Skip to main content
NexITC

FIELD NOTE · AI

What the UAE Agentic AI Mandate actually requires (and what it doesn't)

The Mandate is a services-portfolio sequencing problem, not an enterprise architecture problem. Vendor proposals typically miss this distinction. Here's what the Mandate actually requires — and what it doesn't.

Practice Lead — AI1 September 20265 min read
  • agentic-ai
  • mandate-readiness
  • federal-compliance
  • vendor-evaluation

The Agentic AI Mandate was issued in April 2026 as a federal directive targeting 50% of federal services delivered via agentic AI within two years. Since then, procurement conversations at UAE public sector entities and quasi-government enterprises have been dominated by vendor proposals for "AI-first services transformation" — 24-month programmes at AED 15-25M ranges, with scope statements that read as enterprise-architecture rewrites rather than services-portfolio evolution.

The proposals share a common problem: they don't answer the sequencing question the Mandate actually requires entities to answer.

What the Mandate requires

Three things, specifically:

A defined portfolio of citizen and business services, classified against agentic transformation criteria. This is what the Mandate treats as the unit of compliance — not "the enterprise's AI capability" but "which services in the portfolio are delivered agentically, on what timeline, with what evidence."

Federal reporting on Wave 1 and subsequent wave progress, with reasoning trails for sequencing decisions. Federal reporting expects entities to justify why specific services entered Wave 1 rather than later waves — and equally, why specific services are not on the agentic transformation path at all.

Operational readiness for the services that do transform, including data readiness, human accountability protocols, escalation mechanisms, and audit trail infrastructure. The Mandate does not accept "agent deployed, target counted" — it expects agents to operate within defined governance envelopes with documented accountability.

What the Mandate does not require

Three things that dominate current vendor proposals but are not in the Mandate:

Enterprise-wide "AI-first" architectural transformation. The Mandate is service-portfolio-scoped. An entity that transforms 50% of its services agentically has satisfied the target regardless of whether the underlying architecture is unified or heterogeneous. Enterprise architecture programmes may be legitimate work, but they are not what the Mandate requires — and treating them as prerequisites delays Wave 1 delivery past federal deadlines.

Autonomous agent action across all transformed services. The Mandate does not mandate autonomy — it mandates agentic delivery, which includes agent-assisted workflows with human accountability. In regulated service contexts (adjudication, benefits determination, licensing), autonomous action may be structurally impossible under existing legal frameworks. Agentic delivery with human sign-off at defined confidence thresholds counts.

Every service in the portfolio. This is the point most vendor proposals obscure. Federal reporting explicitly accommodates services classified as unsuitable for agentic transformation, provided the reasoning is documented. Some services shouldn't transform — because the workflow doesn't benefit from autonomous action, or because operational risk exceeds efficiency gain, or because a lower-complexity AI approach fits better. Naming these services honestly is part of Mandate compliance, not a failure of it.

The sequencing framework that actually works

Three buckets, evaluated against six criteria per service:

Wave 1 (proceed to build): Services where alignment with Mandate compliance is high, structural fit for agentic patterns is clear, data readiness is present or achievable within Wave 1 timeline, operational risk is manageable within defined governance envelopes, citizen impact is meaningful, and no blocking prerequisites exist.

Deferred (proceed after prerequisites resolve): Services where the agentic transformation is fundamentally viable but blocked by a specific prerequisite — most commonly data readiness gaps, but also regulatory clarification requirements or upstream policy transitions. Deferred services sequence into Wave 2 or Wave 3 assessment once prerequisites resolve.

Recommend against (not on the agentic path): Services where the workflow doesn't benefit from autonomous action (already-automated flows, query-response patterns better served by generative AI assistants than agents), where operational risk exceeds efficiency gain (regulated adjudication requiring documented human accountability), or where a lower-complexity AI approach delivers the citizen outcome more appropriately.

The evaluation criteria per service: (1) alignment with Mandate compliance requirements, (2) structural fit for agentic patterns, (3) data readiness, (4) operational risk if agent behaviour deviates, (5) citizen impact of successful transformation, (6) prerequisite dependencies.

What this changes for procurement

Two things:

Vendor proposal evaluation shifts from "how much capability can we buy" to "what sequencing decision is this proposal actually informing." Proposals that skip service-portfolio sequencing and jump directly to platform selection or transformation architecture are answering a different question than the one the Mandate requires the entity to answer.

Federal reporting defensibility depends on the reasoning trail, not the transformation count. An entity that transforms 40% of services with documented reasoning for the non-transformed 60% is better positioned federally than an entity that transforms 60% without a defensible framework for the remainder. Auditors and federal reporting functions can inspect reasoning; they cannot inspect assumption.

Assessment engagements that produce the sequencing framework — with the reasoning trail auditable — are what the Mandate actually requires entities to procure. Transformation programmes come later, informed by the sequencing.

Adjacent engagement patterns

Where this shows up in the catalogue.

NexITC's A11 Agentic AI Readiness & Use-Case Discovery engagement covers this framework. Related engagement patterns: B14 Agentic Workflow Agent Build for Wave 1 build execution, A6 Data Trust Sprint for prerequisite resolution, C9 Managed Agent Operations for post-deployment operational discipline.

Case study reference: A11 Agentic AI Readiness & Use-Case DiscoveryPublic Sector illustrative composite →

Reading this to size up a specific decision? Talk to the practice.

Book a clinic. Practice Lead attends. Insights explain how the practice thinks; a clinic conversation explains what that means for your specific engagement.