As the UAE Races Toward Agentic Government AI, Experts Warn Governance Must Move from Policy to Practice
As the UAE accelerates toward transitioning a significant share of government services to autonomous, agentic AI within two years, governance and legal experts warn that frameworks must evolve from strategic policy documents into operational controls covering accountability, explainability, and data sovereignty.
Key Takeaways
- ▸The UAE aims to transition a significant proportion of government services to autonomous, agentic AI models within the next two years.
- ▸Experts warn AI governance frameworks remain stronger at the strategic policy level than in operational practice, a gap that becomes more visible as deployments move beyond pilots.
- ▸Every AI system should have a clearly designated owner responsible for its performance, risks and compliance throughout its lifecycle, with decisions required to be explainable and challengeable.
- ▸Data protection, cyber risk extending into AI models themselves, and data residency requirements are increasingly shaping AI architecture and supplier selection decisions across the GCC.
The UAE's ambition to lead globally in artificial intelligence is entering a new phase as government agencies move from AI experimentation toward large-scale deployment of autonomous, agentic systems, and experts are warning that the governance challenge is shifting from strategy to execution. According to Aben Pagar, head of digital risk consulting at Konexo, GCC governments have demonstrated exceptional commitment to AI-led transformation, but many organisations are still working to close the gap between strategic ambition and operational reality. Governance frameworks, he said, often remain stronger at the policy level than in day-to-day operational practice, a gap that becomes more visible as governments move beyond pilots.
The scale of the UAE's ambition is significant. According to Pagar, the country has set a goal to transition a significant proportion of government services to autonomous, agentic AI models within the next two years, representing a shift from AI as a support tool to AI as an active decision-support and execution layer capable of analysing data, making recommendations and carrying out actions in real time. This builds directly on the institutional foundation the UAE laid on 14 June with the approval of its federal Artificial Intelligence and Data Authority, which consolidates AI and data governance under a single accountable structure reporting directly to Cabinet.
Nasser Ali Khasawneh, global head of technology and digital sector and global co-head of AI at Eversheds Sutherland, said GCC governments have already laid important foundations by creating dedicated AI authorities with a clearly defined remit. As the transition to agentic systems unfolds, he expects governance frameworks to evolve toward clearer expectations on how controls are applied in practice, building on the structured, risk-based implementation models the region has already established.
The operational requirements experts are flagging are specific. Pagar argues that every AI system should have a clearly designated owner responsible for its performance, risks and compliance throughout its lifecycle, and that decisions influenced by AI must be explainable and, where necessary, challengeable. This is no longer a marginal technical detail. As AI is increasingly becoming part of the decision-making layer itself rather than simply a tool supporting human decisions, the accountability architecture has to be built into the system design from the outset rather than retrofitted after deployment. That principle echoes the warning Ramco Systems COO Sandesh Bilagi made earlier this month regarding agentic AI in enterprise ERP environments: accountability established before deployment, not after problems emerge.
Data governance is expected to take on growing weight as agentic deployment scales. Pagar argues that data protection will increasingly form the backbone of AI governance, particularly around data quality, consent and cross-border considerations, while transparency and explainability become more important as AI plays a more active role in decision-making. Cyber risk now extends beyond infrastructure into the models themselves, including risks of manipulation, misuse and unintended behaviour, making security an integral part of AI design rather than a separate layer applied afterward. Data residency requirements are already influencing architecture choices, supplier selection and deployment models across the region, a dynamic directly relevant to the model access and platform diversification questions AWM covered regarding the US restrictions on Anthropic's Fable 5 and Mythos 5 models earlier this week.
For public sector organisations moving AI projects from experimentation into production, the practical advice is to embed governance directly into the AI lifecycle rather than treating it as a separate compliance layer, starting with clear visibility over where AI is being used across the organisation, followed by risk classification based on impact and sensitivity. Experts believe the most significant near-term public sector AI use cases will emerge in automated citizen services, regulatory supervision, intelligent case management and smart infrastructure operations. The central challenge, as Pagar frames it, is no longer identifying use cases but scaling them responsibly: integration with legacy systems, maintaining transparency in decision-making, and building public trust will all be critical to whether the UAE's two-year agentic transition succeeds as a model for other GCC governments to follow.
Frequently Asked Questions
What is the UAE's timeline for agentic AI in government services?
According to Konexo's head of digital risk consulting, the UAE has set a goal to transition a significant proportion of government services to autonomous, agentic AI models within the next two years.
What is the main governance challenge experts are flagging?
Experts say governance frameworks are often well-articulated at the strategic level but still maturing in operational practice. The key requirement is embedding clear ownership, explainability and accountability into AI system design from the outset rather than retrofitting governance after deployment.
How does data governance factor into the UAE's agentic AI push?
Data protection, including data quality, consent and cross-border considerations, is expected to form the backbone of future AI governance frameworks. Cyber risk now extends into the AI models themselves, including risks of manipulation and unintended behaviour.
What use cases are expected to define the next phase of UAE public sector AI?
Experts point to automated citizen services, regulatory supervision, intelligent case management and smart infrastructure operations as the most significant near-term agentic AI use cases in government.
Related Articles
Everyone Expects Two AI Blocs. The Gulf Is Betting It Doesn't Have to Choose
Saudi Arabia is simultaneously the deepest US AI partner in the Gulf and the home of a sovereign AI company that just built its flagship Arabic model on Chinese architecture, and according to a new analysis, that isn't a contradiction, it's the point.
Sep 16, 2026
AnalysisHumain and G42 Look to Raise Outside Capital as Gulf AI Giants Weigh IPOs
Saudi Arabia's Humain and Abu Dhabi's G42 are both exploring outside capital and potential IPOs as their AI ambitions scale beyond sovereign funding alone.
Sep 8, 2026
AnalysisDubai Police Deploy 36 AI Robots, Complete 104 Technology Projects
Dubai Police has deployed 36 RPA robots and completed 104 technology projects over the past year as it expands AI across policing and administrative operations.
Sep 7, 2026
AnalysisDubai Chambers Launches Agentic AI Training for 14,000 Member Companies
Dubai Chambers has launched specialised Agentic AI training tracks through a new e-learning platform, aiming to equip more than 14,000 member companies with the skills to adopt the technology across their operations.
Sep 2, 2026
AnalysisHumain and DataVolt Partner for 100MW AI Data Centre on Saudi Arabia's Red Sea Coast
Saudi AI firm Humain has partnered with DataVolt to build a 100MW data centre at Oxagon, NEOM, the first phase of a larger 1.5 gigawatt AI campus.
Sep 2, 2026