COMPLEX LICENSING EXPERTS
Contact Us

HOME / INDUSTRIES / ARTIFICIAL INTELLIGENCE

INDUSTRIES · ARTIFICIAL INTELLIGENCE IN REGULATED SECTORS

Artificial intelligence is not licensed. Your sector is.

No UAE authority issues an AI licence. What exists is stricter and easier to miss: the regulator of the sector you deploy into holds you to the same standards of governance, explainability and accountability as any other part of your business — and data-protection law governs everything the model touches. Finance, healthcare, insurance, virtual assets, gaming, government. Find your sector? Start here.

Confidential & non-binding · Same-day response in UAE hours

0

Artificial-intelligence licences in the UAE

2

Layers that always apply

6

Sector regulators we work across

2031

National AI Strategy horizon

—— THE SHORT ANSWER

There is no standalone artificial-intelligence licence in the UAE. Your obligations come from two layers: your sector regulator, and data-protection law.

Nobody supervises "AI". Every UAE regulator that already governs your sector — finance, health, gaming, government — applies its existing governance, explainability and accountability rules the moment a model touches a decision it regulates. Separately, data-protection law governs the data the model processes, wherever it goes. Two layers, always, regardless of sector.

AI-SPECIFIC LICENCE

None

Obligations sit inside your existing licence

ALWAYS APPLIES

Sector regulator

Governance, explainability, accountability

ALSO APPLIES

Data protection law

Wherever the model's data goes

SECTORS COVERED

6

Finance, health, insurance, VA, gaming, gov't

STRATEGY HORIZON

2031

UAE National AI Strategy

FIRST STEP

Find your sector

Then the framework and service follow

YOUR SECTOR

Where are you deploying it?

The same model carries different obligations depending on the decision it influences and the regulator that supervises you. Find your sector — each routes to the authority that governs the deployment and the work that gets you cleared.

FinTech & financial services

Credit decisioning, fraud and transaction monitoring, robo-advice, underwriting. Model risk, explainability and outsourcing rules apply directly.

CBUAE·CMA·DFSA·ADGM

See pathway →

Virtual assets & Web3

On-chain analytics, KYT scoring, market surveillance and automated risk engines inside a licensed virtual-asset business.

VARA·ADGM·DFSA

See pathway →

Healthcare & health tech

Diagnostic support, triage, imaging and clinical documentation. Health data is tightly governed, with localisation rules and ADHICS cyber controls.

MoHAP·DoH·DHA

Talk to us →

Insurance & InsurTech

Pricing, underwriting and claims automation — where fairness, appeal rights and the logic behind a declined claim are the exposure.

CBUAE·CMA

Talk to us →

Gaming

Player-harm detection, responsible-gaming monitoring and fraud models inside a GCGRA-licensed operation, on certified systems.

Government & public sector

Citizen-facing services and decision support, where procurement standards, data residency and national cyber policy set the bar.

Federal & emirate frameworks

Talk to us →

Real estate & PropTech

Mortgage decisioning — personal-data and fairness obligations, plus registry alignment where the underlying asset is UAE property.

Data protection·DLD

Talk to us →

Legal, HR & professional services

Contract analysis, screening and candidate assessment. Automated decisions about people carry the sharpest individual rights.

Data protection·DIFC·ADGM

Talk to us →

—— THE UAE LANDSCAPE

A state that actively wants artificial intelligence — and regulates it through the sectors, not around them.

The UAE has a national AI strategy, a dedicated ministerial portfolio and public-sector adoption targets that most markets do not. That posture is genuinely enabling: there is no prohibition to argue with and no waiting for a horizontal AI act. The consequence, though, is that obligations arrive through existing law — financial-services rulebooks, health-data legislation, data-protection regimes and national cybersecurity policy — all of which already require accountable owners, documented controls and defensible outsourcing. Firms that treat AI as an IT initiative discover this at supervision. Firms that treat it as a regulated capability do not.

Enabling

National strategy, no horizontal AI law

Sectoral

Obligations arrive via the existing regulator

PDPL

Federal data-protection law, plus DIFC & ADGM

Cyber

National policy & ADHICS in healthcare

THE REGULATORS

Your regulator, plus the data layer.

Nobody supervises "AI". These are the authorities that supervise the things AI is used to do, and the regimes that follow the data wherever it goes.

CBUAE

FEDERAL · BANKING & PAYMENTS

Governance, risk-management and outsourcing expectations apply to models used in credit, payments and fraud decisions.

Explore CBUAE →

DFSA

DIFC · FINANCIAL SERVICES

Model governance and outsourcing rules reach any model embedded in a DFSA-authorised financial activity.

Explore DFSA →

ADGM (FSRA)

ABU DHABI · FREE ZONE

The same governance and outsourcing rulebooks reach any model embedded in an ADGM-licensed activity.

Explore ADGM →

VARA

DUBAI · VIRTUAL ASSETS

Automated decisioning, market surveillance and monitoring sit within VARA's technology-governance rules where a model touches a licensed virtual-asset activity.

Explore VARA →

CMA

ONSHORE · SECURITIES

Automated advice, algorithmic execution and surveillance sit within the onshore securities regime and its conduct rules.

Explore CMA →

Health authorities

MoHAP · DoH · DHA

Clinical AI sits behind health-data lawful basis, localisation limits and ADHICS cyber controls around the service.

Talk to us →

Data protection

PDPL · DIFC · ADGM

Lawful basis, transfer rules and the individual's rights over automated decision-making — the layer that applies whatever your sector.

Talk to us →

THE OBLIGATIONS

What actually applies, by what the model decides.

Nothing here is an AI rule. Every line is an existing obligation that a model triggers the moment it influences a regulated decision — which is why AI compliance work is mostly mapping, not lobbying.

What the model doesWho it answers toWhat you must be able to showExposure
Decides credit or pricingCBUAE, DFSA, ADGM, CMAModel governance — owner, validation, monitoring, override path and board visibilityHigh
Screens transactions or clientsSector regulator + AML supervisorTuning & testing evidence — thresholds, false-negative testing, human review of alertsHigh
Informs a clinical decisionMoHAP, DoH, DHAHealth-data lawful basis, localisation, clinical oversight and ADHICS controlsHigh
Decides about a person automaticallyData protection regimeTransparency & rights — notice, human intervention, ability to contest the outcomeHigh
Relies on a third-party or foundation modelSector regulatorOutsourcing & concentration — due diligence, contract terms, exit plan, audit rightUnderestimated
Processes data across bordersPDPL, DIFC, ADGMTransfer basis — adequacy, safeguards and a record of where inference happensCommon failure
Touches critical systemsNational cyber policy, sector rulesSecurity assurance — access control, adversarial testing, incident reportingHigh

Indicative mapping, not legal advice on your specific deployment. Exposure reflects what regulators in the UAE are currently focusing on most closely; both follow the decision the model influences, not the technology used to build it. We assess your use cases individually in a perimeter analysis.

THE COMPLIANCE REALITY

Regulators do not audit your model. They audit your control over it.

The question in supervision is never "is the AI accurate". It is who owns this decision, what happens when the model is wrong, and can you show us. These are the artefacts we build and operate with you.

INVENTORY

AI inventory & use-case classification

Every model in the business, what it does, which regime it engages and how material it is — the register a supervisor will ask for first.

GOVERNANCE

Model governance & accountability

A named accountable owner per model, board and committee reporting lines, validation, monitoring, and a documented human override path.

DATA LINEAGE

Data lineage & lawful basis

Where training and inference data came from, the basis for using it, retention, and where processing physically happens — including every cross-border hop.

INDIVIDUAL RIGHTS

Automated decisions & individual rights

Notice, explanation, human intervention and a working route for an individual to contest an outcome — with fairness and bias testing behind it.

SUPPLY CHAIN

Third-party & model supply chain

Due diligence on model and API providers, contractual audit and exit rights, concentration risk, and a plan for the day the provider changes the model.

SECURITY

AI security & adversarial testing

Access control over models and training data, prompt-injection and data-leakage testing, red-teaming and incident response — delivered in-house by ITSEC.

Inventory · governance · data lineage · individual rights · supply chain · security — with AML and screening controls delivered on VerifiX and ComplianceX, and AI security assurance by ITSEC, API-driven with no build.

HOW WE HELP

Five services for artificial intelligence in a regulated business.

Most advisors can write you a policy. Most security firms can test a system. Because KOLL and ITSEC sit under one roof, we can map the obligation, build the governance, test the model and run the controls — and be accountable for all four.

01 · START HERE

AI use-case register & regime mapping

Every model in the business inventoried, classified by the decision it influences, mapped to sector and data-protection obligations, and ranked by exposure.

YOU GET: the register · a regime map per use case · a ranked gap list

02 · GOVERNANCE

AI governance framework build

Accountable owner per model, validation and monitoring standard, human-override paths, bias and fairness testing, and the board reporting pack behind them.

YOU GET: AI policy set · model-risk standard · committee & board pack

03 · REGULATOR-FACING

Applications & supervisory response

The AI and model-risk sections of a licence application, answers to supervisory questions, and the outsourcing file for third-party and foundation-model reliance.

YOU GET: application sections · outsourcing file · response drafting

04 · ASSURANCE · ITSEC

AI security & adversarial testing

Model and data-pipeline access control, prompt-injection and data-leakage testing, red-teaming, and ADHICS alignment where health data is involved.

YOU GET: test report · remediation plan · regulator-ready evidence

05 · DELIVERED, NOT ADVISED

VerifiX & ComplianceX

Where the AI use case is compliance itself — screening, KYT, monitoring — we supply the regulator-aligned engine and its evidence trail, API-driven with no build.

YOU GET: live screening & monitoring · defensible audit trail

06 · ONGOING

Annual review & model change control

Models drift and providers update them. We re-test, refresh the register and keep the governance current — so the file stays defensible between supervisions.

YOU GET: annual re-assessment · change-control process · refreshed evidence

The difference: competitors advise on artificial-intelligence risk. We advise on it, test it, and run it — one team, one accountable engagement. Deploying into financial services? Start with the FinTech licensing service →

GO DEEPER

Your next step.

The industry routes here; the service gets you compliant. Read on.

/ INDUSTRY · FINANCIAL SERVICES

FinTech in the UAE

Most AI-in-finance activity is a FinTech licence in disguise — payments, lending or e-money underneath the model.

  • Which regulator fits your model
  • Governance & outsourcing rules
  • Licensing pathway end to end
See the industry →
/ INDUSTRY · VIRTUAL ASSETS

Virtual assets, Web3 & DeFi

Where the AI model sits inside a licensed virtual-asset activity, VARA's rules govern the technology as much as the token.

  • Seven licensable activities
  • Technology & risk rulebooks
  • On-chain monitoring obligations
See the industry →
/ ECOSYSTEM · ONE ROOF

The KOLL Group ecosystem

Advisory, RegTech and cybersecurity integrated — a model file needs all three, filed as one.

  • Governance & regime mapping
  • Adversarial & penetration testing
  • One accountable team
Explore the ecosystem →

FAQ

Artificial intelligence in regulated UAE industries — the essentials.

Do I need a licence to deploy artificial intelligence in the UAE?

Not for the AI itself — no UAE authority issues an AI licence. But if you operate in a regulated sector, the model sits inside the licence you already hold or need, and your regulator applies its existing governance, outsourcing and accountability rules to it. Separately, data-protection law applies to everything the model processes. The practical answer is that AI rarely needs a new licence and almost always needs new controls.

Which regulator governs artificial intelligence in financial services?

Whichever regulator already licenses the activity — CBUAE for banking and payments, DFSA in the DIFC, ADGM's FSRA in Abu Dhabi, the CMA (formerly SCA) onshore, or VARA where the model touches a licensed virtual-asset activity.

What applies to artificial intelligence in healthcare?

Federal and emirate health authorities (MoHAP, DoH, DHA) govern clinical use, with health-data lawful basis, localisation rules and ADHICS cyber controls sitting alongside.

Can an AI system make decisions about individuals?

Yes, subject to data-protection law: the individual is entitled to notice, an explanation, human intervention and a working route to contest the outcome.

Can I use a foundation model or third-party AI provider?

Yes, but reliance on a third party is itself regulated — outsourcing due diligence, contract terms, an exit plan and audit rights are expected by your sector regulator.

Can training or inference happen outside the UAE?

Often yes, but cross-border processing needs a documented transfer basis, safeguards and a record of where inference physically happens — a common gap in AI deployments.

Does the UAE have an AI law like the EU AI Act?

Not a single horizontal statute. Instead, the UAE's national AI strategy sets direction to 2031 while individual sector regulators layer AI-specific governance expectations onto their existing frameworks.

Where do we start?

With a perimeter analysis: what the model decides, which sector regulator applies, and what data-protection obligations follow. That scoping call is where every engagement begins.

BUILDING TRUST IN A REGULATED WORLD

Map your artificial-intelligence obligations in one conversation.

Tell us what the model decides and who it decides about. In one confidential call we will tell you which regimes it engages, where your exposure sits, and the exact next steps.