Many banks in the UAE and Saudi Arabia answered generative AI with a block list. The public AI sites were blocked at the proxy. A policy told staff not to use them. The risk register was updated. On paper, the problem was closed.
In practice, the problem moved. This article explains where it went, why that is worse for a regulated institution, and how to replace a ban with controlled use.
The ban does not stop the work
Staff use AI tools because the tools save time. A relationship manager wants a first draft of a credit memo. A developer wants help with a failing test. An analyst wants a summary of a long circular. A proxy rule does not remove these needs.
The data shows how fast the need is growing. The Verizon 2026 Data Breach Investigations Report (DBIR) found that regular AI users rose from 15% to 45% of employees in one year. It also found that 67% of employees access AI from non-corporate accounts on corporate devices. That is the pattern a ban produces at scale: the work continues, but under a personal login.
When the corporate device is also locked down, the next step is the personal phone. An employee photographs a screen or types a summary into a personal app. No corporate control sees that session at all. We have no reliable figure for this behaviour, and that is the point. Nobody can measure it.
The DBIR adds three more signals. Shadow AI is now the third most common non-malicious insider action in data loss prevention (DLP) datasets, and detections are up 4x. Source code is the number one data type uploaded to unauthorised AI services. And 15% of users run unauthorised AI browser extensions, which a site block does not catch.
Figure 1. A ban pushes use out of view. Governed use keeps it visible and applies one of four actions.
What the bank loses
A ban feels safe because the block list is visible. The use it creates is not. When a prompt leaves through a personal account, the bank loses four things.
- The log. There is no record of which tool was used, when, or with what data.
- Attribution. The bank cannot tie a session to a user, a role or a business unit.
- The control point. There is no place to warn the user, remove an identifier or stop an upload.
- The evidence. When a supervisor or internal audit asks how AI use is controlled, the only answer is the policy document.
That last point matters most. A policy states intent. It does not show what happened. A bank that bans AI can say what staff were told. It cannot say what staff did.
What regulators actually ask for
Supervisors rarely ask a bank to prove that AI is banned. What the frameworks do expect, in general terms, is that the institution knows its assets, knows who uses them, controls data leaving the perimeter, and can prove it.
- Inventory. The NCA Essential Cybersecurity Controls and the UAE Information Assurance Regulation both expect asset management. An AI tool in use is an asset, whether or not it was approved.
- Attribution. Logging and monitoring expectations in the SAMA Cyber Security Framework and the NCA controls assume events can be tied to a user.
- Controls. SAMA expects data leakage protection. CBUAE regulations and standards expect outsourcing and third-party controls. A public AI service that receives customer data is a third party.
- Evidence. The Saudi PDPL and the UAE PDPL (Federal Decree-Law 45 of 2021) set rules for processors, cross-border transfers and breach notification. Meeting them means showing records, not only policies.
A ban with no telemetry fails all four tests. It has no inventory of what staff really use. It has no attribution for personal-account sessions. It has no control over the data that leaves. And it produces no evidence.
The alternative: sanctioned tools plus usage control
The practical model has two parts. First, give staff a sanctioned AI tool for common tasks. Second, put usage control on every path to AI, so each prompt, paste and upload gets a decision.
Apps fall into three classes: sanctioned, tolerated and unsanctioned. Each decision uses one of four actions, set per app, per user group and per data class.
- Allow. Observe and log. The user sees nothing.
- Coach. Show a banner that points to the approved tool.
- Redact. Strip the identifier, such as an Emirates ID, Saudi National ID or IBAN. The prompt continues.
- Block. Stop the action and log it.
The order matters. Coach and redact come before block. Coaching changes behaviour without stopping work. Redaction removes the regulated data and lets the task finish. Block is for cases where no safe version exists, such as source code to an unsanctioned app. If you block first, you rebuild the ban and push staff back to their phones.
Exceptions need an approver and an expiry date. Identity comes from SSO and SCIM, so every decision has a named user and role.
A one-week path from ban to governed use
You do not need to lift the ban on day one. Find your shadow AI on the day you deploy. Open the approved path, then add controls step by step. Reach full shadow AI governance in one week.
| Days | Step | Output |
|---|---|---|
| Day 0 | Deploy the plugin and endpoint agent in one business unit through Intune, Jamf or Google Admin. See the first shadow AI inventory the same day. | Inventory of apps, personal accounts, agents and MCP servers |
| Day 1 to 2 | Class each app as sanctioned, tolerated or unsanctioned. Map sensitive data by class and lane. Pick the sanctioned tool for common tasks. | App classes, sensitive-data map, corporate vs personal split |
| Day 3 to 4 | Turn on coach and redact for the pilot groups. Redact regulated data classes such as national IDs, IBAN and card numbers. | First coach and redact decisions in the log |
| Day 5 to 6 | Turn on block for unsanctioned and training-by-default tools. Set up exceptions with approver and expiry. | Block rules and exception register |
| Day 7 | All four actions live. Replace the blanket ban with the new policy for the unit. Produce the evidence pack for risk and audit. | Full shadow AI governance, AI Usage Evidence Pack, executive readout |
At the end of the week, the bank has what the ban never gave it: a list of the AI tools in use, a named user for each session, a control on regulated data, and a record it can show a supervisor.
Sources
- Verizon 2026 Data Breach Investigations Report, as summarised by Suzu Labs: suzulabs.com
- Regulatory frameworks are described in general terms: CBUAE regulations and standards, UAE Information Assurance Regulation, UAE PDPL (Federal Decree-Law 45 of 2021), SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, Saudi PDPL. Check the current official text with your compliance team.