What the record proves
The evidence, instrument by instrument.
What UAE instruments ask for about AI and records, and the evidence the Firmantia record produces for each. The record produces the evidence for an obligation; it does not comply on anyone's behalf.
In development. Early access open for regulated teams in the UAE and Qatar.
Central Bank of the UAE (CBUAE)
Guidance Note on Consumer Protection and Responsible Adoption and Use of AI/ML
Issued 11 February 2026
What it asks for
- An AI inventory with each system's name, purpose and risk rating
- Data with provenance and audit trails
- A documented human oversight mode
- The ability to cease use of an AI system
- Audit rights over third-party AI
Firmantia's role: a tamper-evident audit trail of what each AI agent did, with the policy decision and the signed human approval behind each action, that the institution's auditors and its regulator can verify themselves, including for agents run on a third party's platform.
Central Bank of the UAE (CBUAE)
Outsourcing Regulation for Banks (Circular 14/2021)
Effective from 15 July 2021
What it asks for
- A register of all outsourcing arrangements
- Agreements that let the Central Bank access the bank's data upon request
- A Master System of Record continuously maintained and stored within the UAE
Firmantia's role: a record built to be kept in the UAE, that the bank, and the CBUAE on request, can verify without trusting the provider that runs the agents.
Dubai Financial Services Authority (DFSA)
DFSA Rulebook, General Module (GEN): Cyber Risk Management
GEN 5.5 made 21 June 2023
What it asks for
- A Cyber Risk Management Framework
- Identification of ICT assets and assessment of cyber risk
- Notification to the DFSA of a material Cyber Incident no later than 72 hours after becoming aware of it
Firmantia's role: a time-stamped, tamper-evident record of what each agent did, to reconstruct agent activity around an incident. It does not notify the DFSA; notification stays with the firm.
Abu Dhabi Global Market Financial Services Regulatory Authority (ADGM FSRA)
FSRA Rulebook: Cyber Risk Management (GEN 3.5)
Effective 31 January 2026
What it asks for
- An ICT asset inventory
- Notification of a material Cyber Incident no later than 24 hours after becoming aware of it
Firmantia's role: a time-stamped, tamper-evident record of what each agent did, to reconstruct agent activity around an incident. It does not notify the regulator; notification stays with the firm.
United Arab Emirates
Federal Decree-Law 46/2021 on Electronic Transactions and Trust Services
Issued 20 September 2021; effective 2 January 2022
What it asks for
- Admissibility as evidence is not precluded by the mere fact that a record is in electronic form
- A Qualified E-Seal of a legal person is evidence of the authenticity and integrity of the information it is associated with (Art. 18(4))
- A Qualified Time Stamp binds the date and time to data in a manner that reasonably precludes undetectable changes (Art. 23)
Firmantia's role: electronic records sealed with signatures and RFC 3161 time-stamps, which can be anchored to a qualified time-stamp authority the organization uses. Firmantia supports anchoring to a qualified time-stamp authority; it does not itself provide one.
Firmantia produces evidence. Whether that evidence satisfies a given obligation is a determination for the organization and its regulator.
Talk it through with us.
Tell us which instruments you answer to and which agents you run.