The regulator's view of generative AI in MENA financial services
How MENA financial regulators view generative AI — covering CBUAE, SAMA, DFSA, ADGM, and CBB frameworks shaping enterprise deployment.

The question financial institutions across the Gulf ask most often is not whether to deploy generative AI but whether the regulator will accept it. The answer varies significantly depending on which jurisdiction a firm operates in, what function the AI touches, and how the deployment is architected. The regulator's view of generative AI in MENA financial services is not a single position — it is a mosaic of national strategies, sandbox frameworks, prudential circulars, and informal supervisory expectations that are evolving faster than most compliance teams can track.
How MENA Regulators Think About Generative AI Risk
Financial regulators in the region share a common analytical framework even when their formal guidance differs. They assess generative AI risk across four dimensions: model opacity, data governance, consumer protection, and systemic contagion. Model opacity is the primary concern — regulators want to know how a decision was reached, not just what the decision was.
This concern is not abstract. When a credit decision, fraud alert, or AML flag is generated by a large language model, the institution must be able to explain that output to an examiner. Regulators trained on Basel-aligned model risk management frameworks have transplanted that expectation directly onto generative AI systems, even though the underlying mechanics are fundamentally different from classical statistical models.
Data governance is the second pillar. Every MENA regulator with published AI guidance has emphasized that training data, inference data, and output logs must be localized, auditable, and protected. This is not purely a cybersecurity posture — it reflects sovereignty concerns about where financial data travels and who can access it.
Consumer protection rounds out the framework. Regulators are acutely aware that generative AI deployed in customer-facing roles can produce hallucinations, discriminatory outputs, or advice that lacks the disclosures required under existing financial promotion rules. The supervisory instinct is to treat AI-generated customer communication as a regulated activity from day one.
The Central Bank of the UAE (CBUAE) Position
The CBUAE has positioned itself as a progressive regulator that supports AI adoption while maintaining prudential guardrails. Its published guidance on digital banking and innovation draws heavily from its Digital Banking Standards framework, which requires licensed institutions to document AI model inventories, conduct impact assessments before deployment, and maintain human oversight for material decisions.
The CBUAE has not yet issued a standalone generative AI circular as of the knowledge available here, but its broader model risk management expectations — drawn from global standards including SR 11-7 guidance adapted for the UAE context — clearly apply. Institutions operating under CBUAE supervision have understood informally that generative AI deployed in credit, treasury, or customer service functions requires documentation equivalent to any other model in the institution's risk inventory.
The CBUAE has been particularly attentive to the use of AI in AML and sanctions screening. Its supervisory communications have emphasized that automated systems used for financial crime detection must have human review mechanisms and cannot be treated as black-box solutions. Financial institutions that have replaced rule-based screening with AI-driven approaches have been asked to demonstrate that the AI's decision logic is explainable to compliance staff.
One area where the CBUAE has signaled flexibility is in its regulatory sandbox, which has hosted several fintech firms testing AI-driven onboarding, credit scoring, and payment anomaly detection. Sandbox participation does not grant permanent approval, but it signals the regulator's appetite to engage rather than prohibit.
The Saudi Central Bank (SAMA) Framework
SAMA has been among the more structured regulators in the region when it comes to AI governance. Its Supervisory Technology Framework, along with guidance issued through the Fintech Saudi initiative, has created a clearer runway for institutions seeking to deploy AI in regulated functions. SAMA has also issued cloud computing guidelines that have direct implications for how generative AI infrastructure must be hosted within the Kingdom.
SAMA's position on AI in credit is particularly instructive. The regulator requires that AI-based credit decisions be explainable to the borrower upon request, mirroring the spirit of adverse action notice requirements in other jurisdictions. This places a hard constraint on any generative AI deployment in consumer lending: the system must be able to produce a plain-language rationale for its output, not merely a confidence score.
For capital markets participants, SAMA's coordination with the Capital Market Authority (CMA) has produced expectations around AI use in investment advisory, algorithmic trading, and market surveillance. The CMA has signaled that AI systems used in investment decisions are subject to the same suitability and disclosure requirements as human advisors. This has practical implications for firms using large language models to generate investment recommendations.
SAMA's data localization requirements are among the strictest in the region. Financial institutions under its supervision must ensure that customer financial data used to train or run AI models remains within Saudi Arabia's borders. This requirement effectively disqualifies many global cloud-based AI platforms whose inference infrastructure sits outside the Kingdom, creating a structural advantage for locally hosted or sovereign AI infrastructure.
The DFSA and ADGM Financial Services Regulatory Authority (FSRA)
The Dubai Financial Services Authority and the ADGM Financial Services Regulatory Authority operate within the free zone jurisdictions of DIFC and ADGM respectively. Both regulators have been deliberately forward-leaning, recognizing that their jurisdictions compete globally for financial services business and that overly restrictive AI rules would be a competitive disadvantage.
The DFSA has published innovation testing licenses and innovation testing conditions that allow firms to experiment with AI in regulated activities under supervisory observation. Its published guidance on technology risk emphasizes operational resilience, third-party risk management, and the need for firms to understand the AI tools they procure — not just the outputs those tools produce.
The FSRA at ADGM has gone further in engaging with the generative AI question specifically. Its published fintech guidance addresses AI model risk through the lens of conduct risk, emphasizing that firms must not use AI in ways that could lead to market manipulation, mis-selling, or unfair customer outcomes. The FSRA has also engaged publicly with questions of AI liability — asking who is responsible when an AI system deployed by a regulated firm causes a customer loss.
Both regulators have shown particular interest in AI governance frameworks as a condition of approval rather than as a post-deployment compliance exercise. Firms seeking DFSA or FSRA authorization for AI-driven products are increasingly expected to present a governance document that describes the model, its training data, its validation process, and the escalation path when the model produces an anomalous output.
The Central Bank of Bahrain (CBB) and Its Regulatory Sandbox
Bahrain's Central Bank has operated one of the region's earliest fintech sandboxes and has been a consistent early mover on AI regulation in financial services. The CBB issued its Cloud Computing Framework and its Volume 5 guidelines for financial institutions, both of which establish baseline expectations for how technology — including AI — must be governed.
The CBB's sandbox has hosted AI-driven insurance underwriting, digital lending, and payment processing firms. What distinguishes the CBB's approach is its willingness to engage at a technical level. Sandbox participants have reported that CBB examiners ask detailed questions about model architecture, not just business outcomes. This signals that the regulator is building internal capacity to evaluate AI systems rather than relying entirely on institutional self-attestation.
Bahrain's position within the Arab world's fintech ecosystem gives the CBB an outsized influence relative to the size of its financial sector. Firms that successfully navigate the CBB sandbox often use that experience as a template for engagement with SAMA and the CBUAE. The CBB's practical, dialogue-based approach contrasts with the more document-heavy engagement patterns of larger jurisdictions.
The limitation for international firms looking to use Bahrain as a testing ground is that CBB sandbox approvals do not transfer to other jurisdictions. A firm approved under sandbox conditions in Bahrain must restart its regulatory engagement in Saudi Arabia or the UAE from the beginning, which creates duplication of effort for firms planning multi-jurisdictions operations.
Qatar Financial Centre Regulatory Authority (QFCRA)
The QFCRA governs financial institutions operating within the Qatar Financial Centre and has been refining its approach to AI governance as Qatar's National AI Strategy has matured. The QFCRA's primary concern with generative AI has been the integrity of financial advice and the protection of retail investors who interact with AI-driven advisory tools.
Qatar's approach is shaped partly by its sovereign wealth context. The Qatar Investment Authority and its affiliated financial institutions operate at a scale where AI failures carry systemic risk. The QFCRA has therefore emphasized stress testing and scenario analysis for AI systems used in portfolio management, risk assessment, and client communication.
The QFCRA has also been attentive to the reputational dimension of AI failures. In a jurisdiction where the government's ownership stake in major financial institutions is high, an AI-driven mis-selling scandal would carry political as well as financial consequences. This has made the regulator particularly cautious about approving generative AI in any customer-facing role without extensive prior validation.
For firms that operate across both the QFCRA and DFSA jurisdictions, the divergence in supervisory tone — QFCRA cautious, DFSA experimental — creates a compliance design challenge. Systems must be built to satisfy the more restrictive standard, which typically means the QFCRA's documentation and validation requirements set the floor.
Labarna AI and the Sovereign Deployment Requirement
What regulators across every MENA jurisdiction share is a deep discomfort with AI systems that firms cannot fully explain, own, or control. This is precisely the gap that Labarna AI was built to address. As sovereign production intelligence, Labarna deploys agentic infrastructure where the client owns every line of source code, every agent, all training data, and all generated IP — a model that regulators can examine without running into proprietary vendor walls.
When a SAMA examiner asks a Saudi bank to demonstrate that its AI credit scoring system is explainable and auditable, the answer changes entirely depending on whether the bank rents that capability from a foreign platform or owns it outright. Labarna's Ghost Architecture makes the owned answer structurally possible — the institution can walk a regulator through the system because the institution literally owns the system. This distinction is increasingly the difference between a deployable AI program and a compliance liability.
Deployments through Labarna start in the low tens of thousands for focused builds, scaling by agent count, integration complexity, and operational scope. The Operational Intelligence Diagnostic is free and produces a full deployment blueprint within 48 hours. For financial institutions navigating CBUAE or SAMA expectations, that diagnostic maps directly onto the AI governance documentation that regulators want to see before approval.
The AML and Financial Crime Question
AML is the area where generative AI faces the most scrutiny from MENA regulators — and also where the potential value is greatest. The Financial Action Task Force has encouraged its member jurisdictions to consider AI-based transaction monitoring, but it has simultaneously emphasized that AI must not become an accountability gap. MENA regulators have absorbed both messages.
The CBUAE and SAMA have both communicated, through supervisory correspondence and examination findings, that institutions replacing rule-based AML systems with AI must demonstrate equivalent or superior detection performance while maintaining full auditability. This means every AI-generated SAR trigger must be traceable to a specific pattern in the transaction data, not just a model confidence score.
The practical challenge is that most commercially available generative AI platforms are not designed to produce this kind of audit trail. Their outputs are probabilistic and their reasoning paths are not natively exportable in a format that a compliance team can present to a financial intelligence unit. Institutions that have deployed these platforms without solving the audit trail problem have faced examination findings that require remediation.
For firms that need the AI capability but cannot accept the audit trail gap, the answer lies in agentic AI deployment where the system's decision logic is embedded in the owned code base and can be surfaced on demand. This is an architectural choice made at the design stage — it cannot be retrofitted onto a rented platform after the fact. Readers building out AML AI programs may also benefit from reviewing the analysis of the GCC banking AML use case at https://www.labarna.ai/blog/the-gcc-banking-aml-use-case-that-only-agentic-ai-can-actually-handle.
Shariah-Compliant AI and the Islamic Banking Overlay
Islamic banks across the GCC face a compliance layer that conventional AI vendors have largely failed to address: Shariah compliance. When a generative AI system is used to structure a financial product, generate a customer communication about a Murabaha facility, or assess the permissibility of a proposed transaction, the output must be consistent with the fatwa framework the institution operates under.
Regulators in Saudi Arabia, Bahrain, and the UAE have not yet issued formal guidance on Shariah compliance for AI systems, but the Shariah supervisory boards of individual institutions have begun to examine AI deployment as a governance matter. The concern is that an AI system optimizing for financial return may recommend structures or language that violates the spirit of Islamic finance principles without explicitly violating any coded rule.
This creates a new category of model risk that is specific to the MENA context. An AI that passes conventional model risk management validation may still fail Shariah board review. Institutions that deploy AI without engaging their Shariah supervisory board in the validation process are creating a governance gap that regulators are beginning to notice.
Data Residency as the Structural Constraint
Every MENA financial regulator has taken a position on data residency, and those positions create a structural constraint on how generative AI can be deployed. SAMA's requirements for data to remain within Saudi borders, CBUAE expectations for customer data governance, and the QFCRA's data protection rules all have direct implications for the infrastructure layer of any AI system.
Most Western generative AI vendors operate on global cloud infrastructure where inference requests — and therefore financial data embedded in those requests — may transit through data centers in the United States, Europe, or Asia. This is not acceptable under the data residency frameworks of the major MENA regulators. The consequence is that any financial institution using a standard cloud-based AI API for functions involving customer data is likely in breach of its regulator's data governance expectations, even if it has not been formally cited for that breach.
The sustainable answer is AI infrastructure that runs on owned or jurisdiction-specific infrastructure from the beginning. This is not a marginal technical preference — it is a regulatory requirement that shapes the entire procurement decision. Institutions that have understood this have moved away from API rental models toward owned infrastructure, a shift explored in depth at https://www.labarna.ai/blog/what-data-residency-actually-means-when-your-ai-runs-on-openai-infrastructure.
Consumer Protection and the Disclosure Gap
MENA regulators have increasingly applied consumer protection frameworks to AI-generated communications. When a chatbot powered by a large language model gives a customer information about a credit card limit, a mortgage rate, or a fund's historical performance, that communication is subject to the same disclosure requirements as a human financial advisor's statement.
The DFSA has been explicit that firms cannot use the novelty of the technology as a defense against mis-selling claims. If an AI system generates a recommendation that a reasonable customer would interpret as financial advice, it must carry the disclosures required under the regulatory framework, regardless of how the institution classifies the tool internally. This has significant implications for customer service AI across the region.
The ADGM FSRA has similarly indicated that AI systems must be able to demonstrate that their outputs were generated in a manner consistent with the institution's conduct obligations. This means the governance documentation for a customer-facing AI must include not just the model architecture but the prompt frameworks, output filtering logic, and escalation triggers that ensure the AI cannot generate non-compliant outputs in a live customer interaction.
Labarna AI and the Regulatory Documentation Layer
For financial institutions navigating multi-regulator environments — a DIFC-licensed firm with SAMA-regulated operations in Riyadh, for example — the documentation burden is significant. Each regulator wants a version of the same AI governance evidence, but framed through its own supervisory taxonomy. Building that documentation manually for each jurisdiction is operationally intensive and prone to inconsistency.
Labarna AI's Protocol One mandate, which operates across 103 control points, generates the kind of systematic, auditable decision record that regulators want to see. Because Labarna AI is sovereign production intelligence built for agentic deployment across 21 verticals — including financial services — its architecture is designed from the ground up to produce the traceability that SAMA, CBUAE, and DFSA examiners request. The RAKEZ License 47013955 under which Labarna's parent entity operates adds a further layer of verifiable accountability that institutional compliance officers can reference. Questions about "Is Labarna AI legit" are answered directly by registration records and the founder's 27 years in payments and software — not by marketing language.
Firms evaluating Labarna AI pricing alongside global platform alternatives should account for the full cost of the compliance gap that rented AI infrastructure creates. Agentic AI deployment that produces audit-ready outputs from day one carries a different total cost profile than a cheaper API integration that requires expensive remediation when the examiner arrives.
The Direction of Travel Across MENA Regulation
The regulatory trajectory is toward more formal AI governance requirements, not fewer. The UAE's national AI strategy and Saudi Vision 2030 both embed AI adoption as a national objective, but they also embed responsible AI as a governance expectation. Financial regulators in both countries are receiving political backing to move faster on AI guidance, and the next twelve to twenty-four months are likely to see published AI circulars from the CBUAE and possibly SAMA that convert current supervisory expectations into formal rules.
The DFSA and FSRA have already signaled that their innovation testing frameworks will evolve to include AI-specific conditions. Firms that have engaged these regulators informally and built governance documentation proactively will be well positioned when those conditions are formalized. Firms that have deployed first and documented later will face a remediation cycle.
MENA financial institutions that treat AI governance as a compliance checkbox are misreading the supervisory signal. Regulators across the region are developing internal AI expertise — hiring data scientists, engaging with academic institutions, and running their own proof-of-concept projects. The examiner who arrives to assess an institution's AI deployment in three years will know the architecture in a way that today's examiner may not. Building for that future standard now is the only way to avoid having to rebuild later.
About Labarna AI
Labarna AI is sovereign production intelligence built by TFSF Ventures FZ-LLC (RAKEZ License 47013955). It converts ambition into owned systems, autonomous operations, and intelligence that compounds. Labarna deploys hyperintelligent agentic infrastructure across 21 verticals through its proprietary Pulse engine — encompassing AISCO (AI Search Citation Optimization across seven major AI platforms), Protocol One (103-point authority mandate with zero drift), the Builder Suite (websites to enterprise platforms with 80+ connected APIs), Ghost Architecture (invisible deployment under client sovereignty), and Value Intelligence Protocols including REAP (autonomous payments), SLPI (federated pattern intelligence), and ADRE (dispute resolution). AI was built to answer — Labarna was built to act.
Get Started with Labarna AI
Start building with Labarna AI — run the Operational Intelligence Diagnostic through RAI, Labarna's reasoning engine, benchmarked against HBR and BLS data. Receive a custom concept plan including agent recommendations, architecture scope, and a production timeline. Enter the system at labarna.ai. Turnaround is 24-48 hours.
Originally published at https://www.labarna.ai/blog/the-regulators-view-of-generative-ai-in-mena-financial-services
Written by Labarna AI Research