AI security testing in Dubai
- Data regime
- Federal UAE data protection law, with free zones such as DIFC and ADGM operating their own regimes. Which applies depends on where the entity is registered.
- Working hours
- GST, three hours ahead of CET. A full morning of overlap, with the UAE working week running Monday to Friday.
- Languages
- Arabic and English, frequently in the same system.
- Delivery
- Remote testing against your staging or production endpoint, with scoping and findings sessions scheduled in the Dubai working day.
- Frameworks
- OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, EU AI Act Article 15.
- Tools
- Garak, PyRIT, promptfoo, Giskard, Burp Suite and custom Python harnesses.
Authorised testing only
Every assessment runs under a written scope and authorisation from the owner of the system, agreed before any test is run.
Why AI security matters in Dubai
DIFC, free zones and mainland
A DIFC entity operates under the DIFC Data Protection Law and its rules on autonomous systems; a mainland company under the federal PDPL. The same leak is rated against the regime that applies to you.
Dubai's AI security expectations
The Dubai Electronic Security Center has published guidance on securing AI systems, and government-linked entities are expected to follow it. Testing evidence supports that conversation.
Real estate and hospitality bots
Property and hotel assistants hold lead data, pricing rules and booking access. Tricking one into revealing another client's details or confirming a price it should not is a realistic attack.
Arabic and Arabizi attacks
Arabic, transliterated Arabic and mixed-language prompts are tested alongside English, because that is where bilingual assistants are least consistent.
What gets tested
The six attack classes behind most serious findings. The full list, and the tooling used for each, is on the main AI security page.
Direct prompt injection and jailbreaks
Role-play, instruction override, payload splitting, encoding tricks (Base64, leetspeak, invisible Unicode) and multi-turn escalation, to see whether the model can be argued out of its instructions and guardrails.
Indirect prompt injection
Instructions planted in the content your system reads rather than in the chat box: an uploaded PDF, an inbound email, a web page an agent browses, a product review, a CRM note. This is the attack most production systems are least prepared for.
System prompt and configuration leakage
Extracting the hidden instructions, internal URLs, API structure, business rules and occasionally the credentials that developers put in a system prompt on the assumption nobody would see it.
Data exfiltration through output
Markdown images, auto-unfurled links and tool calls that quietly send conversation data or retrieved documents to an attacker-controlled server once a malicious instruction lands.
Excessive agency and tool abuse
Agents persuaded to send emails, issue refunds, change records or call internal APIs outside their intended purpose. Tested against the real tool permissions, including MCP servers and poisoned tool descriptions.
RAG and vector store weaknesses
Cross-tenant document leakage, retrieval that ignores the user's access rights, poisoned documents that steer answers, and embeddings that reveal more than the source permissions allow.
How the assessment runs
1. Scope and threat model
Map what the AI system can read, what it can do, who talks to it and what would hurt most if it went wrong. Written authorisation and rules of engagement are agreed before any testing.
2. Automated scanning
Garak, PyRIT and promptfoo run thousands of known attack patterns against the live or staging endpoint to establish a baseline quickly and cheaply.
3. Manual adversarial testing
The part that finds the serious issues: multi-turn manipulation, indirect injection through your real document and email flows, and chained attacks that scanners cannot plan.
4. Agent and integration testing
Every tool, API and permission the model can reach is tested for abuse, including privilege boundaries between users and tenants.
5. Report and fixes
Each finding comes with a reproduction, a severity, the OWASP LLM and MITRE ATLAS mapping, and a concrete fix — architecture first, filters second.
6. Retest and regression suite
Fixes are retested, and the successful attacks become a promptfoo suite in your pipeline so they cannot quietly come back with the next model upgrade.
Areas served
AI security testing is available across Dubai, including DIFC, Dubai Internet City, Business Bay, Jumeirah Lake Towers, Dubai Silicon Oasis, Downtown Dubai, Deira, Jebel Ali Free Zone, Dubai Media City, Al Quoz. There is no local office — testing is delivered online, which is how AI endpoints are attacked in practice anyway.
AI risk in Dubai's key sectors
Where AI is being deployed fastest here, and the risk tested first in each sector.
Property assistants hold lead data, owner details and pricing rules. Prompt injection that exposes other clients or commits to prices is tested before the bot goes public.
Booking and concierge bots are public and connected to reservations. They are tested for price manipulation, leakage of other guests' details and unauthorised booking changes.
Assistants over accounts, claims and policies are tested for data leakage, manipulation into actions and unsafe advice, with results documented for DORA, the AI Act and your regulator.
AI support agents can be talked into refunds, discount codes and policy exceptions, and product-page content can carry indirect prompt injection. Both abuse paths are tested against the tools the assistant can actually call.
RAG assistants over client files and matters must respect confidentiality between clients and between teams. Retrieval access control and exfiltration through rendered output are the priority tests.
Frequently asked questions
Do you have an office in Dubai?
No. Testing is delivered remotely from Europe with your working morning fully covered. If procurement needs a UAE-registered supplier, working through a local partner is the honest route.
Can you test our WhatsApp or website chatbot?
Yes. Public-facing chat channels are usually the first thing tested, because anyone can reach them.