At a Glance
AI is becoming an integral part of operations across UAE financial services. Regulatory attention is now shifting towards how firms govern AI, with increasing expectations around accountability, transparency, human oversight, and risk management.
AI has rapidly shifted from experimentation to day-to-day operations across the UAE financial services sector. Just as quickly, the regulatory conversation is changing. Rather than focusing solely on whether firms should use AI, regulators are increasingly focused on whether firms can demonstrate that it is governed responsibly.
Asset managers, brokers, advisers, and fund managers are increasingly using AI to support research, client onboarding, compliance monitoring, and operational efficiency. Notably, UAE regulators are not trying to slow adoption. Instead, the message emerging across DIFC, ADGM, and the wider UAE market is clear: firms may use AI extensively, provided accountability, governance, transparency, and oversight remain firmly in human hands.
This is an important distinction between AI adoption and governance. Regulatory focus is shifting from whether firms use AI to how they govern it. In practice, AI governance refers to the policies, controls, oversight arrangements, and accountability mechanisms that help ensure AI systems are used safely, transparently, and in line with regulatory expectations.
UAE Regulators Are Clarifying AI Governance Expectations
In February 2026, the UAE Central Bank issued a Guidance Note on the Responsible Adoption and Use of AI and Machine Learning by Licensed Financial Institutions. While firms in DIFC and ADGM are regulated by the DFSA or the FSRA rather than the Central Bank, the Note provided a strong indication of how supervisory thinking is evolving across the UAE financial sector.
The guidance focuses on:
- Board and senior management accountability
- Fair and non-discriminatory outcomes
- Transparency and explainability
- Human review and intervention capabilities
- Data governance and privacy controls
- Clear governance frameworks
Regulators no longer view AI as simply a technology matter. It is increasingly being treated as a governance, conduct, risk management, and customer protection concern. For regulated firms, this means AI is becoming a board-level priority rather than solely an IT initiative. Firms should be prepared to demonstrate not only where AI is used, but also how its risks are identified, managed, and overseen.
AI Adoption Is Accelerating Across DIFC Firms
The DFSA’s 2025 Artificial Intelligence Survey highlights the pace of change: 52% of DFSA-authorised firms are already using AI, up from 33% in the previous year. Generative AI adoption rose by approximately 166%, with most firms expecting further growth over the next one to three years. However, governance maturity is not always keeping pace. More than one in five firms reported lacking clear accountability or oversight arrangements for AI.
For compliance leaders, this is an important signal. As adoption grows, firms should expect greater scrutiny of how AI systems are governed, monitored, and controlled.
As AI adoption accelerates, governance expectations are likely to become a greater focus during supervisory engagement. Firms that cannot clearly evidence accountability, oversight, and documented controls may find themselves under increasing regulatory scrutiny.
AI Governance Is Becoming a Regulatory Priority
UAE regulators are focusing on principles rather than prescriptive AI rules. Across regulatory communications, the same themes continue to emerge:
- Accountability
- Explainability
- Bias management
- Data quality
- Human oversight
- Ethical use of AI
- Consumer and investor protection
This is consistent with approaches in other leading financial centres, including the UK, Singapore, and Hong Kong.
For regulated firms, the more relevant question is no longer, “Can we use AI?” It is, “Can we demonstrate that our use of AI is effectively governed?”
The ability to answer that question confidently is likely to become an important differentiator as regulatory expectations mature across the UAE.
ADGM Continues to Support Responsible AI Innovation
ADGM has long championed financial innovation. Through initiatives such as the FSRA’s Open Regulation programme, it has encouraged the development of AI-enabled regulatory technology and automated compliance solutions.
Regulators do not view AI solely as a source of risk. They also recognise its potential to strengthen compliance, monitoring, and regulatory understanding. The challenge is to harness these benefits while ensuring decisions remain subject to human judgement and oversight. Firms that strike this balance are likely to be better placed to innovate while maintaining regulatory confidence and protecting clients.
Where AI Creates the Greatest Compliance Risks
While the opportunities are significant, firms should pay particular attention to several higher-risk use cases:
1. Asset and Fund Managers
Many firms are using AI to:
- Screen investment opportunities
- Generate research
- Support portfolio construction
- Draft market commentary
Key governance questions include whether outputs are validated, whether decisions can be explained, and whether effective oversight exists. Generative AI also introduces risks in investor communications. Inaccurate statements, hallucinated content, or unsupported performance claims can create regulatory exposure.
2. Advisers and Arrangers
AI is being used to support client recommendations, suitability assessments, document reviews, and onboarding processes. Where AI contributes to client-facing decisions, firms should ensure outcomes remain accurate, appropriately documented, and subject to meaningful human review.
3. Brokers
Brokers are exploring AI across trade surveillance, market abuse detection, communications monitoring, and algorithmic trading support. The question remains: who is accountable when an AI-generated outcome is incorrect? Regulators consistently favour the same answer: the firm, its senior management, and ultimately its governing body.
Firms do not need to wait for new AI-specific rules before strengthening their governance. Many of the controls regulators expect already align with existing compliance and risk management frameworks.
Practical Steps Firms Should Take Now
Rather than waiting for further regulatory developments, firms should consider whether they have:
- An AI inventory and usage policy
- Clear ownership and accountability
- AI risk assessments and vendor due diligence
- Independent testing and validation processes
- Defined human oversight requirements
- Staff training on AI-related risks
- Record-keeping controls for AI-generated outputs
- Periodic governance reviews
These measures can help firms demonstrate that innovation is being supported by appropriate governance.
Strong AI Governance Creates a Competitive Advantage
The UAE regulatory landscape is clearly moving towards responsible adoption rather than restrictive regulation. Regulators recognise the efficiency and innovation benefits AI can deliver across financial services.
At the same time, they are making it clear that governance, transparency, accountability, and customer protection must evolve alongside adoption. Firms that establish robust governance frameworks now will be better positioned as expectations continue to mature across DIFC, ADGM, and the wider UAE market.
Although the UAE has adopted a principles-based approach to AI regulation, expectations around AI governance are likely to continue evolving as adoption becomes more widespread across financial services. An experienced third-party compliance partner can provide valuable support by helping firms build practical governance frameworks, challenge assumptions, and identify potential gaps before they become regulatory issues.
Build AI Governance That Meets UAE Regulatory Expectations
ACA supports regulated firms across DIFC and ADGM with outsourced compliance, governance, and risk management solutions.
Our dedicated UAE compliance advisory team, ACA Effecta, provides experienced outsourced compliance officers and broader governance support to help firms establish effective oversight arrangements.
ACA Effecta works alongside the ACA Aponix cybersecurity and risk specialists to assist firms with AI governance framework development, AI risk assessments, policy design, vendor due diligence, and responsible AI adoption. Together, these services help firms strengthen governance while enabling innovation with confidence.
If your organisation is exploring or expanding the use of AI, now is the time to ensure your governance framework keeps pace with evolving regulatory expectations.
Speak with one of our governance specialists to assess whether your AI framework is ready for evolving regulatory expectations.
AI Governance FAQs for UAE-Regulated Firms
Which firms should consider establishing an AI governance framework?
Any regulated firm using AI in areas such as research, client onboarding, compliance monitoring, suitability assessments, portfolio construction, communications monitoring or operational processes should consider establishing a formal governance framework. The framework should reflect how extensively AI is used and the level of risk associated with each use case.
How can a firm identify where AI is being used across its business?
Firms can begin by creating an AI inventory that records each tool or system, its purpose, the business owner, the data it uses, whether it affects clients or regulated activities, and the level of human oversight applied. The inventory should include both internally developed systems and third-party tools.
What should firms consider when using third-party AI providers?
Firms should assess the provider’s data handling, security, governance, testing and monitoring arrangements. They should also understand how the tool produces outputs, what limitations apply, how incidents are managed and whether the firm can maintain effective oversight throughout the relationship.
What does meaningful human oversight of AI involve?
Meaningful human oversight requires more than formally assigning responsibility. Relevant employees should understand the system’s purpose and limitations, be able to review and challenge its outputs, and have the authority to intervene where an outcome appears inaccurate, biased or inappropriate.
How should firms manage AI-generated content used in client or investor communications?
AI-generated content should be reviewed before publication to ensure it remains accurate and complies with all applicable legal, regulatory and fiduciary obligations, together with the firm’s internal approval requirements. Firms should also maintain appropriate approval and record-keeping processes, particularly where content includes investment commentary, client recommendations or performance-related information.
What evidence should firms maintain to demonstrate effective AI governance?
Relevant evidence may include an AI inventory, approved policies, clearly documented ownership of AI systems and governance responsibilities, risk assessments, vendor due diligence, testing records, approval logs, staff training records, records of human review and periodic governance reports. Documentation should show how risks are identified, monitored and escalated.
How often should an AI governance framework be reviewed?
The AI governance framework should be reviewed periodically to ensure it remains appropriate for the firm’s business, regulatory obligations and approach to AI governance. Firms should also update supporting documentation, such as AI inventories, risk assessments, policies and controls, whenever new AI tools are introduced, existing use cases change, significant incidents occur or regulatory expectations evolve.
Skip to content