The UAE Cybersecurity Council's own numbers make the scale of the problem hard to miss. Speaking on August 11, 2026, council chairman Dr Mohammed Al Kuwaiti said the country now faces roughly 600,000 cyberattacks every day, the equivalent of about 25,000 an hour, or more than 416 every single minute. He was equally direct about the reason the pace keeps climbing: artificial intelligence is doing as much for attackers as it is for defenders, letting criminals target systems and networks in increasingly complex, professional ways. For UAE infrastructure firms racing to deploy AI across energy grids, water networks, transport systems, and construction sites, that is not an abstract policy concern. It is a direct operational risk sitting inside the same technology stack that is supposed to be delivering efficiency gains.
This creates a genuine paradox. The UAE holds Tier 1, role-model status in the United Nations International Telecommunication Union's Global Cybersecurity Index, a reflection of a mature legal framework and a government that has invested heavily and early in digital defense. At the same time, the country's own Cyber Security Council has acknowledged a substantial domestic "digital debt": nearly half of the vulnerabilities actively exploited in UAE networks are more than five years old, according to the council's State of the UAE Cybersecurity Report cited in Chambers and Partners' 2026 legal guide to UAE cybersecurity. Rapid AI adoption, smart city rollouts, and cloud migration are expanding the attack surface faster than legacy patching cycles can keep up. Infrastructure firms sit at the center of that gap, because the systems they run were rarely designed with AI-era threats in mind.
Why Infrastructure Firms Carry More of This Risk
Not every business feels AI-driven cyber risk equally, and infrastructure operators are near the top of the list. Energy, water, transport, and construction firms typically run a mix of modern IT systems and older operational technology, the industrial control systems that physically run pumps, turbines, signaling equipment, and grid switching. Bolting AI-powered monitoring, predictive maintenance, or scheduling tools onto that environment, a pattern already underway across the sector as covered in our guide to AI predictive maintenance for UAE utilities, creates new connections between systems that were never meant to talk to the open internet. Each new integration point is also a new potential entry point, and the consequences of a breach are physical rather than purely financial: a compromised control system can stop a water pump, disrupt a rail signal, or take down a section of the grid.
Infrastructure firms are also unusually attractive targets simply because of what they represent. A June 2026 Help AG State of the Market Report, covered by Khaleej Times, found that daily cyberattack attempts against UAE targets surged from roughly 200,000 to as many as 700,000 during periods of heightened geopolitical tension earlier in the year, with critical infrastructure squarely in the crosshairs during those spikes. That volatility is now a planning assumption, not an edge case. Firms that treat AI security as a one-time setup task rather than an ongoing operational discipline are building on ground that shifts several times a year.
How AI Is Changing the Attacker's Playbook
The threat side of the equation has moved faster than most infrastructure firms' defenses have. Global research cited in the Chambers and Partners 2026 guide found that the average time between an initial network compromise and lateral movement inside a victim's systems has dropped to roughly 48 minutes, and that 61 percent of hackers now exploit newly disclosed vulnerabilities within 48 hours of public disclosure. Attackers are increasingly using AI to automate reconnaissance, generate more convincing phishing content, and probe for weaknesses at a speed that manual, human-led defense simply cannot match. Set against the UAE's own digital debt problem, where a large share of exploited vulnerabilities are years old, the math is uncomfortable: the patch that should have closed a gap two years ago is now being found and exploited within hours of any new disclosure that touches related systems.
The rise of "shadow agents"
A newer and less understood risk is what security researchers are calling shadow agents. In 2025, the concern was employees pasting sensitive data into public AI chatbots, so-called shadow AI. In 2026, autonomous AI agents have taken that risk a step further. Employees now routinely ask AI systems to carry out multi-step tasks such as reviewing a folder of contracts, searching a mailbox for payment records, or locating the latest financial proposal in cloud storage. Each of these agents holds its own identity and permissions. When an infrastructure firm grants an unvetted AI agent read or write access to a shared drive, a maintenance log, or a SCADA-adjacent reporting system, it has effectively created a new, automated insider account that traditional data loss prevention tools were never built to watch. For firms that have already invested heavily in AI adoption, as most UAE infrastructure operators have, this non-human identity risk is often invisible until an audit forces it into view.
The Regulatory Response Is Tightening, Not Staying Still
UAE policymakers are not standing still on this. The newly issued UAE National Cyber Security Strategy, covering 2025 through 2031, signals what Chambers and Partners describes as a shift from voluntary compliance to mandatory resilience, introducing a stricter system of approvals, supply chain checks, and sector-specific rules. The Cyber Security Council has also folded AI and machine learning security into its published national security policy areas alongside encryption, cloud, and IoT security, treating AI systems as infrastructure that itself needs protecting rather than only a tool that protects other things. That shift lines up with the broader compliance picture we cover in AI compliance in the UAE: firms that treat security and regulatory readiness as separate workstreams are increasingly going to find they are being asked, by regulators or by enterprise customers, to prove both at once.
This regulatory direction also reinforces a theme we have covered before in the context of AI infrastructure readiness in the UAE: governance is not a box to check after a pilot succeeds. It is one of the dimensions that determines whether a pilot is safe to run in the first place. A firm that cannot answer basic questions about where its AI systems get their data, who can access the outputs, and what happens if a vendor is breached is not ready to connect that system to anything that touches physical operations, regardless of how promising the technology looks in a demo.
Where UAE Infrastructure Firms Are Actually Falling Short
The gap is not, generally speaking, a lack of investment or awareness. A May 2026 global workforce password security study sponsored by Zoho, also reported by Khaleej Times, found that 96 percent of UAE respondents believe they already have the tools needed to detect and respond to attacks, and more than 76 percent plan to increase cybersecurity budgets over the next five years. The confidence is real, and so is the spending. What the same study found missing is more specific: only 22 percent of UAE organizations have achieved zero standing privileges, more than 45 percent have not yet adopted multi-factor authentication or enterprise password management everywhere it is needed, and over 40 percent lack identity and access management tools altogether. In other words, the tools exist, but the unglamorous work of governing who and what can access which systems, including AI agents and the infrastructure control systems they increasingly touch, is lagging behind.
That identity gap matters more for AI deployments than for almost any other category of IT investment, because AI systems are unusually good at aggregating access. A single AI assistant connected to scheduling software, maintenance records, and a vendor portal can, in practice, see and touch more of an organization's data than any individual employee would ever be granted directly. Locking that down after the fact is far harder than designing access scoping in from day one, a lesson that echoes the broader pattern of costly retrofits covered in common AI implementation pitfalls in the UAE.
A Practical Starting Framework
Infrastructure firms do not need a perfect security program before starting with AI, but they do need to work through a short list of questions before connecting any AI system to operational data or systems.
- Map every AI tool and agent already in use, including ones adopted informally by individual teams, and note what data and systems each one can access.
- Apply zero standing privileges as the default for any AI agent: grant access to a specific task and revoke it when the task ends, rather than leaving standing permissions in place.
- Prioritize patching for any system, including AI platforms and their integrations, based on how quickly comparable vulnerabilities are being exploited elsewhere, not on an internal maintenance calendar alone.
- Treat every third-party AI vendor as a supply chain risk: ask where data is processed, whether it touches UAE data residency requirements, and what the vendor's own breach history and response plan look like.
- Keep operational technology, the systems that physically run pumps, grids, and signaling equipment, on a separate, tightly controlled network segment from AI tools connected to the wider internet, even when the business case for integration is strong.
- Build an incident response plan that specifically covers an AI system or AI agent being compromised or misused, not just a generic ransomware or data breach scenario.
None of these steps require an infrastructure firm to slow down its AI roadmap significantly. What they do require is sequencing: security groundwork before broad rollout, not as a cleanup exercise afterward. That sequencing matters most at the exact points covered in our guides to the AI implementation roadmap for UAE infrastructure firms and moving from AI pilot to full rollout: the transition from a contained pilot to production access is exactly when identity and access controls need to already be in place, because that is the moment an AI system typically gains its widest reach into live operational data.
Sovereignty and Where Data Actually Lives
The regulatory and security conversation in the UAE is increasingly tied to a third question: not just who can access AI systems, but where the underlying data and models physically sit. The same Help AG report that documented the surge in daily attack volume also found that sovereign cloud and locally governed systems are emerging as a core design priority across the UAE and Saudi Arabia, with organizations rethinking cybersecurity strategy around resilience and data sovereignty rather than treating it as a compliance afterthought. For infrastructure firms weighing where to host AI workloads, that trend adds a security dimension to a decision that is often framed purely around cost or performance, a tradeoff we unpack in detail in cloud versus on-premise AI for UAE infrastructure firms. A firm handling grid telemetry, water network data, or transport scheduling should treat data location and sovereign hosting options as part of the security review for any AI vendor, not a separate procurement question decided later.
Bringing It Together
AI is not simply another item on the UAE infrastructure sector's cybersecurity checklist. It is reshaping both sides of the fight at once, giving defenders faster detection and giving attackers faster, more convincing ways to break in, while quietly expanding the number of identities, both human and non-human, that need to be governed. The firms that will handle this well are not necessarily the ones spending the most on security tools. The Zoho-sponsored research shows most UAE organizations already believe they have adequate tools. The firms that will handle this well are the ones closing the identity and access gap, treating AI agents as accounts that need governing rather than assistants that need trusting, and building security review into the AI rollout process itself rather than bolting it on once a system is already touching live infrastructure. Given that the UAE Cybersecurity Council is now counting attacks by the minute, that is not a project to defer to next year's budget cycle.
Research sources used
- UAE thwarts 600,000 cyberattacks daily as AI-driven threats intensify: Cybersecurity Council chief (Emirates 24|7, Aug 11, 2026)
- GCC firms shift focus to cyber resilience, sovereignty as AI reshapes threat landscape (Khaleej Times, Jun 10, 2026)
- UAE firms face rising cyber risks despite strong security intent, study finds (Khaleej Times, May 14, 2026)
- Cybersecurity 2026: UAE Trends and Developments (Chambers and Partners, updated Mar 17, 2026)