The news: hardware sovereignty, software dependency
On 21 September 2026, Rest of World reported that Nvidia plans to release a free, downloadable AI model by the end of the year, and that it is aimed at buyers already running Nvidia hardware. The report ties the plan to Nvidia's $7 billion purchase of a stake in U.S. coding startup Poolside, which also licenses Nvidia the tools Poolside uses to build models. Few countries fit the target buyer better than the UAE, whose flagship data center is due to run on 400,000 Nvidia chips. The UAE has its own free model, Falcon, from the Technology Innovation Institute. The report frames the choice as a dilemma: own the machines and rent the intelligence, or build the software layer at home.
The model choice is not only commercial. G42, the state-backed AI company, cut its Chinese ties to win access to Nvidia's chips, and it joined Nvidia's Open Secure AI Alliance in July. Adopting Nvidia's model would narrow the UAE's old position as neutral ground between Washington and Beijing.
The strongest case for a mandated sovereign stack
The case for steering public buyers toward Falcon is serious. A country that runs critical services on a foreign model inherits that supplier's licence terms, update schedule and export-control exposure. The U.S. rule that lifted the UAE's chip constraints shows how conditional access is. The Bureau of Industry and Security's final rule, published 14 July 2026 and effective 10 July, moved the UAE from Country Groups D:3 and D:4 to A:5. But advanced-computing shipments are license-free only where the consignee and every end user appear on a named approved list. G42's and Core42's authorization also expires in 2027 unless they become U.S. companies or apply again. If access to chips can be conditioned that way, a government might reasonably ask whether it wants its models conditioned too.
Why procurement mandates would be the wrong tool
The answer to dependency risk is optionality, not a mandate. Nvidia's model is meant to be free to download. Falcon is free too. Open weights change the usual dependency argument. A buyer can inspect, fine-tune and host the model on its own infrastructure, and a licence that stays free is hard to withdraw from downloads already made. Two credible open options competing for the same UAE users is the outcome regulators in most jurisdictions say they want.
A rule that told agencies or regulated firms which model to use would freeze that competition. It would also tie a fast-moving technical choice to a diplomatic judgment about which patron to favor. Model rankings change within months. Neutrality, if it is worth preserving, is better preserved by keeping every serious open model legally usable than by legislating a national champion.
What the UAE's regulatory architecture already gets right
The UAE's approach so far has been to regulate uses and data, not model provenance. That is the proportionate design, and ADGM is its clearest example. The ADGM Data Protection Regulations 2021, explained in a presentation from ADGM's Office of Data Protection, added a right not to be subject to automated decision-making or profiling and required data protection impact assessments for high-risk projects. Those duties attach to what a deployer does with personal data, whichever model sits underneath. A firm in ADGM using Falcon or a Nvidia model faces the same obligations.
Outside the free zones, the federal personal data law, Federal Decree-Law No. 45 of 2021, applies but excludes free-zone entities that have their own data protection regimes, ADGM and the Dubai International Financial Centre among them. That two-track structure has costs, because firms must map which regime governs which activity. It also lets ADGM act as a testbed with rules built for financial and commercial users, while the federal layer stays broader.
The practical lesson is that model-agnostic obligations are more durable than model-specific ones. Requirements for explainability, human review and impact assessment survive a switch from one model family to another. A ban or preference list does not.
What regulators should do next
- Keep the rules use-based. Continue to attach duties to automated decisions affecting people, not to a model's origin.
- Publish security baselines, not brand lists. If the concern is inspectability and control, which is what the Open Secure AI Alliance says it advocates, set an evaluation standard that any open model, Falcon included, can meet.
- Require portability in public contracts. Agencies should be able to swap models without rebuilding systems. That protects against any single supplier, domestic or foreign.
- Clarify the free-zone boundary. Firms straddling ADGM and the mainland need clear guidance on which regime covers a model deployed across both.
The bottom line
The UAE's U.S. alignment is being set by export-control law and chip supply, not by anything a model licence does. What domestic regulation can control is whether the market for models stays open. Nvidia's free model is a competitive gain for UAE buyers if it sits beside Falcon, not in place of it. The proportionate policy is to let both compete under the same use-based rules and to intervene only where a specific deployment causes specific harm.