uae:gov
AI adoption in the UAE public sector.
By Loan Laux · September 17, 2026 · 9 min read
AI adoption in the UAE public sector is further along on strategy than almost anywhere else, and further behind on desk-level reality than the announcements suggest. The gap between the two is where the actual work happens, and three constraints shape all of it: where the data is allowed to live, how well the system handles Arabic alongside English, and how procurement and security accreditation actually run.
We write this from experience rather than from the press releases: out:grow has worked with the Abu Dhabi Department of Culture and Tourism, and the pattern described here is the one we see inside real entities. This is the informational companion to our UAE consulting page; read that one if you're looking for help, this one if you're doing the work yourself.
Where AI adoption in the UAE public sector actually stands.
No government has signalled harder on AI. The UAE appointed the world's first Minister of State for Artificial Intelligence in October 2017, the same month it announced the National Strategy for Artificial Intelligence 2031. Abu Dhabi's Government Digital Strategy 2025-2027 goes further: AED 13 billion to become what it calls the first fully AI-native government by 2027, with over 200 AI solutions planned across government services.
That top-down mandate changes the texture of the work. In most markets we spend the first month arguing about whether AI is worth doing; in a UAE entity the question is settled and the pressure runs the other way, toward showing something real quickly. The risk flips too: pilots launched before anyone mapped the data constraints, then quietly shelved when the constraints surface.
So the honest picture is uneven: flagship citizen-facing programs that are genuinely advanced, and inside the average department, drafting, summarizing, and correspondence that look like they do everywhere else. That second layer is where the practical adoption work sits.
Data residency decides your architecture first.
The first surprise for teams arriving from the private sector: the UAE's federal data protection law is not the constraint. The PDPL (Federal Decree-Law No. 45 of 2021) explicitly excludes government entities and government data from its scope. Public-sector data governance comes from emirate-level frameworks instead, and those are stricter, not looser.
In Dubai, the Dubai Electronic Security Center's Information Security Regulation (ISR) applies to all Dubai government entities. In Abu Dhabi, the 2025-2027 digital strategy targets 100 percent sovereign cloud adoption for government operations. In-country infrastructure exists to build on (Microsoft has run Azure regions in Dubai and Abu Dhabi since 2019), so the practical consequence is that 'can we use model X' is never answerable in the abstract. It depends on which class of data touches the model, and every entity has (or should have) a classification scheme that answers it.
The default we use to start that conversation, before the entity's own scheme takes over:
| Data class | Typical examples | Where inference can run |
|---|---|---|
| Public | Published reports, open data, public web content | Any major model API |
| Internal | Working drafts, routine correspondence | In-country cloud region, entity-approved services |
| Confidential | Resident data, case files, unpublished policy | Sovereign or on-premise infrastructure |
| Restricted | Security-relevant material | Isolated accredited environments, often no LLM at all |
Arabic handling is an evaluation axis, not a checkbox.
UAE government work is genuinely bilingual: official correspondence and decrees in Arabic, much of the internal working material in English, constant translation between the two. A model that is excellent in English and mediocre in Arabic fails half the job, and you will not discover that from a vendor deck.
The region has produced serious Arabic-first options: Jais, the open-source Arabic model built by G42's Inception with MBZUAI, and the open Falcon family from Abu Dhabi's Technology Innovation Institute. Both matter beyond benchmarks, because open weights can run on sovereign infrastructure, which is exactly what the stricter data classes require. Still, treat Arabic as an evaluation, not an ideology: the large commercial models are often stronger in Modern Standard Arabic than teams expect, and the right answer is frequently a mix across data classes. What the evaluation must cover:
- Your own documents, not benchmarks. Run candidate models on twenty real (declassified or synthetic) samples of your entity's correspondence and reports, in both directions of translation.
- Register and formality. Government Arabic is formal Modern Standard Arabic with fixed honorifics and letter conventions. A model that drifts colloquial is unusable for official output, whatever its benchmark scores say.
- Right-to-left and mixed-direction output. Numbers, dates, English entity names, and citations inside Arabic text are where formatting quietly breaks, and where staff lose trust in the tool.
- Terminology consistency. Ministries have official translations for their own titles, programs, and legal terms. The system needs a terminology list injected into every prompt, or it will invent its own.
Procurement shapes the project more than the technology.
None of what follows is written in any regulation we can cite; it is the pattern we see doing the work. Government procurement in the UAE typically means supplier registration in the entity's system before anything is signed, a local contracting entity, security review of anything that touches entity systems, and approval cycles that run on the budget calendar rather than yours.
The teams that handle this well scope in two parallel tracks. Track one is a pilot on public or internal-class data, using already-approved infrastructure, sized to produce evidence in weeks. Track two is the accreditation and procurement path for the production system, started immediately because it is the long pole. Run only track one and you produce demos that die in review; run only track two and you spend a year with nothing to show, which is fatal under a mandate to demonstrate progress.
One more reality: knowledge transfer is usually a genuine requirement, not contract boilerplate. Entities are building internal capability, and a vendor whose system only the vendor can operate will not survive renewal. Plan the handover from the start.
What adoption looks like at desk level.
Strip away the strategy layer and the workflows that get automated first look familiar: bilingual correspondence drafting against the entity's letter conventions, summarization of long case files, meeting minutes in both languages, retrieval over the entity's own policies and precedents, and first drafts of the recurring reports every department owes every quarter.
Finding the right two or three is the same discipline as anywhere: map how work actually moves, score candidates, sequence a roadmap with owners. Our audit method applies almost unchanged, with one addition: data classification becomes the first scoring gate rather than one axis among five. A workflow can score perfectly on everything else and still be a year away because its data class demands infrastructure the entity does not have yet.
The human side transfers too, with one local twist: top-down sponsorship is rarely the problem here, workflow-level fit is. The tactics in our piece on getting employees to actually use AI apply, but start from redesigning the named workflows rather than from access and encouragement.
The first six months, sequenced.
01:
Get the data classification map in writing
Which classes exist, which systems hold what, and who signs off on each class touching an external model. If the entity has no usable scheme, drafting one becomes deliverable zero.
02:
Audit two or three real workflows
Shadow the work, score the candidates, and gate on data class first. The output is a short ranked roadmap the sponsor can defend upward.
03:
Run the Arabic evaluation
Candidate models against real documents from the target workflows, scored by the people who write these documents today, not by the project team.
04:
Pilot on the approved infrastructure you already have
Lowest-viable data class, one department, named owners, a checkpoint date. The purpose is evidence for the production case, not the production system itself.
05:
Start accreditation for production in parallel
Security review, procurement, and hosting decisions for the real system begin the same week as the pilot, because this track is the schedule.
06:
Hand over deliberately
Documentation, prompts, terminology lists, and a named internal operator. In this market, the handover is part of the deliverable, not an afterthought.
Do it yourself, or bring us in.
Everything above is doable internally if the entity has someone who can hold both the technical and the compliance thread for six months. The honest reasons entities bring us in: that person rarely exists in-house yet, an outside team has pattern recognition across engagements that no first-timer can have, and a fixed-scope AI workflow audit is an easy first contract to move through procurement.
We work on-site in Dubai and Abu Dhabi through a UAE entity, and we have done this inside government, not just written about it (more background on the story page). Either path, the goal is the same: working AI on real workflows, on infrastructure your classification scheme allows, in both languages.
Frequently asked questions.
Does the UAE data protection law (PDPL) apply to government entities?
No. Federal Decree-Law No. 45 of 2021 explicitly excludes government entities and government data from its scope. Public-sector data rules come from emirate-level frameworks instead: Dubai's Information Security Regulation, Abu Dhabi's sovereign cloud requirements. In practice your own entity's classification scheme is the document that governs what you can do.
Can a UAE government entity use ChatGPT or Claude at all?
Sometimes, and it depends on data class, not on the tool. Public and some internal-class work can often run on commercial models, especially through in-country cloud regions; confidential classes generally require sovereign or on-premise hosting, which points to open-weight models. The right question is which data class the workflow touches and what infrastructure is accredited for it.
Do we have to use Arabic-first models like Jais or Falcon?
No, and we would not choose on origin. Jais and Falcon matter because open weights can run on sovereign infrastructure, but large commercial models are often stronger in formal Modern Standard Arabic than expected. Run the evaluation on your own documents and let the results decide; the answer is frequently a mix across data classes.
How long does a first public-sector AI project take?
The pilot is weeks: a scoped workflow on already-approved infrastructure can show results inside a quarter. Production runs on a different clock, driven by accreditation and procurement rather than engineering; six to twelve months is realistic. The mistake is running these sequentially; start the accreditation track the same week as the pilot.
Where should an entity start?
With the data classification map and a workflow audit, in that order. The map tells you what is buildable now versus later; the audit tells you which workflows are worth building. Our published audit method works internally if you have the two weeks; gate every candidate on data class first.