Agentic AI can take real cyber-security work away from people before an enterprise fully trusts it. That apparent contradiction changes how CIOs and CISOs should judge automation because useful delegation depends on how much decision authority a process can safely receive and what happens when it fails. Three UAE technology leaders approach that boundary from different operating environments: ENOC is already delegating security work, DMCC varies delegation according to consequences, and Dubai Islamic Bank surrounds consequential AI with verification and controls.

Agentic AI changes the delegation question

For Mohammad Al Rais, senior director of group IT at ENOC, the starting point is continuity with automation that enterprises already understand. “Automation is not something new; we’ve been doing automation for decades,” he said. “When we talk about agentic AI, it’s automation with a brain.” Greater agency lets automation handle more of a process under defined rules and guidance, so an enterprise must decide how much of that process to delegate.

Greater autonomy still needs boundaries because Al Rais sees error and inappropriate behavior as risks on both sides of the human-AI relationship. “It’s a near-human kind of process, yet that needs guidance,” he said. “Humans and agentic AI might be similar – both can go wrong, and both can go beyond the ethical part. What guides them is the rules that we set.” As the system gains authority, rules matter more because more work can proceed without human intervention.

Those rules separate human responsibility from constant human execution. An enterprise can delegate analysis or repetitive operational work while limiting what an agent may do and controlling the consequences of its actions. ENOC, which can gain operational capacity by shifting security work to AI, shows how this separation works while trust is still developing.

ENOC deploys AI while trust develops

ENOC makes the distinction concrete because its cyber-security team already uses AI while confidence in the technology is still developing. “We have extended our AI capability to the cyber team,” Al Rais said. The deployment puts AI inside ongoing security operations, allowing ENOC to test delegated work through actual use.

That delegated work includes tasks familiar to security operations teams. “They are using it for alert triage. They are using it for analysing logs and threats,” Al Rais said. AI can handle the initial processing of alerts, logs and threat information, reducing the routine analysis people must perform themselves.

Operational use still leaves room for ENOC’s confidence to develop. Asked about trusting AI with these activities, Al Rais said, “We are in the process of trusting.” ENOC can therefore assign useful work, observe the technology’s behavior and retain guidance while deciding whether to delegate more.

Graduated trust matters because deployment and unrestricted authority are separate decisions. Complete confidence can develop after useful work has been assigned within defined boundaries, while broader authority can depend on evidence from that operation. ENOC consequently separates permission to perform a task from permission to act freely across the surrounding process.

That separation changes human involvement in day-to-day security work. A person does not have to conduct every alert triage or inspect every log that AI handles for the organization to retain responsibility for the workflow. Once execution and responsibility are treated separately, the next question is which processes can safely receive more authority.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

DMCC makes consequence the boundary for autonomy

ENOC shows how authority can expand as trust develops, but an organization still needs criteria for deciding where that expansion is appropriate. Abdalla Ahmed Mohammed Al Ali, senior director of IT at DMCC, starts with the nature of the service. He describes AI as revolutionary technology with visible value and impact, then evaluates a potential use according to the risk and importance of the work involved.

That evaluation favors work whose consequences are easier to contain. “As long as that service is not risky, is not too critical and is repetitive, then we try to use AI to make things easier and seamless,” Al Ali said. Repetition creates an opportunity to reduce manual work, while limited risk and criticality make greater automation easier to justify.

Reducing manual work also has to produce useful service outcomes for DMCC, which benefits when automation makes operations easier for the people it serves. “Ultimately, we want to make sure that the outcome of leveraging that is beneficial for the team as well as for the members and stakeholders,” Al Ali said. The benefit requirement ties automation to the resulting service and the people affected by it.

As potential consequences increase, DMCC becomes more cautious about delegated authority. “If you have critical services which might have an impact on the reputation of the organisation, or a financial impact, then we have to be extremely conscious,” Al Ali said. Reputation and financial exposure raise the cost of error, while critical operations increase the need to examine whether independent AI action is appropriate.

Those consequences become explicit decision factors in Al Ali’s framework. “It depends on the ROI [return on investment], the impact, the criticality and the severity. Based on these factors, I will decide whether the human needs to be in the loop or whether it can operate without the human.” A human “in the loop” participates directly in the decision or action, so DMCC uses economics and potential harm to determine whether direct participation is required.

Those factors deliberately produce different levels of autonomy across the organization. A repetitive service with limited risk may run without a person approving each action when its value justifies deployment. A process with severe financial, reputational or operational effects can warrant direct human participation because a bad autonomous decision carries a larger downside.

Different levels of autonomy make human participation a process-level design decision. DMCC can reduce routine execution substantially in suitable workflows while retaining direct approval where the consequences demand it. For technology leaders scaling beyond pilots, ROI, impact, criticality and severity provide criteria for making that distinction without imposing the same approval model on every process.

The consequence-based approach creates another design problem. Once an organization gives AI greater authority, especially in critical work, it needs mechanisms to detect bad behavior or compromised information before those problems reach consequential decisions. Dubai Islamic Bank addresses that control layer in a highly regulated setting.

Dubai Islamic Bank pairs greater autonomy with stronger controls

Where DMCC provides criteria for granting autonomy, Dubai Islamic Bank shows what can surround that autonomy when the consequences become serious. Noman Rasheed, CIO at Dubai Islamic Bank, operates in banking, a highly regulated sector where model integrity, data quality and AI security raise particular concerns. The bank has an operational interest in gaining value from AI while containing the financial and regulatory consequences of failure, and Rasheed links greater AI independence to stronger validation and control.

Those controls keep humans involved in roles beyond manually executing each automated step. “The human role is extremely important. There is no concept of handing over processes to AI without control and validity. This is where humans play a role,” Rasheed said. Control defines what autonomous systems may do, while validation tests whether their operation and outputs remain suitable for consequential use.

Rasheed applies the same assumption of fallibility to people. “The concern has always been whether humans can make mistakes. The answer is yes, but does that mean you take humans out of the loop? The answer is no – what you do is deploy controls.” Because mistakes remain possible regardless of who or what acts, the control system must account for both human and AI behavior.

For autonomous AI, those controls include mechanisms that constrain behavior and make it observable. “We need guardrails to protect and observe what the agents and AI are doing. There is no question about humans going out of the loop. Humans will always play a role in different capacities throughout the journey,” Rasheed said. Guardrails are limits and checks around permitted behavior, so people can move from routine execution toward supervision, validation and responsibility for integrity while agents perform more of the underlying work.

Dubai Islamic Bank extends the same logic through zero trust, a security principle under which every attempt to access or use a system is subject to verification. Rasheed applies it symmetrically: “We have one fundamental rule: zero trust. There is no way we trust humans. There is no way we trust machines. There is no way we trust AI.” Independent action consequently gives an AI agent no exemption from verification, just as human or machine activity remains subject to checks.

That verification becomes especially important when agentic AI has authority because model integrity can affect every action that follows. A model can be tampered with, poisoned or altered, which can compromise its behavior or the information it supplies. “There will always be a place for humans in the AI and agentic AI era; humans are responsible for making sure that agentic AI is not being tampered with, poisoned or altered,” Rasheed said.

Rasheed’s CFO scenario makes the integrity risk concrete. “Imagine showing the CFO wrong numbers because the model was poisoned and there was no human to verify the data,” he said. Once corrupted information reaches a senior financial decision-maker as trusted output, a model problem becomes an organizational decision problem because the enterprise can act on false information.

The possible consequence explains why greater automation can require stronger verification. “Any entity could collapse. The decisions being taken based on pure AI would be completely wrong,” Rasheed said. Verification creates a control point between compromised AI output and a decision whose financial or operational effects may be difficult to reverse.

That failure path shifts attention from whether an agent completes its assigned task to the integrity of the information and behavior behind it. An agent can execute its workflow correctly while producing a dangerous result when its model or input has been poisoned, so task completion alone cannot establish that its output is safe to use. Guardrails, observation and integrity verification let the organization inspect those conditions, while human responsibility preserves accountability for consequential decisions.

Key highlights

  • Tie delegation to defined boundaries: Agentic AI can take on cyber-security work before an enterprise fully trusts it. Technology leaders can separate permission to perform a task from broader authority by setting rules around what agents may do and how failures are contained.
  • Build trust through controlled deployment: ENOC already uses AI for alert triage and analysis of logs and threats while confidence develops through operational use. Security teams can expand authority as evidence shows the technology performs reliably within defined limits.
  • Match autonomy to consequences: DMCC uses ROI, impact, criticality and severity to determine whether AI can operate independently or requires direct human involvement. Processes with limited risk and repetitive work are stronger candidates for autonomy, while financial, reputational and operational exposure warrants tighter oversight.
  • Strengthen controls as autonomy grows: Dubai Islamic Bank uses guardrails, observation, validation and zero-trust principles to govern consequential AI use. Organizations granting agents greater authority need controls that verify behavior, model integrity and data before AI output informs high-impact decisions.

Alexander Procter

October 2, 2026

9 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.