Financial services in the UAE stopped being the sector with the most AI ambition and became the sector with the most AI paperwork, in a single year.
That is not a complaint. It is the reason this is the easiest sector in which to write the job description, because the regulator has already written most of it.
What changed on 11 February 2026
The Central Bank of the UAE published its Guidance Note on the consumer protection and responsible adoption and use of artificial intelligence and machine learning by licensed financial institutions.
It reaches every licensed financial institution: banks, insurers, exchange houses, finance companies and payment service providers.
The obligations it sets out read like a job description.
A documented AI governance framework, proportionate to the size, nature and complexity of the institution. AI risk fully integrated into risk management rather than parked in a technology committee. Clear designation of roles across risk, compliance, internal audit and IT. A comprehensive inventory of AI models with documentation. Periodic stress testing to find and address bias. Due diligence on third-party vendors and cloud providers. Clear disclosures to consumers, in Arabic and English, about where AI is used. An explanation of how the system works and the logic behind AI-assisted decisions. A route for a consumer to seek clarification, challenge a decision and complain. Human oversight proportionate to risk, described as human in the loop, human on the loop or human out of the loop.
And the line that decides the org chart: the institution retains full responsibility for AI outcomes regardless of outsourcing arrangements.
The note is guidance rather than regulation. In a supervised institution, guidance is what the examination is run against.
The three regimes a Dubai financial group sits in at once
Most financial groups here are not one entity.
An onshore licensed bank or finance company answers to the Central Bank and to the federal Personal Data Protection Law.
A DIFC authorised firm answers to the DFSA, which issued a letter to Senior Executive Officers on 4 June 2026 setting out its expectations for firms using AI, and to DIFC Regulation 10, which requires a register of use cases, impact assessments for high-risk processing, human intervention where outcomes may be unfair or discriminatory, and an Autonomous Systems Officer where processing is high risk.
An ADGM entity answers to the FSRA and the ADGM Data Protection Regulations 2021.
Above all three, the Central Bank, the SCA, the DFSA and the FSRA have jointly issued Guidelines for Financial Institutions Adopting Enabling Technologies, covering APIs, big data analytics and AI, biometrics, cloud and distributed ledger technology.
One group, four regulators, and one inventory that has to satisfy all of them.
Where the models already are
Before any new programme, the register in a UAE financial institution usually turns up the same list.
Credit decisioning and limit setting. Transaction monitoring and sanctions screening, which is almost always a third-party model the institution cannot fully explain. Fraud scoring inside the card processor. Insurance pricing and claims triage. Customer service assistants in two languages. Collections prioritisation. KYC document extraction and liveness checks at onboarding. And, increasingly, a generative assistant inside the productivity suite that has been given access to a document store nobody has audited.
Every one of those sits inside the Central Bank list. Several affect a consumer's money, which is the trigger for explainability and for a challenge route.
The awkward ones are the vendor models. The guidance is explicit that accountability does not transfer. An institution that cannot explain its screening model still owns the outcome.
The Arabic and English requirement
One obligation in the guidance gets missed in every workshop we have seen, because it is not a technology obligation.
Disclosures to consumers must be clear and available in Arabic and English. That covers the notice on the app, the wording in the complaint flow, and the explanation given when a decision goes against a customer.
It means the AI owner has to work with legal, with the contact centre and with whoever owns customer communications, and it means a model change can require a copy change in two languages. This is a workflow problem, and workflow problems are where AI programmes fail.
Why the first appointment is usually part-time
The DFSA's second annual AI survey, published in November 2025, found 52% of DIFC firms using AI, up from 33% in 2024, with 60% planning to expand in 2026. Adoption is moving faster than hiring.
A full-time Chief AI Officer inside a mid-sized UAE financial institution is a senior package, and in year one the work is a framework, an inventory, an assessment cycle and a reporting line rather than a research team.
Two or three days a week from someone who has built a model inventory under a regulator before will produce the artefacts an examination asks for, and produce the evidence needed to size the full-time role afterwards.
One caution. Controlled functions and named regulatory positions carry their own conditions on residency, approval and presence. Confirm the specific requirement with the Central Bank, the DFSA or the FSRA in writing before the seat is scoped. Nothing on this page is legal advice.
Where to go next
For the full stack across every UAE regulator, read the map of UAE AI regulation. For what the seat holds, read the Chief AI Officer job description.
Atlas lists an AI Officer category. If you have run an AI programme inside a regulated institution here, claim a page. If your examination is coming and the inventory does not exist, read the register.
