UAE Launches First National AI Test and Validation Lab with Cisco and Open Innovation AI

The UAE Cyber Security Council, Cisco, and Open Innovation AI have launched a first-of-its-kind national facility to test, validate, and certify AI models and agents against UAE cybersecurity standards and global frameworks including ISO 42001 and NIST AI RMF.

Layla Haddad
Cyber Policy & Digital Risk Correspondent5 min read
Engineers at the UAE National AI Test and Validation Lab reviewing AI security assessments on high-performance server infrastructure in Abu Dhabi

Engineers at the UAE National AI Test and Validation Lab reviewing AI security assessments on high-performance server infrastructure in Abu Dhabi

The UAE has taken a landmark step in the global governance of artificial intelligence security, announcing the establishment of a National AI Test and Validation Lab designed to independently assess and certify AI models, agents, and applications before they are deployed across government and critical infrastructure.

The facility was announced at the Make in the Emirates Conference in Abu Dhabi and established through a strategic collaboration between the UAE Cyber Security Council, Cisco, and Open Innovation AI, with Emircom supporting the initiative. It is the first national-level facility of its kind, purpose-built to assess AI systems against both UAE cybersecurity policy requirements and internationally recognised standards.

"Artificial intelligence is becoming part of the fabric of government services, critical infrastructure, and everyday life in the UAE. The National AI Test and Validation Lab offers the country a sovereign capability to ensure that every AI model and every AI agent deployed in our economy is secure, trustworthy, and aligned with our national policies. This is how we turn the UAE's ambition to lead in AI into concrete, verifiable assurance for our citizens." - H.E. Dr. Mohamed Al-Kuwaiti, Head of Cybersecurity for the UAE Government and Chairman of the UAE Cyber Security Council.

What the Lab Tests

The lab is hosted in the UAE and operates under the governance of the Cyber Security Council. It is designed to assess AI systems against UAE cybersecurity policies covering AI, cloud, and critical information infrastructure, as well as international standards including ISO 42001, MITRE ATLAS, NIST AI RMF, and the OWASP frameworks for large language models and AI agents.

ISO 42001 is particularly significant for enterprise and government organisations in the region. Known as the AI Management System (AIMS) standard, it is the AI equivalent of ISO 27001 for information security. Certification against it provides compliance officers with the evidence base required to satisfy international audit requirements and gives organisations seeking cross-border AI deployments a credible, globally recognised assurance framework.

The lab's assessment framework covers six areas:

  • Model Security: Testing for robustness and safety against adversarial inputs.
  • Threat Defence: Identifying vulnerabilities such as prompt injection and jailbreak attempts.
  • Data Integrity: Monitoring for data leakage and privacy risks.
  • Supply Chain Security: Verifying the integrity of model weights and third-party components.
  • Agent Autonomy and Permissions: Evaluating the risks associated with what AI agents are permitted to do, not only what they say. This includes the authority an agent holds to execute actions such as file operations, financial transactions, and system calls, which represent a fundamentally different and more consequential risk profile than standard language model outputs.
  • Regulatory Compliance: Ensuring alignment with UAE AI, cloud, and cybersecurity mandates.

AI systems that successfully pass all evaluation categories receive a national certification mark. This provides regulators, operators, and organisations with independent assurance that the system is secure and compliant before it enters deployment across critical services.

Technology Foundation

The lab is built on a unified technology stack combining Cisco's secure, AI-ready infrastructure, powered by NVIDIA GPUs, with Open Innovation AI's software platform. The architecture includes the Open Innovation Cluster Manager (OICM) for end-to-end AI workload orchestration, and the OI AI Security platform combined with Cisco AI Defense for automated red-teaming and continuous policy conformance testing.

The lab's infrastructure is designed to handle the substantial compute requirements of large language model validation at national scale. By integrating Cisco AI Defense with NVIDIA's accelerated computing, the facility can perform automated, large-scale Red-Teaming-as-a-Service, enabling the continuous stress-testing of models against evolving jailbreak techniques and emerging attack vectors as they appear in the global threat landscape.

Crucially, the unified stack ensures that sensitive government data and AI model weights remain within the UAE's sovereign digital borders throughout the entire validation process. For GCC government entities and critical national infrastructure operators, this data residency guarantee is a foundational requirement, and one that distinguishes this facility from third-party or offshore AI assurance alternatives.

"In the AI era, security cannot be an afterthought. It must be embedded within all infrastructure. Our collaboration with the UAE Cyber Security Council and Open Innovation AI marks a pivotal moment in securing the future of the UAE's digital economy. By combining our secure, AI-ready infrastructure with the UAE's proactive regulatory vision, we are creating a global blueprint for an AI ecosystem that is resilient by design, protected at scale, and inherently trustworthy." - Fady Younes, Managing Director for Cybersecurity at Cisco Middle East, Turkey, Africa, Romania, and CIS.

Dr. Abed Benaichouche, Chief Executive Officer of Open Innovation AI, highlighted the continuous nature of AI security the lab enables: "Securing AI cannot be a one-time exercise. Models evolve, agents act autonomously, and new attack techniques emerge every week. We expect the lab to analyse tens to hundreds of thousands of agents per year, and we are proud to put our platform at the service of the UAE's national mission."

Already Operational, Open to Government and Industry

The lab is already operational. Over the coming months, it aims to scale to analyse tens of thousands of AI agents annually. It will serve federal and local government entities, critical national infrastructure operators in financial services, healthcare, energy, and telecommunications, as well as UAE-based AI developers seeking national certification before market entry.

The facility is also significant in the context of agentic AI adoption. Unlike language models that generate text, AI agents are capable of taking autonomous actions within systems and workflows. The lab's specific testing of agent permissions and tool-use authority means the UAE is not simply certifying what an AI says, but what it is permitted to do. For enterprise security leaders, this distinction is material.

The announcement positions the UAE as a global reference point for sovereign AI assurance, pairing its ambition to lead AI adoption with a verifiable, standards-aligned framework that gives both public and private sector organisations a credible basis for deploying AI with confidence.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.

Intelligence Focus Areas

UAE AI Governance 2026Sovereign AI MENAAI Security Certification GCCUAE Cybersecurity PolicyAgentic AI Risk GCC