, this catches a problem common across GCC banks. Departments have deployed AI tools — a procurement chatbot here, a fraud scoring model there — without those deployments passing through any formalised governance gate. The CBUAE guidance requires institutions to know what AI they are running, who owns the accountability for each system, and how that accountability integrates into the existing risk management framework.
For banks with complex vendor ecosystems, the accountability extension is particularly significant. If a third-party AI model produces a discriminatory credit outcome, the guidance makes clear that the licensed financial institution bears the regulatory accountability — not the vendor. This changes procurement due diligence and contract structuring materially.
Principle 2: Fairness and Non-Discrimination
AI systems must not produce, as the guidance states, "discriminatory, manipulative or unfair outcomes." Financial institutions are required to conduct periodic stress testing of their AI models specifically to identify biases and unintended consequences.
This principle addresses a well-documented problem in financial AI globally: models trained on historical data reproduce historical inequities. A credit scoring model trained on decades of lending data in a market where certain demographic segments were underserved will, without bias correction, continue to underserve those segments. CBUAE is signalling that it expects institutions to test for this actively, document the findings, and demonstrate corrective action.
For UAE banks, which serve an exceptionally diverse customer population — more than 200 nationalities resident in the country — the fairness requirement is both commercially and ethically critical. A model that systematically disadvantages expatriate workers in specific income brackets or visa categories will not simply be an ethical failure; under the February 2026 guidance, it will be a regulatory one.
Principle 3: Transparency and Explainability
Customers must receive adequate disclosure when AI is used to make or significantly influence decisions about them. CBUAE specifically requires that these disclosures be provided in both Arabic and English, with customer support available to address questions or challenge outcomes.
The explainability standard here is one of the most technically demanding elements of the guidance. Modern AI systems — particularly deep learning models and transformer-based architectures — do not always produce explanations that are meaningful to a non-technical audience or even to the institution's own risk teams. The push toward explainable AI, or XAI, is therefore not merely a product ethics matter; it is a compliance requirement.
Institutions offering AI-driven mortgage approvals, investment suitability assessments, or insurance underwriting will need to build explanation interfaces capable of communicating, in plain language, the factors that contributed to a decision. Where a model cannot produce such an explanation, the CBUAE framework implies that the appropriate disclosure is that AI was involved and a human review pathway is available.
Principle 4: Effective Human Oversight
This is the principle that most directly structures how banks must architect their AI workflows. CBUAE recognises three human oversight models:
- Human in the loop: A person reviews and approves every AI-generated decision before it takes effect.
- Human on the loop: AI executes decisions in real time, but a human monitors continuously and can intervene.
- Human out of the loop: Fully automated — permitted only for low-risk processes, and only with documented justification.
The guidance is explicit that the oversight model must be calibrated to consumer risk. High-impact decisions — credit refusals, suspicious transaction flags, fraud blocks — require higher levels of human involvement than, say, an AI system that categorises transactions for a customer dashboard. Institutions that have allowed AI to operate with insufficient oversight in high-stakes contexts will need to restructure workflows.
This is a significant operational undertaking for institutions with large retail books. A bank processing tens of thousands of credit decisions monthly cannot put every AI-assisted decision through a human reviewer without substantial staffing investment. The practical answer is a tiered approach: AI handles routine, low-risk cases with monitoring; edge cases and high-impact decisions escalate to human review. Building that tiering logic, and demonstrating it to the CBUAE, is the work ahead.
Principle 5: Data Management and Privacy
AI systems are only as reliable as the data on which they run. The fifth principle requires financial institutions to implement rigorous data governance frameworks covering data quality, lineage, and security, consistent with the UAE's Personal Data Protection Law.
The GCC's underlying data infrastructure challenge makes this principle hard. Roland Berger's research found that only 34% of GCC organisations have an enterprise-wide data foundation adequate for AI. For financial institutions, this manifests as siloed data architecture — core banking systems that do not communicate with CRM platforms, transaction data warehouses that are not real-time, and customer identity data fragmented across products and geographies. Responsible AI requires clean, consistent, and governed data. Building that foundation is not a short-term project.
The MENA Regulatory Ripple Effect
The CBUAE guidance does not exist in isolation. DIFC's Innovation Testing Licence provides a sandbox for AI-driven financial services experimentation, and ADGM has maintained parallel frameworks for digital asset AI applications. Across the region, Saudi Arabia's SAMA has signalled attention to AI in consumer finance through its updated supervision frameworks. The February 2026 CBUAE guidance is likely to serve as a reference document for regulatory bodies across the GCC, as it has in previous cycles — the UAE's approach to digital assets licensing, open finance, and now AI governance tends to set the pace for the region.
International context is relevant too. The EU AI Act, now in phased implementation, classifies AI systems used in credit scoring, insurance risk assessment, and employment evaluation as high-risk, requiring mandatory conformity assessments and third-party audits. The CBUAE approach is principles-based and non-binding, offering more flexibility — but also placing full accountability on institutions. As cross-border financial institutions align their global AI governance with EU requirements, those same frameworks will increasingly inform UAE operations, with CBUAE compliance requirements layered on top.
Where Most Institutions Are Falling Short
Based on the Roland Berger GCC AI strategy data and the pattern I observe across financial institutions in this region, there are three consistent gaps:
First, the AI inventory gap. Most banks cannot produce a comprehensive, up-to-date list of every AI or machine learning model they have in production. Models deployed by one business unit are invisible to risk and compliance teams. Without an inventory, governance is impossible.
Second, the vendor accountability gap. Institutions have assumed that because they purchased an AI system from a reputable vendor, the vendor carries the regulatory risk. The CBUAE guidance removes that assumption. Financial institutions need vendor AI due diligence processes that are at least as rigorous as they apply to outsourced operational processes — and most do not have these in place yet.
Third, the data quality gap. The data foundations required to run AI responsibly — clean, consistent, governed, real-time — require investment that many institutions have deferred. The CBUAE guidance creates the regulatory pressure to stop deferring it.
A Five-Step Strategic Response
For chief risk officers, heads of digital, and compliance teams reviewing the February 2026 guidance, the immediate priorities are clear:
1. Conduct an AI inventory audit. Map every AI and machine learning model in production, including vendor-supplied systems, and assign clear accountability for each. This is the foundation without which no other element of the framework can be built.
2. Classify models by consumer risk. Using the CBUAE's own language, categorise each model by its potential consumer impact and assign the appropriate human oversight tier. High-impact decisions need documented escalation pathways.
3. Establish a bias testing protocol. For every model affecting customer-facing decisions, schedule periodic bias tests and document the results. Where biases are identified, record the remediation steps taken.
4. Redesign customer disclosure frameworks. Review every AI-assisted touchpoint from a customer's perspective and ensure that disclosures are clear, bilingual, and accompanied by a human review pathway for challenged decisions.
5. Revise vendor contracts. Insert AI accountability clauses that clarify the institution retains full regulatory responsibility, while creating contractual mechanisms for vendors to support bias audits, model documentation, and incident response.
Closing: The Governance Foundation Is the Infrastructure
There is a pattern I have observed in every major technology transition in financial services, from the shift to mobile banking through to the digital asset licensing cycle in the UAE: institutions that build the governance architecture early end up with a competitive advantage, not just a compliance tick. Those that delay pay three times — once to rush-build governance under regulatory pressure, once in the reputational costs of any high-profile failure, and once in the commercial cost of deploying less-capable AI because they lack the data and oversight infrastructure to deploy it responsibly.
The CBUAE's February 2026 guidance is non-binding today. The trajectory of financial services AI adoption in the UAE — 166% GenAI growth in a single year — means the regulatory framework will tighten. Institutions that treat the five principles as a voluntary framework to examine at leisure are misreading the signal. Those that build the AI governance stack now will find, when the binding regulations arrive, that they are already compliant. More importantly, they will be deploying AI that actually works: better data, cleaner models, accountable outcomes.
The governance foundation is not a constraint on AI capability in financial services. It is the infrastructure that makes advanced AI trustworthy enough to deploy at scale.
The time to build it is now.
