As artificial intelligence moves from generating answers to taking actions, the security implications are becoming harder for businesses and governments to ignore.
On the sidelines of GISEC Global 2026 in Dubai, Gulf Business spoke with Amr Kamel, GM of Microsoft UAE, about the rise of agentic AI, the new cybersecurity risks created by autonomous systems and how organisations can maintain control as AI agents become embedded across critical workflows.
Kamel also discusses the UAE’s push towards large-scale AI adoption, the challenge of turning investment into measurable productivity, data sovereignty and how the relationship between AI and cybersecurity is likely to evolve over the next three years.
The UAE is moving quickly from generative AI towards agentic AI. What changes when AI systems are no longer simply providing answers but are able to make decisions and take actions on behalf of organisations?
The shift to agentic AI changes the role of AI inside an organisation. Generative AI primarily helps people create, analyse and retrieve information. Agentic AI can go further by reasoning across tasks, interacting with systems and data, and taking a sequence of actions towards a defined outcome.
This creates the potential for a fundamentally different operating model, where people and AI agents work together across business functions. But greater autonomy also requires stronger governance. Human judgement, accountability and oversight must remain central, particularly when agents are making decisions or acting on sensitive data and systems.
This is what Microsoft means by a ‘frontier organisation’: not simply an organisation that uses more AI, but one that redesigns workflows around human and agent collaboration, securely connects AI to organisational data and knowledge, and focuses on measurable outcomes.
The UAE is already moving in this direction at scale. Abu Dhabi Government, for example, has expanded Microsoft 365 Copilot across 35,000 employees, while initiatives such as TAMM AutoGov demonstrate how AI can evolve from supporting users with information to executing services on their behalf.
AI is giving cyber defenders more powerful tools, but it is also lowering the barriers for attackers. Where do you see the biggest new cybersecurity threat emerging as agentic AI becomes more widely deployed?
As agentic AI becomes more widely deployed, one of the biggest risks is that compromised or poorly governed agents can act across multiple systems at speed.
Many of the underlying threats are familiar, including identity compromise, excessive permissions, data leakage and malicious manipulation. What changes is the potential scale and speed of impact. An agent may be able to access applications, data and workflows, which means a single security weakness can have a much broader operational effect.
This is why identity, access control and visibility are becoming increasingly important in an agentic environment. Organisations need to know which agents are operating across their systems, what they can access, what actions they are authorised to take and how those actions are monitored throughout the agent lifecycle.
As companies deploy potentially thousands of AI agents across their operations, how do they control what those agents can access and do, and who ultimately remains accountable when an agent makes the wrong decision?
The principle should be the same one organisations already apply to people and applications: every agent should have a clear identity, defined permissions and an accountable owner.
As organisations scale the use of AI agents, they will need robust controls around authentication, least-privilege access, data permissions, monitoring and lifecycle management. Governance cannot sit outside the deployment model; it has to be designed into the way agents are created and operated from the outset.
Microsoft’s own Cyber Pulse research highlights identity, permissions, data access, governance and visibility as critical requirements for organisations deploying AI agents.
Ultimately, accountability remains human. AI agents may execute tasks and support decision-making, but organisations are still responsible for defining the objectives, policies, permissions and escalation points that govern their behaviour. The more autonomy an agent has, the stronger the requirement for transparency, oversight and clearly defined accountability.
Governments and businesses across the Gulf are investing heavily in AI. Are organisations moving quickly enough on security, governance and resilience, or is AI adoption currently running ahead of their ability to manage the risks?
In many organisations, AI adoption is moving faster than the governance structures around it. That is understandable because the technology is developing quickly and the barriers to experimentation are relatively low. But it also means security and governance maturity need to accelerate just as quickly.
The next phase of AI adoption cannot be measured simply by how many tools or agents an organisation has deployed. It has to be measured by whether those systems are secure, governed, resilient and delivering meaningful outcomes.
In the UAE, this is particularly important because AI is moving from experimentation into core government and enterprise operations. Microsoft’s view is that security, resilience, responsible AI and sovereignty are not separate considerations that can be added later. They are foundational requirements for trusted AI transformation at scale.
The UAE’s own direction reflects this maturity. Its ambition is increasingly focused on moving from isolated AI use cases towards systemic, agentic transformation, supported by governance, skills and institutional capability.
Microsoft has committed significant investment to AI infrastructure and skills in the UAE. Where do you see the biggest gap today: computing capacity, data, cybersecurity, AI skills or the ability of companies to turn AI investment into measurable productivity gains?
All of these elements matter, but the biggest challenge is increasingly the ability of organisations to turn AI capability into measurable business value.
Infrastructure and compute capacity are essential, but they are only part of the equation. Organisations also need modern and well-governed data, strong cybersecurity, skilled people and leadership teams that are prepared to redesign workflows rather than simply add AI onto existing processes.
That is why Microsoft’s investment in the UAE is broader than infrastructure alone. The company’s planned US$15.2 billion commitment between 2023 and 2029 spans cloud and AI infrastructure, local operations, skills and ecosystem development.
On skills, Microsoft has committed to equipping one million people in the UAE with AI skills by 2027, alongside broader initiatives focused on government employees, students, educators and the wider workforce. The priority is not only building technical capability but helping people apply AI effectively in their roles.
The focus now has to move from access to AI towards organisational absorption: whether companies can embed AI into real workflows, redesign how work gets done and convert investment into productivity, growth and better outcomes.
How do you expect AI agents to change the workforce in the Middle East over the next three to five years? Which jobs or functions are likely to change first, and where will human judgement remain essential?
AI agents are likely to change tasks and workflows.
Functions with high volumes of repeatable knowledge work are likely to evolve first. That includes areas such as customer service, software development, finance, HR, sales operations, research and administrative processes. In these areas, agents can increasingly handle multi-step execution, allowing employees to focus more of their time on judgement, problem-solving, relationships and higher-value work.
This is why Microsoft’s frontier organisation model is fundamentally human-led. The objective is not to remove people from the process, but to give them greater leverage by combining human judgement with AI capability.
Over time, skills such as domain expertise, critical thinking, creativity, leadership and the ability to orchestrate work across humans and AI agents will become even more important. Human judgement will remain essential wherever decisions involve ambiguity, accountability, ethics, trust or significant consequences.
Read: Core42’s Rajeev Nair on how AI governance and security are moving into the infrastructure layer
The Gulf wants to build sovereign AI capabilities while remaining connected to global technology platforms. How do you balance data sovereignty and national security requirements with the scale and innovation offered by global cloud infrastructure?
Data sovereignty and global innovation should not be treated as opposing choices.
For governments and regulated industries, sovereignty is fundamentally about control: control over where data is stored and processed, who can access it, how workloads are governed and how operational continuity is maintained.
The role of global cloud infrastructure is to provide the scale, security and pace of innovation that organisations need, while giving them the architectural and governance choices required to meet national and regulatory requirements.
This is the approach Microsoft is taking in the UAE. Microsoft operates cloud regions in Abu Dhabi and Dubai, is working with G42 and Core42 on sovereign cloud capabilities and has introduced in-country data processing for eligible Microsoft 365 Copilot interactions.
Microsoft’s sovereign technology portfolio also supports connected, intermittently connected and fully disconnected models, depending on the sensitivity and regulatory requirements of the workload.
The objective is therefore not isolation, but trusted choice: giving organisations the ability to benefit from global innovation while maintaining appropriate control over their data, systems and critical workloads.
If we meet again at GISEC in three years, what do you think will have changed most dramatically about the relationship between AI and cybersecurity?
The biggest change will be that AI and cybersecurity will no longer be treated as separate technology categories.
AI will increasingly be embedded on both sides of the security equation. Attackers will use AI to identify vulnerabilities, automate reconnaissance and adapt techniques more quickly. At the same time, defenders will use AI agents to correlate signals, investigate incidents, prioritise threats and respond at machine speed.
As this happens, the central security question will shift from simply protecting AI systems to governing autonomous action across the entire digital environment.
Microsoft is already moving in this direction. Its AI-native security work is focused on helping defenders detect, reason and respond at the speed of emerging agentic threats, while its broader security approach is extending identity, permissions, governance and visibility to AI agents.
In three years, cybersecurity will increasingly be about securing an operating environment in which people and AI agents are continuously working alongside one another.