Securing Agentic AI for Dubai Government: A DESC and AI Seal Vendor Security Checklist
Building agents for Dubai's Agentic AI Accelerator? A DESC and Dubai AI Seal vendor checklist: procurement gates, agent attack tests, and the evidence to hand over.
If you are building agentic AI for Dubai government, you face two gates and one test. The gates are the Dubai AI Seal (who may sell AI work to Dubai entities) and DESC rules (who may formally pentest them). The test is proving your agent cannot be hijacked into leaking data or taking actions it should not. This checklist covers all three.
The timing matters. On 5 October 2026, the Dubai Future Foundation launched the Agentic AI for Government Services Accelerator, organised by the Dubai Centre for Artificial Intelligence with Digital Dubai and the Dubai Electronic Security Centre (DESC) as partners. According to The National, 33 government entities will assess more than 300 public-facing use cases in the first phase, working with companies certified under the Dubai AI Seal. DESC’s chief executive put the security position in one line: “Cybersecurity cannot be an afterthought in the adoption of AI.”
So the security bar is set from day one, not after launch.
What changed for vendors in October 2026?
Agentic AI in Dubai government moved from strategy to procurement. Three things now stack on top of each other:
- A federal target. In April 2026 the UAE announced that half of federal government sectors, services and operations should run on agentic AI within two years (Khaleej Times).
- A Dubai buying rule. In October 2025, Dubai’s Department of Finance called on government entities to contract AI services and consultancy with AI Seal-certified suppliers (Dubai Media Office).
- A security partner in the room. DESC is a named partner of the accelerator. DESC already publishes the Dubai AI Security Policy (launched September 2024) and runs the ISR standard and the Cyber Force provider scheme.
The practical effect: a vendor pitching an agent to a Dubai entity will be asked about the Seal at the commercial stage and about security evidence at the technical stage. Having only one of the two stalls the deal.
Which gate is which: AI Seal vs DESC Cyber Force?
These get confused constantly, so here they are side by side.
| Dubai AI Seal | DESC Cyber Force | |
|---|---|---|
| Issued by | Dubai Centre for Artificial Intelligence | Dubai Electronic Security Centre |
| What it decides | Which AI companies Dubai government should buy AI services from | Which firms may deliver penetration testing to Dubai government entities |
| Who applies | Dubai-licensed tech companies providing AI products or services | Offensive security providers |
| What it assesses | Company activities, AI headcount, projects, partnerships | Methodology, tester competency, DESC reporting format |
| Cost to apply | Free | See DESC |
| Is it a security test of your agent? | No | No, it vets the tester, not your product |
The AI Seal uses tiers (reported as A to E plus S) and every certificate has a serial number buyers can check, per Baker McKenzie’s summary. For the Cyber Force side, our DESC penetration testing guide covers accreditation and the ISR v3.1 testing cadence in detail.
The gap neither gate fills: is your specific agent secure? That is a testing question, and it is the one reviewers will push on.
What does a security reviewer worry about in a government agent?
A public-facing government agent is a worst-case design from an attacker’s view. It reads untrusted input from residents (messages, uploaded documents, emails), it holds credentials to internal systems, and it acts on its own. One successful prompt injection can turn a helpful assistant into a data exfiltration tool with a government API key.
The OWASP Top 10 for Agentic Applications (published December 2025 by the OWASP GenAI Security Project) is now the reference list reviewers reach for. The risks that matter most in a government setting:
- ASI01 Agent Goal Hijack. Hidden instructions in a resident’s uploaded PDF or email redirect the agent.
- ASI02 Tool Misuse and Exploitation. The agent calls a legitimate tool with attacker-chosen parameters.
- ASI03 Identity and Privilege Abuse. The agent uses a service account that can see far more citizens than the current user.
- ASI06 Memory and Context Poisoning. A poisoned knowledge-base article misleads every future conversation.
- ASI07 Insecure Inter-Agent Communication. One entity’s agent trusts messages from another without verification.
- ASI09 Human-Agent Trust Exploitation. The agent persuades a staff member to approve something they should not.
For the mechanics behind each, see our AI agent penetration testing field guide and how AI agents get hijacked.
The vendor security checklist
Use this before your agent goes anywhere near a government pilot. It is split into what you need to prove commercially and what you need to prove technically.
Procurement and governance
- AI Seal status confirmed. Your certificate serial number is current and the tier matches the work you are bidding for.
- Formal pentest route agreed. You know whether the entity will commission its own DESC-route penetration test, and you have confirmed the current Cyber Force standing of any provider who will deliver it.
- Data map documented. Every data source the agent reads and every system it can write to, with classification and hosting location.
- Human approval points defined. Which actions the agent may take alone and which need a named human to approve.
Agent security testing
- Prompt injection, direct and indirect. Test every channel: chat, uploaded documents, email, web content, and tool outputs.
- Tool scoping and parameter validation. Each tool has the narrowest permission it needs, and the backend rejects out-of-policy parameters even when the agent asks nicely.
- Per-user authorisation. The agent cannot fetch one resident’s record while serving another. Test with two accounts, not one.
- Memory and RAG poisoning. Plant content in the knowledge base and conversation memory and check whether it changes behaviour later.
- Sensitive data leakage. Try to extract personal data, system prompts, API keys and internal URLs.
- MCP and connector review. If the agent uses Model Context Protocol servers or third-party connectors, test them as part of the attack surface. Our MCP server security assessment guide covers this.
- Logging and kill switch. Every tool call is logged with user, input and outcome, and the agent can be disabled fast.
Evidence pack
- Dated report with scope, methodology, findings mapped to OWASP agentic and LLM categories, and proof for each finding.
- Remediation record showing what was fixed and when.
- Retest confirmation that closes the high and critical findings.
| Checklist area | What the reviewer wants to see | Typical artefact |
|---|---|---|
| AI Seal | Valid certificate, matching tier | Certificate serial number |
| Pentest route | Who tests, under which rules | Confirmed provider and scope |
| Prompt injection | Every input channel tested | Test cases and results per channel |
| Tools and identity | Least privilege, per-user authorisation | Tool permission matrix, test evidence |
| Memory and RAG | Poisoning tested | Planted payloads and outcomes |
| Evidence | Closed findings | Report, fix log, retest letter |
When should you test in an accelerator timeline?
Twice. First when the agent is functionally complete but before any resident data touches it. This is where you find the expensive design problems, such as an agent running on a single over-privileged service account. Second after fixes, as a retest, so the report you hand over shows closed findings rather than open ones.
Testing only at the end is the common mistake. By then the tool design is fixed, and the fix for a confused-deputy problem is often an architecture change, not a patch.
How much does this cost?
For a single LLM application, UAE market pricing for a scoped test sits around AED 40,000-80,000, and a full agentic red team runs higher because of tool chains, memory and multi-agent scope. Our AI red teaming cost guide breaks down what drives the number, and the general penetration testing cost guide covers everything else.
Get your agent ready for a Dubai government review
pentest.ae runs a fixed-scope pre-launch agent red team for vendors building on agentic AI: we map the agent’s tools, data and identities, test against the OWASP agentic and LLM lists, deliver first findings within 48 hours, and include a retest so your evidence pack shows closed issues. For a single LLM application, the 5-day LLM penetration test is the fastest route. For multi-tool or multi-agent systems, the agentic red team exercise is the right fit.
Book a 20-minute scoping call. We will tell you which tests your agent needs before review and give you a fixed-scope quote for a pre-launch agent red team with retest included.
Scope a pre-launch testFrequently Asked Questions
What is the Dubai Agentic AI for Government Services Accelerator?
It is a Dubai Future Accelerators programme launched on 5 October 2026 by the Dubai Future Foundation and organised by the Dubai Centre for Artificial Intelligence, with Digital Dubai and DESC as partners. In its first phase, 33 Dubai government entities will assess more than 300 public-facing use cases for agentic AI, working with technology companies certified under the Dubai AI Seal.
Do I need the Dubai AI Seal to build AI agents for Dubai government?
In practice, yes. In October 2025 Dubai's Department of Finance called on government entities to contract AI services and consultancy only with Dubai AI Seal-certified suppliers, and accelerator participants work with Seal-certified companies. The Seal is issued by the Dubai Centre for AI, is free to apply for, and each certificate carries a serial number buyers can verify.
Does the Dubai AI Seal cover security testing?
No. The Dubai AI Seal classifies trusted AI companies based on their activities, AI headcount, projects and partnerships. It is not a security test of your agent. Formal penetration testing for Dubai government entities sits under DESC rules, where only DESC Cyber Force-accredited providers may deliver it. You still need to prove the agent itself is secure.
What security tests should a government AI agent pass before launch?
At minimum: direct and indirect prompt injection through every content source the agent reads, tool misuse and parameter abuse, identity and privilege checks on each API the agent calls, memory and RAG poisoning, data leakage of personal or classified data, and human approval on high-impact actions. Map results to the OWASP Top 10 for Agentic Applications so reviewers can see coverage.
Who pays for security testing in an AI accelerator project?
It depends on the contract, but vendors should plan to test their own agent before handover. The government entity commissions its own formal assessments under DESC rules, but a vendor that arrives with a pre-launch agent red team report, fixes and retest evidence moves through review faster. Scoped AI tests in the UAE typically fall in the AED 40,000-80,000 band for a single LLM application, per our pentest cost guide.
Complementary NomadX Services
Related Articles
Find It Before They Do
Book a free 30-minute security discovery call with our AI Security experts in Dubai, UAE. We identify your highest-risk AI attack vectors - actionable findings in days.
Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian
Talk to an Expert