Analysis

DFSA AI Supervision 2026: What the Regulator Is Looking For

8 min read Published March 2026

The DFSA's 2026 supervisory posture

The Dubai Financial Services Authority's public posture on AI is consistent with the approach it has taken to cloud, outsourcing, and cyber over the last decade: technology-neutral, principles-based, and enforced through existing rules rather than a bespoke rulebook. The DFSA's AI research paper and subsequent Dear SEO commentary make the direction clear — firms are expected to identify where AI is used, to govern it in proportion to the risk it creates, and to evidence that governance on request.

What is new in 2026 is intensity. AI is now a standing topic in routine risk assessments for authorised firms with meaningful AI deployment, and it appears in thematic reviews across banking, asset management, and insurance intermediation.

Where the DFSA's authority comes from

The DFSA supervises AI through the Rulebook it already operates. The relevant anchors are:

GEN — Principles for Authorised Firms. Principle 2 (due skill, care and diligence), Principle 3 (management, systems and controls), Principle 4 (resources) and Principle 6 (customer interests) all bite on AI-driven activity.

GEN 5 — Systems and controls, including outsourcing.Vendor AI, foundation-model access, and embedded AI in core platforms are outsourcing arrangements and must be governed as such.

COB — Conduct of Business. Communications with clients, suitability, and complaint handling apply to AI-generated content and decisions in the same way as to human-generated ones.

DIFC Data Protection Regulation 10. Regulation 10 creates specific processing obligations for AI systems handling personal data. The Commissioner of Data Protection and the DFSA coordinate on findings that cross both regimes.

The DFSA does not need a new AI rule to act. It needs to show that an AI use case fell short of one of the above — and it can request the evidence to make that case at any time under GEN 5.3.

What examiners ask for first

Across recent supervisory engagements, DFSA examiners open with a tightly-scoped set of requests. Firms should assume these are coming and pre-package the answers:

1. A current AI/ML inventory. Every model the firm develops, procures, or uses via a vendor. Business purpose, data inputs, owner, risk tier, validation status, last review date. Vendor and embedded AI are in scope — "we don't build models" is not an answer.

2. The governance paper. An AI policy or standard approved by the Board or the SEO, with a documented risk appetite, named accountable executive, and defined escalation paths.

3. The list of material third-party AI dependencies.With outsourcing risk assessments, contractual rights to audit and to be notified of material model changes, and a viable exit plan.

4. Evidence of human oversight. For any AI system that materially affects a client outcome — suitability, KYC risk scoring, transaction monitoring alerts, marketing personalisation at scale — how a qualified person reviews or can override the output, and the audit trail proving it happens.

5. Incident and complaint records. AI-related incidents captured through the firm's operational-risk framework, and complaints where an AI-driven decision was contested.

What triggers deeper scrutiny

Follow-up work is not automatic. In DFSA practice, deeper reviews tend to be triggered by a small number of signals:

Inventory gaps. The firm cannot produce a full list of AI systems on request, or the list omits vendor and embedded AI. This is the single most reliable trigger for a follow-up letter.

Unowned models. An AI system in production without a named business owner or a validation record.

Customer-impacting decisions without human oversight.Suitability, credit or pricing, or claims decisions that a customer could contest, where the firm cannot show a documented human-in-the-loop or human-on-the-loop control.

Generative AI in client communications. Marketing copy, research summaries, or client-facing chatbots produced or powered by GenAI without a review workflow and disclosure.

Concentration in a single foundation-model provider.Material dependence on one provider with no exit plan.

Data protection findings. A finding by the Commissioner of Data Protection under DIFC Regulation 10 that intersects with prudential or conduct rules — for example, an automated decision without adequate safeguards.

Generative AI and customer-facing use

Generative AI receives disproportionate examiner attention because it changes the risk profile of client communications and internal research. The DFSA does not prohibit GenAI use — but where the output is client-facing, reaches a regulator, or informs a regulated recommendation, firms must show:

Human review. A workflow in which a qualified person reviews and takes accountability for the output before it leaves the firm.

Disclosure. That AI is in use in a way the recipient can reasonably understand.

Records. The prompt, the output, and the reviewer's disposition retained for the applicable record-keeping period.

Firms that deploy customer-facing chatbots without human escalation paths, or that generate research and marketing at scale without review workflows, are the most common candidates for Dear SEO follow-ups in 2026.

Third-party and vendor AI

GEN 5 treats a material AI dependency as any other outsourcing arrangement. The DFSA expects:

A due-diligence file for every material AI vendor, including model provenance, security posture, and sub-processor chain; contractual rights to be notified of material model changes and to audit; and an exit plan that does not leave the firm unable to serve customers if the provider is unavailable. Concentration risk on a single foundation-model provider is now a distinct examiner question.

Thematic reviews and Dear SEO letters

The DFSA typically communicates sector-wide findings through thematic review reports and Dear SEO letters rather than enforcement in the first instance. Firms that receive a Dear SEO letter on AI should treat it as a supervisory expectation with a deadline — the DFSA's follow-up cycle will check whether the gaps identified were closed and, if not, escalate.

How to prepare an examiner-ready pack

The most efficient way to be ready for a DFSA request is to build a small evidence pack that can be produced within days:

Model inventory export. Filterable by business line and risk tier, including vendor AI.

AI policy pack. The Board- or SEO-approved policy, risk appetite statement, and named accountable executive.

Governance minutes. Extracts showing AI was considered by the risk committee or an equivalent forum.

Validation and monitoring records. Independent validation reports for high-materiality models and evidence of ongoing performance monitoring.

Outsourcing files. Due-diligence and contractual artefacts for each material AI vendor.

Human-oversight evidence. Workflow documentation and sampled audit trails from customer-impacting AI systems.

Incident and complaint extracts. AI-related entries from the operational-risk register and complaints log.

Firms that assemble this pack once — and keep it live — reduce a multi-week information-request cycle to a same-day response, and consistently move through DFSA supervision with fewer follow-ups.

When the DFSA asks, the answer should already exist.

© 2026 Magpie. Product of Steinn Labs.Based in Dubai, UAE