[{"data":1,"prerenderedAt":135},["ShallowReactive",2],{"uc-reg-cbuae-ai-guidance":3},{"regulation":4,"includeUnpublished":11,"indexable":12,"useCases":13},{"id":5,"label":6,"issuer":7,"region":8,"url":9,"description":10},"cbuae-ai-guidance","CBUAE guidance on AI and ML","Central Bank of the UAE","middle-east","https://www.centralbank.ae/","UAE central bank expectations for the enabling technologies, AI and machine learning used by licensed financial institutions.",false,true,[14,45,79,104,122],{"slug":15,"title":16,"shortTitle":17,"definition":18,"status":19,"industries":20,"functions":24,"patterns":28,"audience":33,"autonomy":34,"adoptionStage":35,"segment":36,"evidenceCount":37,"publicEvidenceCount":37,"organizations":38,"bestGrade":40,"headline":41,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":44},"shariah-compliance-screening","AI assistant for Shariah compliance screening and review","Shariah compliance screening","An AI assistant that screens Islamic financing contracts, deal structures and investments for Shariah compliance risks such as riba, gharar and exposure to prohibited activities, retrieves the relevant standards and fatwas, drafts the Shariah review documentation and flags issues for the Shariah board, which keeps sole authority over any ruling.","published",[21,22,23],"banking","wealth-and-asset-management","insurance",[25,26,27],"regulatory-compliance","legal","product-and-pricing",[29,30,31,32],"rag-knowledge-assistant","document-processing","classification-and-routing","content-generation","employee-facing","copilot","emerging","specialized-businesses",1,[39],"Zoya","B",null,"2026-09-26","minimal","An internal assistant that screens contracts for compliance with Shariah standards is not listed in Annex III: it assesses contracts, structures and securities, not the creditworthiness of natural persons (Annex III point 5(b)). If a customer facing version answers product questions, it must disclose that people are interacting with an AI system under Article 50(1). National Islamic finance regulators set their own Shariah governance expectations.",{"slug":46,"title":47,"shortTitle":48,"definition":49,"status":19,"industries":50,"functions":52,"patterns":55,"audience":33,"autonomy":34,"adoptionStage":58,"segment":59,"evidenceCount":60,"publicEvidenceCount":60,"organizations":61,"bestGrade":40,"headline":69,"lastVerified":77,"indexable":12,"euAiActTier":43,"euAiActBasis":78},"pep-and-adverse-media-screening","AI for PEP and adverse media screening","PEP and adverse media screening","AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.",[21,51,22],"payments",[53,54],"financial-crime-compliance","onboarding-and-kyc",[29,56,31,57],"summarization","translation","early-adopters","middle-office",7,[62,63,64,65,66,67,68],"Deutsche Bank","HSBC","Mashreq","OCBC","Santander UK","Save the Children","Scotiabank",{"kpi":70,"label":71,"unit":72,"n":37,"nUpTo":37,"kind":73,"value":74,"qualifier":75,"claimant":76,"organization":67,"vendorReported":12},"handling-time-reduction","Handling time reduction","percent","reported",60,"at-least","vendor","2026-09-27","Adverse media and PEP screening for due diligence is not listed in Annex III. It processes personal data, including data about alleged offences, so GDPR Article 10 and national AML law govern what may be collected and how long it is kept.",{"slug":80,"title":81,"shortTitle":82,"definition":83,"status":19,"industries":84,"functions":85,"patterns":86,"audience":88,"autonomy":89,"adoptionStage":35,"segment":59,"evidenceCount":90,"publicEvidenceCount":90,"organizations":91,"bestGrade":40,"headline":95,"lastVerified":42,"indexable":12,"euAiActTier":102,"euAiActBasis":103},"perpetual-kyc","AI for perpetual KYC and event driven customer due diligence","Perpetual KYC","AI that keeps each customer's due diligence file current by replacing calendar driven KYC reviews with continuous, event driven refreshes: it watches for trigger events such as a change of ownership, address, behaviour or a new adverse finding, refreshes the file automatically where it can, and involves an analyst only when something material has changed. The risk rating itself and the first file for a new business client are separate use cases.",[21,51,22],[54,53],[87,30,29,56],"agentic-workflow","back-office","supervised-agent",5,[62,92,93,65,94],"First National Bank of Omaha (FNBO)","JPMorgan Chase","Origin Bank",{"kpi":96,"label":97,"unit":72,"n":37,"nUpTo":98,"kind":73,"value":99,"qualifier":100,"claimant":101,"organization":93,"vendorReported":11},"cost-reduction","Cost reduction",0,40,"exact","organization","context-dependent","Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.",{"slug":105,"title":106,"shortTitle":107,"definition":108,"status":19,"industries":109,"functions":110,"patterns":111,"audience":88,"autonomy":89,"adoptionStage":58,"segment":59,"evidenceCount":60,"publicEvidenceCount":60,"organizations":113,"bestGrade":40,"headline":118,"lastVerified":42,"indexable":12,"euAiActTier":43,"euAiActBasis":121},"sanctions-screening-adjudication","AI for sanctions screening alert adjudication","Sanctions screening adjudication","AI that works the alerts raised when customer, counterparty or payment names match sanctions and watchlists: it resolves fuzzy matches across transliterations, aliases and naming conventions, clears clear non matches with a documented reason, and escalates true or uncertain hits with the evidence attached.",[21,51],[53],[31,112,87],"prediction-and-scoring",[114,92,63,64,115,116,117],"AJ Bell","Ratepay","Standard Chartered","United Overseas Bank (UOB)",{"kpi":119,"label":120,"unit":72,"n":37,"nUpTo":98,"kind":73,"value":74,"qualifier":100,"claimant":101,"organization":117,"vendorReported":11},"false-positive-reduction","False positive reduction","Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.",{"slug":123,"title":124,"shortTitle":125,"definition":126,"status":19,"industries":127,"functions":128,"patterns":130,"audience":88,"autonomy":89,"adoptionStage":58,"segment":59,"evidenceCount":37,"publicEvidenceCount":37,"organizations":132,"bestGrade":40,"headline":41,"lastVerified":77,"indexable":12,"euAiActTier":102,"euAiActBasis":134},"dynamic-customer-risk-rating","Dynamic AML customer risk rating with machine learning","Dynamic customer risk rating","Explainable machine learning that produces the money laundering risk rating itself: it computes and continuously updates each customer's rating from due diligence data, products, geography, behaviour and screening results, and shows which factors drive the rating and when enhanced due diligence is warranted.",[21,51,22],[53,129],"risk-management",[112,131],"anomaly-detection",[133],"bunq","An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.",1790598320084]