In February 2026, the Central Bank of the United Arab Emirates published operational guidance on artificial intelligence and machine learning specifically for banks. The Gulf, often perceived as a state-supervised technology testing ground, is producing sectoral norms that regulators administer within the framework of existing powers and regulations, rather than upstream of classical legislative processes. Several jurisdictions in the region have adopted national AI strategies, but the real constraint comes from elsewhere—from sectoral regulators who, through data protection and financial supervision, produce their requirements through administrative channels.

The Essentials

  • The UAE Central Bank published in February 2026 operational guidance on AI in banking finance, joining operational frameworks already in place in the United States and the United Kingdom.
  • The Gulf in institutional terms refers to the Gulf Cooperation Council, which groups six states. Their sectoral regulators, central banks, and data protection authorities set out requirements that apply to financial institutions under their supervision.
  • The central mechanism: sectoral regulators anchor their AI requirements to existing prudential frameworks, which can extend the application of these rules to AI uses without automatically transforming every AI guidance into a legally binding obligation.
  • The underlying tension: this fragmented sectoral architecture could converge into a readable regional standard, or produce a stack of incompatible rules that slows adoption where it should accelerate it.
  • The stakes for the rest of the world: if international banks align with Gulf requirements to operate in the region, these standards could carry weight in global AI governance negotiations, just as the GDPR did for data protection.

The UAE Central Bank Gets Ahead of Every Banking Regulator in the World

The guidance published by the Central Bank of the United Arab Emirates in February 2026 sets out principles for governance and accountability in AI use: validation and testing of models, transparency and explainability of decisions, attention to bias and fairness, quality data with traceability and auditability. Comparable operational precision already existed in American and British banking supervision.

The European Union has the AI Act, which entered into force in 2024, but its sectoral provisions for finance remain to be specified in delegated acts. The United States already imposed documentation and validation of models by the Federal Reserve since 2011. The United Kingdom published detailed principles for managing model risk in 2023 through the PRA, including governance, documentation, and independent validation.

The Emirates have binding prudential standards on models, while the February 2026 AI note is guidance. Foreign banks must comply with the applicable rules of their competent supervisory authorities.

Fourteen Countries, a Two-Speed Architecture

The Gulf in institutional terms refers to the Gulf Cooperation Council, which groups six states: the United Arab Emirates, Saudi Arabia, Qatar, Kuwait, Bahrain, and Oman. Several have published national AI strategies. These strategies are public policy documents: they set ambitions, investments, and sectoral priorities. They do not create direct obligations for businesses.

The constraint comes from a level below. In Saudi Arabia, sectoral authorities have set out frameworks for AI governance. The Personal Data Protection Law (PDPL), which entered into force in 2023, governs international data transfers through conditions and guarantees, and requires transparency concerning the processing of personal data. These provisions apply to personal data processing carried out by financial AI systems when they fall within its material and territorial scope. In Qatar, the Central Bank has integrated technological risk management requirements into its existing prudential circulars.

The sectoral regulator anchors its AI requirements to a pre-existing legal framework. Banks must comply with these frameworks. Failures can result in prudential or supervisory measures depending on the applicable framework. This approach moves faster than parliamentary processes.

It produces standards without producing new legislation.

This model has a precedent in how Europe imposed technological requirements through the banking sector even before its major digital laws were fully operational. In the Gulf, sectoral regulators have more extensive discretionary authority.

The Regulator as De Facto Legislator

This architecture raises a question of governance methodology. In liberal democracies, the sectoral regulator is supposed to apply the law as voted, not create it. It can clarify, detail, interpret, but within the limits of an explicit legislative mandate. In the Gulf, regulators operate differently. Their mandate is broader, their independence from the parliamentary process greater, and they produce binding standards through administrative channels.

For banks, this speed has a concrete advantage. They know what is expected of them. Regulatory uncertainty, one of the principal brakes on AI investment in European financial institutions, is reduced. Compliance teams can plan. Technology suppliers can certify their solutions.

The downside is the absence of public debate. Technical requirements on model validation or documentation of training data are produced by experts within central banks, without explicit legislative consultation. For foreign establishments, this lack of transparency about the reasoning behind each requirement complicates harmonization with other regulations they must simultaneously comply with.

The question of data use in banking AI models is symptomatic of this gap between the speed of Gulf markets and the broader social concerns that the region shares with the rest of the world, as shown by analysis on the Arab labor market facing AI.

International Banks Forced to Adapt

Foreign establishments operating in the region—HSBC, Standard Chartered, BNP Paribas, and Citigroup—are on the front lines. For them, the UAE guidance of February 2026 can be added to the European AI Act, US Treasury principles, and British FCA expectations only for establishments or activities actually subject to each of these regimes. These texts contain distinct elements. International cloud transfers must comply with conditions of the Saudi PDPL; their incompatibility with a given architecture depends on the architecture and guarantees actually put in place.

In practice, large banks have created teams dedicated to multi-jurisdictional compliance. They map requirements by country, identify friction points, and sometimes choose to apply the most stringent standard as their global internal standard to simplify their governance.

Between Regional Convergence and Fragmentation: The Stakes for 2028-2030

The Gulf will produce more standards in the years ahead. The decisive question is whether these standards will converge with each other and with those of the rest of the world, or whether they will accumulate in incompatible layers.

Two trajectories are emerging. In the first, Gulf regulators build a harmonized architecture at the regional scale. Requirements for model governance and data protection become similar from one country to another. A bank that complies with the requirements of one jurisdiction can operate in others without fundamentally adapting its architecture. This scenario is technically feasible: Gulf regulators cooperate within the framework of the Gulf Cooperation Council.

In the second trajectory, each regulator continues to produce its own sectoral standards autonomously. Fragmentation grows as AI integrates into more financial products. For international banks, the cost of compliance rises. Large global establishments retain the resources to navigate this complexity; more modestly-sized actors struggle more.

The 2028-2030 horizon will become clear through a few precise signals. The first: will Gulf regulators publish common positions on AI model governance. The second: will the Gulf Cooperation Council strengthen its coordination on financial AI. The third: will international institutions begin to take into account Gulf standards in their recommendations.

Regional alignment could allow the Gulf to carry weight in global standards for financial AI governance. The ability to produce a readable and stable standard determines global convergence more than market size does.

Lessons from This Method for the Rest of the World

The Gulf experience offers a practical lesson on AI governance. Waiting for general legislation before producing sectoral standards leaves financial institutions navigating without clear guidance while they deploy their most critical models. Early sectoral regulation creates requirements before best practices are stabilized, but it also forces institutions to document their design choices from the outset.

European and American regulators watch the Gulf closely, because large international banks advance needs for operational clarity arising from this region. Regulated institutions seek to reduce regulatory ambiguity.

AI governance in financial services rests primarily on a superposition of sectoral and local rules, in parallel with general international instruments on AI such as the Council of Europe’s Framework Convention opened for signature on September 5, 2024. The Gulf produces sectoral standards that can serve as a reference.


Sources

  1. VerifyWise, AI Regulation in the Middle East, June 2026
  2. UAE Central Bank, Guidance Note on AI and Machine Learning in Financial Services, February 2026 (official document of the Central Bank of the UAE, consulted via the CBUAE website)
  3. SDAIA, Saudi Data and AI Authority, AI Governance Framework 2024 (official documentation available on the SDAIA website)
  4. Qatar Central Bank, prudential circulars on technological risk management (official QCB website)
  5. Regulation (EU) 2024/1689, AI Act, Official Journal of the European Union, July 12, 2024