The DFSA's 2026 supervisory posture
The Dubai Financial Services Authority's public posture on AI is consistent with the approach it has taken to cloud, outsourcing, and cyber over the last decade: technology-neutral, principles-based, and enforced through existing rules rather than a bespoke rulebook. The DFSA's AI research paper and subsequent Dear SEO commentary make the direction clear — firms are expected to identify where AI is used, to govern it in proportion to the risk it creates, and to evidence that governance on request.
What is new in 2026 is intensity. AI is now a standing topic in routine risk assessments for authorised firms with meaningful AI deployment, and it appears in thematic reviews across banking, asset management, and insurance intermediation.
What examiners ask for first
Across recent supervisory engagements, DFSA examiners open with a tightly-scoped set of requests. Firms should assume these are coming and pre-package the answers:
1. A current AI/ML inventory. Every model the firm develops, procures, or uses via a vendor. Business purpose, data inputs, owner, risk tier, validation status, last review date. Vendor and embedded AI are in scope — "we don't build models" is not an answer.
2. The governance paper. An AI policy or standard approved by the Board or the SEO, with a documented risk appetite, named accountable executive, and defined escalation paths.
3. The list of material third-party AI dependencies.With outsourcing risk assessments, contractual rights to audit and to be notified of material model changes, and a viable exit plan.
4. Evidence of human oversight. For any AI system that materially affects a client outcome — suitability, KYC risk scoring, transaction monitoring alerts, marketing personalisation at scale — how a qualified person reviews or can override the output, and the audit trail proving it happens.
5. Incident and complaint records. AI-related incidents captured through the firm's operational-risk framework, and complaints where an AI-driven decision was contested.
What triggers deeper scrutiny
Follow-up work is not automatic. In DFSA practice, deeper reviews tend to be triggered by a small number of signals:
Inventory gaps. The firm cannot produce a full list of AI systems on request, or the list omits vendor and embedded AI. This is the single most reliable trigger for a follow-up letter.
Unowned models. An AI system in production without a named business owner or a validation record.
Customer-impacting decisions without human oversight.Suitability, credit or pricing, or claims decisions that a customer could contest, where the firm cannot show a documented human-in-the-loop or human-on-the-loop control.
Generative AI in client communications. Marketing copy, research summaries, or client-facing chatbots produced or powered by GenAI without a review workflow and disclosure.
Concentration in a single foundation-model provider.Material dependence on one provider with no exit plan.
Data protection findings. A finding by the Commissioner of Data Protection under DIFC Regulation 10 that intersects with prudential or conduct rules — for example, an automated decision without adequate safeguards.
Generative AI and customer-facing use
Generative AI receives disproportionate examiner attention because it changes the risk profile of client communications and internal research. The DFSA does not prohibit GenAI use — but where the output is client-facing, reaches a regulator, or informs a regulated recommendation, firms must show:
Human review. A workflow in which a qualified person reviews and takes accountability for the output before it leaves the firm.
Disclosure. That AI is in use in a way the recipient can reasonably understand.
Records. The prompt, the output, and the reviewer's disposition retained for the applicable record-keeping period.
Firms that deploy customer-facing chatbots without human escalation paths, or that generate research and marketing at scale without review workflows, are the most common candidates for Dear SEO follow-ups in 2026.
Third-party and vendor AI
GEN 5 treats a material AI dependency as any other outsourcing arrangement. The DFSA expects:
A due-diligence file for every material AI vendor, including model provenance, security posture, and sub-processor chain; contractual rights to be notified of material model changes and to audit; and an exit plan that does not leave the firm unable to serve customers if the provider is unavailable. Concentration risk on a single foundation-model provider is now a distinct examiner question.
Thematic reviews and Dear SEO letters
The DFSA typically communicates sector-wide findings through thematic review reports and Dear SEO letters rather than enforcement in the first instance. Firms that receive a Dear SEO letter on AI should treat it as a supervisory expectation with a deadline — the DFSA's follow-up cycle will check whether the gaps identified were closed and, if not, escalate.
How to prepare an examiner-ready pack
The most efficient way to be ready for a DFSA request is to build a small evidence pack that can be produced within days:
Model inventory export. Filterable by business line and risk tier, including vendor AI.
AI policy pack. The Board- or SEO-approved policy, risk appetite statement, and named accountable executive.
Governance minutes. Extracts showing AI was considered by the risk committee or an equivalent forum.
Validation and monitoring records. Independent validation reports for high-materiality models and evidence of ongoing performance monitoring.
Outsourcing files. Due-diligence and contractual artefacts for each material AI vendor.
Human-oversight evidence. Workflow documentation and sampled audit trails from customer-impacting AI systems.
Incident and complaint extracts. AI-related entries from the operational-risk register and complaints log.
Firms that assemble this pack once — and keep it live — reduce a multi-week information-request cycle to a same-day response, and consistently move through DFSA supervision with fewer follow-ups.