Launching soon

Atlas opens to its first companies this quarter. Leaders can list now.

List yourself

AI in UAE professional services, where non-adoption fell from 52% to 29%

Law firms, audit practices and tax advisers in the Gulf adopted generative AI faster than their clients did. The exposure is not the technology. It is privilege, independence and what the engagement letter says.

A geometric facade pattern repeating across a wall.
Teddy, rawpixel. Public domain, CC0.

Professional services firms in this market are further into artificial intelligence than most of the clients they advise on it.

Deloitte's regional survey of tax, finance and legal functions across the GCC reported that non-adoption of generative AI fell from 52% in 2024 to 29% in 2025. That is one firm's survey on its own methodology, and the direction it describes matches what any partner here will tell you about their own associates.

The interesting question is not adoption. It is what a firm has already promised its clients about where their information goes.

The exposure is contractual before it is regulatory

There is no UAE regulation governing AI in law, audit, tax or consulting as at August 2026.

What binds a firm is a stack of promises it made earlier.

The engagement letter, which sets out what the firm does with client information and who may access it. In almost every firm here that letter was drafted before generative models and says nothing about them.

Confidentiality obligations, which are professional as well as contractual, and which are breached by disclosure regardless of whether disclosure caused harm.

Privilege, where it applies, which is a fragile status. A firm that cannot describe exactly where a document went is a firm that cannot defend a privilege claim over it.

Auditor independence, which constrains what an audit practice may build for a client it also audits. A model developed for a client's finance function is capable of becoming a self-review problem.

Professional indemnity cover, whose terms and exclusions predate the technology in most policies.

Federal Decree-Law No. 45 of 2021 sits over all of it wherever the client information includes personal data of UAE residents, and DIFC Regulation 10 applies additionally to firms established in the DIFC.

The four use cases that work

Document review and extraction. High volume, structured output, reviewable by a junior. This is where the hours are and where the technology is genuinely competent.

First drafts of standard instruments. Board minutes, standard clauses, engagement letters, routine correspondence. Not the negotiated document.

Retrieval over the firm's own precedent. The highest-value use case in most firms and the least deployed, because it requires the firm's knowledge base to be in order and most are not. It also carries the lowest external risk, because nothing leaves the building.

Time, billing and realisation analysis. Not glamorous. It is the number partners argue about most.

What does not work is advisory judgement. A model that produces a plausible opinion creates a review burden that consumes the saving, and it creates a document that has to be checked line by line before anyone signs it.

The question a firm has to answer before it deploys anything

Where does client information go, and has the client agreed to it.

Three answers are defensible. It stays inside the firm's own tenancy under contracted terms that prohibit training on the data. It goes to a named provider disclosed in the engagement letter with a data processing agreement in place. Or it does not go, and the tool is used only on the firm's own material.

One answer is not defensible, and it is the current situation in a large number of firms here: nobody knows, because associates adopted tools individually and no one asked.

Finding that out is a two-week exercise. It is also, in our experience, the conversation that produces the most surprise in the room.

What clients are starting to ask

Financial services clients ask first, because their own regulator told them to. The Central Bank of the UAE told licensed financial institutions in February 2026 to conduct due diligence on third-party vendors and cloud providers, and stated that accountability for AI outcomes is retained regardless of outsourcing.

A bank that is required to conduct that diligence on its vendors will conduct it on its advisers. The firm that can answer with a written position wins the panel review. The firm that answers with a reassurance does not.

That is the commercial reason to do this work, and it is a better reason than the compliance one.

What the seat holds in a firm

The register of tools in use, including the ones adopted informally. A written position on data handling that maps to the engagement letter, and an updated engagement letter where it does not. An independence check for audit practices. A policy that distinguishes clearly between firm material and client material, because that is the only distinction fee earners will reliably remember. Training by grade, because a partner and a first-year associate need different guidance. And one use case with a number: hours per document reviewed, realisation, or write-offs.

In a firm of 50 to 500 people this is not a full-time role and it should not report into IT. It is a partner-level responsibility, held part-time, supported by someone who has done the data and vendor work before.

Nothing on this page is legal, audit or regulatory advice.

Where to go next

For the client-side view your financial services clients are working from, read AI in UAE banking and financial services. For the full stack of rules, read the map of UAE AI regulation.

If you have built AI governance inside a professional firm here, claim a page. If your engagement letters need updating before your next panel review, read the register.

Questions

How fast are GCC professional firms adopting AI?
Deloitte's regional survey of tax, finance and legal functions in the GCC reported non-adoption of generative AI falling from 52% in 2024 to 29% in 2025. That is a survey of functions across the region on Deloitte's own methodology, not a licensing statistic.
What is the main risk of AI in a law or audit firm?
Client data leaving the firm's control. A model hosted outside the engagement's agreed processing arrangements can breach confidentiality, undermine privilege where it applies, and put the firm outside its own engagement letter, regardless of whether the output was accurate.
Does the client have to be told?
Increasingly the engagement letter answers this, and in most firms here it does not yet mention AI. Firms that update the letter first and deploy second avoid a conversation they otherwise have after the fact.
Where does AI pay in professional services?
Document review and extraction, first-draft production on standard instruments, research retrieval over the firm's own precedent, and time and billing analysis. Advisory judgement is not the use case and the firms selling it as one are creating the review burden that removes the saving.

Sources

  1. Deloitte Middle East, GCC leaders accelerate GenAI adoption in tax, finance and legal functions
  2. DLA Piper, data protection laws of the world, United Arab Emirates
  3. DIFC, Regulation 10 on autonomous and semi-autonomous systems
  4. CBUAE, Guidance Note on the responsible adoption of AI and machine learning by licensed financial institutions, 11 February 2026

The Atlas letter

One leader added to the register, by name. One thing that changed in the rules. One number, with its geography on it.

Once a month. Atlas sends one email to confirm the address before adding it. Nothing arrives until that link is clicked.

Back to writing