The Central Bank Already Wrote Your Agent Policy
Co-Founder & CEO of CLRT
If you sit on the executive floor of a UAE bank, a payments company or an insurer, you have probably given the board the same answer more than once this year: we are ready to run agents, we are waiting for regulatory clarity. It is a comfortable answer, and since 11 February 2026 it has been wrong. That day the Central Bank of the UAE issued its guidance note on the responsible adoption and use of artificial intelligence by licensed financial institutions, and it applies, in the regulator's own words, to all of them, "including insurance providers". The note does not withhold permission. It defines how far a machine may run alone, names the records it expects you to keep, and quietly moves the constraint from the regulator's desk to yours.
Start with the clause everyone was waiting for, because it already exists. The guidance describes three models of human oversight and quotes them plainly. Human-in-the-loop, where the AI "provides recommendations but a human decision maker retains full authority to approve or reject the outcome". Human-on-the-loop, "where the AI works autonomously for routine tasks, while a human monitors outcomes and can intervene where necessary". And human-out-of-the-loop, "where the AI operates without direct human involvement, which should only be utilised for low-risk, non-material processes with appropriate controls in place". The level of involvement, it adds, "should be commensurate with the identified and potential risks posed to a consumer", and a consumer must be able to request human review of any AI decision. That is the whole permission question, answered. Nobody is deciding whether you may run an agent. The regulator has drawn the zones, and left you to prove which process belongs in which.
The obligations that come with the answer are where the real work sits. The note asks for "an inventory of all AI models, systems or technologies developed or deployed", carrying "as a minimum model name, purpose, risk rating", kept in line with the central bank's existing Model Management Standards. It asks for processes to "rate the risk of each AI system" in use. It asks that deployed AI be tested "once a year or each time a model is upgraded, materially changed or a new one is introduced", specifically to find and remove embedded bias. It asks that automatic updates to AI tools be tested before they take effect. And it places responsibility with senior management and the board, not with the technology function. None of this is exotic. It is the ordinary discipline of a model risk framework extended to a category of software most institutions have never catalogued. That is precisely why so few can answer it today.
The third obligation is the one that will surprise procurement. The note tells institutions to "consider and try to utilise a range of AI providers if feasible, to try to ensure there is no over reliance on one AI system or provider". Third-party models are to be held to "the same standards of fairness, explainability and robustness as in-house models". Contracts should carry audit rights, and deployments of a third-party provider's models should include annual cybersecurity reviews by independent parties. Read together, the central bank has described an engine-agnostic architecture without using the phrase. An institution that has bought one vendor's agent platform, wired its workflows to that vendor's model and accepted that vendor's update cadence has not simply made a procurement choice. It has adopted a posture the regulator has asked it to avoid, and the cost of unwinding that is engineering, not paperwork.
Now put the obligations beside the people available to meet them. Evident, a research firm that sells an AI index for banks and scores them on publicly disclosed evidence, published its first Middle East and Africa edition in June 2026, covering 25 banks. Its banking brief states that Emirates NBD and First Abu Dhabi Bank "employ two-thirds of all the Gulf's bank employees focused on AI implementation". Across the 25 banks, AI development talent relative to headcount is "half that found in Evident's benchmark of global banks". Those same 25 banks have publicly documented "more than 50 AI use cases" in two years, which is roughly one per bank per year. UAE banks account for almost a quarter of those use cases; South African banks account for almost half. The people who could build the inventory, run the annual bias test and sustain a multi-vendor posture exist in the region. Two institutions employ most of them.
Even the bank at the top of that ranking is still assembling its capability. In July 2023 Emirates NBD announced that more than a thousand of its developers had been given a coding assistant. Three years on, by the bank's own account as compiled by Evident, AI tools author more than a quarter of its code, and its strongest documented outcome is an interview-automation tool in human resources credited with 13,000 hours saved. On 10 August 2026 the bank announced a partnership with the Dubai Future District Fund to gain "a curated pipeline of enterprise-grade FinTech and AI solutions" and "structured pilots". The region's most AI-advanced bank is, on its own description, still sourcing pilots. The guidance applies identically to the insurer with three hundred staff and a claims chatbot switched on by a vendor last spring. The regulator wrote one policy for both. Only one of them can currently read it back.
Nobody is deciding whether you may run an agent. The regulator has drawn the zones. Which zone each process sits in is yours to prove.
A deeper dive
The reason the inventory is hard is that the note's definition is wider than the mental picture most executives carry. "All AI models, systems or technologies developed or deployed" does not mean the fraud model the risk team built and the chatbot the digital team launched. It means the scoring add-on inside the card platform, the document reader the operations vendor bundled last year, the assistant a software supplier switched on in the core system through an automatic update, and the generative tools staff are using with or without a licence. Each is a model with a purpose and a risk to a consumer, and each needs a rating and an owner. Producing that list is not a form-filling task. It requires someone who can read a vendor's architecture, work out what the model actually decides and for whom, and translate that into a risk rating a board can defend. In most licensed institutions that person does not exist, or exists once, and the annual re-test the note describes turns a one-off effort into a standing function with nobody assigned to it.
The second-order trap is classification, and it cuts both ways. The obvious temptation is to declare every process human-in-the-loop, because a human approver seems to answer every question. But an approver who accepts four hundred recommendations a day and has never rejected one is not "retaining full authority"; the process is running on the loop in practice while the inventory says in the loop on paper, and a supervisory visit will see the difference. The opposite error is to read "low-risk, non-material processes" so narrowly that nothing qualifies, so agents are parked in pilots indefinitely and the institution forfeits the very zone the regulator opened. The note is written to be proportionate, "commensurate with the size, nature and complexity" of the institution, which means the right classification is decided process by process, with evidence of what the humans in each loop actually do. That judgment, applied across a real operation, is the agent policy. The central bank has supplied the vocabulary. It cannot supply the classification, and neither can a vendor whose interest is in the widest possible reading of routine.
Work with CLRT
This is the work CLRT does with regulated institutions in the UAE: not lobbying for permission that has already been granted, but building the thing the permission is conditional on. We inventory what is actually running, rate it, classify each process against the three oversight models with evidence rather than aspiration, and engineer the verification and multi-vendor posture the guidance describes so an agent can be defended in front of a supervisor, not just a steering committee. If you are the executive giving the board the waiting answer, the CLRT Ascent diagnostic at ascent.clrtstudio.com is where you find out how far your institution is from being able to read the policy back.

Vishal Sachar is the Co-Founder and CEO of CLRT, where he helps UAE businesses make sense of applied agentic AI and put it to work. He writes on agentic systems, AI governance, and the economics of automation. Reach him at vishal@clrtstudio.com or on LinkedIn.


