AI in UAE Financial Services: What Regulators Expect

The main AI-specific documents for UAE financial firms are regulatory guidance rather than binding rules, but they set clear expectations on AI governance, transparency and accountability. Here is what applies to your licence, and what to have in place.

9+ Years of Compliance Expertise
Saudi Arabia
Oman
Bahrain
End-to-End Execution
Europe
UAE financial regulators have set out their AI expectations through guidance. In November 2021 the Central Bank (CBUAE), the Securities and Commodities Authority (SCA, now the Capital Market Authority), the DFSA and the FSRA jointly issued the Guidelines for Financial Institutions Adopting Enabling Technologies. For AI, they cover governance, accountability of the board and senior management, reliable and explainable models, ongoing monitoring, fair outcomes and transparency to customers. They apply alongside binding regulations, which take precedence. On 11 February 2026 the CBUAE added guidance on consumer protection and the responsible adoption of AI by licensed financial institutions. Binding rules still apply to AI use: data protection law (PDPL, DIFC and ADGM regimes), each regulator's own requirements such as those on outsourcing, and, for virtual asset firms in Dubai, VARA's Technology and Information Rulebook, which includes a binding Algorithm Governance requirement.
Why This Matters

Guidance is not optional in practice. The CBUAE's 2026 note expects a documented AI governance framework proportionate to the firm's size and complexity, an inventory of AI models, and accountability that stays with the institution even when AI is outsourced.

Customer transparency is a core expectation, including clear disclosures in Arabic and English, an explanation of the logic behind AI-assisted decisions, and a way for customers to challenge them.
Adoption is moving fast: a DFSA survey found generative AI use among financial institutions rose 166% between 2024 and 2025.
Which regulator applies depends on your licence and location: the CBUAE and CMA on the mainland, the DFSA in the DIFC, the FSRA in ADGM, and VARA for virtual asset firms in Dubai outside the DIFC.
Firms serving EU clients may also fall under the EU AI Act, which is binding and carries its own penalties.
What's Included

Mapping of which regulators and guidance apply to your licence or licences

Inventory and classification of AI use cases: credit, AML and KYC, advisory, trading, customer service
Documented AI governance framework: ownership, approval, monitoring and escalation, with clear roles across risk, compliance, audit and IT
Policies on human oversight, fairness review and incident handling
Customer-facing disclosures and a process for questions, challenges and redress
Due diligence documentation for AI vendors and outsourced AI services
For virtual asset firms: Algorithm Governance policies, documentation and staff-competency evidence under VARA's Technology and Information Rulebook

Frequently Asked Questions

Related

Not sure how AI governance expectations apply to your licence?
By submitting this form, I acknowledge that I have read and agree to the Privacy Policy, and I consent to the processing of my personal data.


Please note: We do not provide any personalized investment advice, token selection guidance, or transaction recommendations. AMLzone is a compliance consultancy and project management services provider, not a Virtual Asset Advisor.