Dubai Regulator Clarifies: Firms Remain Fully Accountable for AI and Outsourced Actions
The Virtual Assets Regulatory Authority (VARA) in Dubai has issued a firm reminder that licensed virtual asset companies cannot use artificial intelligence or third-party vendors as a buffer against liability. Speaking at the FutureSec 2026 conference, Sean McHugh, the authorityâs Senior Director of Market Assurance, emphasized that any entity acting on behalf of a firm effectively operates in its shoes. Consequently, companies cannot claim the profits generated by these tools while distancing themselves when errors or financial losses occur. McHugh highlighted that for market-facing AI, such as trading bots, firms are strictly required to maintain a manual "kill switch" to intervene in the event of an algorithmic malfunction.
VARAâs regulatory philosophy focuses on four core pillars: customer protection, cybersecurity, the prevention of financial crime, and the overall financial health of the companies themselves. With the number of licensed firms in Dubai surging from 14 to 57 in just two years, the regulator is shifting its focus toward the evolving threat landscape. While direct blockchain hacks have become less frequent due to improved infrastructure, vulnerabilities have migrated toward web interfaces, insider risks, and remote work environments. Ultimately, the authority expects firms to view cybersecurity as an embedded culture rather than a checklist, holding management fully responsible for the outcomes of their chosen technology, regardless of its sophistication.