Agentic AI governance in the UAE – Part 2

Agentic AI governance in the UAE – Part 2

Author: Gerard Rahman
              Blesson Mathew

              

Explore the governance, risk and assurance implications of agentic AI with Gerard Rahman, Partner at BDO UAE and a Fellow Member of the Association of Chartered Certified Accountants of UK and Blesson Mathew, Manager in Digital Transformation at BDO UAE. In Part 2 of this series, they examine how organisations across the UAE can prepare for increasingly autonomous AI systems.

Part 1 established where accountability sits when an autonomous system decides and what breaks in the control environment when AI executes rather than recommends. Part 2 turns to what organisations should be doing about it - in compliance, at board level and across the workforce.
 

Why can’t AI governance wait?

Regulation does lag technology and it almost always will. But the short answer is straightforward: build the governance infrastructure now, before it becomes mandatory.

BDO UAE's AI policy has taken a clear position: it advocates a proactive governance approach rather than waiting for regulation to catch up. The whole philosophy is that governance, oversight and evidence collection should be established before problems arise.

Boards and senior leadership teams should also avoid treating AI as a purely technical topic. Decisions about autonomy, accountability, risk appetite, ethical boundaries and acceptable use are governance decisions.

Before getting into the governance checklist, Gerard Rahman makes one important point:
 

“Agentic AI governance cannot be separated from data governance. Most autonomous systems process, analyse or make decisions using personal data, employee data, customer data or commercially sensitive information. That means organisations should not view AI governance as a future regulatory issue - they should already be considering their obligations under existing laws such as the UAE Personal Data Protection Law and, where applicable, the DIFC Data Protection Law.”


AI governance cannot be separated from data governance

Even where AI-specific regulation is still evolving, many of the underlying obligations already exist today. Organisations should be able to explain how personal data is being used, maintain appropriate security controls, govern cross-border data transfers, assess the impact of automated processing activities and ensure accountability for decisions supported by AI. In practice, some of the most immediate AI risks are often data-governance risks rather than technology risks.

 

9 practical steps for governing agentic AI

  1. Know what you actually have. Build a full GenAI inventory and include shadow AI: the tools people are quietly using without telling anyone. Map each use case to the business processes, risks and key controls it touches.
  2. Classify by impact and gate the high-impact cases. Rank use cases by impact level. Anything high-impact should require a formal AI Impact Assessment and prescribed risk controls before deployment, not bolted on afterwards.
  3. Assign an oversight mode to every use case. Human in the loop, on the loop, or out of the loop, decided by risk and documented. Fully autonomous operation is reserved for low-risk processes.
  4. Rebuild segregation of duties for non-human actors. Separate identities for generation and approval, short-lived task-scoped credentials and runtime policy evaluation at each release point.
  5. Turn on logging and traceability before go-live. Capture model versions, prompts, key inputs and outputs and approvals. That is the evidence base that makes governance and audit possible at all and it is very hard to reconstruct after the fact. Monitor model performance continuously: AI systems change behaviour over time as data patterns, environments and user interactions evolve. Establish performance thresholds, monitor for model drift, investigate unexpected outputs and define escalation procedures when outcomes fall outside approved parameters.
  6. Adopt ISO/IEC 42001 as your management-system spine. It provides a recognised structure rather than a home-made one. Dubai Police has already certified its AI Management System against the standard, so there is regional precedent.
  7. Control the supply chain. Organisations are often inheriting an entire AI ecosystem: foundation-model providers, cloud platforms, embedded third-party models, API providers, software vendors, training datasets and external support providers. Each component can introduce operational, security, legal, privacy and compliance risk. The organisation deploying the system remains accountable for outcomes regardless of who built the underlying technology. Due diligence, contract management, security assessment, ongoing monitoring and documented controls over third-party providers should form part of every AI governance programme.
  8. Prepare explainability and redress in advance. Plain-language explanations of how AI is used, disclosure of the logic behind AI-assisted decisions, a route to request human review and accessible channels to challenge or complain.
  9. Put names against systems. Assign clear accountability through designated Deployer and Operator roles and for high-risk processing, appoint an Autonomous Systems Officer responsible for governance, risk reviews, compliance oversight and engagement with senior management.
BDO UAE team emphasises that organisations do not need to wait for new regulations to begin strengthening AI governance. In practice, this means identifying and classifying AI systems, assigning oversight responsibilities, maintaining clear segregation of duties, ensuring comprehensive audit trails, certifying systems where appropriate, managing third-party risks, establishing redress mechanisms and clearly defining accountability. According to the experts, implementing these foundations today is significantly more effective and less costly than attempting to retrofit governance controls at a later stage.

 

How will agentic AI reshape the workforce?

Gerard Rahman explains:
 

“I want to start with where BDO UAE's AI policy sits on this. The policy does not frame AI as a workforce-reduction exercise. It positions AI as a strategic enabler - something that lifts productivity, quality, innovation and professional effectiveness. And it expects AI literacy and responsible AI use to become core professional skills across the whole organisation. The implication is simple: jobs evolve, they don't just disappear. People move toward supervising and validating AI outputs, applying professional judgement and scepticism, managing exceptions and risks and designing and governing the AI-enabled processes themselves.”


BDO sums up its whole vision in one phrase - AI-Assisted. Human-Led. Trust-Driven.

What should not change is the need for professional judgement. AI may help people reach conclusions faster, but responsibility for challenging assumptions, exercising scepticism, considering context and making difficult decisions remains fundamentally human. In many professions, judgement becomes more important as automation increases, not less.

 

What the global evidence shows

The World Economic Forum's Future of Jobs Report 2025 projects 170 million jobs created and 92 million displaced by 2030, a net gain of 78 million. The more useful signal sits underneath the headline: 22% of current jobs face disruption and nearly 40% of required skills will change. Employers are moving on both fronts at once - 77% plan to upskill their people, while 41% expect to reduce headcount where automation genuinely takes over the task.

The ILO's finding is arguably more useful still. Generative AI is more likely to augment jobs than to destroy them and the real impact lands on job quality - work intensity and autonomy - rather than on whether the job exists at all. Clerical work is the most exposed category, with close to a quarter of its tasks highly exposed.

 

The role that is emerging

The shift is from human in the loop to human on the loop. Agents execute routine decisions autonomously and people become operators, supervisors and architects: setting strategic priorities, interpreting outputs, ensuring ethical compliance and stepping in on complex, unprecedented or morally sensitive cases.

Abu Dhabi frames its own programme the same way - AI adoption as a workforce transformation initiative creating new career pathways, so that AI enhances rather than replaces human-centred public service.

 

Two risks that never make the headlines

The OECD names both and both are worth watching closely.
  • Automation bias - people begin over-trusting the machine's output and stop asking questions.
  • Digital Taylorism - work quietly intensifies and individual autonomy erodes.
The OECD's recommendation is pointed: HR leaders need to become smart buyers of AI, with the capability to interpret and challenge AI results rather than simply accept them.

 

The readiness gap

Regional survey data suggests the gap is wide. Most organisations have not yet redesigned their roles around AI, while a large majority are investing in it and only a small minority have moved from pilots to full-scale deployment. The result is high ambition, high investment and roles still built for a pre-agentic workflow.

Four capabilities close that gap.
  • Data and API readiness. A substantial share of organisations still lack the data maturity to support agentic operations.
  • Agent identity and machine-to-machine trust. Treat agents as workforce members with defined roles, credentials and audit trails.
  • Data-residency architecture. Abu Dhabi Government Copilot licences, for example, are provisioned with Advanced Data Residency to keep processing inside UAE borders.
  • Certification. The Dubai AI Seal is becoming the qualification for supplying AI services to Dubai Government and comparable expectations are emerging across the region.

Blesson Mathew puts it in one line:
 

“The workforce question is whether you redesign roles around supervision, judgement and exception-handling before the agents arrive.”


One piece of advice for a UAE business or government entity right now

“If I had to boil it down to one thing, it would be this: build your governance before you scale your AI - not after.” – mentions Gerard Rahman.


The point is that organisations should stop treating AI as a technology initiative and start treating it as an enterprise risk issue. The most significant AI failures are rarely caused by the model itself. They are usually caused by weaknesses in governance, data quality, oversight, accountability or decision-making. For that reason, AI risk should be integrated into the organisation's existing Enterprise Risk Management framework alongside operational, financial, regulatory, cyber-security and reputational risks rather than being managed as a standalone technology project.

It's tempting to chase adoption first and worry about the guardrails later. But everything the policy points to says the opposite. The more autonomy you give an AI system, the more you need strong human oversight, clear accountability, rigorous risk management and continuous monitoring sitting underneath it. AI shouldn't just be switched on - it should be formally onboarded, approved, monitored across its whole lifecycle and deployed only with the right controls and a responsible owner attached to it.

And here's the practical reason this matters so much: designing governance in from day one is dramatically cheaper - and dramatically more effective - than trying to bolt it on once the system is already live. Retrofitting controls after the fact is expensive, messy and usually too late.

 

What controls are needed to govern agentic AI?

  1. An AI management system aligned with ISO/IEC 42001.
  2. An agent inventory, with an impact classification for every use case.
  3. Audit trails established before the system goes live, so every action can be traced later.
  4. Segregation of duties re-engineered, so the approver sits outside the agent's execution path.
  5. Every use case mapped to an oversight mode - in the loop, on the loop, or out of the loop.
  6. A named, accountable officer for every agentic service.
 

Why now, rather than when the rules land

The technology will always move faster than the regulation and that gap is not closing. But waiting is not necessary, because the governance frameworks already exist and they are already good enough to keep pace.

Historically, technological change has rewarded organisations that scale quickly. Agentic AI is different. In an agentic environment, speed without governance amplifies risk as fast as it amplifies productivity. The organisations that succeed will be those that scale capability and control at the same time.

Adopt AI aggressively and govern it more aggressively still. The organisations that win will not be the ones with the most AI. They will be the ones with the clearest accountability, the strongest oversight and the most mature governance.

 

How BDO UAE can help

At BDO UAE, our teams are equipped with the knowledge, skills and practical experience to help government entities and private-sector organisations strengthen the governance, risk and assurance foundations of AI adoption. We support organisations with AI governance frameworks aligned to ISO/IEC 42001, AI risk and impact assessments, internal controls and segregation of duties for agentic environments, third-party and vendor risk across AI supply chains, data protection and PDPL readiness and assurance over AI-enabled processes.

CONTACT US