We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

AI governance assessment and transformation roadmap

AI is already inside your business. Govern it before it governs you.

Nearly half of employees now use AI on work devices, and two thirds of them do it through personal accounts your security team cannot see. The companies that get the value without the breach do one thing first: they put a framework around AI before they scale it. Our assessment measures where you stand against NIST and ISO, and the roadmap takes you from policy to a private model enclave in twelve defined steps, with your data classified, your people trained and the attackers priced in.

Take the 3-minute AI readiness check
NIST AI RMF and ISO/IEC 42001 alignedShadow-AI inventory from your own logsTwelve steps, three phases, one roadmap
YOUR DATARegulatedConfidentialInternalPeoplePolicy, roles, training,acceptable useProcessReadiness, feasibility,impact assessmentTechnologyAllow-list, enclave,testing, monitoringEvidenceNIST AI RMF, ISO/IEC 42001,one evidence setGovernance wraps the data first. Tools, models and agents are admitted by data class.ACCUSIGHTS
45%of employees are regular AI users on corporate devices, up from 15% a year earlier; 67% of them use non-corporate accountsSource: Verizon 2026 Data Breach Investigations Report
43%of breaches involved shadow AI, up from 20%, at an average cost of $5.39 million; 68% of breached organizations had no AI use policySource: IBM Cost of a Data Breach Report 2026
34.8%of the data employees put into AI tools is sensitive, and more than 60% of it moves through personal accountsSource: Cyberhaven AI Adoption and Risk Report 2026
223generative-AI data policy violations per month in the average organization, double the prior year; 54% involve regulated dataSource: Netskope Cloud and Threat Report 2026

Where are you on the curve?

The AI train left the station. The question is whether your data is on it with no ticket.

Four stages, drawn from the transformations we have assessed. Most businesses are at stage one and believe they are at stage two. Click a stage to see what it looks like, what it exposes, and the next move.

1Adoption withoutboundaries2Governance and datagovernance in place3AI in front-officeworkflows4Back-office workflowsand a private enclaveExposure high, value lowValue high, exposure governedAI TRANSFORMATION MATURITYACCUSIGHTS

Where most businesses are today

What it looks like

Staff use whatever AI tool answers fastest. Customer records, contracts and source code go into personal accounts. Nobody has written down what is allowed.

What it exposes

Regulated data leaves through browsers you do not manage. A breach here is also a notification event, and the 68% of companies without an AI policy discover that in the incident report.

The next move

An acceptable-use policy this month, a shadow-AI inventory from your firewall and proxy logs, and a short list of approved tools with company accounts.

The transformation roadmap

Twelve steps, three phases, one evidence set.

Policy before tools, data classification before models, testing before customers. Every step maps to a NIST AI RMF function and an ISO/IEC 42001 control, so the work you do for adoption is the same work that proves governance to a customer, an insurer or a regulator.

Phase 1 · Foundational people and process controls

  1. 01

    AI acceptable-use policy

    Define acceptable and unacceptable AI use across the company, by data type and role, and put it in front of every employee.

  2. 02

    Governance framework and roles

    Assign ownership, decision rights and risk management for AI adoption, mapped to the NIST AI RMF Govern function.

  3. 03

    Data governance and GenAI allow-list

    Classify data into regulated, confidential and internal; align the classification with your security stack and approve the tools that may touch each class.

  4. 04

    Security and privacy awareness training

    Train the workforce on AI-specific risks: prompt injection, data leakage, deepfake fraud and the rules in step one.

Phase 2 · AI feasibility, data readiness and responsibility

  1. 05

    AI data readiness and cleansing

    Scan and categorize data by type, location and sensitivity; recommend and run the cleansing needed before any model sees it.

  2. 06

    Front-office feasibility

    Evaluate readiness for customer-facing assistants: chat, voice, messaging and the customer-experience data behind them.

  3. 07

    Back-office feasibility

    Define requirements and assess readiness for a private model enclave that automates internal workflows.

  4. 08

    Responsible-impact assessment, before and after

    Audit the AI ecosystem for transparency, explainability, compliance, security and privacy, mapped to the NIST Map and Measure functions.

Phase 3 · Build, test, measure

  1. 09

    Private model enclave, build and train

    Develop and test private models in a controlled environment, with your data classification enforced at the boundary.

  2. 10

    AI ecosystem security and privacy risk assessment

    Assess the models, plugins, agents and vendors in the ecosystem against ISO/IEC 42001 controls and the CIS AI companion guides.

  3. 11

    Chatbot and prompt-engineering penetration test

    Simulate attacks on the assistant using MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications, then fix what breaks.

  4. 12

    ROI and cost-benefit analysis

    Align AI outcomes with business goals and set the KPIs the management review will track every quarter.

Foundational people and process controls

  1. AI acceptable-use policy. Define acceptable and unacceptable AI use across the company, by data type and role, and put it in front of every employee.
  2. Governance framework and roles. Assign ownership, decision rights and risk management for AI adoption, mapped to the NIST AI RMF Govern function.
  3. Data governance and GenAI allow-list. Classify data into regulated, confidential and internal; align the classification with your security stack and approve the tools that may touch each class.
  4. Security and privacy awareness training. Train the workforce on AI-specific risks: prompt injection, data leakage, deepfake fraud and the rules in step one.

AI feasibility, data readiness and responsibility

  1. AI data readiness and cleansing. Scan and categorize data by type, location and sensitivity; recommend and run the cleansing needed before any model sees it.
  2. Front-office feasibility. Evaluate readiness for customer-facing assistants: chat, voice, messaging and the customer-experience data behind them.
  3. Back-office feasibility. Define requirements and assess readiness for a private model enclave that automates internal workflows.
  4. Responsible-impact assessment, before and after. Audit the AI ecosystem for transparency, explainability, compliance, security and privacy, mapped to the NIST Map and Measure functions.

Build, test, measure

  1. Private model enclave, build and train. Develop and test private models in a controlled environment, with your data classification enforced at the boundary.
  2. AI ecosystem security and privacy risk assessment. Assess the models, plugins, agents and vendors in the ecosystem against ISO/IEC 42001 controls and the CIS AI companion guides.
  3. Chatbot and prompt-engineering penetration test. Simulate attacks on the assistant using MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications, then fix what breaks.
  4. ROI and cost-benefit analysis. Align AI outcomes with business goals and set the KPIs the management review will track every quarter.

The AI threats that hit before you know

Six ways AI becomes the breach, and the control that stops each.

Prompt injection

A customer, a document or a web page tells your assistant to ignore its instructions, and it does. Still the number one risk in the OWASP 2026 list.

The control: Input and output filtering, least-privilege tool access for the model, and a penetration test that tries it before an attacker does.

Data leaving through personal accounts

Source code is the top data type leaked to AI tools, and shadow AI is now the third most common insider action in DLP data, four times last year.

The control: A GenAI allow-list enforced at the proxy, company accounts for approved tools, and DLP that watches the browser, not only email.

Excessive agency

An agent with a mailbox, a payment API and a vague instruction is an insider with no judgment. OWASP moved this to number three for 2026.

The control: Scoped credentials per agent, human approval for money and access changes, and audit logs you actually read.

AI-assisted phishing and deepfake fraud

Phishing accounts for 44% of AI-assisted initial access in the 2026 DBIR; cloned voices now approve wire transfers.

The control: Phishing-resistant MFA, callback rules for any payment change, and training that uses the real lures.

Poisoned models, plugins and packages

Model weights, prompt libraries and agent plugins are software you did not write. This year’s npm and Rust incidents showed how fast trust can be rented.

The control: A bill of materials for AI components, signature checks, and the same vendor review your other software gets.

No policy, no owner, no evidence

68% of breached organizations had no AI policy and 92% of those with AI-related breaches lacked adequate AI access controls.

The control: Steps one to four of the roadmap. They cost the least and remove the most.

Sources: OWASP Top 10 for LLM Applications 2026; Verizon 2026 DBIR; IBM Cost of a Data Breach 2026; Cyberhaven and Netskope 2026 reports. Figures verified 2 September 2026.

What the assessment measures against

NIST for the structure, ISO for the controls, OWASP and MITRE for the test.

NIST AI Risk Management Framework 1.0

The spine of the assessment: Govern, Map, Measure, Manage. Each of our scoring areas maps to one function.

NIST, January 2023; the Generative AI Profile (NIST AI 600-1, July 2024) adds the GenAI-specific risks.

ISO/IEC 42001:2023

The management-system standard for AI. We use its Annex A controls as the control catalogue so the roadmap can lead to certification if a customer or regulator asks.

Certifiable; adopted in Europe as EN ISO/IEC 42001:2026.

OWASP Top 10 for LLM Applications, 2026

The test plan for anything that takes a prompt. Prompt injection remains number one; excessive agency is now number three.

OWASP GenAI Security Project, 4 August 2026; the Agentic Applications Top 10 (December 2025) covers agents.

MITRE ATLAS

The adversary playbook for AI systems, in the same shape as ATT&CK. Our penetration test in step eleven is built from it.

Data release v5.4.0, February 2026, with agentic techniques added.

CIS Controls v8.1.2 with the AI companion guides

The security baseline the AI program sits on: asset and software inventory, data protection, access control, logging.

CIS AI and LLM Companion Guide; AI Agents Companion Guide, April 2026.

NIST Cybersecurity Framework Profile for AI (IR 8596)

How AI risk folds into the security program you already run: secure AI components, defend with AI, thwart AI-enabled attacks.

Preliminary draft, December 2025; we track it and do not present it as final.

The UAE and the frameworks regulators reference

The Emirates set the direction early. The sector rules are now arriving.

UAE Charter for the Development and Use of Artificial Intelligence
June 2024
Twelve principles for safe, fair, transparent and accountable AI. Voluntary, and the reference point regulators use when they write sector rules.
Every organization operating in the UAE
Federal Authority for Artificial Intelligence and Data
Approved by the Cabinet, June 2026
The new federal body absorbing the AI Office and the UAE Data Office; the address for federal AI and data policy going forward, under the National AI Strategy 2031.
National
DIFC Data Protection Regulation 10
In force since 1 September 2023
Deployers act as controllers and operators as processors; notice, human-intervention mechanisms, audit or certification evidence, and alignment with the DIFC ethics code.
DIFC entities deploying or operating autonomous and semi-autonomous systems
CBUAE guidance on responsible adoption of AI and machine learning
23 February 2026
Board accountability, fairness, explainability, human oversight and data governance for AI and ML used in consumer-facing decisions.
Licensed financial institutions
Department of Health Abu Dhabi Responsible AI Standard V1
2025
Secure-by-design AI, alignment with ADHICS, patient consent and opt-out, and accountability for clinical AI tools.
DoH-licensed healthcare facilities and their AI suppliers
Dubai Health Authority AI in healthcare policy
2025
Governance, validation and data-protection duties for AI used in care delivery and administration.
DHA-licensed facilities, developers using Dubai health data, insurers
National Cybersecurity Strategy 2025 to 2031 and the National AI Test and Validation Lab
Strategy published September 2025; lab announced May 2026
The Cyber Security Council’s strategy treats AI security as a national capability; the validation lab tests AI systems before deployment in critical settings.
National
ISO/IEC 42001:2023
Certifiable now
The management-system standard that regulators and enterprise buyers increasingly ask for; the roadmap is built so certification is a step, not a restart.
Any UAE organization that wants proof

Dates verified 2 September 2026 against the primary instruments. Guidance is described as published; we do not speculate about enforcement.

Three ways to start

Assess, roadmap, or test what you already built.

Fixed fee, scoped in 15 minutes

AI Governance Framework Assessment

Companies at stage one or two that need to know where they stand before the next tool gets approved.

  • Scored assessment against NIST AI RMF and ISO/IEC 42001 Annex A
  • Shadow-AI inventory from 30, 60 or 90 days of your firewall and proxy logs
  • Data-classification readiness and the GenAI allow-list
  • Policy pack: acceptable use, governance roles, training outline
  • Gap register and a 90-day plan

Fixed fee, scoped in 15 minutes

AI Transformation Roadmap

Companies ready to move from policy to production without losing control of their data.

  • Everything in the assessment
  • Front-office and back-office feasibility, data readiness and responsible-impact assessment
  • The twelve-step roadmap with owners, dates and KPIs
  • Vendor and model review for the tools you have chosen
  • Quarterly management review for the first year

Fixed fee, scoped in 15 minutes

AI Security Testing and Private Enclave Readiness

Companies deploying assistants, agents or a private model that must not become the next breach.

  • Chatbot and prompt-engineering penetration test (OWASP 2026, MITRE ATLAS)
  • AI ecosystem security and privacy risk assessment
  • Private model enclave architecture review with our enclave partner
  • Continuous monitoring of AI components inside your existing program

The 3-minute AI readiness check

Six questions. Your stage on the curve, and the first thing to fix.

1. Do you have a written AI acceptable-use policy that employees have been trained on?

2. Do you know which AI tools your staff actually use, including personal accounts?

3. Is your data classified (regulated, confidential, internal) with rules for what may go into AI tools?

4. Does someone own AI risk, with decision rights and a review cadence?

5. Have your AI assistants or agents been tested for prompt injection and data disclosure?

6. Can you show a customer or regulator evidence of your AI controls today?

Answer all six to see your stage immediately; the stage report and the call come next. 0 of 6 answered.

Questions owners ask

AI policy, shadow AI and the frameworks, without the jargon.

Does my business need an AI policy?
Yes, if any employee uses a consumer AI chatbot, Copilot, Gemini or similar tools, which in most firms they already do. A one-page policy that says what data may not be pasted into public AI tools, which tools are approved, and who to ask makes the difference between managed use and a leak. 2026 surveys show most organisations that had a shadow AI incident had no policy at the time.
What is shadow AI, and why is it a risk?
Staff using AI tools the company has not approved or does not know about, usually through personal accounts. The risk is data leaving your control: 2026 surveys report roughly a third of data entered into AI tools is sensitive and most pastes come from personal accounts. For a clinic that is patient notes; for a bank supplier it is a customer file.
Is AI use a risk under the PDPL or the health data law?
Yes. Pasting personal data into a public AI tool is processing by a vendor you have not assessed, which the PDPL expects you to control. For health information, Federal Law No. 2 of 2019 restricts storing or transferring it outside the UAE, and most public AI tools do exactly that. The fix is the same in both cases: an approved-tools list, business-grade accounts with data-use protections, and a policy staff have signed.
What is the NIST AI RMF?
The NIST AI Risk Management Framework, released January 2023 with a generative AI profile added July 2024, is a free, voluntary guide for managing AI risk. Four functions: Govern (rules and accountability), Map (where AI is used and who it affects), Measure (test for accuracy, bias and security) and Manage (fix and monitor). It is a sensible skeleton for an AI policy with no certification required, and it sits well beside the UAE AI Charter.
What is ISO 42001?
ISO/IEC 42001:2023 is the first international standard for an AI management system, ISO 27001 for how you govern AI: policy, risk assessment, impact on people, data quality, transparency and supplier controls. Certification is optional and mainly matters if you build AI products or sell to large enterprises and government. Firms already holding ISO 27001 reuse most of their policies and audit programme.
What should an AI acceptable-use policy include?
Keep it short: approved tools and accounts; data that must never be entered (customer, patient, financial, source code, credentials); a rule that AI output is checked by a human before it reaches a customer; disclosure expectations; and who owns the policy. Add a review date, because the tools change every few months.
Will you tell us to stop using AI?
No. We will tell you which tools may touch which data, and put the guardrails in so the answer to most requests becomes yes. The point of governance is to use AI faster with less exposure, not to ban it.

Talk about your AI transformation before it is too late.

Thirty minutes with an engineer who has assessed AI programs inside banks and hospitals. Bring the tools your staff already use; leave with your stage, your first three steps and a fixed-fee scope. Delivered from Dubai, with the read-only compliance agent keeping the picture continuous afterward.

Take the readiness check first