UAE UAE AI strategy regulation ADGM

The UAE Answers Wartime AI Attacks With an Industrial Policy for Cyber Defense

As AI-driven hacking attempts against UAE banks and infrastructure quadrupled, Abu Dhabi chose to build sovereign defenses rather than just buy them.

UAE's Wartime Cyber Buildup People of Internet Research · UAE ~800,000 Daily attack attempts About 4x the prewar rate since Feb… 3 Major attack waves in 2026 Government, finance, then aviation… May 12, 2026 Cyber Factory launch date Cyber Security Council and CPX Hol… June 14, 2026 New federal AI authority UAE consolidated AI and data overs… peopleofinternet.com
UAE's Wartime Cyber Buildup People of Internet Research · UAE ~800,000 Daily attack attempts 3 Major attack waves in 2026 May 12, 2026 Cyber Factory launch date June 14, 2026 New federal AI authority peopleofinternet.com

Key Takeaways

A Wartime Spike, Measured in Hundreds of Thousands

Since fighting broke out between Iran, Israel, and the United States in February 2026, hacking attempts against the United Arab Emirates have climbed to roughly 800,000 a day — about four times the prewar rate, according to the UAE Cyber Security Council. The council said on August 10, 2026 that it had detected and contained a coordinated, multi-vector campaign targeting aviation, energy, and education systems, the third such wave this year after earlier attempts against government platforms and financial institutions (Rest of World, Aug. 24, 2026). What has changed, security officials told Rest of World, is not just volume but speed: AI now compresses attack chains that once took days into hours, generating phishing lures, probing for software flaws, and assembling malware faster than defenders can patch.

The UAE's response, launched in May and now scaling up, is not a new law. It is an industrial policy: the Cyber Security Council and its national partner CPX Holding stood up the 'UAE Cyber Factory' on May 12, 2026, to design and manufacture AI-driven security tools domestically rather than import them, with a National Operations Center coordinating the government-wide response (The National, May 12, 2026). Dr. Mohamed Al Kuwaiti, the UAE's cybersecurity chief, framed it as a shift from buying protection to building it — what officials call "cyber sovereignty."

The Case for Building at Home

There is a real argument here, and it deserves to be stated plainly before it's contested. A government whose banks, airports, and power grid are under sustained, AI-accelerated attack during an active regional war has a legitimate interest in not depending on foreign vendors for the tools that detect and stop those attacks — especially when the war itself involves states with cyber capabilities. Supply-chain dependence in security tooling is a genuine vulnerability: a foreign vendor can be pressured, sanctioned, or compromised in ways a domestic capability is not. Centralizing incident response through one National Operations Center also solves a coordination problem that fragmented, sector-by-sector responses handle badly — speed matters more than usual when an exploit chain that used to take days now takes hours.

This isn't happening in a regulatory vacuum, either. The UAE Cyber Security Council's National Cyber Security Policy for Artificial Intelligence already sets baseline requirements — governance, infrastructure hardening, algorithm and training-data protection, human oversight of critical decisions, and real-time threat monitoring — for any organization deploying AI in the country (u.ae, Cyber Activities Policies). The Cyber Factory sits on top of that framework rather than replacing it, and it arrived weeks before the UAE consolidated its AI and data oversight into a single Federal Authority for Artificial Intelligence and Data on June 14, 2026, absorbing the former AI Office, TDRA's digital-government arm, and the Emirates Data Office (Morgan Lewis, June 2026). That's a coherent sequence, not improvisation: policy, then institution, then capability.

Where 'Sovereignty' Can Curdle Into Protectionism

The risk is what "sovereignty" tends to become once the emergency framing fades. A state-directed factory for security software, built with a single anointed national partner, can just as easily calcify into a mandate that banks and infrastructure operators buy domestic tools whether or not they are the best available — the same logic that produces data-localization rules dressed up as security policy elsewhere. Proportionate crisis response looks like accelerated procurement and information-sharing; disproportionate response looks like a permanent preference regime that locks out competing vendors, including the foreign cybersecurity firms whose products the UAE's own banks and airlines have relied on for years.

There is also an accountability gap worth naming. A National Operations Center that both detects intrusions and reports on its own success, without independent technical audit or public disclosure of methodology, asks the public and the private sector to trust its account of 800,000 daily attempts without a way to verify it. That's not a reason to doubt the figure — Rest of World's reporting and the Council's own statements are consistent — but transparency mechanisms should scale with the powers a National Operations Center accumulates, not lag behind them.

The Right Test Going Forward

The UAE has, so far, kept the sequence right: a published AI security policy first, a consolidated regulator second, an emergency capability-building program third. The test of whether this stays proportionate is whether the Cyber Factory sunsets its wartime urgency into competitive, interoperable standards once the acute threat recedes — or whether "sovereign by design" quietly becomes "foreign vendors need not apply." Given how directly AI has lowered the cost of attack, building faster domestic detection and response capacity is a defensible, even necessary, move. Keeping that capacity open to competition and subject to independent scrutiny is the part regulators elsewhere should watch closely.

Sources & Citations

  1. Rest of World: UAE fights AI cyberattacks with AI defenses
  2. UAE National Cyber Security Policy for Artificial Intelligence (u.ae)
  3. UAE Cyber Activities Policies hub (u.ae)
  4. The National: UAE Cyber Factory launched
  5. Morgan Lewis: UAE establishes Federal Authority for AI and Data