The Central Bank of the UAE has brought a new Operational Risk Management Regulation into force for Licensed Financial Institutions, adding a demanding reporting timetable to a broader shift toward demonstrable Operational Resilience.

The regulation, C 1/2026, became effective on 14 September 2026. Article 15.2 requires an institution to notify the Central Bank within four hours of an Operational Risk event that significantly impacts, or may significantly impact, the continuity or integrity of Critical Operations. A summary report is then required within 24 hours.

The reporting window is significant because it changes what good Operational Risk management has to look like in practice. A financial institution cannot meet a four-hour requirement if it does not have timely visibility into incidents, clear escalation paths, well-defined Critical Operations and the ability to assemble evidence quickly.

Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.

The regulation also makes clear that Incident Response and Recovery Plans cover, but are not limited to, ICT and cyber security incidents, and its broader framework addresses third-party dependencies and operational failures. For institutions deploying AI into critical processes, that raises a practical question about how an AI-related failure would be detected, classified and escalated if it threatened a Critical Operation.

This is part of a wider supervisory direction away from treating resilience as a collection of recovery plans. The regulation requires institutions to identify threats and vulnerabilities affecting Critical Operations and to manage disruption within an integrated Operational Risk and Operational Resilience framework.

The four-hour requirement will also place pressure on supplier and third-party arrangements. Financial institutions may depend on cloud providers, cyber security vendors, identity platforms, data processors and AI systems that sit outside their direct operational control. Contracts and technical integrations therefore need to support rapid incident notification and evidence gathering rather than only periodic assurance.

For vendors selling into UAE financial services, the regulation creates a practical test of 'regulated-industry readiness'. Products that claim to improve visibility, resilience or AI governance will increasingly need to show what evidence they can produce during an incident and how quickly that evidence can be delivered.

The broader lesson is that Operational Resilience is becoming measurable. Policies and recovery plans still matter, but supervisors are asking whether institutions can identify disruption quickly, protect Critical Operations and explain what happened on a timetable measured in hours rather than days.


The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.
Share this post
The link has been copied!