Social cardScreenshot-ready view for social posts

The right login, the wrong decision: UAE AI push raises security stakes

Abu Dhabi’s ANSEN says companies need clearer limits on AI agents as the UAE targets wider use of systems that act on users’ behalf.

By Teqwah Desk03 Oct 06:33Updated 03 Oct 06:503 min read
The right login, the wrong decision: UAE AI push raises security stakes — Photo: Khaleej Times
The right login, the wrong decision: UAE AI push raises security stakes — Photo: Khaleej Times

Key takeaways

  • ANSEN’s Zheng Li warns that an authorised AI agent can make a harmful decision while using valid credentials.
  • NIST and Microsoft favour separate agent identities, limited permissions and clear activity records.
  • The UAE targets moving 50% of government sectors, services and operations towards agentic AI within two years.
  • More than 300 participants from 50 UAE federal entities began mapping potential uses in June.
  • The central challenge is balancing the speed of automation with oversight of high-impact actions.

An employee’s account can show who opened a database or changed a file. But when an AI agent uses that account, the record may no longer reveal who actually made the decision. That gap is becoming a security challenge as companies give artificial intelligence permission to act on their behalf, according to Khaleej Times. In the UAE, a government drive towards more autonomous systems is bringing the issue into sharper focus.

Zheng Li, co-founder and Group Vice President of Abu Dhabi-based AI company ANSEN, told the newspaper that a major future AI-security incident could involve an authorised agent using valid credentials but making the wrong decision. AI agents—software that can perform several steps towards a task—are gaining access to email, company files and other applications. Checking whether they are allowed into a system is only the starting point. Organisations also need to decide which actions they should be allowed to take.

Li’s warning: valid access does not guarantee that an AI agent will make a safe decision.

A login is no longer enough

The US National Institute of Standards and Technology, or NIST, warned in August that early agent deployments were repeating a familiar security error: sharing credentials. Connecting agents through an employee’s existing account or a long-lived access token, a digital key to a system, can be convenient. But the activity record may then attribute everything to that employee, without separating human instructions from decisions made by the agent or actions involving another tool.

NIST argues that agents should increasingly have their own identifiers, credentials and permissions, linked to the person or system that authorised them. Microsoft’s security guidance takes a similar approach. It recommends a separate identity for each agent, narrow access rights and a record of the full chain of activity. Those records should help an organisation establish what occurred, whose authority supported it and what was altered.

A separate identity does not settle the question of authority. An agent permitted to summarise a security alert might also have the ability to disable an account or stop a service. Li argues that controls should reflect the consequences of an action, with high-impact decisions remaining subject to oversight. Microsoft also warns that agents can gather wider permissions as their roles grow. Access to email, files, support tickets and databases can become more powerful in combination than each permission appears on its own.

UAE rollout puts control in focus

The Open Worldwide Application Security Project has also introduced an Agent Control Standard calling for agents to be open to inspection and their actions traceable. Its approach includes visibility into what agents can access, records of what they have done and ways to restrict their behaviour while they operate. The broader shift is towards controls that govern not just entry, but the scope and duration of permission.

The UAE federal government is targeting a transition of 50% of government sectors, services and operations towards agentic AI within two years, including systems built for autonomous execution and decision-making. In June, more than 300 participants from 50 federal entities began mapping possible uses. The target does not imply unrestricted authority, but it makes identity, permissions and activity records important design decisions as deployment expands.

Li also links these controls to sovereign AI, arguing that control is incomplete without the ability to observe, restrict or intervene in a system’s actions. The challenge ahead is to preserve useful automation without surrendering oversight. As deployments widen, the practical test will be whether organisations can reserve human judgement for consequential decisions while still reconstructing who authorised the thousands of routine actions agents take.

Sources

Comments

No comments yet — be the first.

Related