CBUAE AI Guidance: What Licensed Financial Institutions Must Do for Customer-Facing Agents

The CBUAE AI guidance issued on 11 February 2026 sets ten obligations for customer-facing AI at UAE banks and insurers. Here is the practical read.

Shadi Hossam
Shadi Hossam
Modern glass office towers in Dubai's financial district

On 11 February 2026 the Central Bank of the UAE issued its Consumer Protection AI Guidance Note, and every licensed financial institution operating in the country now has a written standard to meet before it puts an AI agent in front of a customer. The CBUAE AI guidance applies to banks, exchange houses, finance companies and insurance providers.

This article maps each of the guidance's ten sections to the operational question compliance officers, heads of digital and product owners face on Monday morning.

Key Takeaways

  • CBUAE's AI guidance took effect February 2026 — Issued 11 February 2026, it applies to banks, exchange houses, finance companies and insurance providers. Insurers running claims triage bots or automated underwriting sit inside the same perimeter as banks running credit chatbots.
  • Guidance sits on top of two prior frameworks — It must be read alongside the UAE Charter for the Development and Use of AI (July 2024) and the CBUAE Enabling Technologies Guidelines (15 November 2021). A programme built only against the 2021 document is not compliant with this new layer.
  • Every deployed AI model needs a live inventory — In-house and vendor-supplied systems alike must be logged with an owner, risk classification and scheduled review date, with compliance measures and ongoing monitoring built in rather than a one-off spreadsheet.
  • Customers get three guaranteed rights with AI agents — Transparency about interacting with an AI system, a fair and non-discriminatory outcome, and a clear route to a human, particularly for complaints and consequential decisions.
  • Vendor platforms don't shift compliance off the LFI — Section 9 keeps the compliance and data obligations with the licensed institution regardless of whose logo is on the chat window, and the PDPL applies to the same data at the same time.

What the February 2026 Guidance Note Actually Covers

The Guidance Note was issued on 11 February 2026 and applies to licensed financial institutions in the UAE, including insurance providers. Insurers running claims triage bots or automated underwriting are inside the same perimeter as banks running credit chatbots.

The CBUAE says the Note must be read in conjunction with the UAE Charter for the Development and Use of AI (published July 2024), the UAE National Strategy for AI, and the CBUAE's own Enabling Technologies Guidelines issued on 15 November 2021. If your AI programme was designed only against the 2021 document, you are not compliant against the new consumer-protection layer on top.

The framing is important. The guidance's stated objective is a culture of responsible and ethical use "with a focus on the end user" in the development, deployment and use of AI and ML systems. That phrase makes this a consumer-protection instrument, not a technical one.

CBUAE is one of several UAE regulators with active AI expectations, and the picture across the UAE's sector regulators, DHA, DoH, CBUAE, RERA, KHDA and TDRA, is now consistent enough that a single AI governance programme can be built to cover them all.

Several numbered sections carry distinct obligations worth tracking side by side.

The OECD AI Policy Observatory tracks how different countries are regulating AI, which matters as soon as you operate in more than one market.

Section Focus What It Requires
Section 3 Fairness, non-discrimination and ethics Active, evidenced check for bias before deployment
Section 5 Data quality, privacy and security Data quality and privacy safeguards alongside the PDPL
Section 6 Continuous monitoring and review Ongoing cadence for checking performance, bias and drift
Section 7 Human oversight and consumer protection Clear route to a human; staff review outputs before they bind
Section 9 Outsourcing and third-party risk LFI keeps the compliance obligation regardless of the vendor

Governance: Who Is Accountable for Each AI Agent Inside Your Institution

Professionals in a business meeting around a boardroom table
Photo: Werner Pfennig on Pexels

Ask this question of your own institution today: who has documented, board-level accountability for the WhatsApp bot answering your customers right now? If the answer is "the digital team," you are already out of step.

Governance structures must facilitate informed decision-making, enable the identification and mitigation of risks, and ensure AI systems align with the institution's risk appetite and legal obligations. AI-related risks must be incorporated into the governance framework in a "cohesive and consolidated manner", with specific adaptable roles and responsibilities for the Audit and Risk Committee, Risk Management, and Internal Audit.

The three lines of defence need named owners for AI, the risk appetite statement needs to say what the institution will and will not accept from AI-driven interactions, and the board minutes need to show the conversation happened.

There is a second obligation baked in. LFIs are expected to develop their own internal policies on the ethical and responsible use of AI with respect to consumers.

That is a living document. A policy signed off in Q1 and never touched again does not meet the standard.

Transparency and Explainability: What Customers Must Be Told

The transparency principle collapses into two customer-facing commitments. First, a customer has the right to know they are interacting with an AI system. Second, if an AI-influenced decision affects the customer, the institution must be able to explain how that decision was reached, not just confirm that AI was involved.

Both commitments have to survive the UAE's actual channels. Customers reach your bank on WhatsApp. They write in Arabic, in English, and often mix both inside a single message.

The disclosure that says "you are chatting with a virtual assistant" and the escalation path to a human need to work in both languages, and the explanation of a declined loan or a rejected claim needs to be available in whichever language the customer used.

Explainability is harder than disclosure. A deep model that scores creditworthiness or flags a claim as fraudulent has to be paired with a mechanism, human or automated, that produces a reason the customer and the regulator can read. If your vendor cannot give you that mechanism, you have a compliance gap.

Fairness and Ethics: Bias in Credit, Insurance and Automated Advice

Section 3 of the guidance is fairness, non-discrimination and ethics, treated as a distinct pillar rather than a footnote to governance. It says the CBUAE expects an active, evidenced check for bias, not a general commitment in a policy document.

Customer-facing AI that shapes credit approvals, insurance underwriting, or product recommendations must not introduce or perpetuate bias against any protected group. The test to run before deployment: what characteristics could our training data inadvertently encode, and what would the output look like if we changed only those characteristics? If nobody in the institution can answer that for a model in production, it is not ready.

Human Oversight: When the AI Agent Must Hand the Customer to a Person

Staff member helping a customer at a modern office reception desk
Photo: cottonbro studio on Pexels

Section 7 pairs Human Oversight and Consumer Protection as inseparable obligations. Read together, they say a customer-facing agent cannot be a dead end. The customer needs a clear, accessible route to a human, particularly for complaints and for consequential decisions.

Human oversight also runs upstream. Staff need to review AI-generated outputs before those outputs become binding on the institution or the customer.

That is a different obligation from a helpdesk escalation. It is a control on the model, not just a fallback for the caller.

Voice adds a layer. If your AI agent is a voice bot handling outbound calls, you carry the CBUAE human-oversight obligation and the TDRA rules for voice agents at the same time: prior approval, registered numbers, calling windows, and the Do Not Call Registry.

Data Privacy for AI Agents: Where CBUAE Obligations Meet the PDPL

Section 5 of the guidance covers Data Quality, Privacy and Security. Every piece of customer data an AI agent collects, learns from, or processes sits under this section and under Federal Decree-Law No. 45 of 2021, the UAE Personal Data Protection Law, which has been in force since 2 January 2022.

Two frameworks, one dataset, both apply.

Data quality is a regulatory obligation, not just an accuracy concern. Feeding low-quality or unrepresentative data into an AI agent that issues financial guidance creates a CBUAE exposure and a PDPL exposure at the same time.

Section 9 on Outsourcing and Third-Party Risk is the one that catches most institutions off guard. If your customer-facing agent runs on a vendor platform, the LFI keeps the data obligation and the compliance obligation. The vendor contract cannot transfer them.

The regulator will hold the licensed entity accountable regardless of whose logo is on the chat window. The dual data obligation is not unique to finance either: schools face a similar overlap between KHDA's expectations and the PDPL on parent and student data.

The Model Inventory Requirement: Logging Every Agent You Have Deployed

The guidance requires that an inventory of all AI models, systems or technologies developed or deployed be maintained, with compliance measures and training embedded in every function responsible for their use, management and monitoring. This is a live register, not a one-off spreadsheet.

An LFI running a customer-support chatbot, a credit-scoring model and a fraud-detection engine needs each one logged separately, with an owner, a risk classification, and a scheduled review date.

Section 6 on Continuous Monitoring and Review is what makes the register work. A launch sign-off is not enough. Every customer-facing agent needs a cadence for revisiting performance, bias, drift and customer outcomes.

The RERA marketing rules for property agent bots layer on top of the CBUAE inventory requirement for a bank that finances real estate.

For a read on whether your AI deployments align with the CBUAE guidance, book a free 30-minute consultation.

FAQ

Does the CBUAE guidance apply to a WhatsApp chatbot our bank uses for customer service?

Yes. A WhatsApp chatbot is an AI system deployed by a licensed financial institution to interact with consumers, which puts it inside the guidance's scope.

Do we have to tell customers they are speaking with an AI and not a human agent?

The guidance centres on transparency "with a focus on the end user", which the CBUAE reads as the customer's right to understand they are interacting with an AI system. In practice that means a clear, upfront disclosure at the start of the interaction, in the language the customer is using.

Who inside an LFI is formally responsible for AI governance under the February 2026 guidance?

The guidance names specific, adaptable roles for the Audit and Risk Committee, Risk Management and Internal Audit, with AI risks incorporated into the governance framework in a cohesive and consolidated manner. That means named accountability at board or board-committee level.

Does the guidance cover third-party AI tools we have licensed rather than built ourselves?

Yes. Section 9 on Outsourcing and Third-Party Risk keeps the compliance obligation with the LFI regardless of who built the platform.

How does the CBUAE AI guidance interact with the UAE Personal Data Protection Law?

They apply in parallel.

The guidance's Data Quality, Privacy and Security section governs how an AI agent handles customer data at the sector level, and Federal Decree-Law No. 45 of 2021, in force since 2 January 2022, applies as the general data protection regime. An AI agent processing customer data owes obligations under both.

Is the CBUAE Consumer Protection AI Guidance Note legally binding or is it advisory?

The Note sets out principles the CBUAE expects LFIs to follow, alongside all relevant CBUAE regulations and standards. In supervisory practice, this sets the standard against which the regulator will assess an institution's conduct.

What does the model inventory requirement capture, only in-house models or vendor platforms too?

Both. The guidance requires an inventory of all AI models, systems or technologies developed or deployed, and Section 9 makes clear that outsourced and third-party systems remain the LFI's responsibility.

Found this useful? Share it with your team.

Ready to find your highest-ROI AI opportunity?

We map your workflows, identify quick wins, and build a custom AI roadmap in one free strategy call.

Book a Free Strategy Call →