UAE digital sovereignty

The UAE's 'Cyber Factory' Bets National Security on Sovereign AI Defense — Not Decoupling

As AI-driven hacking attempts quadrupled since February 2026, the UAE answered with a state-industry AI security venture, not a foreign-vendor ban.

UAE's AI Cybersecurity Surge, By the Numbers People of Internet Research · UAE ~800K/day Daily hacking attempts About 4x the ~200K/day prewar base… 3 Major attack waves in 2026 Finance (Jul), then aviation/energ… May 7, 2026 Cyber Factory launch Unveiled by the Cyber Security Cou… 60 National strategy initiatives UAE's cybersecurity strategy spans… peopleofinternet.com
UAE's AI Cybersecurity Surge, By the N… People of Internet Research · UAE ~800K/day Daily hacking attempts 3 Major attack waves in 2026 May 7, 2026 Cyber Factory launch 60 National strategy initiatives peopleofinternet.com

Key Takeaways

A wartime spike, measured in hours not days

When fighting broke out between Iran, Israel, and the United States in February 2026, the UAE's digital perimeter absorbed the shock almost immediately. The UAE Cyber Security Council says the country now faces roughly 800,000 hacking attempts a day, about four times the ~200,000-a-day baseline before the war, with activity traced to actors in some 20 countries and more than 40 organizations, including Iran-linked groups, according to Rest of World. Check Point's Ram Narayanan told the outlet that the gap between a vulnerability's disclosure and its exploitation "has fallen from days to just hours" — a compression attackers owe almost entirely to generative AI doing reconnaissance, phishing-copy writing, and exploit assembly at machine speed.

The Council has now disclosed three major campaigns this year. On August 10, it confirmed a coordinated, multi-vector intrusion attempt against aviation, energy, and education systems — phishing, account takeovers, and infrastructure-breach attempts that were "contained before the attackers could achieve their objectives," per the official announcement carried by The National. That followed a July disclosure targeting the financial sector, and both sit downstream of the war's opening weeks.

Building the defense domestically

The UAE's answer, launched three months into the war rather than in its aftermath, is institutional rather than reactive. On May 7, 2026, at the Make it in the Emirates industrial exhibition in Abu Dhabi, the Cyber Security Council and CPX Holding — the government's designated strategic cybersecurity partner — unveiled the "UAE Cyber Factory," a domestic program to design and scale AI-powered detection and response tools rather than license them from abroad. Dr. Mohamed Al Kuwaiti, the UAE's federal Head of Cyber Security, called it a move toward positioning the UAE "as a global hub for advanced cybersecurity"; CPX CEO Hadi Anwar described it as a step toward "a sovereign, future-ready cybersecurity ecosystem." Both framed the goal explicitly as national cyber sovereignty — building the capability domestically rather than relying on foreign vendors for the systems that watch the country's banks, airports, and grid.

This is a narrower move than a decoupling policy. The Cyber Factory is a defensive-tooling program layered onto existing national infrastructure — the Telecommunications and Digital Government Regulatory Authority's Information Assurance Regulation, the Cyber Security Council's national incident-response framework, and the National Cybersecurity Strategy launched in 2019 around five pillars and 60 initiatives. Nothing announced bars UAE entities from using Western or Israeli threat-intelligence products; it adds a state-backed domestic alternative and, per CPX, a startup and IP pipeline behind it.

The case for sovereignty here is real

Steelmanning the push matters, because the argument isn't manufactured nationalism. When AI compresses exploit timelines to hours, latency in a foreign vendor's patch cycle, licensing renewal, or incident-response queue becomes a live operational risk during an active regional war. Critical-infrastructure operators also have a defensible reason to distrust black-box security tooling sourced from vendors headquartered in states with their own intelligence interests in the Gulf — a supply-chain-trust concern that mirrors why the US restricts Chinese telecom gear in its own networks and why the EU pushed its own cloud-sovereignty rules. And a domestic AI-security industry, if it actually ships competitive products, is a legitimate economic diversification play for a country explicitly trying to build non-oil technology exports.

But sovereignty is not a substitute for scale

The risk is what "sovereign" quietly expands to mean over time. Cybersecurity is one of the few technology domains where being cut off from the outside world is a vulnerability, not a protection — the strongest AI security tools improve because vendors like Check Point, Trellix, Microsoft, and CrowdStrike see telemetry from billions of endpoints across every geography and sector, then retrain detection models on patterns no single country's traffic could ever produce alone. A cybersecurity stack built entirely in-house, however well-funded, starts with a narrower dataset and a smaller adversarial testing base than the global vendors it's meant to reduce reliance on. If "national cyber sovereignty" ever hardens from an additional domestic option into a preference or mandate that crowds out foreign tools for critical infrastructure, the UAE would be trading a supply-chain-trust risk it can manage through vetting and contracts for a threat-intelligence isolation risk it cannot manage at all.

So far, nothing in the public record suggests that hardening. The Cyber Factory is additive, not exclusionary, and pairing homegrown tooling with continued access to global threat intelligence is the version of sovereignty worth encouraging — a hedge against vendor risk during wartime, not a wall against the global security ecosystem that actually catches AI-driven attacks fastest. The Council's own numbers make the stakes plain: every hour saved in detection matters when exploit windows have collapsed from days to hours. The UAE should keep building the Cyber Factory — and keep the front door open.

Sources & Citations

  1. Rest of World: UAE fights AI cyberattacks with AI defenses
  2. The National: UAE thwarts cyberattacks on aviation, energy, education (Aug 10, 2026)
  3. TDRA — UAE Telecommunications and Digital Government Regulatory Authority
  4. u.ae — UAE Government cyber safety and digital security portal
  5. G42: UAE Cyber Security Council and CPX launch Cyber Factory