Authors: Gerard Rehman
Blesson Mathew
Gerard Rahman, Partner at BDO UAE and a Fellow Member of the Association of Chartered Certified Accountants of UK, together with Blesson Mathew, Manager in Digital Transformation at BDO UAE, sat down to unpack what the agentic AI shift means in practice — for the government entities driving it and for the businesses operating around it.
The UAE Government's Agentic AI Framework announced on 23 April 2026 explains how much government runs without a human in the loop — with a target of 50% of sectors, services and operations within two years. His Highness Sheikh Mohammed Bin Rashid Al Maktoum, Vice President, Prime Minister and Ruler of Dubai described AI as the government's "executive partner" — a system that analyses, decides, executes and improves in real time.
In Part 1, Gerard Rahman together with Blesson Mathew discuss 3 questions: why the wave of agentic AI governance is structurally different from everything that preceded it, who carries accountability when an autonomous system makes the decision and what breaks in the control environment when AI executes rather than recommends.
The UAE's next leap: from digitalisation to AI execution
For the last 20 years, everything the UAE did was about digitising government. Moving services online, e-forms, apps, UAE Pass, paperless offices and Dubai's big headline win, scrapping more than 336 million sheets of paper. And success was always measured the same way — how much of government is online? Even the 2025 UAE Digital Government Strategy set targets like 100% of services digitised end-to-end and 90% citizen satisfaction. As recently as January 2026, the most advanced use of AI at the federal level was basically an advisory seat at the Cabinet table. AI was there to advise.4 ways agentic AI is changing the UAE government
- From AI advising decisions to AI executing transactions. Agentic systems now execute operational processes and decision-making, manage operations and perform independent sequences of actions with minimal human intervention. Ajman has already demonstrated highly automated trade-licensing services along these lines.
- From digitising the existing process to redesigning it around what AI can do. Entities are no longer simply moving established workflows online.
- From front-office, citizen-facing services to back-office operations. The UAE's agentic AI implementation programme prioritises ten internal operational domains, including human resources, procurement and contracts, financial and administrative affairs, internal audit, legislative affairs, digital transformation and technical support, institutional communication and media, facilities management, maintenance and shared operational processes across ministries.
- From training as a checkbox to training as a national programme. Federal AI training has moved from around 10% of the workforce to one of the largest AI workforce transformation initiatives the UAE Government has undertaken.
The measure of success has changed
The UAE Government's Agentic AI Framework announced on 23 April 2026 even changed the question being asked. Now it asks "how much of government runs without a human in the loop?" — with a target of 50% of sectors, services and operations within two years. Sheikh Mohammed described AI as the government's "executive partner" — a system that analyses, decides, executes and improves in real time.And here's the fifth difference that makes all of this credible: accountability is now personal. The performance of ministers, directors-general and entities will be assessed against their ability to adopt the transformation
“Now, I'll be honest about one caveat. Practitioners on the record are cautious — that 50% target may only be reachable if you count "AI-assisted" and "AI-enabled" services, because fully autonomous decision-making in complex areas is still constrained by trust, governance and accountability challenges. The benchmark has moved from digital maturity to agentic readiness — from putting services online to preparing institutions for AI agents to do the work safely and accountably.” – mentions Gerard Rahman.
So, to sum it up in one line: previous pushes changed how citizens access government. This one changes who actually does the work — and it's being measured and appraised, on exactly that. And that's exactly why governance, accountability and human oversight matter far more now than in any earlier wave. As BDO UAE's own Responsible AI policy puts it — "greater autonomy demands stronger human oversight, clearer accountability and more rigorous monitoring, not less."
If an autonomous system decides, who is accountable?
“Let me give you the short answer first, because it's actually very clear: the entity that deployed the system. Autonomy is not a defence. The AI doesn't become the accountable party — it never does.” – explains Blesson Mathew.
The reality is that autonomy changes who performs the task, but it does not change who owns the outcome. Organisations can delegate execution to an AI system, but they cannot delegate accountability. That distinction will become one of the defining governance principles of the agentic economy.
BDO AI policy states plainly that "humans remain in control" and that accountability for AI outcomes must be clearly assigned. You cannot delegate responsibility for outputs and decisions to an AI system. Ultimate responsibility stays with the responsible individual and the leadership overseeing the process. For a government entity, that means accountability stays with the agency deploying the system and the officials designated to oversee it.
Global frameworks converge on the same answer
The OECD AI Principles establish that those involved in developing, deploying and operating AI systems remain accountable according to their respective roles, supported by traceability and systematic risk management. UNESCO reinforces this position by stating that responsibility throughout an AI system’s lifecycle must always be traceable to a person or legal entity, as AI cannot replace ultimate human responsibility.Frameworks and legal approaches adopted in other jurisdictions reflect the same underlying principle: organisations deploying autonomous systems, together with the people responsible for overseeing them, remain accountable for their actions and outcomes. An AI system’s autonomy does not interrupt or remove the chain of accountability.
Accountability is a trust requirement. Citizens may accept decisions that are automated. The long-term success of agentic government depends not only on efficiency gains but on whether people retain confidence that there is always a responsible person, a mechanism for challenge and a clear route to redress.
DIFC Regulation 10 and the Deployer
DIFC Regulation 10 is the most advanced autonomous-systems accountability regime in the country. It deems the Deployer — whoever the system operates under the authority of, or for the benefit of — to be the controller. As organisations adopt increasingly autonomous AI systems, accountability remains a key governance consideration. Effective oversight often includes maintaining clear records of AI use cases, documenting decision-making processes, establishing appropriate human review mechanisms and defining responsibilities for monitoring and managing AI-related risks.The procurement accountability gap
One commonly identified problem is that entities buy algorithmic architectures from vendors, then disclaim knowledge of how those systems work internally. The result is an accountability gap — algorithmic systems shaping entities decisions with no clear mechanism of accountability attached.In practice, that translates into two obligations.
- Designate a named accountable individual for every agentic service. Not a committee. A person, whose name is attached before the service goes live.
- Allocate responsibility explicitly through vendor agreements. Contracts should clearly address accountability for data quality, model behaviour and human-escalation thresholds. Relying on legacy contract terms is risky, because the financial impact of a wrong AI decision can far exceed the vendor's liability cap.
How should internal controls change when AI executes rather than recommends?
When AI moves from recommending to executing, three things break and each needs re-engineering.But before we get into those, let us frame it with BDO UAE's AI policy, because it sets the direction:
“Greater autonomy requires stronger governance, not weaker. That sounds obvious, but it flips the instinct most people have. The natural assumption is that if the AI is doing more, we can relax — actually it's the opposite. BDO's policy calls for defined human oversight for every use case, continuous monitoring across the lifecycle, explicit risk assessments before deployment, comprehensive logging and incident reporting and human checkpoints for consequential actions. And the practical shift underneath all of that is this: controls should not just review AI decisions after they happen. They should actively monitor and limit what the AI can do while it is operating.” – observes Gerard Rahman.
First — segregation of duties collapses
Segregation of duties assumes different actors at each step: one party prepares, another approves, a third executes. That logic falls apart the moment a single agent can both generate an action and release it. Analysts describe create-plus-approve authority held by one agent as a toxic combination, turning a safeguard into a self-confirming loop.The subtle trap is this: a workflow that displays "approved" does not prove that any meaningful independent approval took place. Self-approval remains a control failure, however convincingly the system reports a green status.
Segregation of duties therefore must be re-engineered for non-human actors.
- Separate identities for generation and approval. The agent that creates a transaction should not be the agent that approves it. As one employee prepares a payment and another approves it, different AI identities or a human reviewer should perform these roles.
- Short-lived, task-scoped credentials. Give an agent only the access it needs, only for as long as it needs it. Credentials that expire automatically on task completion limit the damage when something goes wrong.
- Runtime policy evaluation rather than static permissions. Check authorisation at the moment the action is performed. The system should evaluate whether the agent is authorised to perform that specific action, at that time, under those conditions.
- An approver outside the agent's execution path. This is the most important safeguard. The agent should be unable to approve its own work, alter approval rules or influence the approval process. Final approval should sit with a separate person, team or independent system the agent cannot reach.
Second — assurance must become continuous
Traditional audits and control reviews are periodic. That approach does not hold when AI is making decisions in real time.Every action an agent takes should be logged and monitored continuously, so unusual behaviour, errors or unauthorised actions are detected quickly. It is closer to supervising an employee than to reviewing a quarterly control sample. Frameworks such as COSO's AI guidance and ISO/IEC 42001 make the same point: AI systems require ongoing oversight and governance across their lifecycle.
There is a second shift alongside it — applying the Three Lines Model to AI-enabled operations. The first line remains responsible for managing the AI-enabled process and the risks arising from it. The second line establishes governance, policies, monitoring and risk oversight. The third line, Internal Audit, provides independent assurance over the design and effectiveness of AI controls.
What changes is that each line now has to understand the behaviour of the autonomous systems operating within it. Internal Audit will increasingly be expected to assess model governance, agent permissions, decision traceability, oversight controls and the effectiveness of monitoring activities. This changes the nature of assurance itself. Historically, Internal Audit tested the effectiveness of controls operated by people. Increasingly it will need to evaluate controls operated by autonomous systems. The audit universe is expanding.
Third — the human checkpoint needs a defined mode
This is the step most organisations skip. Saying that a human is involved is not an oversight model. The applicable model has to be specified. UAE Central Bank guidance frames it as three modes.- Human in the loop — a person approves before the action executes.
- Human on the loop — a person supervises and can intervene.
- Human out of the loop — the agent acts alone.
At BDO UAE we increasingly treat AI risk as an enterprise-wide governance issue rather than an IT issue. As agentic systems become embedded in finance, procurement, human resources, customer service and regulatory processes, governance can no longer sit solely with technology teams. Business leadership, risk, compliance, information security and Internal Audit all have a role in providing effective oversight.
Part 2 will set out what compliance functions, boards and HR leaders should be doing about the latest developments in AI governance, digital transformation and emerging regulatory expectations in the UAE.
FOLLOW BDO UAE ON LINKEDIN

