Guide

Human in the loop, on the loop or out of the loop: what Gulf central banks accept

Two Gulf central banks have written down how people should oversee AI. The Central Bank of the UAE’s AI guidance note of 11 February 2026 names three models, human-in-the-loop, human-on-the-loop and human-out-of-the-loop, and keeps the third to low-risk, non-material processes with appropriate controls. The Qatar Central Bank’s Artificial Intelligence Guideline, in force since 4 September 2024, requires every AI system to have a human oversight protocol, records that protocol in the register the QCB receives every year, and puts full autonomy in the regulator’s hands: a system with no human override needs very detailed information to support QCB approval even when it is rated low risk, and a high-risk one needs prior QCB approval, limits the AI cannot override and a supervisor able to shut it down. In both countries a customer can ask for a person to review an AI decision.

Human oversight of AI in Gulf financial services. The way a person reviews, monitors or can stop an AI system’s decisions at a bank, insurer or other regulated financial firm in the Gulf, as section 7 of the Central Bank of the UAE’s AI guidance note and Part C of the Qatar Central Bank’s Artificial Intelligence Guideline define it.

Checked . The CBUAE guidance note’s Rulebook web text and the QCB Artificial Intelligence Guideline, a scanned PDF of 22 pages, were read in full on this date. Both regulators revise their texts, so check the current version before you rely on it. This page is not legal advice.

Two central banks, three modes each, and different names for them

The UAE and Qatar central banks both describe human oversight of AI as a choice between three modes, and both expect the choice to be made system by system rather than once for the institution. The texts are close enough to compare and different enough that a design which passes in Dubai can fall short in Doha.

The Central Bank of the UAE put its version in section 7 of its Guidance Note on Consumer Protection and the Responsible Adoption and Use of Artificial Intelligence and Machine Learning, which its Rulebook records as issued on 11 February 2026 [1]. It asks licensed financial institutions, insurers included, for “meaningful human oversight and judgement”, particularly for decisions with significant implications for consumers, and says the level of human involvement should match the risk the AI poses to a consumer [1]. This page reads only the oversight parts; the whole CBUAE note, section by section, is covered in its own guide.

The Qatar Central Bank gave oversight a part of its own. Part C of its Artificial Intelligence Guideline, in force since 4 September 2024, opens with “Any AI Systems must have a Human Oversight protocol” and then sets out what each protocol demands [2]. The guideline applies whether an entity builds AI itself, buys it, or outsources a process that relies directly on it [2].

The three oversight modes, as each central bank names them
DimensionModeCBUAE guidance note, section 7(a)QCB guideline, sections 2 and 13
A person decidesHuman-in-the-loop: the AI provides recommendations and a human decision maker keeps full authority to approve or reject the outcomeAI-assisted decision-making: no decision can be made without human approval for designated outputs, and the operators using the output are trained to interpret it (13.8)
A person watches and can step inHuman-on-the-loop: the AI works autonomously on routine tasks while a human monitors outcomes and can intervene where necessaryHuman exception oversight: a person monitors, intervenes when the model performs outside expected parameters or fails, and has the power to close the system down (13.7)
No person in the pathHuman-out-of-the-loop: only for low-risk, non-material processes with appropriate controls in placeFully autonomous AI: normal operations fully under the algorithm’s control; detailed information for QCB approval even when low risk, and prior approval when high risk (13.5 and 13.6)

Both columns summarise the regulators’ texts [1, 2]. The row labels are mine.

Full autonomy is where the two regulators part company

In the UAE, taking the person out is a risk decision the institution makes and documents. The note limits human-out-of-the-loop operation to low-risk, non-material processes with appropriate controls, and separately asks institutions to keep, at all times, the clear and immediate ability, with human intervention, to stop using any AI system [1]. It sets no approval step for an automated system. The decision and its evidence stay with the institution.

In Qatar, the regulator decides. A system with no human oversight of the execution of decisions and no option for human override needs “very detailed information to support the use of such a system for QCB approval”, even when the entity rates it low or no risk (section 13.5.1) [2]. A high-risk system of that kind needs prior QCB approval before launch, and the QCB expects to be told as soon as one is being actively considered or developed (section 13.6.1) [2]. It must also carry guard rails and limits the AI cannot override, reviewed on a set schedule or after external volatility spikes, limits linked to warning levels or auto-close routines, and a supervisor able to shut it down if its outputs or data look aberrant (sections 13.6.2 to 13.6.5) [2].

The mode also moves the risk rating. The QCB guideline says a system that allows no direct human oversight will probably be judged higher than normal risk, while one where a human with relevant expertise always makes the final determination will likely be judged lower (section 9.5.1) [2]. Some systems are high-risk whatever the rating says: those determining consumer access to financial services, internal decisions that affect employees in a material manner, and processing of sensitive personal information (section 9.7) [2].

My reading is that in Qatar full autonomy is a regulatory project with its own timeline, and in the UAE it is a design option that needs a written case. Of the three modes it is the one I would argue for least often, and only where a wrong output costs little and can be reversed.

The person on the other end needs authority, tools and time

Both texts assume a person who can act, and the QCB spells out what that means. The user of a system must assign oversight to a supervisor with the necessary competence, training and authority (section 13.3). For a high-risk system the supervisor needs the tools to understand its limits, interpret its output, decide not to use it or override or reverse what it produced, and interrupt it through a “stop” button or a similar procedure (section 13.4) [2]. Where the supervisor monitors rather than approves, the system has to give them information they can respond to in a manageable time frame (section 13.7.2) [2].

The CBUAE asks for meaningful oversight and judgement without defining either word, and puts its stop control in the monitoring section rather than the oversight one [1]. For a bank under both regulators I would take the Qatari list as the working definition of meaningful, because it is the more complete of the two on what a supervisor must be able to do.

The failure I would plan for is the reviewer who agrees with everything. Give a person a long queue of AI recommendations and too little time, and the easy path is to approve them; a human-in-the-loop design that relies on that reviewer is automated in practice. Oversight you can defend shows the reviewer the evidence behind each recommendation as well as the answer, keeps the queue at a size a person can actually work, and tracks how often reviewers overturn the AI. An override rate close to zero is a question to answer before it is a result to report.

Underneath every mode sits the same shape: the model proposes and a separate check, human or rule-based, decides what happens next. The modes differ only in where the person stands relative to that check.

Which mode for which use case

This is how I would set the mode for the AI systems a Gulf bank or insurer is most likely to run. It is a starting point built from the two texts, and a written rating for each AI use case should confirm it or move it.

Oversight mode by use case, for a bank or insurer under the CBUAE or the QCB
DimensionUse caseWhat the texts sayThe mode I would designWhat to log
Retail credit decisionsCBUAE: a loan application is its example of a high-impact decision, and full automation is for low-risk processes only. QCB: decisions on consumer access to financial services are high-risk (9.7.1), so full autonomy needs prior approval (13.6)In the loop for every decline and for approvals outside set limits; on the loop at most for approvals inside themModel version, the inputs used, the recommendation, the reviewer, the final decision and the reason for any override
Insurance claimsCBUAE: an insurance claim is its other high-impact example. QCB: names insurance among high-risk AI when it sets its customer notice rules (20.3.4)In the loop for denials and part payments; on the loop for fast-track payments under a fixed limitAs for credit, plus the limit in force when each claim was paid
Fraud and transaction monitoringCBUAE: encourages AI to find fraud and suspicious activity (5(e)). QCB: keeps fraud model details out of customer disclosure (20.11). My reading: a hold that stops a customer using their money comes close to the 9.7.1 testOn the loop for real-time holds, within hard limits; a person decides account closures and regulatory reportsEvery alert and hold, who released or confirmed it, and when
Customer service assistant that only answers questionsCBUAE: customers told when they are dealing with AI (4(a)), and chatbots meet the disclosure rules (7(d)). QCB: chatbots are its example of a non-high-risk system (20.3.1), but one with no human override still needs detailed information for approval (13.5.1)On the loop: a handover to a person on request or on low confidence, and a sampled review of conversationsThe conversation, the model and prompt versions, each handover and the review sample
Staff screening and performance decisionsCBUAE: the note is written for consumer outcomes, though its governance sections cover every AI system. QCB: internal decisions that materially affect employees are high-risk (9.7.2)In the loop, with the reviewer able to see why the system ranked or flagged a personInputs, output, reviewer and decision, kept with the HR record
Drafting and summarising for staffNeither text treats a draft as a decision. QCB: operators who use AI output to make decisions must be trained to interpret it (13.8.1)AI-assisted by nature: the member of staff owns what they send or signWho used it, on which documents, and the sources each answer drew on
Product recommendations and marketingCBUAE: no AI targeting of unsuitable products and no pressure selling (7(d)). QCB: customers told about the AI, its risks and its limits before the service (20.3)On the loop, with suitability rules outside the model and a person signing off each campaign’s rulesWho was shown what, the rule that allowed it and the campaign sign-off

The second column summarises the two texts [1, 2]. The third and fourth columns are my reading and not legal advice, and a system’s own risk rating can move it up a mode.

When the customer asks for a person

Both regulators give the customer a way back to a human, and they describe it differently. The CBUAE asks that consumers can request a human review or an explanation of an AI decision, that alternative arrangements exist for a customer who does not want to be subject to one, and that customers can challenge decisions and correct inaccurate data feeding the AI, with complaints handled under Article 8 of the Consumer Protection Regulation (section 7(c)) [1]. It also asks institutions to consider opt-out rights, particularly for high-impact decisions (section 4(c)) [1].

The QCB is more mechanical. For decisions made by AI with no human intervention, the customer gets a two-choice process: supply data and resubmit to the AI, or ask for a review of a negative decision by a qualified human decision-maker (sections 21.1 and 21.2) [2]. The entity must tell customers how an AI decision may affect them and whether it can be reversed (section 20.6), and if it decides against offering an opt-out, it must give another route, such as a channel for reviewing the decision (section 22.2) [2].

In build terms that is one feature, and it is far easier to design in than to add later. Every automated decision needs a reference the customer can quote, a way to resubmit corrected data against it, and a queue where a qualified person sees the original inputs, the AI’s output and the new evidence side by side.

The records that prove the mode you declared

Declaring a mode takes a line in a policy. Showing it takes records. The QCB register must hold, for each AI system, whether it is high-risk, whether the entity is its user or its provider, its category and “the Human Oversight protocol used” (section 10.7), and the full register goes to the QCB every year and whenever it asks (section 10.6) [2]. An entity using a system from a provider also gives the QCB the results of its own use testing, its data sources and its human oversight plan (section 14.2.2) [2].

The CBUAE inventory asks for at least the model name, purpose and risk rating [1]. It does not list the oversight mode as a field. I would add it anyway, because section 7 expects the mode to follow the risk, and a supervisor comparing the two columns is the quickest check that it does.

Behind the register sits the decision log. The QCB asks for audit logs and traceability of AI decisions and outcomes, a record of every model version, and archived data sets (section 19.3) [2], and the CBUAE asks for data with clear provenance and audit trails (section 5(a)) [1]. For oversight, the log has to show who reviewed what, when, and whether they changed it. Without that, a system declared in the loop and a fully automated one look identical to an auditor.

Residency is a separate set of rules with its own evidence, set out in the guide to where a Gulf AI system’s data and models are allowed to run.

Where to start

The order I would work in for a bank or insurer with a handful of live AI systems and a policy that names oversight without saying how:

List decision paths, not systems
Every place an AI output changes something for a customer, an employee or the books. One assistant can hold three paths: answering a question, starting a complaint and waiving a fee.
Rate each path and give it a mode
Rate the path, check it against the QCB’s always-high-risk list if you operate in Qatar, and record the mode and the reason in the inventory or register.
Name the supervisors
A person for each path with the competence, training and authority the QCB describes, and a queue sized so they can work it rather than clear it.
Put the limits and the stop outside the model
Hard limits and a stop control the AI cannot override, tested before launch and on a schedule after it.
Wire the customer’s route to a person
A decision reference, a way to resubmit corrected data, a human review and a link into the complaints process.
In Qatar, talk to the QCB early
Any design with no human override goes to the QCB with detailed information, and a high-risk one is notified as soon as it is being actively considered.

Where 1AYM fits

This is the work we sell as agentic workflow design and AI governance implementation: for each decision path, the oversight mode chosen and written down, a review queue a supervisor can actually work, limits and a stop control that sit outside the model, and a decision log that shows the mode is real. Where the AI system is still to be built, the oversight goes in with it, because a reviewer’s screen, a limit and a stop are far cheaper to build first than to add after launch. 1AYM works in financial services, with clients across the UK, the US and the Gulf, and Gulf clients can contract through our UAE entity. We have built Arabic-language AI, including bilingual Arabic and English search and Arabic document OCR, which matters when the reviewer reads Arabic and the evidence behind each recommendation has to be shown in it.

The closest published proof is our work for a government-accredited EdTech in the Middle East, whose database we replatformed into Google Cloud’s Doha region, me-central1, to meet Gulf data-residency requirements. It is education rather than banking; what carries over is turning a written requirement into something built and recorded. A fixed-scope build can start within a day of the scope being signed, and if you already have a scoped job, such as a review console or a decision log, we can resource it on contract from the collective of associates who work with us, held to the same standard. Which mode each system runs in is your institution’s decision, and whether the design satisfies the CBUAE or the QCB stays with your compliance function and your counsel. The call is booked from the end of this page.

For engineers: modes in configuration, limits outside the model, stop controls and the decision log

The oversight modes in engineering terms. Each item is something an auditor can check in configuration, code or logs, rather than by asking someone.

The mode as configuration
Store the oversight mode for each decision path in the inventory and enforce it in code. A path declared in the loop cannot write its outcome without a reviewer identity and a recorded action; a path declared on the loop writes its outcome and raises the events a supervisor watches.
Limits the model cannot override
QCB sections 13.6.2 and 13.7.5 ask for guard rails and operational constraints the AI cannot override. Build them as deterministic checks in the service that executes the action: amount caps, permitted actions, rate limits and allow-lists. An instruction in a prompt is not a limit, because the model can ignore it.
Warning levels and auto-close
Section 13.6.4 links limits to warning levels or auto-close routines. Track override rate, error rate, volume and input drift per path, page the named supervisor at a first threshold, and switch the path to its fallback queue automatically at a second.
A stop that needs no deployment
One switch per path, owned by the named supervisor, that routes traffic to a manual queue or the previous process without a release. CBUAE section 6(f) and QCB section 13.4.4 both expect it. Test it on a schedule and log each test.
A review console that shows the evidence
Show the reviewer the inputs, the retrieved sources, the model and prompt versions and any rules that fired, next to the recommendation. Capture accept, amend or reject and a reason code as structured fields. Send a sample of cases to a second reviewer without the AI’s answer, and measure agreement, which is the plainest test of whether reviewers are deciding or confirming.
A decision log per path
One append-only record per decision: a reference the customer can quote, the path and its declared mode, model and prompt versions, a pointer to the inputs, the output, the reviewer, their action and timestamps, and a link to any resubmission. That is the traceability QCB section 19.3.1 asks for, and it is what answers a customer who asks for a review.
Resubmission and human review
Expose the QCB’s two-choice process (section 21.2) as two operations on a decision reference: resubmit with corrected data, run against the same model version, or route to a qualified reviewer with the original record attached.
Arabic in the review loop
For Arabic-language paths, show the reviewer the Arabic source text and the model’s output side by side, and staff the queue with reviewers who read Arabic. A reviewer who cannot read the input is not overseeing it.

Sources

  1. [1]CBUAE Rulebook, Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in the U.A.E., issued 11/2/2026, web text, read 30 September 2026
  2. [2]Qatar Central Bank, Artificial Intelligence Guideline (Regulating the use of Artificial Intelligence by QCB Licensed Entities), in force 04/09/2024, read 30 September 2026

Questions heads of AI and risk ask

What is human-in-the-loop under the CBUAE AI guidance note?

Section 7(a) of the note describes human-in-the-loop as the model where AI provides recommendations and a human decision maker keeps full authority to approve or reject the outcome. Its other two models are human-on-the-loop, where the AI works autonomously on routine tasks while a person monitors and can intervene, and human-out-of-the-loop, which should only be used for low-risk, non-material processes with appropriate controls.

Does the QCB allow fully autonomous AI?

Only with the QCB involved. A system with no human oversight of the execution of decisions and no human override needs very detailed information to support QCB approval, even when it is rated low or no risk. A high-risk one needs prior QCB approval before launch, notice to the QCB as soon as it is being actively considered or developed, and built-in limits the AI cannot override. This is not legal advice.

Which AI systems are always high-risk under the QCB guideline?

Section 9.7 requires an entity to classify a system as high-risk where it can harm people through interactions determining consumer access to financial services, internal decisions that affect employees in a material manner, or processing of sensitive personal information, whatever the entity’s own rating says.

Can a UAE bank fully automate a credit decision with AI?

The CBUAE note gives a loan application as its example of a high-impact decision and keeps human-out-of-the-loop operation to low-risk, non-material processes, so a fully automated credit decision sits outside what it describes. A person in or on the loop, with a route for the customer to request a human review, is the design that fits the note. This is not legal advice.

What must a QCB AI register say about human oversight?

Section 10.7.4 requires each system’s entry to record the human oversight protocol used, alongside its high-risk classification, the entity’s role as user or provider and a category for its function. The full register goes to the QCB every year and on request.

Who can be the human supervisor of an AI system in Qatar?

Section 13.3 of the QCB guideline says the user must assign human oversight to a supervisor with the necessary competence, training and authority to operate or oversee the system. For a high-risk system, the supervisor must be able to override or reverse its output and to interrupt it through a stop button or a similar procedure.

What can a customer do about an AI decision in Qatar?

Where AI decided with no human intervention, the entity must let the customer either supply data and resubmit to the AI, or ask a qualified human decision-maker to review a negative decision. A later complaint goes through the standard complaints process.

Is the QCB AI guideline binding?

It calls itself a guideline, but it describes its contents as instructions in force from 4 September 2024, most of its clauses say “must”, and an exemption from any requirement needs QCB approval. I would plan on the basis that it binds. This is not legal advice.

More in this topic

  • For a firm in Dubai’s financial centre: the evidence of when an AI system hands a decision to a person, under the DIFC’s own data rules.

  • What Saudi Arabia’s data law asks when a decision rests on automated processing, for a bank that also serves the Kingdom.

Further

  • AI governance implementation · The register, the oversight records and the decision log, built into the systems they describe.
  • Engagement file D-02 · A government-accredited EdTech in the Middle East, with its database replatformed into Google Cloud’s Doha region.
  • Agentic workflow design · The engagement that places the person, the limits and the stop control in each AI workflow before it runs.

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM