By the time software reaches you, it has been compiled, and compiling throws away almost everything a person put into it: the names the programmer chose, the notes left for whoever came next, the way the work was divided into files. What comes out is a long run of machine instructions a processor executes perfectly and a human being can barely follow.
“Most of the software that the world runs on ships as compiled binaries, with no source code, no symbols, and no documentation,” Maitha Alshaali, Lead Research Engineer, AI and Digital Science Research Center (AIDRC), Technology Innovation Institute (TII) said. “You cannot simply read it to know whether it is safe.”
Somewhere inside almost every substantial piece of that software sits a flaw nobody has found yet. Alshaali spent years watching the search for those flaws proceed at walking pace. “I spent years in security operations where the work that mattered most was slow, manual, and dependent on a handful of experts,” she says. Almost everything else in security had been automated to some degree. This had held out.
“I kept asking myself: does it have to be this way?”
She is now a Lead Research Engineer at the AI and Digital Science Research Center at Abu Dhabi’s Technology Innovation Institute, and is finishing a PhD in computer science at Durham University on how AI can be integrated with program analysis to improve vulnerability detection. Ask her what she builds and she declines the grand version of the answer. “My current work focuses on building agentic AI systems for binary analysis and vulnerability discovery. In practice, this means designing multi-agent systems that can investigate software like an expert analyst would.”
UNESCO puts the proportion of the UAE’s STEM graduates who are women at 61%, against roughly 57% across the Arab world, and the figure gets read out from a stage every August. It describes a cohort at the moment of graduation and follows it no further. Healthcare informatics takes a great many of them. So do aerospace, energy analytics and enterprise data work. Binary reverse engineering takes almost nobody, anywhere, of any gender.

Reading software that was never meant to be read
Reverse engineering held out against automation for a structural reason, and Alshaali states it more economically than the literature does. “This kind of analysis has resisted automation because it demands long, hypothesis-driven investigation rather than a single prediction. The analyst must plan, probe, be wrong, and revise.”
Every generation of machine learning before this one was built to produce an answer. Analysis of compiled software does not decompose into a single prediction, which is why agentic systems arrived in cybersecurity research with more force than in almost any other domain. “In our research, we are building multi-agent systems that use large language models to plan investigations, drive tools for disassembly, emulation and fuzzing, and ground their conclusions in evidence from the software itself,” Alshaali says. “It can tackle complex security problems at a scale and speed that human teams alone cannot match.”
Anyone who has sat through the standard briefing on autonomous agents should notice the one thing separating this from the pitch. The agent has a verifiable ground truth. A binary either contains the vulnerability or it does not, the emulator either reproduces the crash or it does not, and the hypothesis dies cheaply and unambiguously. Agents deployed in finance, procurement and customer operations work under the opposite condition, generating outputs nobody can check without a second expensive process, which is why so many of those deployments have stalled at pilot.
“The opportunity to conduct advanced AI and cybersecurity research here in the UAE is especially meaningful to me,” Alshaali says. “I aim to help protect our national cyber infrastructure, and because the same software underpins systems everywhere, the impact of this work reaches well beyond our borders.”
A sovereign stack is a staffing problem before it is an infrastructure one
In a classroom at Canadian University Dubai, Dr Najla Al Futaisi teaches AI and computing ethics to undergraduates who will spend their working lives inside systems whose legitimacy she is still arguing about. She entered the field sideways, through a single course during a Master’s degree at the University of St Andrews more than ten years ago. What held her there was a use for it. She wanted to build things that could help neurodivergent children, and has since worked on several, from systems exploring the language environments children grow up in to early diagnostic tools for conditions including autism.
“AI was what finally made that kind of work possible,” she says. “That was the moment technology stopped being abstract for me and became something I could point to and say, this changes a real person’s life.”
In her account the Gulf has moved past the adoption of AI and towards a fully sovereign stack, running from giga-scale infrastructure such as the UAE’s Stargate project and Saudi Arabia’s HUMAIN through to ownership of the intelligence layer itself. She points to TII’s Falcon Arabic and Falcon H1 Arabic as the evidence. The institute announced Falcon-H1 Arabic in January 2026, built on a hybrid Mamba-Transformer architecture, released in 3B, 7B and 34B configurations, and says the family leads the Open Arabic LLM Leaderboard across model sizes while outperforming considerably larger systems.
Sovereignty in this market gets discussed almost entirely as a question of location. Where the GPUs sit, whose data centre holds the weights, who signs the export licence. No amount of capital expenditure answers the version underneath, which is who builds the layer above the silicon and who can find the flaws in what has been built.
“I want to be part of building the future rather than simply watching it happen,” Al Futaisi says.
The advice both women give cuts against the way the sector recruits
Alshaali walked away from her own expertise on purpose. “Moving from operational cybersecurity into research at TII while committing to my PhD was a major turning point for me. It meant leaving an area I knew well and entering one where I had to learn from scratch, and that experience showed me how much I was capable of.” She raises the absence of a route as a recommendation rather than a warning. “It was a new field with no playbook and no established path.”
Her message to young Emirati women contains no encouragement to take the accessible route. “Invest in your education and not be afraid of pursuing hard things. The hardest fields may challenge you, but they are also where you will grow the most and have the greatest opportunity to contribute to your country.”
Al Futaisi reaches a compatible position from the other side of the lectern, with a qualification about who gets counted as technical. Low-code tools have brought the barrier to entry down, and she argues the industry needs designers, strategists and researchers as much as people who can write a training loop. What she pushes students towards is making something and watching it fail. “There is a real gap between understanding a concept and actually creating with it, and that gap only closes through doing.”
On the cultural question, she is blunter. “Do not let outdated ideas of what is for girls and what is for boys talk you out of technology. If you are curious about it, pursue it. Full stop.”
Neither position sits comfortably alongside enterprise AI hiring in the Gulf, where job specifications lean heavily on platform experience, vendor certification and prior deployment history. That answers a real shortage of proven practitioners and also screens out anyone whose value lies in what they can learn. Both careers here would have failed that filter at the moment it mattered.
The 61% figure will be read out again this August, and it deserves to be. The measure worth watching sits further along the track: how many of those graduates reach roles that carry technical risk and take ten years to get good at. People stay out of jobs like these because being wrong in them has consequences, and a country intending to own its own intelligence layer cannot afford for that avoidance to hold.




