UAE residents face AI platform verification gap as cybersecurity guidance emerges
Cybersecurity authority issues verification protocols for AI platform use amid expanding threat landscape
Residents across the UAE using AI tools daily face a concrete operational question: is the platform they are clicking into actually safe? The UAE Cybersecurity Council has issued guidance on verifying AI platforms and managing permissions, framing the issue as one of infrastructure trust and individual responsibility.
The core challenge is distinguishing legitimate AI services from platforms built to harvest personal information without user knowledge. The Cybersecurity Council advised residents to verify whether a website or AI service is reliable before use and to examine carefully what permissions each tool requests. The authority specifically warned against granting unnecessary access to device cameras and other hardware features, particularly when working with unfamiliar platforms.
Three categories of data carry the highest risk if uploaded to AI tools.
Banking and financial information, including credit card numbers, account details and financial statements, should never be entered into these systems. The exposure risk is direct: if a conversation is shared, an account is compromised or the AI service operates with weaker privacy protections, financial credentials can reach unauthorized parties. Personal identification documents present a second critical vulnerability. Passports, Emirates IDs, driver’s licenses and visas contain sensitive information that increases identity theft risk if exposed. If AI analysis of such documents is necessary, users should consider redacting personal details before uploading. Medical records form a third protected category. Health information, including diagnoses, prescriptions, test results and insurance details, should be stripped of names, identification numbers and other personally identifiable information before any AI platform access.
The threat landscape has expanded well beyond traditional attack vectors. At the 3rd Government Cybersecurity Summit in Abu Dhabi on June 9, Dr Mohamed Al Kuwaiti, head of the UAE Cyber Security Council, described how malicious actors have shifted tactics. “We are no longer seeing AI used only for phishing and email attacks. It is now being leveraged across a broader spectrum of cyber threats, including data exfiltration, data wiping and sophisticated cyber operations that we have witnessed almost daily in recent months,” he said.
The operational scope of AI-enabled attacks has broadened considerably. Cyberattacks are no longer confined to critical infrastructure but increasingly target government entities, operational technology systems, businesses, supply chains and individuals as digital ecosystems grow more interconnected. Al Kuwaiti emphasized that malicious actors are using AI in cyber terrorism and cyber warfare to orchestrate attacks and overcome conventional security measures. AI-generated deepfakes, misinformation and disinformation campaigns add another layer of operational risk, with such tools capable of spreading fear, confusion and panic within communities.
Meanwhile, the Cybersecurity Council stressed that cyber threats do not distinguish between governments, companies or individuals, underscoring the need for collaboration between governments, the private sector and technology providers. For residents in the UAE, the practical guidance is consistent: use AI tools from trusted and verified sources, think carefully before granting access to personal information or device functions, and know which data should never be shared with these platforms at all.
Whether that guidance translates into measurable changes in how residents interact with AI tools, particularly as these platforms become more embedded in everyday tasks, remains the open question for the Council and its partners to track.
Q&A
What three categories of data does the UAE Cybersecurity Council identify as highest-risk for AI platform upload?
Banking and financial information (credit card numbers, account details, financial statements); personal identification documents (passports, Emirates IDs, driver's licenses, visas); and medical records (diagnoses, prescriptions, test results, insurance details).
How has the threat landscape for AI-enabled attacks expanded according to Dr Mohamed Al Kuwaiti?
Malicious actors have shifted from using AI only for phishing and email attacks to leveraging it across data exfiltration, data wiping, cyber terrorism, cyber warfare, and AI-generated deepfakes and disinformation campaigns.
What specific permissions does the Cybersecurity Council warn residents against granting unnecessarily?
The Council specifically warned against granting unnecessary access to device cameras and other hardware features, particularly when working with unfamiliar platforms.
What is the stated implementation challenge for the Cybersecurity Council regarding its guidance?
Whether the guidance translates into measurable changes in how residents interact with AI tools, particularly as these platforms become more embedded in everyday tasks, remains an open question for the Council and its partners to track.