You are currently viewing CMI Talks: UAE Newsletter July 2026

CBUAE Law transitional period closes 16 September 2026, final month for regularisation under Federal Decree-Law No. 6 of 2025

August 2026 is the final full month for all entities within scope of Federal Decree-Law No. (6) of 2025 (the New CBUAE Law) to regularise their licensing and compliance position. The Law, which came into force 16 September 2025, repealing both the 2018 Central Bank Law and the 2023 Insurance Decree-Law, grants a one-year transitional period under Article 184, closing on 16 September 2026. Entities that have not regularised by that date face administrative fines of up to AED 1 billion and, in cases of unlicensed financial activity, criminal liability under Article 170.

Key Takeaways:

  • Article 62 of the New CBUAE Law extends the licensing requirement to technology providers, API operators, and decentralised platforms that enable Licensed Financial Activities, bringing fintechs, infrastructure providers, and platform operators previously in regulatory grey zones within CBUAE supervision. Any entity facilitating payments, credit, insurance, open finance, or virtual asset activities through technology must assess Article 62 exposure and regularise before 16 September 2026.
  • For insurance companies, capital structures, governance models, claims handling SLAs, fraud prevention controls, and outsourcing arrangements built under the old Insurance Law no longer carry forward by default after 16 September 2026. The CBUAE has been progressively issuing replacement implementing instruments; entities must track and align with each as published.
  • The CBUAE issued a detailed FAQ in June 2026 clarifying Article 62’s technology-provider licensing perimeter. Entities that relied on pre-FAQ ambiguity to defer compliance planning should treat the FAQ as a definitive regulatory signal and accelerate gap analysis and regularisation workstreams immediately.
  • All in-scope entities, including banks, insurers, finance companies, exchange houses, PSPs, and technology enablers, should be in active regulatory dialogue with the CBUAE regarding any outstanding gaps. No extension to the transitional period has been announced; none should be assumed in planning.

UAE National KYC Digital Platform, Cabinet Resolutions No. 55 and No. 56 of 2026 operationalise the framework

The UAE Cabinet has issued two resolutions completing the legislative architecture for the national digital KYC platform established under Federal Decree-Law No. (30) of 2024: Cabinet Resolution No. (55) of 2026 providing the Executive Regulations, and Cabinet Resolution No. (56) of 2026 prescribing the schedule of administrative violations and sanctions. Together they operationalise the platform, a centralised digital infrastructure for the secure collection, management, and sharing of verified KYC data between authorised entities, and establish enforcement consequences for non-compliance.

Key Takeaways:

  • Cabinet Resolution No. 55 of 2026 requires data providers, including federal and local government authorities, private sector companies, financial institutions, and insurance-related professions, to enter into formal supply agreements with the platform management company and provide accurate data at no cost. All data handling, storage, processing, and transmission must comply with UAE national cybersecurity policies and applicable confidentiality rules.
  • Cabinet Resolution No. 56 of 2026 grants the Central Bank authority to impose administrative sanctions, suspend dealings with non-compliant entities, and integrate administrative and criminal penalties. Core offences, including unauthorised disclosure of KYC reports, fraudulent platform access, and wilful misrepresentation of data, carry a minimum two-year prison term plus a fine of at least AED 50,000, with aggravated penalties for insiders.
  • The platform enables consent-based shared KYC: a customer who consents to a KYC report can share it across multiple financial institution users without repeating the underlying data collection and verification process, reducing onboarding timelines, improving customer experience, and cutting the cost of AML/CFT compliance for adopting institutions.
  • Financial institutions, government-affiliated data providers, and entities in financial services should review data governance frameworks against the Executive Regulations and ensure data supply and confidentiality arrangements comply with the platform’s operational requirements before active CBUAE supervision of platform participants begins.

CBUAE Resolution 16 of 2026, CBUAE-licensed institutions permitted to undertake CMA-regulated virtual asset activities

The CBUAE issued Resolution No. (16) of 2026, opening a regulatory pathway for licensed banks, finance companies, exchange houses, and payment service providers to undertake virtual asset activities regulated by the Capital Market Authority under CMA Resolution No. (4) of 2026. Resolution 16 enables incumbent, prudentially-supervised financial institutions, with established balance sheets, capital buffers, and existing customer relationships, to compete directly in the virtual asset space previously dominated by standalone VASPs and the free-zone regimes of VARA, ADGM/FSRA, and DIFC/DFSA. Insurance companies are expressly excluded.

Key Takeaways:

  • Resolution 16 operates as a permissions gateway: CBUAE-licensed institutions may undertake CMA Resolution 4 activities, including dealing as principal or agent, custody, arranging deals, portfolio management, and operating trading facilities, subject to obtaining CMA authorisation and meeting applicable capital, governance, and conduct requirements. The detailed application mechanics await further implementing rules from the CMA and CBUAE jointly.
  • The strategic advantage for incumbent institutions lies in their existing regulatory credibility, AML/CFT infrastructure, established KYC data, and pre-existing customer relationships across retail and institutional segments, capabilities that standalone VASPs cannot replicate. Where implementing mechanics permit, banks may offer integrated digital asset and traditional banking services within a single regulatory relationship.
  • Compliance and regulatory teams at CBUAE-licensed institutions should immediately scope which CMA Resolution 4 activities are commercially relevant, map probable capital, custody, and conduct requirements against existing infrastructure, and design governance and ring-fencing arrangements for virtual asset activities ahead of the joint implementing framework.
  • Institutions with activities across mainland UAE, DIFC, and ADGM face concurrent licensing and capital requirements across the CMA, CBUAE, DFSA, and FSRA. A comprehensive regulatory mapping exercise is essential before committing to any UAE virtual asset market entry or expansion strategy.

UAE Emiratisation, second-half 2026 enforcement intensifies as MoHRE targets sector-specific quota shortfalls

Following the 30 June 2026 AED 6,000 salary deadline and H1 quota checkpoint, MoHRE has entered H2 2026 with a markedly more assertive enforcement posture. Its AI-powered monitoring system, cross-referenced against WPS 2.0, the Nafis platform, and trade licence records, is actively flagging establishments that missed either the salary threshold or the 1% H1 headcount increase. The full-year targets, a 2% cumulative increase in Emirati representation in skilled roles and an overall 10% Emiratisation rate, must be met by 31 December 2026.

Key Takeaways:

  • MoHRE has intensified sector-specific enforcement targeting the six highest-gap sectors: banking and financial services, insurance, ICT, retail, healthcare, and food and beverage. Establishments in these sectors below target face accelerated inspections, faster penalty issuance, and inclusion risk on MoHRE’s published non-compliant list, triggering reputational and procurement consequences beyond the direct financial penalty.
  • The per-position penalty remains AED 9,000 per month per unfilled role. For a business 5 positions below quota in H2 2026, that represents up to AED 540,000 in potential liability for the six-month period, significantly exceeding the cost of proactive Emirati recruitment and onboarding. MoHRE’s 2025 enforcement resulted in over 1,300 establishments losing Nafis benefit eligibility for fake Emiratisation.
  • The Nafis programme continues to offer meaningful financial support, including salary supplements, social insurance contributions, and training subsidies. Establishments that maximise Nafis uptake materially reduce the net cost of compliance; HR and finance functions should ensure all eligible Emirati employees are correctly registered and that monthly supplement claims are submitted promptly.
  • Businesses behind on H2 targets should treat August as the final window to accelerate recruitment, onboarding, and upskilling pipelines. MoHRE’s digital monitoring issues penalties without advance warning. Establishments that wait for a formal notification before acting forfeit multiple months of penalty-free correction opportunity.