CBUAE's AI Guidance Is a Preview of What Every Gulf Insurer Will Be Asked to Prove
source[code] | BFSI Technology Insight | 9 September 2026
Key Takeaways
-
In February 2026 the Central Bank of the UAE (CBUAE) published a Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E., and the note explicitly extends to "licensed financial institutions, including insurance providers" (Central Bank of the UAE, 2026a).
-
The guidance sets out expectations across six practical areas: governance and accountability, fairness and non-discrimination, transparency and explainability, human oversight, data management and privacy, and third-party/outsourcing accountability (Central Bank of the UAE, 2026a; Pinsent Masons, 2026).
-
CBUAE's own published insurance-sector guidance library - solvency, reinsurance, Takaful, motor, health TPAs - currently contains no AI-specific circular, which means insurers today face a consumer-protection standard articulated at the LFI level with no insurance-specific rulebook translation yet (Central Bank of the UAE, n.d.).
-
Qatar Central Bank issued its own Artificial Intelligence Guideline for QCB-licensed financial firms in September 2024, and UAE's four financial regulators (CBUAE, SCA, DFSA, FSRA) have a track record of issuing joint cross-sectoral technology guidance, which together suggest the CBUAE note is part of a regional pattern rather than an isolated document (Pinsent Masons, 2024; DFSA, 2021).
-
source[code]'s reading - stated here as analytical inference, not confirmed regulatory fact - is that insurance-specific supervisors across the Gulf are likely to echo CBUAE's principles within the next 12-18 months, in the same way APRA's supervisory letters preceded CPS 230 in Australia, a parallel source[code] examined in its 4 September analysis of vendor concentration risk.

What CBUAE's February 2026 Guidance Actually Says
Most regulatory "AI guidance" in financial services arrives as broad principle statements - fairness, transparency, accountability - with little that a compliance team can act on directly. CBUAE's note is more specific than that pattern, and it is worth reading closely rather than summarising from headlines, because the specificity is the story.
The guidance requires licensed financial institutions to adopt "a documented governance framework for AI and ML that is commensurate with the size, nature and complexity of their operations," with boards and senior management explicitly accountable for model selection, development and deployment decisions (Central Bank of the UAE, 2026a). It states plainly that "LFIs should not employ AI models that they have no control over" - a line aimed squarely at black-box third-party models and unexplainable vendor tooling.
On fairness, the note requires that "AI and ML systems do not result in discriminatory or manipulative outcomes," that training data be "sufficiently accurate, relevant and representative," and that models undergo periodic testing "once a year or each time a model is upgraded" (Central Bank of the UAE, 2026a). On transparency, institutions must be "transparent with customers about the use of AI, particularly in respect of high-impact decisions," with disclosures required in both Arabic and English, and institutions are asked to consider offering consumers an opt-out from AI-driven processes.
The human oversight section is unusually concrete for a principles-based note: it names three recognised oversight models - human-in-the-loop, human-on-the-loop, and human-out-of-the-loop - and requires that consumers be able to "request human review or explanation of AI generated decisions," with alternative non-AI arrangements available where a customer does not want to be subject to an automated decision (Central Bank of the UAE, 2026a; Pinsent Masons, 2026). On third-party risk, the guidance is direct that "the responsibility for AI outcomes remains with LFIs, even where functions are outsourced" (Pinsent Masons, 2026), and it asks institutions to maintain an inventory of AI models - including those developed or hosted by vendors - and to consider using a range of AI providers rather than concentrating on one.
Two things distinguish this from a generic ethics statement. First, it names an institution's control obligation over models it does not build itself - directly relevant to insurers who license pricing engines, fraud-detection tools, and claims-triage software from third parties rather than building in-house. Second, it ties transparency and human-review rights to "high-impact decisions" without narrowly defining that term for banking use cases only - leaving room, deliberately or not, for supervisors to apply the same language to underwriting declines, claims denials, and premium loading, all of which are high-impact decisions in an insurance context.
Why This Reads as a Preview for Insurance-Specific Supervision
CBUAE is unusual among Gulf regulators in that it directly supervises insurance - the guidance note's own scope line includes "insurance providers" inside its definition of licensed financial institutions (Central Bank of the UAE, 2026a). That is a meaningful structural fact: this is not a banking-sector regulator's guidance that insurers might loosely analogise to. Insurers licensed in the UAE are named participants in the guidance as issued.
What is not yet true is that CBUAE has published an insurance-specific circular translating these principles into underwriting, claims, or distribution language - the kind of granular rulebook insurers are used to for solvency or reinsurance. A review of CBUAE's published insurance guideline library, which runs to solvency, reinsurance, Takaful, motor, health third-party administrators and brokerage, currently shows nothing AI-specific (Central Bank of the UAE, n.d.). That gap is exactly why we call this a preview rather than a rule: the principles apply today by virtue of the guidance's own scope language, but the operational detail - how a claims-denial explanation should read, what "periodic testing" means for a pricing model, what counts as a "high-impact" underwriting decision - has not been spelled out for insurance specifically.
Two regional signals make it reasonable to expect that translation is coming rather than hypothetical. Qatar Central Bank's Artificial Intelligence Guideline, issued in September 2024 for QCB-licensed financial firms, already requires firms to identify high-risk AI systems, disclose AI use to customers and obtain consent, and hold boards accountable for AI outcomes (Pinsent Masons, 2024) - a near-identical architecture to CBUAE's, arrived at independently by a neighbouring regulator eighteen months earlier. And within the UAE itself, CBUAE, the Securities and Commodities Authority, DFSA and ADGM's FSRA have a precedent of coordinating: their 2021 joint Guidelines for Financial Institutions Adopting Enabling Technologies named "Big Data Analytics and Artificial Intelligence" as one of five technology categories requiring cross-sectoral principles (DFSA, 2021). Regulatory coordination across UAE financial supervisors on technology topics is therefore an established pattern, not a one-off.
Put together: a Gulf regulator with insurance directly in scope has published detailed AI principles; a neighbouring Gulf regulator independently converged on comparable principles; and UAE regulators have a history of turning cross-sectoral technology guidance into more specific, sector-by-sector expectations over time. None of that guarantees an insurance-specific AI circular in the next 12-18 months. It does make it the more likely path than the alternative - that CBUAE's principles remain permanently general and no supervisor in the region ever operationalises them for underwriting and claims specifically.
The Operating Gaps Most Gulf Insurers Carry Today
Set against CBUAE's actual language, most Gulf insurers' current AI programmes have a specific and recurring shape of gap - not an absence of AI governance intent, but an absence of evidence that would satisfy a supervisor asking the guidance's own questions.

No consolidated inventory of AI-influenced decisions. The guidance asks institutions to maintain "an inventory of AI models, including those developed or hosted by third parties" (Central Bank of the UAE, 2026a). Many insurers can describe their major AI initiatives - a fraud-scoring tool here, a chatbot there - but few maintain a single register mapping which specific underwriting, pricing, claims and distribution decisions are AI-influenced, at what stage, and with what vendor dependency. Without that inventory, a supervisor's first question - "show us everywhere AI touches a customer decision" - has no ready answer.
Explainability that exists in a data science notebook, not a customer-facing sentence. CBUAE requires disclosure "in both Arabic and English" and the ability to give consumers an explanation of an AI-generated decision (Central Bank of the UAE, 2026a). Feature-importance outputs from a pricing model are not the same artefact as a plain-language reason code a claims handler can read to a policyholder. Most insurers we observe in the region have the former and not the latter.
Human oversight that is designed but not tested. The guidance names human-in-the-loop, human-on-the-loop and human-out-of-the-loop as distinct models and expects institutions to know which applies to which system (Central Bank of the UAE, 2026a). Insurers frequently describe a human-in-the-loop process for a use case that, in practice, has drifted toward automatic approval because the human reviewer's workload makes genuine review impractical. The gap is not the policy document; it is whether the override capability is exercised often enough to prove it is real.
Vendor accountability that stops at the contract. The guidance is explicit that "the responsibility for AI outcomes remains with LFIs, even where functions are outsourced" (Pinsent Masons, 2026), and asks for due diligence on a vendor's "reputation in the field of AI, governance, security and data-protection practices" (Central Bank of the UAE, 2026a). Insurers that license pricing, fraud, or claims-triage models from third parties often have a signed vendor agreement but no ongoing evidence trail - model change logs, retraining notices, audit access - that would let them answer for an outcome the vendor's model produced.
None of these gaps require an insurance-specific rulebook to close. They can be closed against CBUAE's existing LFI-level language today, which is precisely the point: institutions that wait for an insurance-specific circular before building the underlying capability will find the retrofit takes longer than the runway a first insurance-specific enforcement action is likely to give them.
Counterpoint: This Is a Forward-Looking Inference, Not Yet Codified Insurance Law
It would overstate the evidence to claim CBUAE has issued insurance-specific AI rules, or that insurance supervisors elsewhere in the Gulf have committed to a timeline for doing so. They have not. CBUAE's guidance note is a guidance note, not a binding regulation with stated penalties; its own insurance guideline library, as published, contains no AI-specific document as of this writing (Central Bank of the UAE, n.d.). Saudi Arabia's SAMA has cybersecurity and IT-governance frameworks that touch on model risk indirectly, but this analysis did not find a SAMA-published AI-specific guidance document comparable to CBUAE's or QCB's, and we are deliberately not asserting one exists. Bahrain's Central Bank rulebook likewise was not confirmed to carry an AI-specific insurance circular at the time of research.

The thesis in this article - that insurance-specific AI expectations are likely to follow within 12-18 months - is source[code]'s own analytical judgment, built from the pattern of CBUAE's scope language, QCB's independent convergence on similar principles, and UAE regulators' history of sector-by-sector translation of cross-sectoral guidance. It is a reasoned bet on regulatory direction, not a report of a stated deadline. Readers should treat the 12-18 month window as a planning horizon worth preparing against, not a date any regulator has committed to.
The AI Consumer-Impact Stack: A Self-Assessment for Gulf Insurers
To make this practical rather than merely directional, source[code] has structured CBUAE's principles into four layers an insurer can audit today, independent of whether an insurance-specific circular ever arrives. We call it the AI Consumer-Impact Stack (ACIS) - deliberately built around the point where AI decisions meet a policyholder, since that is where CBUAE's guidance places its own emphasis.

1. Decision Inventory - Can you produce, on request, a single list of every underwriting, pricing, claims and distribution decision that is AI-influenced, which model or vendor drives it, and whether it is fully automated or human-reviewed? If this list lives only in individual team heads, this layer fails.
2. Explainability Ledger - For each item in the inventory, is there a pre-written, plain-language reason code - available in both Arabic and English - that a frontline claims handler or underwriter could read to a customer today without escalating to data science? CBUAE's disclosure language points directly at this artefact.
3. Override Pathway - For each AI-influenced decision, is the human review or appeal mechanism actually used at a measurable rate, or does its existence on paper mask a process that has drifted to automatic approval in practice? This layer tests whether human-in-the-loop is a real control or a compliance fiction.
4. Vendor Chain of Custody - For every third-party or hosted model in the inventory, do you hold current evidence - not a one-time onboarding document - of the vendor's governance practices, model change history, and your own ability to audit or exit the relationship? This is the layer CBUAE's "responsibility remains with LFIs" language makes non-delegable.
An insurer that can answer all four with evidence, not intent, is in a materially stronger position than one relying on a written AI policy alone - regardless of when, or whether, an insurance-specific circular follows CBUAE's LFI-level guidance.
The source[code] perspective
We think the more useful question for a Gulf insurer's risk and technology leadership right now is not "has our regulator told insurers specifically to do this yet" but "could we answer CBUAE's own questions today, given that insurers are already named inside the guidance's scope."
Building the ACIS four layers is not a compliance project undertaken on faith that a rule is coming; it is capability that a CBUAE-supervised insurer arguably needs regardless, and that other Gulf insurers will need in the near term if the regional pattern holds.
Treating this as an operating-model investment rather than a wait-and-see compliance question is, in our experience, what separates institutions that absorb a new supervisory expectation smoothly from those that scramble.
Conclusion
CBUAE's February 2026 guidance note is specific enough - on governance, explainability, human oversight and vendor accountability - to function as a practical checklist today, and it already places insurance providers inside its scope. What it has not yet done is translate those principles into an insurance-specific rulebook the way CBUAE has for solvency or reinsurance.
Given Qatar Central Bank's independent convergence on similar principles and the UAE regulatory community's history of sectoral follow-through on cross-sectoral technology guidance, source[code] reads the current gap as a timing question rather than a scope question. Talk to us!
Insurers that build AI Consumer-Impact Stack-level capability now are positioned to demonstrate compliance whenever, and in whatever form, insurance-specific expectations arrive - and to operate more defensibly under CBUAE's existing LFI-level guidance in the meantime.
Frequently Asked Questions
Does CBUAE's AI guidance apply to insurance companies in the UAE? Yes. The guidance note's scope explicitly covers "licensed financial institutions, including insurance providers," so UAE-licensed insurers fall within its stated scope as issued (Central Bank of the UAE, 2026a).
Has CBUAE issued insurance-specific AI rules? No. As of this research, CBUAE's published insurance-sector guideline library - covering solvency, reinsurance, Takaful, motor and health TPAs - contains no AI-specific circular; the AI principles currently apply at the general licensed-financial-institution level (Central Bank of the UAE, n.d.).
What are the core requirements in CBUAE's guidance note? Six practical areas: a documented, board-accountable AI governance framework; fairness and non-discrimination testing; transparency and bilingual (Arabic/English) disclosure for high-impact decisions; human oversight with consumer review rights; data quality and privacy-by-design; and non-delegable accountability for outsourced AI models (Central Bank of the UAE, 2026a; Pinsent Masons, 2026).
Is this the same as APRA's approach in Australia? It rhymes rather than matches. APRA's supervisory letters on AI and operational risk preceded its binding CPS 230 standard, a sequence source[code] examined separately on 4 September. CBUAE's note is a guidance document, not a binding prudential standard, and no Gulf regulator has announced an insurance-specific AI standard on CPS 230's model - the parallel is in the sequencing pattern (guidance before codification), not in current legal force.
Have other Gulf regulators issued AI guidance for financial services? Yes. Qatar Central Bank issued an Artificial Intelligence Guideline for QCB-licensed financial firms in September 2024, independently arriving at governance, risk-disclosure and board-accountability principles comparable to CBUAE's (Pinsent Masons, 2024). This analysis did not confirm a comparable AI-specific document from Saudi Arabia's SAMA or Bahrain's Central Bank at the time of research.
What should a Gulf insurer's risk or compliance team do now? Build evidence against CBUAE's existing language rather than waiting for an insurance-specific circular: a full inventory of AI-influenced decisions, plain-language bilingual explainability for each, a measurably functioning human-override pathway, and current (not one-time) vendor governance evidence - the four components of source[code]'s AI Consumer-Impact Stack described above.
Reference List
Central Bank of the UAE (2026a) Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E. Available at: https://rulebook.centralbank.ae/en/rulebook/guidance-note-consumer-protection-and-responsible-adoption-and-use-artificial-intelligence (Accessed: 9 September 2026).
Central Bank of the UAE (2026b) CBUAE Issues Guidance Note to Protect Consumers and Ensure Responsible Use of Artificial Intelligence in the Financial Sector. Press release. Available at: https://www.centralbank.ae/media/mykn5fue/cbuae-issues-guidance-note-to-protect-consumers-and-ensure-responsible-use-of-artificial-intelligence-in-the-financial-sector-en.pdf (Accessed: 9 September 2026).
Central Bank of the UAE (n.d.) Insurance Guidelines. Available at: https://www.centralbank.ae/en/our-operations/supervision/insurance-guidelines/ (Accessed: 9 September 2026).
DFSA (2021) UAE regulatory authorities jointly issue "Guidelines for Financial Institutions Adopting Enabling Technologies". Available at: https://www.dfsa.ae/news/uae-regulatory-authorities-jointly-issue-guidelines-financial-institutions-adopting-enabling-technologies (Accessed: 9 September 2026).
Pinsent Masons (2024) Qatar Central Bank issues guidelines to ensure ethical use of AI in the financial sector. Out-Law. Available at: https://www.pinsentmasons.com/out-law/news/qatar-central-bank-guidelines-ethical--ai-financial-sector (Accessed: 9 September 2026).
Pinsent Masons (2026) UAE Central Bank publishes responsible AI guidance for financial sector. Out-Law. Available at: https://www.pinsentmasons.com/out-law/news/uae-central-bank-responsible-ai-guidance-financial-sector (Accessed: 9 September 2026).
The National (2026) UAE Central Bank issues new guidelines on the use of AI in financial sector. Available at: https://www.thenationalnews.com/business/banking/2026/02/23/uae-central-bank-issues-new-guidelines-on-the-use-of-ai-in-financial-sector/ (Accessed: 9 September 2026).