We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / AI and new risks

AI and new risks

AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill

An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 7 min read

The customer who asked how the machine decides

The operations director of a 30-person insurance brokerage in Houston set up an AI tool in the spring to read incoming claims emails, pull out the policy number and loss details, sort them by urgency and draft the first reply. It cut the claims inbox from two people to one, and the one who stayed likes it.

In August a commercial client's risk manager writes in. Her company's own governance team has asked every vendor a set of questions, and she is passing them on. How are claims prioritised? Is an automated system involved? What data does it see? How does a human review its output before a customer is affected? Who is accountable if it gets one wrong? Please respond in writing within 30 days.

The operations director knows the answers in her head. On paper there is nothing. The tool was set up under the IT contractor's account. The prompt that tells it how to sort claims has been edited four times and nobody kept the old versions. The "human review" is the claims handler reading the draft if she has time, and she does not always have time. The vendor's contract was accepted by clicking a box.

The broker's own errors-and-omissions insurer sent a similar questionnaire in June. It is still in the inbox, unanswered.

What the heck does this mean

AI governance is the boring part of using AI: knowing which systems you run, what they decide, what data they touch, who checks them and who is accountable. Big companies buy frameworks for it. A small business needs about five documents and one named person.

The frameworks, one line each.

NIST AI RMF 1.0: the US National Institute of Standards and Technology's risk framework for AI, built on four functions, Govern, Map, Measure and Manage. It is version 1.0; there is no 2.0.

NIST AI 600-1: the July 2024 companion profile for generative AI, with the specific risks of chatbots and content generators.

ISO/IEC 42001:2023: the certifiable international standard for an AI management system, the outline of a complete programme.

UAE AI Charter: the June 2024 statement of principles that sector regulators now build their rules on, with a Federal Authority for AI and Data announced in June 2026.

Sector rules: in the DIFC, Regulation 10 of September 2023 on personal data in AI systems; for CBUAE-licensed firms, the AI guidance of 23 February 2026; in healthcare, the Abu Dhabi DoH Responsible AI Standard V1 of 2025 and the DHA AI policy of 2025.

EU AI Act: the European law whose high-risk obligations were deferred to 2 December 2027 by Regulation 2026/1744; relevant if you sell into Europe, not otherwise.

Human in the loop: a person who reviews the system's output before it affects someone, and can overrule it. The customer's question was really about this.

None of these frameworks tells a broker how to sort claims. All of them ask the same five things: inventory, data, review, accountability, supplier. Answer those and you can answer any of them.

The numbers that matter

Of the organisations hit by AI-related breaches in IBM's 2026 Cost of a Data Breach Report, 92% lacked basic AI access controls. The tools were running with whatever access the person who set them up happened to have.

In the same IBM 2026 study, 35% of breached organisations had no AI policy at all and a further 33% had one still in development, which leaves 68% operating without a working policy on the day it mattered.

One in four malicious breaches in IBM's 2026 report was AI-enabled. The attackers have adopted the tools faster than the defenders have written the rules for them.

What to do this week

  1. Write the AI inventory: every tool that uses AI, what it decides or drafts, what data it sees, whose account it runs under and which vendor is behind it. Include the ones inside software you already own; the CRM's "smart" features count. (CIS 2 Inventory and Control of Software Assets)
  2. For each tool that affects a customer, patient, employee or payment, write a half-page impact note: what happens if it is wrong, who reviews it before it lands, and how a person can appeal. This is the answer to the risk manager's letter. (CIS 3 Data Protection)
  3. Move every AI tool onto a company-owned account with the least access it needs, and take it off the contractor's login. Version the prompts the way you would version a contract. (CIS 2 Inventory and Control of Software Assets)
  4. Read the vendor's terms for the three things that matter: is your data used for training, where is it stored, and what happens to it when you leave. Get a written answer where the click-through does not say. (CIS 15 Service Provider Management)
  5. Name the accountable person and give them a quarterly review: inventory updated, impact notes current, prompts versioned, vendor answers on file. Put the review date on the calendar before you close this page. (CIS 15 Service Provider Management)
  6. Check the rule that already binds you. A CBUAE licensee reads the February 2026 guidance; a DIFC firm reads Regulation 10; a clinic reads the DoH or DHA AI standard; a US firm starts with NIST AI RMF and AI 600-1. One afternoon, one page of notes. (CIS 3 Data Protection)

Where AccuSights fits

Our assessment adds the AI inventory and impact review to the security assessment you already need, mapped to NIST AI RMF, ISO 42001 and whichever sector rule applies to you, and ranks the gaps so the five documents get written in the right order. The Cyber Hygiene Test takes three minutes; 15 minutes with an engineer settles who owns what.

The read-only compliance agent keeps the inventory and the regulator mapping current with read-only insight. We have no access and do not remediate; you or your IT partner fix, we show you where.

Questions people ask

Do small businesses need an AI governance policy? If AI touches a decision about a customer, a patient, an employee or money, yes, and most 30-person firms are already there through a claims tool, a hiring screen or a chatbot. The policy does not need to be long. It needs to say what the tools are, what data they see, who checks the output and who answers when a customer asks. Without it, the answer to the customer's letter is improvised, and improvised answers to regulators age badly.

What is ISO 42001? ISO/IEC 42001:2023 is the international standard for an AI management system, the AI equivalent of ISO 27001. It asks you to inventory AI systems, assess their impact on people, assign roles, control the data and suppliers behind them, and review the whole thing on a cycle. A small firm rarely needs the certificate, but the structure is the best free outline of what a grown-up AI programme contains.

Does the UAE have an AI law? Not a single federal AI statute as of September 2026. There is the UAE AI Charter of June 2024, a new Federal Authority for AI and Data announced in June 2026, and sector rules that already bind: DIFC Regulation 10 for personal data in AI systems, CBUAE's AI guidance of February 2026 for licensed financial firms, and the DoH and DHA AI standards for healthcare. If you sit in a regulated sector, your regulator's rule is the one that counts today.

The risk manager's letter was a gift. She asked the five questions before a regulator or a plaintiff did, and she gave you 30 days. Use them.

Questions people ask

Do small businesses need an AI governance policy?

If AI touches a decision about a customer, a patient, an employee or money, yes, and most 30-person firms are already there through a claims tool, a hiring screen or a chatbot. The policy does not need to be long. It needs to say what the tools are, what data they see, who checks the output and who answers when a customer asks. Without it, the answer to the customer's letter is improvised, and improvised answers to regulators age badly.

What is ISO 42001?

ISO/IEC 42001:2023 is the international standard for an AI management system, the AI equivalent of ISO 27001. It asks you to inventory AI systems, assess their impact on people, assign roles, control the data and suppliers behind them, and review the whole thing on a cycle. A small firm rarely needs the certificate, but the structure is the best free outline of what a grown-up AI programme contains.

Does the UAE have an AI law?

Not a single federal AI statute as of September 2026. There is the UAE AI Charter of June 2024, a new Federal Authority for AI and Data announced in June 2026, and sector rules that already bind: DIFC Regulation 10 for personal data in AI systems, CBUAE's AI guidance of February 2026 for licensed financial firms, and the DoH and DHA AI standards for healthcare. If you sit in a regulated sector, your regulator's rule is the one that counts today.

Controls this post maps to

CIS 2 Inventory and Control of Software AssetsCIS 15 Service Provider ManagementCIS 3 Data Protection

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.