WHAT A MACHINE MAY DECIDE.

The UAE is drafting a classification for which tasks an autonomous system may execute and which it may only recommend. It is the most reusable AI artifact published in the region this year — and copying it costs you an afternoon.

2026-08-24 · UAE · 3 MIN READ
UAEGOVERNANCEAGENTIC AI

WHAT HAPPENED

The National Committee for the Agentic AI Project ran a workshop for more than 100 federal officials in August. The headline numbers were set by the Cabinet on 23 April 2026: half of UAE Government sectors and services to run on agentic models within two years, a 90-day window to identify which services go first, and a national training program covering around 80,000 employees. Under those numbers sits the part that decides private-sector budgets: the committee is building a classification for which tasks an autonomous system may execute on its own, and which it may only recommend. Its stated operating principle is "human leads, AI enables."

AGENT PERMISSIONS ARE A BUILD SPEC, NOT A GOVERNANCE PAPER

Most AI programs we audit have a tool list, a budget and a vendor. Almost none have a written answer to the only question that actually blocks deployment: what the agent is allowed to do without asking.

That absence surfaces late, and expensively. Legal will not sign off because nobody can say what the agent decides. Ops will not hand over the queue because the failure mode is undefined. The pilot works, everyone is pleased, and it sits in staging for four months while three departments negotiate something that should have been one page written before the build started.

A decision boundary is that page. It is not governance theater. It is a build specification. Every downstream question resolves from it: what gets logged, what triggers escalation, who owns the outcome, what the rollback looks like. Write it first and the integration work becomes ordinary engineering. Write it last and it becomes a committee.

A DECISION BOUNDARY TAKES ONE AFTERNOON

Take one workflow — not the company, one workflow. List its steps. Put each step in exactly one of three columns.

BANDTHE AGENTTHE TEST
EXECUTEacts, logs, moves onreversible within minutes, and a wrong answer costs less than reviewing every right one
RECOMMENDdrafts, a human approvesthe action touches money, a contract, or a customer relationship
REFUSEstops and escalateslegal, medical, safety, pricing exceptions, and anything with a regulator attached

Two rules make this work. First, the default for an unlisted step is REFUSE, not EXECUTE — an agent that improvises on unclassified work is what ends programs. Second, one named human owns each band and reviews the classification on a fixed cadence, because the boundary moves: things start in RECOMMEND and earn their way into EXECUTE on measured performance, not on enthusiasm.

That last rule is the difference between a policy and a system. Companies that do write one write it once and never move it, so the agent stays a drafting assistant forever and the ROI never arrives. The boundary should be a ratchet with evidence behind each click.

PROCUREMENT, LEGAL AND THE COST MODEL RESOLVE FROM ONE PAGE

  • Procurement gets a spec. "Which of these steps can your product execute unattended, and can you show us the audit trail?" is a far better vendor question than a feature comparison.
  • Legal gets something to approve. Reviewing a one-page boundary is a meeting. Reviewing "AI in customer service" is a quarter.
  • You get a cost model. EXECUTE steps run on cheap fast models. RECOMMEND steps can afford a better one because a human reads the output anyway. That single split is usually the largest cost lever in an agent deployment.

The federal program will publish its version because it has to. By the time the federal version lands, the organizations that wrote their own will already know which bands they got wrong.

SOURCES//
RELATED//
ALL INSIGHTS ▸