What the Guidance Note is
The CBUAE AI Guidance Note (issued February 2026) sets out the Central Bank's supervisory expectations for the responsible adoption of artificial intelligence and machine learning across the UAE financial sector. It is issued under the CBUAE's general supervisory powers and does not create a stand-alone AI licence — instead, it clarifies how existing prudential, consumer protection, outsourcing, IT risk, and governance obligations apply when an LFI deploys AI in any part of its value chain.
In practical terms, that means CBUAE examiners can and will cite the Guidance Note in supervisory letters, thematic reviews, and Pillar 2 add-ons. There is no grace period: the Note took effect on issuance and LFIs are expected to demonstrate a credible plan of compliance at their next supervisory engagement.
Who is in scope
The Guidance Note applies to every entity licensed and supervised by the CBUAE. That includes national and foreign banks, Islamic banks, finance companies, insurance and reinsurance undertakings, insurance brokers, exchange houses, stored-value facility providers, retail payment service providers, and any subsidiary or affiliate whose activities are consolidated for supervisory purposes.
Scope is technology-agnostic. It covers traditional machine learning (credit scoring, transaction monitoring, propensity models), generative AI (customer-facing assistants, document drafting, code generation), and vendor-supplied AI features embedded in core banking, KYC, or AML platforms. If a decision, recommendation, or piece of content produced with AI reaches a customer, a control function, or a regulator, it is in scope — even if the model itself sits with a third party.
The five supervisory pillars
The Guidance Note is organised around five pillars that the CBUAE treats as a minimum baseline for a safe and sound AI programme:
1. Governance and accountability. Board ownership, clear individual responsibility, and an AI strategy aligned with the LFI's risk appetite.
2. Model risk management. A complete inventory of AI/ML systems, tiered by materiality, with independent validation, ongoing monitoring, and defined change-control.
3. Data and fairness. Lawful data sourcing, documented lineage, and regular testing for bias and disparate impact on protected groups.
4. Security, resilience, and third-party risk.Security-by-design across the AI lifecycle, including for foundation models and vendor AI features, with resilience testing and exit plans.
5. Consumer protection and transparency. Meaningful disclosure that AI is in use, plain-language explanations of material AI-driven decisions, and human recourse when a customer contests an outcome.
Board and senior management accountability
The single biggest shift in the Guidance Note is that AI is no longer a technology topic — it is a board-level topic. The Board is expected to approve the LFI's AI strategy, its risk appetite for AI, and the policies that operationalise both. Senior Management must appoint a named accountable executive (in most institutions, aligned with the CRO or Head of Compliance) with a documented mandate covering AI risk across the three lines of defence.
The Board must receive at least annual reporting on the AI model inventory, material incidents, bias-testing outcomes, and the status of remediation actions. For systemically important LFIs, the CBUAE expects Board-level reporting more frequently, and it may request minutes of the relevant committee at supervisory review.
Model risk management and inventory
Every LFI must maintain a live inventory of the AI and ML systems it uses — developed in-house, procured, or embedded in vendor products. Each entry should carry, at minimum: the business purpose, data inputs and sources, the model owner, the risk tier, the validation status, and the date of the last independent review.
High-materiality models — those that drive credit, pricing, financial crime, or claims decisions — require independent validation prior to deployment and periodic revalidation thereafter. The CBUAE explicitly references the principles of its existing Model Risk Management expectations and extends them to non-traditional models, including large language models used in customer service and back-office automation.
A model that cannot be located, described, or explained on request during a supervisory visit is, by default, a finding.
Annual fairness and bias testing
For any AI or ML system that affects customer outcomes — credit decisioning, insurance pricing, fraud thresholds, KYC risk scoring, collections prioritisation — the Guidance Note expects at least annual testing for bias and disparate impact. Testing must cover protected characteristics relevant in the UAE context, including gender, nationality, and age, and results must be documented and retained.
Where testing surfaces material disparate impact, the LFI must have a defined remediation path: retraining, feature removal, threshold adjustment, or withdrawal of the model. Failure to test, or failure to act on adverse test results, is a supervisory issue in its own right.
Security-by-design and third-party AI
AI systems must be built and operated to the same security and operational-resilience standards as any other critical banking system. The Guidance Note calls out prompt-injection, data exfiltration through model outputs, and training-data poisoning as specific threats that must be covered in threat modelling and testing regimes.
For third-party AI — foundation models accessed via API, vendor features embedded in core platforms, or outsourced AI services — LFIs remain fully accountable. The CBUAE expects due diligence commensurate with the outsourcing regulation, contractual rights to audit and to information about material model changes, and an exit plan that does not leave the LFI dependent on a single provider.
Consumer protection and explainability
Where AI is used to interact with, or make decisions about, a retail customer, the LFI must (a) disclose that AI is in use in a way the customer can reasonably understand, (b) provide a meaningful explanation of any material adverse decision on request, and (c) offer a human review channel. These map directly onto the Consumer Protection Regulation and are enforceable through the same mechanisms.
"Meaningful" does not require exposing model weights. It does require telling the customer what factors mattered and how they can influence the outcome — for example, what would need to change for a credit application to be approved.
What LFIs must do now
The CBUAE has been explicit in supervisory dialogue that it does not expect perfection in the first cycle — but it does expect evidence of a serious, prioritised programme. Concretely, in the next two supervisory cycles LFIs should be able to show:
A complete AI/ML inventory. Including vendor and embedded AI, tiered by materiality, with named owners.
An AI policy and risk appetite statement approved by the Board. Referenced in the minutes.
Independent validation on high-materiality models.With documented evidence retained for supervisory review.
Bias testing on customer-impacting models.Completed at least once and scheduled annually thereafter, with remediation actions tracked.
Vendor due diligence and contractual rights.For every material third-party AI dependency, aligned with the Outsourcing Regulation.
Customer-facing disclosures and human recourse.Wherever AI materially influences a retail outcome.
Incident logging. AI incidents (hallucinations that reached customers, model outages, bias failures, prompt-injection events) captured through the operational-risk framework.
How it fits with DIFC Reg 10 and the UAE AI Act
The Guidance Note sits alongside — and does not replace — DIFC Data Protection Regulation 10, the DFSA's supervisory expectations for DIFC-authorised firms, and the UAE AI Act's four-tier risk framework. For a group with both an onshore CBUAE-licensed entity and a DIFC or ADGM affiliate, all three regimes apply in parallel.
The good news is that the underlying evidence base is common. A single AI/ML inventory, a single set of model documentation, and a single bias-testing programme can be presented to the CBUAE, mapped to DIFC Regulation 10 processing records, and submitted into the UAE AI Act self-assessment due in September 2026. Institutions that build the evidence layer once — and structure it for reuse — will spend materially less time on the second and third submissions.