Dubai Regulator Holds Companies Accountable for AI Operations as Virtual Asset Licenses Tr
Dubai regulator enforces operator accountability as virtual asset licensee base expands threefold
FIRMS REMAIN LIABLE FOR AI AND OUTSOURCED SYSTEMS, DUBAI REGULATOR WARNS AS LICENSED BASE TRIPLES
Fifty-seven firms now hold licenses under Dubai’s Virtual Assets Regulatory Authority, up from just 14 when Senior Director of Market Assurance Sean McHugh joined the regulator a little over two years ago. That near-fourfold expansion signals the commercial momentum building inside the emirate’s virtual asset sector. The message accompanying it, delivered this week at the FutureSec 2026 conference organized by Khaleej Times, is less celebratory: growth does not dilute accountability, and no firm can offload liability onto a vendor or an algorithm.
McHugh was direct on the economics of outsourcing. “Having a vendor is not a get out of jail free card. You’re taking client assets, you’re engaged with clients, you’re engaged with the market… they’re standing in your shoes, they’re acting on your behalf. When they help you make a lot of money, you want to take credit for that. If they lose money or blow something up, you can’t point to them. The up and the down is on your balance sheet.” The framing is deliberately financial: profit and loss attribution cannot be separated from operational responsibility.
The same logic governs artificial intelligence. Vara draws a regulatory line between AI that faces customers or markets directly, such as trading bots, and systems deployed internally for compliance or finance. Market-facing tools carry the stricter burden. Firms must maintain a functioning kill switch capable of halting a malfunctioning algorithm, and they bear full accountability for any errors the system produces. McHugh offered a pointed analogy during his fireside chat with Rahul Banga, Regional Information Security Officer at GIG Gulf: “I kind of see AI like new grads, super smart new grads. They don’t need a break, they don’t sleep, they can work 24/7. But like any firm that hires new grads, you train them up, you do your best, and they make mistakes.” The cost of those mistakes, he made clear, sits with the firm.
Vara’s supervisory framework rests on four pillars: customer protection, cybersecurity risk, financial crime, and the financial soundness of licensed operators. That last pillar ties the regulatory model explicitly to commercial viability, a deliberate alignment with Dubai’s D33 economic agenda for responsible sector development. The authority wants firms to remain profitable. It also wants them solvent and clean.
By contrast, the threat landscape itself has shifted. McHugh noted that on-chain hacks targeting blockchains and smart contracts directly have declined as decentralized finance infrastructure has matured. Risk has migrated to web interfaces, insider threats, and distributed remote workforces. “It’s almost less about the chain, the blockchain, and it’s more about the other nature of the business,” he said. For investors and operators, that migration matters: the attack surface now looks more like a conventional financial services firm than a purely cryptographic one.
The licensed population Vara oversees reflects that complexity. It now spans major institutional traders, hedge funds, algorithmic trading firms, and early-stage startups. To serve that range without reducing compliance to a checkbox exercise, Vara employs a principles-based rulebook rather than prescriptive standards. Requirements scale with firm size and business model. A two-person startup faces different expectations than a large global trading platform, though both are expected to treat cybersecurity as organizational culture rather than an annual audit event.
The commercial rationale is straightforward: UAE residents and international clients will only route capital through regulated platforms if they trust those platforms to deliver best execution and screen out bad actors, including sanctioned wallets and fraudsters. Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government, reinforced that point in his opening keynote at FutureSec 2026.
The open question for the sector’s next phase is whether the principles-based model scales cleanly as the licensed population grows further. With 57 firms already under supervision and the sector still attracting new entrants, Vara’s capacity to calibrate requirements firm by firm will face its own stress test.
For more details on Vara’s regulatory approach and accountability framework, see https://www.khaleejtimes.com/business/firms-cannot-outsource-accountability-even-to-ai-says-dubai-regulator.
Q&A
How many virtual asset firms now hold licenses under Dubai's regulator, and what does this represent in terms of growth?
57 firms now hold licenses under the Virtual Assets Regulatory Authority, up from 14 when Sean McHugh joined as Senior Director of Market Assurance two years ago, representing a near-fourfold expansion of the licensed base.
What is the regulator's position on firms outsourcing operations to vendors?
The regulator states that having a vendor is not a liability shield. Firms remain fully accountable for vendor actions; profit and loss attribution cannot be separated from operational responsibility, and both gains and losses sit on the operator's balance sheet.
How does the regulator differentiate between types of AI systems in terms of accountability?
Vara distinguishes between market-facing AI tools such as trading bots, which carry stricter regulatory burden, and internal systems used for compliance or finance. Market-facing tools require functioning kill switches and full operator accountability for errors; firms bear the complete cost of algorithm malfunctions.
What are the four pillars of Vara's supervisory framework?
Vara's supervisory framework rests on four pillars: customer protection, cybersecurity risk, financial crime, and the financial soundness of licensed operators. The framework explicitly ties regulatory requirements to commercial viability and Dubai's D33 economic agenda.