
In February 2026, the UAE Central Bank published its Guidance Note on Consumer Protection and the Responsible Adoption and Use of Artificial Intelligence, a detailed set of supervisory expectations for licensed financial institutions covering AI governance, human oversight, vendor accountability, and audit trails. Notably, it carries no stated transition period, no compliance countdown, and no fixed enforcement date. The guidance itself describes its principles as expectations to be applied now, calibrated to each institution’s complexity, and revisited as the sector evolves, not a future milestone to plan around.
That absence of a deadline is worth sitting with, not glossing over. It means there is no grace period to wait out: this is already the standard regulators expect institutions to be operating against. Businesses that treat the guidance as a document to produce only if asked will always be a step behind. Businesses that treat it as the occasion to build the operating model their AI deployments already needed, will be the ones who are ahead of the competition and who are still improvising. This blog is about what that operating model actually looks like and how to build it without slowing down.
What Governance Actually Means Here
The word gets used loosely, so it’s worth being precise. Governance is not a compliance department’s paperwork exercise, and it isn’t a brake on innovation. Deloitte’s 2026 State of AI in the Enterprise report based on 3,235 IT and business leaders across 24 countries, found that only 21% of enterprises currently have mature governance for agentic AI and identified the same three missing pieces almost everywhere: clear decision boundaries defining what an agent can decide autonomously versus what needs a human, real-time monitoring to catch anomalies as they happen, and audit trails documenting the complete chain of an agent’s actions. That’s the whole definition. Governance is simply knowing, for every AI agent in production, what it’s allowed to do, whether it’s doing that safely right now, and being able to reconstruct exactly what it did after the fact. Most organizations haven’t built this not because it’s technically difficult, but because they built the agent first and never came back to build the oversight around it.
The Agent Sprawl Problem: Building Because You Can, Not Because It’s Worth It
This is where the caution against mindless expansion belongs, and the data on it is stark. IBM’s Think 2026 enterprise research found that large organizations will be running roughly 1,600 AI agents each by the end of this year. Ninety-four percent of organizations say they are concerned about agent sprawl, the uncontrolled proliferation of agents built by different teams on different frameworks with different permission structures and no shared oversight. Yet only 18% maintain a current, complete inventory of which agents are actually running, and just 12% have the centralized infrastructure to manage them. IDC’s finding that 88% of AI agent pilots never reach production is, in large part, a symptom of exactly this pattern. Agents built quickly by individual teams, with no governance home to graduate into and no one able to say confidently what would break if the agent were switched off.
The lesson isn’t that businesses are building too much AI. It’s that most agents get built the way departments once bought software with a personal credit card. One team solving one problem, without anyone asking whether the process actually needed an autonomous agent, whether a simpler workflow would have done the job, or who would be accountable for it a year later. An agent that nobody can find in an inventory is not a productivity win. It’s a liability nobody has priced yet.
What CBUAE Actually Requires, in Plain Terms
Stripped of legal language, the CBUAE’s guidance asks for five things, and a well-run business is likely already halfway toward most of them:
- A documented AI model inventory forevery AI system in use, what it does, and who owns it.
- Board-level accountability at the top of the organization, not just a technical team formally responsible for AI oversight.
- Annual bias testing using representative data to confirm the system treats customers fairly and consistently.
- Vendor accountability built into contracts with audit rights and the ability to immediately halt a third-party AI system if it breaches expectations, rather than assuming the vendor’s own assurances are sufficient.
- Evidence-quality audit trails with logs detailed and centralized enough to reconstruct what an AI system did and why, on demand. This is the area where organizations currently fall shortest: research on UAE compliance readiness found 61% of organizations have audit logs too fragmented across systems to produce usable regulatory evidence, and 33% have no evidence-quality trail at all.
None of this is exotic. It’s what a disciplined vendor selection and internal ownership process should have included from the start. The CBUAE has simply made it an explicit, standing expectation rather than a nice-to-have left to each institution’s discretion.
This Isn’t a UAE-Only Moment
Worth noting briefly: the same gap is being addressed everywhere at once. PwC’s own framework for responsible AI agent adoption recommends nearly identical measures such as integrating agents into existing governance rather than managing them separately, maintaining a centralized inventory, and keeping humans central to high-impact decisions with clear escalation paths. UAE businesses acting on the CBUAE’s guidance now aren’t complying with a local peculiarity. They’re building the operating model that serious AI deployment is converging on globally, ahead of most of their international peers.
A Practical Governance Framework that Lets You Scale Faster
The payoff for doing this properly is not abstract. IBM’s research found that organizations with real orchestration-led governance, with a unified way of tracking and managing every agent, rather than ad hoc oversight per team, are 13 times more likely to successfully scale their AI practice, see 30% fewer operational irregularities, and report 20% higher ROI on AI investment, with 169% greater transparency into how their agents actually reach decisions. Governance, done well, is the thing that makes scaling possible. It synthesizes into four concrete habits:
- Keep a living agent inventory. Every deployed agent, what it’s allowed to decide, and who owns it reviewed on a set schedule, not built once and forgotten.
- Tier oversight to risk. Light-touch monitoring for low-stakes agents (checking store hours, confirming an appointment); mandatory human review for anything financial, medical, legal, or irreversible.
- Build vendor accountability into every contract, not just the ones a regulator requires it for. Audit rights and a cessation clause cost little to negotiate and matter enormously when they are needed.
- Instrument monitoring and audit trails from day one. Retrofitting logging after an incident is far more expensive than building it in from the start, and it’s the exact gap 61% of organizations are currently carrying.
The Value Test: Three Questions Before Building the Next Agent
This is the direct answer to the sprawl problem, and it belongs in the hands of whoever approves new AI initiatives, not just the technical team building them. Before greenlighting any new AI agent, a business should be able to answer all three:
- What specific cost or risk does this remove that a simpler automation couldn’t? If the honest answer is “it would be convenient” rather than a measurable reduction in cost, risk, or response time, it isn’t ready to build yet.
- Who owns this agent’s decisions, and can they explain them six months from now? An agent with no accountable owner is exactly how a business ends up unable to account for most of its own AI footprint, the way IBM’s inventory data suggests most currently are.
- Does our existing governance infrastructure already cover this, or are we creating a new blind spot? An agent that needs an entirely new monitoring and audit setup isn’t automatically a bad idea but it’s a bigger commitment than the one-line business case usually presented for it.
An agent that fails this test isn’t a bad idea. It’s simply not ready yet and building it anyway is exactly how a business ends up as one more entry in next year’s sprawl statistics.
The Real Takeaway
The question was never whether to build AI agents for customer service. The case for doing so, covered throughout our recent blog series, remains strong. The question this blog highlights is who is accountable for the ones already running and whether the next AI solution a team wants to build has actually earned its place. The businesses that answer both well won’t just satisfy a regulator on paper. They’ll be the ones still scaling with confidence in 2027, while their less disciplined competitors are explaining an incident to a regulator, a board, or a customer who deserved a clearer answer than “the AI decided that.”
Frequently Asked Questions
1.Does this only apply to financial institutions?
The CBUAE’s specific guidance is written for licensed financial institutions (LFIs), but the underlying practices such as an agent inventory, tiered human oversight, vendor accountability, and real audit trails… are a sound baseline for any business deploying customer-facing AI, regulated or not.
2.What’s the first governance step to take if we’re starting from zero?
Build the inventory first. You cannot govern, tier, or audit agents you cannot currently list. Most organizations find this single step surfaces more than they expected.
3.Does this slow down our AI roadmap?
The data suggests the opposite. Organizations with real governance in place are 13 times more likely to scale successfully. Governance built in from the start is faster than governance retrofitted after an incident forces the pace.
4.If we use a vendor’s AI product, are we still accountable for what it does?
Yes. The CBUAE’s guidance explicitly requires audit rights and cessation clauses in vendor contracts precisely because accountability doesn’t transfer just because the AI wasn’t built in-house. The deploying business remains responsible for what it does to its customers.

