Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E.
CBUAE Guidance Note on Consumer Protection and Responsible Use of AI and ML
Guidance, not a law: the Central Bank of the UAE's reading of Consumer Protection Standards: reasons for rejecting an application or reducing credit, and complaint decisions. It binds nobody by itself; the law it reads does.
Guidance on an AI sector rules rule, addressed to private bodies.
- Enforcement body
- Central Bank of the UAE
- Instrument type
- guidance published by a regulator
- Obligation class
- Governance, Disclosure
- Audit expectation
- periodic
- Who audits it
- Independent third party, Self
- Where the report goes
- Kept
As of .
What the regulator expects
- It reaches you if you are a licensed financial institution in the UAE, including an insurance provider (an LFI in the Guidance Note), that uses AI systems or ML technologies. The Guidance Note sets out the Central Bank's expectations and no rule of its own, so each line below states what the Central Bank says LFIs should do: adopt a documented governance framework for AI and ML that is commensurate with the size, nature and complexity of your operations, with the Board and senior management responsible and accountable for AI and ML systems and outcomes, and do not employ AI models you have no control over (Sections 2(a) and 2(b)).
- Maintain an inventory of all AI models, systems or technologies you develop or deploy, with at least the model name, purpose and risk rating, following the Central Bank's Model Management Standards and Model Management Guidance (2022) (Section 2(f)).
- Make sure AI and ML systems do not result in discriminatory or manipulative outcomes, train models on data that is sufficiently accurate, relevant and representative of the customer populations they are applied to, and test AI once a year or each time a model is upgraded, materially changed or introduced to identify and remediate undue or unintended biases (Sections 3(a) to 3(c)).
- Be transparent with customers and relevant stakeholders about your use of AI, particularly in respect of high-impact decisions and when a customer is communicating or interacting with an AI application, be clear how AI systems operate and make decisions, make disclosures in plain language in both Arabic and English, and consider offering customers opt-out rights with respect to AI, particularly for high-impact decisions (Sections 4(a) to 4(c)).
- Keep AI and ML systems under meaningful human oversight and judgement, particularly for decisions with significant implications for consumers, set the level of human involvement by the risk to the consumer, and use operation without direct human involvement only for low-risk, non-material processes with appropriate controls in place (Sections 7(a) and 7(b)).
- Let consumers request human review or an explanation of AI generated decisions, make alternative arrangements available where a customer does not wish to be subject to an AI decision, inform consumers of their right to challenge decisions and correct inaccurate data inputs that affect AI, and maintain clear and accessible channels for complaints and redress in line with Article 8 of the Consumer Protection Regulation (Section 7(c)).
- Do not use AI to target consumers with unsuitable products or to engage in pressure-selling or misleading marketing, and make sure promotional materials and chatbots comply with disclosure requirements in line with the Consumer Protection Regulation (Section 7(d)).
- Monitor AI continuously in accordance with the Model Management Standards, test automatic updates to AI tools before implementation, have mechanisms to detect, report and remediate performance issues, biases or unintended consequences before implementation and over time, and retain the clear and immediate ability, with human intervention, to cease use of an AI model, system, technology or application (Sections 6(a), 6(c), 6(d) and 6(f)).
- Where you rely on third-party vendors or cloud service providers for AI and ML, conduct due diligence on the provider's reputation in AI, governance, security and data protection practices, include contract provisions for access to relevant information, audit rights and compliance with CBUAE requirements, and remain responsible for outsourced AI functions (Sections 6(e) and 9(a)).
What this law does
The Central Bank of the UAE issued the Guidance Note on , and it outlines principles and guidelines for the use of Artificial Intelligence systems and Machine Learning technologies by licensed financial institutions, including insurance providers, in the United Arab Emirates.
The Guidance Note is focused on areas that may have bearing on consumers, with the aim of promoting consumer protection and good market conduct by all licensed financial institutions in their use of AI and ML. The Guidance Note says its broad principles and guidelines should not be taken to be static or fixed, but rather as flexible principles to be used to guide and inform responsible AI and ML use over time.
The Guidance Note says it is expected that licensed financial institutions will refer to it as they develop their own internal policies and guidance on the ethical and responsible use of AI and ML with respect to consumers. The Guidance Note says it shall supplement and not replace any laws, regulations or directives issued by the CBUAE or other competent authorities, and that licensed financial institutions remain responsible for complying with all applicable laws, regulations and requirements.
The Consumer Protection Regulation states that the Financial Consumer Protection Department of the Central Bank may issue further guidance relating to the Regulation and Standards. The Guidance Note defines a high-impact decision as any determination by a licensed financial institution using AI that materially affects a customer's access to financial products or services, for example in respect of a potential loan application or insurance claim.
The Guidance Note defines MMS as the Model Management Standards, as issued by the Central Bank of the UAE. The Guidance Note says licensed financial institutions should adopt a documented governance framework for AI and ML that is commensurate with the size, nature and complexity of their operations. The Guidance Note says the governance, usage and validation of AI use in licensed financial institutions should follow the principles of the MMS.
The Guidance Note says senior management and the Board of Directors of licensed financial institutions should be responsible and accountable for AI and ML systems and outcomes, including model selection and development, deployment, human resourcing and oversight and monitoring on an on-going basis. The Guidance Note says licensed financial institutions should not employ AI models that they have no control over.
The Guidance Note says an inventory of all AI models, systems or technologies developed or deployed should be maintained, containing as a minimum the model name, purpose and risk rating. The Guidance Note says licensed financial institutions are expected to ensure that AI and ML systems do not result in discriminatory or manipulative outcomes against individuals or groups.
The Guidance Note says data used to train AI and ML models should be sufficiently accurate, relevant and representative of the customer populations to which the models will be applied. The Guidance Note says AI deployed should be subject to periodic testing, once a year or each time a model is upgraded, materially changed or a new one is introduced, to identify and remediate undue or unintended embedded biases or discriminatory outcomes.
The Guidance Note says licensed financial institutions should be transparent with customers and relevant stakeholders about the use of AI, particularly in respect of high-impact decisions, and if they are communicating or interacting with an AI application. The Guidance Note says disclosures should be made in understandable plain language, accurate, and in both Arabic and English, with telephone support available in all major languages of the UAE.
The Guidance Note says licensed financial institutions should consider the provision of opt-out rights with respect to AI for customers, particularly for high-impact decisions. The Guidance Note says licensed financial institutions should ensure that AI and ML systems operate under meaningful human oversight and judgement, particularly for decisions that have significant implications for consumers.
The Guidance Note says the level of human involvement should be commensurate with the identified and potential risks posed to a consumer by any AI. The Guidance Note says operation of AI without direct human involvement should only be utilised for low-risk, non-material processes with appropriate controls in place.
The Guidance Note says consumers should be able to request human review or explanation of AI generated decisions, and that alternative arrangements should be available where a customer does not wish to be subject to an AI decision. The Guidance Note says licensed financial institutions should maintain clear and accessible channels for complaints and redress in line with Article 8 of the Consumer Protection Regulation.
The Guidance Note says consumers should be informed of their right to challenge decisions, correct inaccurate data inputs having impact on AI and the process to challenge data and decisions by AI. The Guidance Note says AI should not be used to target consumers with unsuitable products or to engage in pressure-selling or misleading marketing, and that promotional materials and chatbots should comply with disclosure requirements in line with the Consumer Protection Regulation.
The Guidance Note says that, in accordance with the MMS, AI should be subject to continuous monitoring to ensure ongoing understanding, reliability, relevance and alignment with consumer protection objectives. The Guidance Note says licensed financial institutions should ensure that automatic updates to their AI tools are tested before implementation and should not result in bias in the model output.
The Guidance Note says mechanisms should be in place to detect, report and remediate any performance issues, biases or unintended consequences that may arise from any AI tool or model before implementation and over time. The Guidance Note says licensed financial institutions should remain responsible for outsourced AI functions.
The Guidance Note says licensed financial institutions should at all times retain the clear and immediate ability, with human intervention, to cease use of an AI model, system, technology or application deployed or utilized.
The Guidance Note says licensed financial institutions that rely on third-party vendors or cloud service providers for AI and ML models, products or solutions should conduct due diligence on the provider and include contract provisions that ensure access to relevant information, audit rights and compliance with CBUAE requirements.