United Arab Emirates / Banking and financial services
What AI rules apply to banks in the UAE?
The CBUAE Guidance Note is voluntary on its face and examinable in practice.
The Central Bank of the UAE issued AI guidance for licensed financial institutions on 11 February 2026. It is framed as flexible principles, but it routes almost every expectation into instruments that already bind: the Model Management Standards, the Consumer Protection Regulation, and the Outsourcing Regulation. The practical question is not whether it is binding. It is what evidence you can produce when an examiner asks.
Primary source
Every requirement on this page was read in the issuing authority's own text.
Scope
Who this applies to
- All licensed financial institutions under CBUAE jurisdiction, including insurance providers
- Banks, finance companies, exchange houses and payment service providers
- In-house developed AI and AI procured from third parties, on the same standard
- Generative AI and large language models, named explicitly in the definitions
What pulls a system into scope
- Any AI or ML system deployed by a licensed financial institution that has bearing on consumers
- High-impact decisions: any determination using AI that materially affects a customer's access to financial products or services, with loan applications and insurance claims given as the examples
- Customer-facing generative AI, including chatbots, which fall under the same inventory, testing and oversight expectations as a credit model
- AI supplied or hosted by a third party, which carries the same fairness, explainability and robustness standard as in-house models
Obligations
What is actually required
Documented AI governance framework
Guidance Note §2(a)Proportionate to the size, nature and complexity of operations, read alongside all relevant CBUAE regulations and standards. Governance, usage and validation must follow the principles of the Model Management Standards.
Board and senior management accountability
Guidance Note §2(b)Accountable for AI systems and outcomes, model selection, deployment, resourcing and ongoing monitoring. The text goes further than accountability language usually does: institutions should not employ AI models that they have no control over.
Inventory of all AI models and systems
Guidance Note §2(f)Covering everything developed or deployed, following the Model Management Standards and Model Management Guidance (2022). Minimum metadata: model name, purpose, risk rating.
Bias testing on a defined cadence
Guidance Note §3(c)Periodic testing once a year, and again each time a model is upgraded, materially changed, or a new one is introduced, to identify and remediate embedded bias or discriminatory outcomes.
Arabic and English disclosure
Guidance Note §4(b)Plain-language, accurate disclosures in both Arabic and English, with telephone support in all major languages of the UAE, and measures to check that disclosures are actually understandable.
Human oversight matched to consumer risk
Guidance Note §7(a)Three named modes: human-in-the-loop, human-on-the-loop, and human-out-of-the-loop. The last is reserved for low-risk, non-material processes with appropriate controls.
Consumer right to human review
Guidance Note §7(c)Consumers can request human review or explanation of an AI-generated decision, with alternative arrangements where a customer does not wish to be subject to one. Complaints and redress run through Article 8 of the Consumer Protection Regulation.
Demonstrable kill switch
Guidance Note §6(f)The institution must retain at all times the clear and immediate ability, through human intervention, to cease use of any deployed AI system. An examiner can test this with one question: who switches it off, and how fast.
Third-party AI due diligence and audit rights
Guidance Note §9(a)-(b)Due diligence on provider reputation, governance, security and data protection. Contracts must secure access to information and audit rights. Selection of each provider must be documented and justified, with annual cybersecurity reviews by independent qualified third parties and pre-deployment testing.
Concentration risk across AI providers
Guidance Note §9(d)Institutions should use a range of AI providers where feasible, to avoid over-reliance on any single system or vendor.
Per-system risk rating
Guidance Note §8(d)A documented process to rate the risk of each AI system deployed, informed by data quality and sensitivity, the capability of the system, controls in place, impact, and dependence on third parties.
Integration with enterprise risk
Guidance Note §8(a), §2(e)AI risk assessment must inform and be informed by the enterprise-wide risk framework rather than operating in isolation. Control functions, including compliance and internal audit, must be able to understand and challenge AI-driven processes.
If you already built for the EU AI Act
An institution that has built to the EU AI Act for Annex III high-risk systems: risk management under Article 9, data governance under Article 10, technical documentation under Article 11, human oversight under Article 14, and deployer duties under Article 26.
| Dimension | EU AI Act | UAE | Delta |
|---|---|---|---|
| Risk tiers and who assigns them | A closed statutory list. Annex III names the high-risk categories; creditworthiness assessment of natural persons is one of them. Everything outside the list carries no high-risk obligations. | No statutory list. The institution rates the risk of each AI system itself under §8(d), and the inventory duty under §2(f) covers all AI models and systems regardless of rating. | Extends EU work |
| Regulator sign-off before launch | No regulator approval before launch. Self-assessment through internal control for Annex III points 2 through 8, with biometric systems under point 1 requiring a notified body where harmonized standards are not applied. | Neither regime requires it. The Guidance Note contains no approval gate: nothing requires the CBUAE to see or approve an AI system before it is deployed, or before a vendor contract is signed. This dimension has been assessed and found empty on both sides. | Does not map |
| Internal register of AI systems | Technical documentation and quality management obligations attach per high-risk system. There is no enterprise-wide inventory duty covering all AI. | An inventory of every AI model, system or technology developed or deployed, with name, purpose and risk rating as minimum metadata. | No EU equivalent |
| Bias testing | Article 10 requires examination for bias in data governance for high-risk systems, without prescribing an annual cycle. | Explicit cadence: once a year, and again on any upgrade, material change, or new model. | Extends EU work |
| Recurring disclosure to the supervisor | Article 49 registration attaches to providers of Annex III systems and to public-authority deployers, not to private-sector deployers generally. No recurring filing. | Neither regime requires it. The inventory duty under §2(f) is internal, and the Guidance Note does not require it to be filed with the CBUAE on any cycle. This dimension has been assessed and found empty on both sides. | Does not map |
| Human oversight | Article 14 requires oversight measures for high-risk systems, specified by the provider and implemented by the deployer. | Three named operating modes, applied across consumer-facing AI, with the fully autonomous mode confined to low-risk non-material processes. Substantively close to Article 14, applied to a wider set of systems. | Already covered by EU work |
| Language of disclosure | No Arabic-language obligation. Article 50 transparency duties, which the Digital Omnibus left on their original timeline, are language-neutral. | Plain-language, accurate disclosures in Arabic and English, with telephone support in the major languages of the UAE, and a duty to check understandability. | No EU equivalent |
| Vendor diligence and contracts | Obligations split along the provider and deployer roles under Articles 25 and 26; assurance is largely documentary. | Annual cybersecurity reviews of procured AI by independent qualified third parties, documented procurement justification, contractual audit and information rights, and an explicit expectation to avoid single-vendor concentration. | No EU equivalent |
| When it bites | High-risk obligations for standalone Annex III systems apply from 2 December 2027 after the Digital Omnibus deferral; Annex I embedded systems from 2 August 2028. | Guidance is live now and shapes what examiners ask in the current supervision cycle. There is no transition period because there is no new binding rule to transition to. |
Instruments
What the requirements rest on
Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E.
Central Bank of the UAE
Flexible principles by its own terms. Its force comes from what it points to.
CBUAE Rulebook, read in full. The Rulebook states 'Issued on 11/2/2026'; the CBUAE press announcement followed on 23 February 2026, which is the date most secondary coverage reports.
Model Management Standards and Model Management Guidance (2022)
Central Bank of the UAE
The load-bearing instrument. AI and ML models sit inside the model risk framework examiners already test against, which closes off the argument that a chatbot or a credit model is something separate from the model inventory.
Cited throughout the Guidance Note as the standard AI governance, usage and validation must follow.
Consumer Protection Regulation, Article 8
Central Bank of the UAE
An AI decision a customer cannot challenge becomes legible as a conduct failure under an existing regime with enforcement history, not a gap in a future one.
Cited at Guidance Note §7(c) as the channel for complaints and redress.
Outsourcing Regulation for Banks
Central Bank of the UAE
Third-party AI is treated as an extension of outsourcing obligations institutions already carry.
Cited at Guidance Note §9(a) alongside MMS §4.7.
UAE Personal Data Protection Law and Information Assurance Regulation
UAE federal
Data provenance, quality and in-country retention rules apply to training and inference data.
Cited at Guidance Note §5(b) as governing data used in AI and ML models.
UAE Charter for the Development and Use of AI (July 2024)
UAE federal
Context rather than obligation, but it is the frame the CBUAE expects institutions to read the Guidance Note inside.
Named in the Guidance Note preamble as a document to be read in conjunction. Publication date as stated in the Guidance Note; the Charter text itself was not independently reviewed for this entry.
Enforcement
How this is actually supervised
- Supervisor
- Central Bank of the UAE, through its Supervision and Consumer Protection functions
- Mechanism
- Periodic examination. Because the Guidance Note routes into the Model Management Standards, the Consumer Protection Regulation and the Outsourcing Regulation, a shortfall surfaces as a finding under those binding instruments rather than under the Guidance Note itself.
- Observed to date
- No AI-specific enforcement action identified as of the verification date. The signal to watch is whether AI findings begin appearing in examination reports, which would confirm the guidance has entered supervisory practice.
Action
What to do Monday morning
- 1Pull the model inventory and check whether customer-facing generative AI is on it. In most institutions the chatbot deployed in 2025 was never entered as a model, and §2(f) does not distinguish.
- 2Identify every high-impact decision as the Guidance Note defines it: anything materially affecting access to a product or service. Loan origination and insurance claims are the named examples; the list is usually longer than the first draft.
- 3Answer the kill-switch question in writing for each deployed system. Who has authority to stop it, through what mechanism, and how long does it take.
- 4Audit the Arabic disclosure gap. Model documentation, vendor materials and governance frameworks are almost always English-only, and producing accurate Arabic AI disclosures is a governance task rather than a translation task.
- 5Check AI vendor contracts for audit and information rights, and find out whether the annual independent cybersecurity review of procured AI has ever been commissioned.
This page tells you what applies. It cannot tell you what you are running.
The Diagnostic maps your actual AI systems against these requirements and returns the gaps in priority order, with the evidence an examiner would ask for. Built once against the most demanding specification you face, it answers the questions in every other jurisdiction you operate in.
Request the DiagnosticWatch list
What would change this verdict
- Whether AI-related findings appear in CBUAE examination reports over the next twelve months, which is the test of whether the guidance has entered supervisory practice.
- Whether the CBUAE converts any part of the Guidance Note into a binding standard, or continues to rely on the instruments it cross-references.
- How examiners will treat institutions that rate their own AI systems generously under §8(d), given there is no statutory risk list to check the rating against.
Questions
Common questions
Is the CBUAE AI Guidance Note binding?
Not on its face. It describes itself as flexible principles rather than a regulation. But it routes its expectations into the Model Management Standards, the Consumer Protection Regulation and the Outsourcing Regulation, all of which bind the institutions they cover. A shortfall becomes a finding under those instruments.
Does it apply to ChatGPT-style chatbots?
Yes. The definitions cover generative AI and large language models by name, so a customer-facing chatbot falls under the same inventory, risk-rating, testing and oversight expectations as a credit model.
If we already comply with the EU AI Act, are we covered in the UAE?
Mostly, with three gaps. EU work does not produce an enterprise-wide inventory of all AI systems, Arabic-language consumer disclosure, or the annual independent cybersecurity review of procured AI. Human oversight and risk management transfer well.
When did the CBUAE Guidance Note take effect?
The CBUAE Rulebook records it as issued on 11 February 2026. The Central Bank announced it publicly on 23 February 2026, which is the date most secondary coverage cites. It carries no transition period, because it introduces no new binding rule.
Verification notes
- The Guidance Note was read in full on the CBUAE Rulebook. The instruments it cross-references were confirmed as cited within that text, but their own provisions were not separately reviewed for this entry: the Model Management Standards, Consumer Protection Regulation Article 8 and the Outsourcing Regulation.
- The characterization of examination practice is an inference from how principles-based supervision generally operates, not a statement of CBUAE internal procedure.
Last verified August 31, 2026 by Rabii Agoujgal.
This entry is provided for informational purposes and does not constitute legal advice. Applicability of any regulation, guidance, or standard discussed depends on the facts, deployment context, and relevant jurisdiction. Regulatory positions change; check the verification date before relying on this page.