What does the UAE data say about agents and control?
That UAE companies run agents at scale, and that most could not stop a bad one quickly. The UAE cut of a Dataiku and Harris Poll, reported on 29 September (the global report came out on 24 September), found that 62% of UAE CIOs estimate more than 50 AI agents are running in production, and 15% say more than 500. The global average for more than 500 is 9%. On more than 50 the global figure is higher, at 67%, so the UAE stands out at the top end. KPMG's UAE Tech Report shows the same push: 97% of UAE respondents say they are embedding AI agents into workflows, products, services and value streams, against 87% globally.
The same poll found that 80% of UAE CIOs have met an agent that broke business intent or policy while still working technically. Most caught it early. 62% say the incident was caught before it caused customer, financial, compliance or operational harm, the highest share in the study, and only 18% report actual impact. UAE teams are good at noticing.
Stopping is where the numbers turn. Only 5% say they could reliably identify and contain a problem agent across environments within one to two hours. The global figure is 10%.
How fast UAE CIOs say they could contain a problem agent, % of respondents
Dataiku's chief executive put it in one line: an agent you can spot in one system but cannot stop everywhere else is not contained, it has just been noticed. Dataiku sells agent management tools, so weigh the framing accordingly. The percentages come from a Harris Poll of 685 CIOs in eight countries, fielded 9 to 29 July 2026.

Why is stopping an agent harder than spotting one?
Because the agent is rarely in one place. It signs in to a CRM, calls a connector, answers in a chat channel and writes to a second system, and each of those has its own switch, its own owner and its own log. Spotting needs one signal. Stopping needs a list of every place the agent can act, and someone who can reach all of them.
The surveys point at the missing list.
Agents built outside the approved channels make it harder. Across all eight countries in the Dataiku poll, 81% of CIOs lack complete oversight of agents created outside approved systems. 84% say employees are building agents faster than IT can govern them. 60% lack a central governance layer across their apps and tools. An earlier Red Hat survey of 100 UAE IT leaders, from October 2025, found 70% reporting a shadow AI problem.
The pattern is control across systems, not detection. That is the part a partner can build, because it sits between the platforms rather than inside one of them.
What does DIFC Regulation 10 add?
For work inside the Dubai International Financial Centre, it puts the accountability on the party that deploys the system. Regulation 10 of the DIFC Data Protection Regulations covers personal data processed through autonomous and semi-autonomous systems. Under Regulation 10.3.4, the Deployer is deemed to act as a controller for what the system does with personal data. DIFC's guidance goes further: a system that acts under a Deployer's authority is in a position much like an employee, and the Deployer is responsible for making sure it stays inside human-established limits.
High-risk uses carry more. A system used commercially for high-risk processing must be certified. It must process personal data only for purposes that humans define or approve, and the Deployer or Operator must appoint an Autonomous Systems Officer, with a role similar to a data protection officer. DIFC sets certification at a maximum of three years, with monitoring in between.

Two limits. Regulation 10 is a DIFC rule, so it applies to DIFC entities and to personal data under the DIFC law. The federal UAE data protection law is separate, and this post does not cover it. And whether your use is high-risk is a legal call. DIFC publishes an assessment, and its own guidance says to seek legal advice first if you are unsure.
What it means for a stop step is practical. If a person answers for the system's behavior, a person needs a way to make it stop, and evidence that they can.
What counts as a kill switch?
Four levers, and a single button rarely reaches all of them. This is our framing, built from how the platforms we work with actually stop things.

The four stop levers
Vendors differ on which lever exists at which plan. On Grok Bot, the admin switches and computer management are Enterprise only, and all of one user's Bots share one computer. On Dots, ask what turning off the workspace beta does to a running Dot. We covered those in Dots vs Grok Bot and the Salesforce levers in Salesforce MCP server: switch on read first.
Here is a worked order for one agent that writes to Salesforce through an MCP client. In Setup, open OAuth Usage and revoke all tokens for the app, refresh tokens included, then end the Salesforce session through the app's single logout. Confirm that a follow-up tool call fails before you treat the agent as contained. Then deactivate the MCP server if no other client needs it. Then restrict the app to a pre-authorised permission set, and remove the agent from the chat channel it answers in. That order is ours. The right one changes with the platform, which is why it is written down.
The point of the list is reach. A login revoked in one system does not stop the agent's connector in another. That is the gap the CIOs describe.
How do you run a stop drill?
Write the order, then time it. The benchmark to beat is the survey's own: only 5% of UAE CIOs say they can contain a problem agent in one to two hours. Aim for inside an hour on your first agent. The survey's fastest category is one to two hours, so an hour beats every category in it. It is our target, not a standard.

- 01List every agent that touches the process, including ones a team built on its own. If it is not on the list, nobody can stop it.
- 02Name an owner and a deputy for each agent. Give them permission to pull every lever, not just the one in their own team.
- 03Write the stop order: which lever first, where it lives, and how you confirm the agent has stopped. Contained means it can no longer act and you have checked. Reversing what it already wrote is a separate step.
- 04Run it in a sandbox and time it. Record the minutes and every place someone lacked access.
- 05Repeat after every change to the agent's tools, and once a month if nothing changed.
The drill also produces the evidence a regulator or an auditor will ask for: the list, the owners, the order and the timings. Under Regulation 10 that is the difference between saying a person is accountable and showing it. It sits next to whatever framework you already report against, such as NIST AI RMF or ISO 42001.
A stop is only half the record. You also need to say who acted. Route tool and model calls through one front door, such as a gateway (see our Flex Gateway page), so every call carries an identity and the stop itself is logged.
The same order works below the enterprise scale. If your agent is a lead-reply bot on a broker's WhatsApp number, the levers are the same: pause the bot, cut its access to the number, take it out of the CRM flow, and name who answers leads in the meantime. A team with two or three agents can run the drill as a short working session.

What do these numbers not tell you?
Less than the headlines suggest. The Dataiku poll was commissioned from Harris by a vendor of agent management tools. It covers CIOs at companies with more than $500 million in annual revenue, and every figure is what a CIO estimates, not what an audit found. The coverage we read does not give the UAE share of the 685 respondents, so the 5% could rest on a small base, and it does not say who the 62% who caught an incident is drawn from. KPMG's UAE sample is 70 people and ServiceNow's is 100 executives. Read the direction, not the decimals.
The one-to-two-hour line is a survey category, not a standard, and we use it only as a benchmark. Dataiku, KPMG, ServiceNow and Red Hat, in four separate surveys, point the same way: agents arrive faster than the list of them, the owners, and the way to stop them.
What would we do first?
Start with one process and read what already touches it. At Mindcat, we begin the same way we begin any work: read the org first, then write down what is worth fixing. For an agent estate that means one process someone runs today, every agent and connector on it, who owns each, and the stop order with a timed run. You get it as a written note, not a dashboard.
We work on the layer between the platforms: Salesforce and MuleSoft integration, the control plane, observability and a named person on the exceptions. Our UAE desk works Gulf hours, and we do not replace your counsel on the DIFC and PDPL questions.

Before your next agent goes live, get three answers in writing: who can stop it, which four levers reach it, and how many minutes the last drill took. Our AI governance playbook has the wider checklist.

