Every company we speak to in Dubai has already had this argument, and most have not finished it.
The argument is usually framed as a turf question. It is not. It is an arithmetic question about what four existing seats already carry, and what happens to a fifth set of duties when you add them to a full desk.
What each seat already owns
The CTO owns the platform: infrastructure, the build, security architecture, the vendor stack, and in a product company the roadmap. AI capability sits naturally here. AI accountability does not, for one reason. The register covers systems the technology function itself bought and deployed. A seat that audits its own purchases is not an audit.
The CIO owns the estate: the applications the business runs on, licensing, integration, service. The CIO is the only person who can tell you every place a copilot has already been switched on, which makes the CIO the best supplier of the register's first draft. Owning the draft is not the same as owning the accountability.
The CDO owns the data: quality, lineage, definitions, access, retention. Every AI failure traces back to data eventually, so the CDO is upstream of everything. The CDO does not own what the business chooses to do with a model once it exists.
The Chief Risk or Compliance Officer owns the regulatory response and, in a licensed institution, the relationship with the regulator. This seat will end up carrying AI risk in the risk register whatever else happens. What it cannot do is run the programme it is meant to challenge.
Four seats, four legitimate claims, and a hole in the middle.
What sits in the hole
Four duties, and they travel together.
A current inventory of every AI system, with data, vendor, owner and oversight mode. The impact assessments for anything that touches a person's money, health, employment or housing. One page to the board, the same page every quarter. And the internal policy plus the training that makes it real.
Split those four across four seats and each becomes the fifth priority on a full desk. The inventory ages, the assessments lapse, the board sees a different deck each time, and the policy stays a memo nobody read.
That is not a hypothetical failure mode. It is the observed one, and it is why the Data Protection Officer became a named seat rather than an extra duty on the general counsel.
Why the UAE forces the question earlier than most markets
Three regulators have now written the bundle down.
DIFC Regulation 10, enacted September 2023 with enforcement running from January 2026, binds the Deployer and the Operator of autonomous and semi-autonomous systems. It requires a record of use cases and processing activities, certification against applicable standards, human intervention where processing may produce unfair or discriminatory impacts, impact assessments for high-risk processing, and an Autonomous Systems Officer where the processing is high risk.
The Central Bank of the UAE, on 11 February 2026, told licensed financial institutions to hold documented AI governance frameworks proportionate to their size, nature and complexity, to maintain a comprehensive inventory of AI models, to stress test for bias, to conduct due diligence on third-party vendors and cloud providers, and to retain full responsibility for AI outcomes regardless of outsourcing. Boards and senior management are named as accountable.
Abu Dhabi's Department of Health went further in its Responsible AI Standard of October 2025, which requires that AI systems have designated owners, that specific individuals or teams are assigned to monitor outputs, review override events and report adverse outcomes to governance bodies, and that every decision and change is logged and traceable to a responsible party.
Read those three together and the common instruction is the same: name someone.
The test that settles the argument in one meeting
Ask the executive team a single question. Who, by name, can produce the current inventory of AI systems in this company by Thursday, and who signs it.
If a name comes back and the person agrees, the argument is over and the seat exists already. If the room looks at each other, the seat does not exist, and the company has been operating on the assumption that it did.
We have watched this question end the turf argument in under ten minutes, because it converts a status conversation into a task with a deadline.
The shape most UAE companies land on
A separate seat, held part-time, reporting to the Chief Executive, with the four duties above and no headcount in year one.
The CTO keeps the platform. The CIO keeps the estate and supplies the register's data. The CDO keeps the data. The risk seat keeps the risk register and receives the assessments. The new seat holds the bundle and the board line, and has a veto on anything that fails an assessment.
IBM's 2026 CEO study found 76% of organisations globally now have a Chief AI Officer, up from 26% a year earlier. It publishes no Gulf cut. What it does say is that the argument above is being had everywhere and is resolving the same way.
When the answer is no new seat
Small company, no regulated entity, no personal data inside any AI system, fewer than six touchpoints in total. Give the register to the CIO, book a review in twelve months, and spend the money on the one use case instead.
Be honest about the count first. Companies that assume they have three touchpoints and then look usually find eleven.
Where to go next
If the seat is agreed and the question is what to write down, read the Chief AI Officer job description. If the question is which rules apply to which entity in your group, read the map of UAE AI regulation.
If you need the person rather than the argument, read the register.
