The UAE Cybersecurity Council issued a warning on 28 August that AI tools found through online searches may be designed to harvest users’ personal data without their knowledge, and urged residents to verify any platform before using it.
The council said the greatest privacy risk from an AI tool may not be what a user types into it, but what the tool is permitted to access: cameras, location data, and other device functions. Residents were told to review permissions carefully and decline requests for access that the service does not clearly need.
What the UAE Cybersecurity Council AI warning covers
The advisory sets out three categories of information that carry the highest risk when entered into AI platforms.
Financial data, including credit card numbers, bank account details, online banking credentials and financial statements, should never be shared with an AI service. If a conversation is exposed or the platform has weak privacy protections, that data can be compromised.
Identity documents such as passports, Emirates IDs, driver’s licences and visas contain information that enables identity theft if exposed. The council advised users who need AI to help analyse a document to redact personal details before uploading it.
Health records, including diagnoses, prescriptions, test results and insurance details, carry similar risks. Where AI is being used to interpret a medical report, names and identification numbers should be removed first.
The council said users should rely only on trusted and verified sources and think carefully before granting any application access to personal information or device functions.
The broader threat picture behind the advisory
The warning sits against a sharply worsening threat environment. According to the UAE Cybersecurity Council, AI-powered phishing now contributes to more than 90 per cent of digital breaches. The council has also reported that between 90,000 and 200,000 breach attempts strike UAE infrastructure every day, all of which are blocked before affecting services or data.
Since the beginning of 2026, 128 confirmed cyber threat incidents have targeted entities across the UAE, covering ransomware attacks, government breaches, and data leaks, according to Dr Mohamed Hamad Al Kuwaiti, head of the council. State-sponsored and advanced persistent threat groups account for 71.4 per cent of the tracked actors targeting UAE infrastructure.
Separately, the council recorded more than 12,000 breaches through open and untrusted public Wi-Fi networks in the UAE since the beginning of 2025, according to a WAM report issued in August 2025.
Al Kuwaiti addressed the scale of the shift at the 3rd Government Cybersecurity Summit in Abu Dhabi on 9 June: ‘We are no longer seeing AI used only for phishing and email attacks. It is now being leveraged across a broader spectrum of cyber threats, including data exfiltration, data wiping and sophisticated cyber operations that we have witnessed almost daily in recent months.’
He also warned of AI-generated deepfakes and disinformation campaigns, saying such tools can spread fear and confusion within communities. ‘Cyber threats do not distinguish between governments, companies or individuals,’ he said.
The most targeted sectors in the UAE are government administration at 9.4 per cent, financial services and banking at 9.3 per cent, and real estate at 5.5 per cent, the council said in its State of the UAE Cybersecurity Report 2025, published jointly with CPX on 25 February 2025.
The council’s National Cyber Security Policy for Artificial Intelligence defines minimum security requirements for AI adoption in the UAE, covering governance, infrastructure, algorithm protection, operational safety, threat monitoring and performance evaluation.
The most immediate action residents can take is checking a platform’s permission requests before granting access, particularly to cameras and location data on mobile devices.
