AI in Insurance: CBUAE Sets Expectations for Responsible Use

time 4 min 53 sec May 18, 2026 (Edited)

Artificial intelligence is rapidly reshaping how insurers underwrite risk, assess claims, engage with customers, and distribute products. In the UAE, however, its adoption now carries a clear and evolving regulatory dimension.

The Central Bank of the UAE (CBUAE) has issued a Guidance Note on Consumer Protection and the Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions (the Guidance Note). It sets out a principles-based framework governing the use of artificial intelligence (AI) and machine learning (ML), with a strong emphasis on consumer protection, transparency, and market conduct.

While not prescriptive, the Guidance Note signals a clear regulatory expectation: AI deployment is no longer purely a technology decision — it is a conduct, governance, and accountability matter. It is also intended as a living framework, expected to evolve alongside developments in AI use across the sector.

A layered framework: Integrating AI governance across regulatory regimes

The Guidance Note does not operate in isolation. It sits alongside the Guidelines for Financial Institutions Adopting Enabling Technologies (the Enabling Technologies Guidelines), jointly issued by the CBUAE, the Securities and Commodities Authority, the Dubai Financial Services Authority, and the Financial Services Regulatory Authority on 15 November 2021.

These frameworks create a two-tier regulatory architecture. The Enabling Technologies Guidelines establish baseline requirements around governance, model design, validation, monitoring, and accountability. The Guidance Note builds on this by introducing more explicit consumer protection obligations, including bias testing, human oversight, transparency, and conduct risk management.

For insurance companies, brokers, and agents — particularly those operating across onshore UAE — this reinforces the need to treat AI compliance as a unified exercise. These frameworks must be implemented cohesively, rather than as parallel or siloed obligations.

Scope and regulatory intent

The Guidance Note is designed to promote responsible, ethical, and transparent AI use, particularly in areas that directly affect customers. It focuses on decision-making integrity, explainability, fairness, accountability, and data protection.

For insurance entities, the key implication is that AI adoption cannot be assessed in isolation. It must be aligned with existing consumer protection and conduct requirements, including those introduced under the SME Consumer Protection Regulation, which becomes effective from 13 September 2026.

High-impact decisions: Expanding regulatory scrutiny

A central concept under the Guidance Note is that of a ‘high-impact decision’ — any AI-driven determination that materially affects a customer’s access to financial products or services.

In the insurance context, this will typically capture underwriting outcomes, pricing decisions, claims assessments, and coverage determinations. For such use cases, insurance companies, brokers, and other distribution channels are expected to to consider offering customers the ability to opt out of AI-driven processes in relation to high-impact decisions, taking into account factors such as customer risk, fairness, and operational feasibility.

These requirements bring core insurance processes within a more formalised conduct and governance framework, with a clear emphasis on transparency, customer understanding, and accountability.

Human oversight: From principle to practice

Human oversight is a core requirement under the Guidance Note and must be calibrated to the level of risk posed by each AI application. For high-impact decisions, meaningful human involvement is expected, supported by clear escalation and review mechanisms. Customers must also be able to request human review of AI-driven outcomes. This reinforces that automation cannot displace accountability in customer-facing insurance processes.

Transparency and explainability: Raising disclosure standards

Insurance providers and intermediaries must be transparent about the use of AI, particularly in customer-facing interactions and high-impact decisions. This includes providing clear, plain-language explanations of how AI systems influence outcomes, with disclosures made in both Arabic and English.

Customers should also be able to request further explanation and, where appropriate, opt out of AI-driven processes. For insurers deploying digital tools such as chatbots or automated claims platforms, this will require a reassessment of customer journeys and communication practices.

AI systems must be designed and operated in a manner that avoids discriminatory or manipulative outcomes. Data must be accurate, representative, and regularly tested for bias. Under this framework, biased outcomes are not treated as technical deficiencies — they are viewed as failures in regulatory compliance and customer protection.

Data governance and resilience

AI deployment must be supported by robust data governance frameworks, ensuring data quality, traceability, and compliance with applicable data protection laws. Insurance companies and intermediaries — given their reliance on sensitive customer data — must ensure that AI systems incorporate privacy-by-design and security-by-design principles, alongside operational resilience measures to mitigate system failures and cyber risks.

Third-party risk: Managing AI supply chains

The Guidance Note and Enabling Technologies Guidelines both address reliance on third-party AI providers. Insurance entities must conduct due diligence on vendors, implement appropriate contractual protections (including audit rights and data safeguards), and maintain oversight of outsourced AI systems. Institutions are also expected to retain the ability to suspend or discontinue any AI application where necessary. This places increased emphasis on vendor governance and contractual risk management across AI supply chains.

Practical considerations for insurance entities

In light of these developments, insurance companies, brokers, and agents should prioritise:

  • mapping and classifying AI use cases across the organisation;
  • embedding AI risk within governance and board oversight structures;
  • testing models for bias and documenting remediation;
  • reviewing customer-facing AI interactions for transparency and disclosure compliance;
  • strengthening third-party AI risk management; and
  • aligning AI governance with broader consumer protection frameworks.

Key takeaways

The Guidance Note and the Enabling Technologies Guidelines together signal a clear regulatory direction: AI adoption in the UAE financial sector will be assessed not only on technical capability, but on alignment with consumer protection, fairness, ethics, and governance standards.

For insurance companies, brokers, and agents, this introduces both operational and cultural implications, requiring structured governance, enhanced documentation, and demonstrable oversight of AI-driven outcomes.

The insurance team at Al Tamimi & Company is well placed to advise on the interpretation and application of these frameworks, including conducting AI governance gap assessments, reviewing third-party arrangements, and supporting alignment with the CBUAE’s evolving consumer protection and conduct requirements.