Legal advisors in the UAE have cautioned that shadow AI, defined as artificial intelligence operating outside institutional governance, can expose organisations to serious vulnerabilities when employees introduce unapproved tools into workplace systems. A KnowBe4 study conducted in the UAE and Saudi Arabia and published by Business Wire in June found that 41 percent of employees resort to acquiring their own Agentic AI tools when official options are unavailable or restricted. This practice leaves organisations open to cyberattacks according to the study, which highlighted how such tools bypass corporate security protocols and data controls. The findings come as the UAE accelerates official AI adoption, including a government directive to convert 50 percent of federal operations to Agentic AI within two years that the Presidential Court announced earlier this year.
Dr. Ammar Ali, a legal advisor, warned of the legal risks associated with employees using artificial intelligence tools that are not approved or subject to institutional control. He explained that the danger arises when an employee inputs contracts, customer data, financial reports, health files or internal correspondence into personal AI accounts under the belief that it amounts only to copying and pasting information. Such actions may legally amount to processing or disclosing data to an external party outside the corporate environment, Dr. Ali stated in the Emirates 24|7 report. The advisor’s assessment aligns with broader regional concerns, where a separate review of information assurance standards noted that shadow AI creates unmonitored data flows incompatible with required controls.
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data sets clear requirements that any data processing must be legitimate, limited to a specific purpose and surrounded by security measures, according to Dr. Ali’s analysis. Article 5 of the law mandates that data be kept securely and protected from hacking or unauthorised processing, while Article 7 obliges the data controller to implement appropriate technical and organisational safeguards for confidentiality and privacy. Uploading customer or employee information to an unapproved AI platform can therefore trigger organisational obligations to report breaches under Article 9 when certain conditions are met, the legal advisor noted. Administrative penalties can also be imposed on controllers or processors found in violation of the law’s provisions.
Dr. Ali further pointed to Federal Decree-Law No. 34 of 2021 on combating rumours and cybercrimes as another layer of exposure for unauthorised AI use. Article 45 of that law criminalises the disclosure of confidential information obtained through work, job or profession via information technology means without authorisation, carrying penalties of imprisonment for at least six months and a fine between Dh200,000 and Dh1 million, or either penalty. The law treats use of the information to secure a benefit for the perpetrator or others as an aggravating factor that could increase the severity of sanctions. A NESA assessment of Information Assurance Standards places potential fines in regulated sectors as high as AED5 million alongside possible licence suspension for compliance failures tied to unmanaged data flows.
Organisations in the UAE must navigate these rules against a backdrop of rapid AI integration across both public and private sectors, according to government announcements on national AI projects. The Presidential Court and Ministry of Cabinet Affairs have driven initiatives that include capability building and pilot deployments of specialised AI agents to boost efficiency while emphasising human oversight. Yet experts stress that shadow AI undermines such efforts by introducing ungoverned risks, particularly in sectors handling sensitive personal or financial data where Public Authority for Civil Information statistics show a large expatriate workforce reliant on compliant systems. Dr. Ali’s warnings underscore the need for companies to establish clear governance frameworks to prevent internal violations from escalating into legal breaches.
The combination of data protection obligations and cybercrime provisions means that even inadvertent use of consumer-facing AI platforms for work tasks can create liability for both employees and their employers, a PwC Middle East review of regional digital transformation found. Companies are advised to conduct due diligence on approved AI tools, implement monitoring and provide training to align usage with regulatory thresholds. As the UAE positions itself as a leader in artificial intelligence deployment, closing the gap between official adoption and shadow practices has become a priority for maintaining compliance and protecting sensitive information across the economy.
ع