
Agentic artificial intelligence (AI) may be enabling unprecedented levels of automation in cyber security. Still, enterprise leaders in the United Arab Emirates (UAE) believe organisations are not yet ready to remove humans from decision-making.
“Automation is not something new; we’ve been doing automation for decades,” said Mohammad Al Rais, senior director of group IT at ENOC. “When we talk about agentic AI, it’s automation with a brain.”
Speaking during a panel discussion on the future of autonomous AI in cyber security, Al Rais argued that agentic AI should be viewed as the next evolution of automation rather than a replacement for human expertise. “It’s a near-human kind of process, yet that needs guidance,” he said. “Humans and agentic AI might be similar – both can go wrong, and both can go beyond the ethical part. What guides them is the rules that we set.”
Organisations are increasingly exploring how agentic AI can improve security operations by automating tasks such as threat analysis, alert triage and incident investigation. At ENOC, Al Rais said the company has already begun extending AI capabilities into its cyber security function.
“We have extended our AI capability to the cyber team,” he said. “They are using it for alert triage. They are using it for analysing logs and threats.”
Asked whether he trusts AI systems to perform these activities, Al Rais said confidence is still being built: “We are in the process of trusting.”
For Abdalla Ahmed Mohammed Al Ali, senior director of IT at DMCC, the decision to introduce agentic AI depends largely on the risk level associated with a particular process. “When it comes to AI adoption, it is a revolutionary technology, and we can see the value and the impact.”
Al Ali said AI can deliver significant benefits when applied to repetitive tasks that do not involve highly sensitive or business-critical outcomes.
“As long as that service is not risky, is not too critical and is repetitive, then we try to use AI to make things easier and seamless,” he said. “Ultimately, we want to make sure that the outcome of leveraging that is beneficial for the team as well as for the members and stakeholders.”
However, he cautioned that the equation changes when AI is introduced into systems that could affect an organisation’s reputation, finances or critical operations. “If you have critical services which might have an impact on the reputation of the organisation, or a financial impact, then we have to be extremely conscious,” he added.
While Al Ali said he supports introducing AI across a broad range of use cases, he stressed that organisations must carefully assess where human oversight remains necessary: “It depends on the ROI [return on investment], the impact, the criticality and the severity. Based on these factors, I will decide whether the human needs to be in the loop or whether it can operate without the human.”
Noman Rasheed, CIO at Dubai Islamic Bank, shared the same point of view and argued that governance and control mechanisms become even more important as AI systems gain greater autonomy: “The human role is extremely important. There is no concept of handing over processes to AI without control and validity. This is where humans play a role.”
Rasheed noted that concerns about AI making mistakes should be viewed in the same way organisations have traditionally approached the risk of human error: “The concern has always been whether humans can make mistakes. The answer is yes, but does that mean you take humans out of the loop? The answer is no – what you do is deploy controls.”
According to Rasheed, the same principle applies to agentic AI systems: “We need guardrails to protect and observe what the agents and AI are doing. There is no question about humans going out of the loop. Humans will always play a role in different capacities throughout the journey.”
Rasheed also argued that organisations should apply zero-trust principles to AI in the same way they do to users and devices: “We have one fundamental rule: zero trust. There is no way we trust humans. There is no way we trust machines. There is no way we trust AI.”
The growing adoption of agentic AI also introduces new risks around model integrity, data quality and AI security, particularly in highly regulated sectors such as banking. “There will always be a place for humans in the AI and agentic AI era; humans are responsible for making sure that agentic AI is not being tampered with, poisoned or altered,” said Rasheed.
“Imagine showing the CFO wrong numbers because the model was poisoned and there was no human to verify the data,” he added. “Any entity could collapse. The decisions being taken based on pure AI would be completely wrong.”
As organisations continue to experiment with agentic AI across cyber security operations, the panellists agreed that the technology’s success will depend not only on its capabilities, but also on the governance frameworks surrounding it.