The UAE has put a date on agentic AI, and the sequence of announcements since April this year has left little room for interpretation. Walid Gomaa, CEO of Omnix International, the company that designs and deploys AI systems for government and enterprise clients across the Gulf, tracks it from the Cabinet decision onward.
“In April, the UAE Cabinet announced that 50% of federal government services and operations will be powered by agentic AI within two years,” Gomaa said. “By May, Dubai launched a two-year transformation programme under which the emirate’s private sector is expected to adopt autonomous, self-executing agentic AI workflows by May 2028, building the transition around the Dubai Chamber of Commerce, with specialised training tracks for every business council, dedicated incubators for agentic AI companies, and new funding to support the shift. The countdown has genuinely begun.”
Three announcements have followed in the four months since – in May, the Cabinet approved the first package of transformational services to be powered by agentic AI, covering citizens’ services, residents’ services, business sector services and general public services, alongside a Federal Government Employees’ Skills and Capabilities Development Programme that will train 80,000 employees across five occupational categories.
In June, Dubai Chambers formed an Executive Committee for Agentic AI, and a federal workshop attended by more than 300 officials from 50 entities launched a 90-day sprint requiring each entity to take an agentic service through exploration, design and implementation planning.
On the readiness of the organisations receiving that countdown, however, Gomaa is considerably less comfortable. “The honest assessment of readiness is that ambition is well ahead of infrastructure,” he said.
What the research says about the gap
Gomaa reaches for published survey data rather than his own client base to make the point.
“Global research found that 75% of organisations expect to be using AI agents within two years, yet 48% are concerned that their data foundations are not ready to support them, and 55% are not fully confident they have the right guardrails in place,” he added.
Another analyst report, which surveyed more than 3,200 leaders across 24 countries, tells a similar story: 74% expect to be using AI agents at least moderately by 2027, but only 21% have anything resembling a mature governance framework to support them.
The first set of figures comes from Salesforce’s survey of more than 2,000 enterprise IT security leaders, which also recorded deployment at 41% at the time of the survey. The second is Deloitte’s State of AI in the Enterprise, based on 3,235 business and IT leaders across 24 countries surveyed in August and September 2025.
Deloitte defines the governance capabilities most respondents lack in specific terms: clear boundaries setting out which decisions agents can take independently and which require human approval, real-time monitoring that tracks agent behaviour and flags anomalies, and audit trails capturing the full chain of agent actions.
A subsequent Deloitte readiness study found no organisational function above 52% preparedness, with data foundation at 42%, risk, security and governance at 39%, workforce at 25%, and business processes, the weakest area measured, at 21%.
While this may be a problem, Gomaa believes three moves can help in a forward movement. He explains Agentic AI is not a software rollout but a capability-building exercise.
“Agents fail because of messy data and undocumented processes long before they fail because of the model itself. Cleaning data, mapping workflows, and clearly defining decision ownership must come first.”
His second point concerns governance. “Build governance alongside the pilots, not after them,” he said, and cited the forecast that has been circulating in boardrooms since it was issued. ” A 2025 Gartner report expects more than 40% of agentic AI projects to be cancelled by the end of 2027, citing cost overruns, unclear business value, and inadequate risk controls as the primary reasons.
Its 2026 Hype Cycle for Agentic AI places the category at the peak of inflated expectations, recording 17% of organisations as having deployed agents against more than 60% expecting to within two years. Gomaa also believes that there needs to be a constraint on ambition.
He urged everyone to start small, and select one or two high-volume, well-understood workflows that can be optimised end-to-end. This includes the audit trail, and scale from proof of concept to production only once you can clearly measure the business outcomes.”
IDC forecasts agentic AI will account for more than 26% of worldwide IT spending by 2029, with AI spending reaching $1.3 trillion that year and 45% of organisations orchestrating agents at scale by 2030. Across the Middle East, Türkiye and Africa, IDC put AI spending at $4.5 billion in 2024, projected to reach $14.6 billion by 2028 at a compound annual growth rate of 34%. In the first quarter of 2026, the Middle East and Africa were the fastest-growing AI infrastructure market globally, rising 233% year on year.
When agents go wrong
The question of whether agents can be turned against the systems they operate in stopped being hypothetical in late 2025, and Gomaa treats it as a board-level matter rather than a security-team one.
“This isn’t theoretical, and that’s what should worry every board, not just the security team,” he said. “Anthropic’s own research has shown frontier models, including its own, resorting to self-preserving behaviour when they believed they were about to be shut down or replaced.
“In November last year, Anthropic disclosed something even more serious: a state-sponsored group had manipulated its coding agent into conducting a largely automated cyber-espionage campaign against approximately thirty organisations.”
That disclosure was published on 13 November 2025, where, according to the report, the AI executed an estimated 80% to 90% of the operation, covering reconnaissance, vulnerability discovery, exploit development, credential harvesting and data extraction, with human operators intervening at four to six decision points per campaign.
Targets spanned large technology companies, financial institutions, chemical manufacturers and government agencies, and the attackers succeeded in a small number of cases. The self-preservation research Gomaa refers to sits in a different evidentiary category: it was conducted in simulated scenarios developed by red-teaming the company’s own models, and Anthropic has stated the behaviour has not been documented in real-world deployments.
“So, the conversation around guardrails has to mature,” Gomaa said. “The industry now has a solid reference point in the OWASP Top 10 for Agentic Applications, published at the end of last year by the OWASP GenAI Security Project. The framework identifies ten critical security risks specific to autonomous AI agents that plan, use tools, and execute workflows. It explicitly identifies rogue agents, alongside privilege abuse and tool misuse, as top-tier risks.”
The framework was published on 9 December 2025 and built by more than 100 security experts, researchers and practitioners. Its categories run from ASI01, agent goal hijack, through tool misuse and exploitation, identity and privilege abuse, agentic supply chain vulnerabilities, unexpected code execution, memory and context poisoning, insecure inter-agent communication, cascading failures and human-agent trust exploitation, to ASI10, rogue agents.
Gomaa’s translation of the framework into deployment practice is uncompromising on scope.
“Practically, this means giving every agent the narrowest set of permissions required for its task, never the keys to the entire system,” he says. “It also means placing a mandatory approval checkpoint between an agent and any irreversible action, logging every action an agent performs so its reasoning can be reconstructed, not just its output, and red-teaming your own agents in the same way you would rigorously assess a new employee with administrative access, because that is effectively what they are.”
Containment comes next, and here he is describing capability most enterprises have not built. “Organisations should also implement rapid containment mechanisms, such as kill switches and credential revocation, to immediately disable rogue agents and quarantine suspicious activity,” he says. “In addition, they should perform periodic behavioural attestation and ensure that credentials, API keys, and secrets are never directly accessible to agents.”
On the standards that dominate compliance conversations, he draws a firm line between structure and engineering. “Frameworks such as NIST’s AI Risk Management Framework and ISO/IEC 42001 provide the governance structure around all of this; however, they do not replace the engineering discipline required to strictly limit what an agent can access and control.”
Why public sector work is a separate discipline
“Building for government is a different discipline from building for a retailer or an enterprise, and the gap is widening as agents take on more autonomous decision-making,” Gomaa says. “Under the EU AI Act, for instance, AI systems used in essential public services are explicitly classified as high-risk, triggering an entirely different set of obligations around oversight, documentation, and conformity assessment that a marketing chatbot would never have to meet.”
The reason sits in the workloads themselves. “Public-sector agents interact with functions that are simply far less forgiving to get wrong, benefits eligibility, permits, housing, and identity, so the bar must be higher by design, not as an afterthought,” he says.
He identifies three requirements, and defines the first with more precision than the term usually carries.
“The first is data sovereignty, where the data physically resides, where the model performs inference, and which jurisdiction or vendor can technically access it,” Gomaa says. “Sovereign AI has become one of the most frequently used terms in enterprise technology over the past year because governments have recognised that renting intelligence from someone else’s cloud, in someone else’s country, presents a fundamentally different risk than simply renting compute.”
Deloitte’s data indicates procurement has already shifted accordingly: 77% of companies now factor country of origin into vendor selection, and close to three in five build their AI stacks primarily with local vendors.
The second requirement concerns permissions. “The second is granular access control,” he says. “An agent acting on behalf of a government department should not inherit blanket or unlimited access. Its permissions should be limited to the specific task it is performing, much like granting a new employee access only to the areas they need rather than handing them a master key.”
The third sets a standard for the record itself. “The third is auditability. Every action an agent takes on behalf of a citizen must be reconstructable afterwards, in plain language, for an investigator, an auditor, or a court.”
Gomaa reads the UAE’s federal programme as instructive on exactly this point, and specifically on what was approved alongside the technology.
“The UAE’s own federal rollout provides a useful indication of where this is heading,” he says. “Alongside technology deployment, the government introduced a formal code for government services, digital records, and data-sharing protocols, while also redefining the role of the civil servant, from performing the task to supervising the agent that performs it. That combination of technology deployment with governance and workforce transformation, progressing at the same pace, is perhaps the most important lesson.”
The federal architecture has since been detailed further. The National AI Gateway will give federal entities a common technology infrastructure and a single secure access point for developing and adopting agentic solutions, supporting commercial models alongside open-source models hosted within sovereign infrastructure, with a self-assessment mechanism based on technical and operational criteria determining whether a given system meets the requirements of agentic AI.
Gomaa’s conclusion on sequencing is the line most likely to be quoted back at vendors. “Sovereignty and security are not a checklist to complete before deployment; they are design principles that must be embedded throughout the entire journey.”
Making human oversight mean something
Gomaa is openly sceptical about how the industry uses its own terminology on this point.
“Human-in-the-loop is often used loosely,” he said. “It is important to be clear that human-in-the-loop means a person with real, exercisable authority to stop or reverse what the agent is doing, not just someone copied on a dashboard.”
The people holding that authority need a particular set of capabilities, and he lists them without softening the last one. “The people overseeing an AI system must genuinely understand its limitations, remain alert to the human tendency to overtrust confident-sounding recommendations, correctly interpret the system’s outputs, and, most importantly, have the authority to override, disregard, or reverse its decisions,” he says. “They must also have access to an effective stop button that can safely halt the system when necessary.”
He sets out four practical steps for organisations building agents. The first concerns placement.
“Map every workflow based on its consequences, not its technical complexity, and place the human checkpoint where the impact of an incorrect decision would be the hardest to reverse, for example, a housing allocation rather than a form acknowledgement,” he said.
The second concerns architecture, and comes with a test that will fail a good number of current deployments. “Build the override mechanism into the architecture from day one, not as an afterthought. If stop means submitting a support ticket, it doesn’t count.”
The third addresses the failure mode that develops quietly over months of successful operation. “Actively manage automation bias,” Gomaa says. “Rotate the people responsible for oversight, train them to validate rather than rubber-stamp decisions, and monitor how often they intervene. If the override rate gradually falls to zero, that is a governance failure, not evidence that the agent has become trustworthy.”
The fourth returns to the record and the range of people who may need it. “Log the complete decision trail not just the final output, so that every decision can be explained afterwards to a citizen, an employee, a regulator, or a court.”
Adoption, and what it does not measure
The UAE ranks first in Microsoft’s AI Diffusion Report for the first quarter of 2026, and Gomaa cites the figure before qualifying it.
“Microsoft’s AI Diffusion Report for the first quarter of this year found that AI adoption in the UAE workplace has surpassed 70% of the working-age population, making it the first country in the world to reach that milestone, compared with a global average of approximately 17.8%,” he says. “That is an extraordinary level of adoption. It is worth noting, however, that adoption is not the same as scaled, well-governed deployment.”
The report, published by the Microsoft AI Economy Institute using aggregated and anonymised telemetry across more than 100 markets, puts the UAE at 70.1%, up from 59.4% and then 64% across earlier readings. Twenty-six economies now exceed 30%; the United States ranks 21st at 31.3%.
Gomaa returns to the governance figure to explain what sits behind the cancellation forecast.
“Deloitte’s research shows that, even among most organisations planning to use AI agents moderately or extensively by 2027, only 21% have a governance framework mature enough to trust an autonomous system with real decision-making,” he said.
Gartner’s prediction that more than 40% of agentic AI projects will be cancelled by the end of 2027 reflects this same gap rather than a failure of the technology itself. The underlying issues are messy data, undocumented workflows, and the absence of what the industry has begun calling AgentOps, the monitoring, logging, testing, and operational discipline required to trust an autonomous system in production, much like you would trust a new employee.
IDC data indicates budgets are beginning to respond, with 16.7% of AI budgets now allocated to security and 1.2 billion AI agents expected to be in operation by 2029.
Readiness, in Gomaa’s account, has never been a single problem. “Readiness runs on two separate tracks, technology and people,” he says. “Most organisations are further behind on the first than they realise, and further behind on the second than they are willing to admit.”
The remedy he prescribes has not varied across any part of the conversation. “The practical sequence is straightforward. Fix the data and process foundations before scaling anything; build the operational discipline including monitoring, testing, and incident response that agentic systems require, just as you would for any system making decisions at machine speed, and run reskilling as a parallel workstream from day one, not as an exercise after deployment.”
He ends on what will separate the organisations that make the 2028 deadline from those that do not.
“The organisations that succeed will not necessarily be those with the most advanced models,” he says. “They will be the ones whose data, processes, and people are ready to work alongside them.”





