Preparing only what matters to you
whatmatters.ae

UAE’s Biggest Cyber Blind Spot Isn’t AI or the Cloud — Experts Point to Human Error

UAEs Biggest Cyber Blind Spot Isnt AI or the Cloud — Experts Point to Human Error
UAEs Biggest Cyber Blind Spot Isnt AI or the Cloud — Experts Point to Human Error

By Thasmiya

As UAE organisations invest heavily in artificial intelligence, cloud infrastructure and advanced cybersecurity systems, experts are warning that one of the biggest security weaknesses remains much simpler: **people making mistakes**.

New UAE-specific research from Thales found that **54% of respondents identified human error as the leading cause of data breaches**, even as cloud infrastructure and AI introduce new attack surfaces.

The warning is particularly relevant as cybercriminals increasingly use AI to create more convincing phishing emails, deepfake videos and cloned voices — making it harder for ordinary users to recognise a scam.

## **Human error remains a major UAE cybersecurity risk**

Businesses are spending heavily on cybersecurity tools designed to protect cloud platforms, data and increasingly AI-powered systems.

But technology cannot completely protect an organisation when an employee clicks a malicious link, reuses a password, shares confidential information with the wrong AI service or approves a fraudulent payment request.

Thales’ **2026 UAE Data Threat Report** found that 54% of UAE respondents cited human error as the leading cause of breaches. The same research found significant concern around cloud security, with cloud storage, cloud applications and cloud-management infrastructure among prominent attack targets.

In other words, organisations need to secure sophisticated technology while also addressing everyday human behaviour.

## **AI is making familiar scams harder to recognise**

AI has not replaced traditional cybercrime. Instead, it is making many familiar attack methods faster and more convincing.

At GISEC Global 2026 in Dubai, cybersecurity experts warned that poor grammar and obviously suspicious messages can no longer be relied upon as signs of fraud.

AI can help criminals produce professional-looking phishing emails, imitate voices and generate realistic fake video content. Dubai cybersecurity officials have consequently urged people to verify unusual requests rather than trusting something simply because it looks or sounds authentic.

## **Deepfake calls could sound like someone you know**

Voice cloning creates a particularly difficult challenge.

A criminal may be able to imitate the voice of a relative, colleague or executive and then make an urgent request for money or sensitive information.

Experts speaking at GISEC recommended that families and close contacts consider establishing a private **“safe word”**that can be used to verify identity if a suspicious call or message arrives.

The basic rule is becoming increasingly important: an urgent message that sounds convincing should still be independently verified.

## **Think twice before uploading company information to AI**

Another emerging source of human risk is the way employees use publicly available AI tools.

Experts at GISEC warned users to understand which AI service they are using before submitting information. Depending on the platform and its terms, information entered into publicly available services could potentially be retained or used for model improvement.

For businesses, employees pasting confidential contracts, customer information, internal documents, passwords or proprietary data into an unauthorised AI platform can therefore create security and privacy risks.

Companies increasingly need clear policies defining which AI tools employees are permitted to use and what information can be shared with them.

## **AI still creates new cybersecurity challenges**

Focusing on human error does not mean AI itself is harmless.

AI can accelerate cyberattacks and reduce the time organisations have to respond after vulnerabilities are discovered. UAE cybersecurity specialists have warned businesses that this shrinking window requires faster detection, patching and stronger controls throughout digital supply chains.

The UAE Cyber Security Council has also warned about deploying AI systems without sufficient cybersecurity standards and governance.

AI therefore creates risks on both sides: criminals can use it to strengthen attacks, while organisations can create additional vulnerabilities if they deploy it carelessly.

## **Cloud security remains another major target**

Cloud infrastructure is also firmly on the cybersecurity agenda.

The Thales UAE report found cloud storage, cloud applications and cloud-management infrastructure among important attack targets. It also reported that **74% of respondents were seeing increases in credential theft and misappropriated secrets**.

That makes stolen usernames, passwords, access tokens and other credentials particularly important threats.

A technically secure cloud environment can still become vulnerable if someone gains access through legitimate credentials obtained from an employee.

## **UAE faces hundreds of thousands of attempted attacks every day**

The scale of the challenge is significant.

UAE cybersecurity officials said in August that the country was blocking approximately **600,000 cyberattacks every day**, equivalent to about 25,000 per hour. Officials said AI was increasingly being used to make attacks more sophisticated and difficult to detect.

The UAE has also faced coordinated attacks against critical sectors.

In August, the UAE Cyber Security Council said organised cyberattacks targeting aviation, energy and education had been contained before attackers could disrupt critical systems or services.

## **AI can also strengthen cyber defence**

The story is not entirely about AI increasing risk.

UAE organisations are increasingly using AI to analyse alerts, detect unusual behaviour and respond to threats faster.

Dubai’s Electronic Security Centre has developed **Saraab**, an AI-powered open-source tool designed to analyse videos frame by frame to help detect deepfakes.

Experts have therefore described AI as a technology that can work on both sides of cybersecurity: attackers can use it to scale attacks, while defenders can use it to identify and respond to threats more quickly.

## **What UAE residents can do to protect themselves**

Individuals can reduce their exposure by following a few basic habits:

- Never share OTPs, passwords or banking details over calls or messages. - Verify unexpected requests for money through a second communication channel. - Use strong, unique passwords and enable multi-factor authentication. - Be suspicious of urgent messages, even when they appear to come from someone familiar. - Avoid uploading sensitive personal or company information to unapproved public AI tools. - Check links carefully before opening them. - Keep phones, computers and applications updated. - Consider using a family safe word to verify suspicious emergency calls.

The goal is not to distrust every digital interaction, but to introduce a verification step before taking an action that could expose money, credentials or sensitive information.

## **What businesses need to rethink**

For companies, cybersecurity can no longer be treated only as an IT department problem.

Regular employee awareness training, access controls, multi-factor authentication, phishing simulations, clear AI-use policies and procedures for verifying sensitive financial requests can all help reduce human-related risks.

Organisations also need to consider what happens when an employee makes a mistake. Strong security should limit how far an attacker can move even after one account or device has been compromised.

## **Why this matters**

The UAE is rapidly expanding its use of AI, cloud computing and digital government services. That transformation creates enormous opportunities, but every new system still involves people making decisions.

The latest evidence suggests that the weakest point may not always be the most sophisticated technology.

A convincing email, a reused password, an unverified payment request or confidential information pasted into the wrong AI platform can be enough to bypass expensive cybersecurity systems.

As cyberattacks become smarter, **human awareness, verification and good digital habits are becoming just as important as the technology designed to protect us.**

## Related Reads - [Global Village VIP Packs 2026: What We Know About Season 31 Perks, Prices and Sale Dates](/post/global-village-vip-packs-2026-we-know-about) - [Why More Professionals Are Talking About Burnout in the UAE](/post/more-professionals-talking-about-burnout-uae) - [Living in Dubai Becoming More Expensive? What Residents Are Paying More for in 2026](/post/s-living-dubai-becoming-more-expensive-residents-paying) - [UAE Job Market 2026: Salaries, Hiring Trends and Challenges for Job Seekers](/post/uae-job-market-2026-salaries-hiring-trends-challenges) - [More stories like this](/category/things-to-do)

What Matters — UAE news, events and guides