When My AI Meets Your AI: The Next Trust Challenge for UAE Businesses

Date Posted:Wed, 30th Sep 2026

When My AI Meets Your AI: The Next Trust Challenge for UAE Businesses

When buyers and suppliers both use AI, a new governance question emerges: how do two businesses know what their systems are authorised to say, share or do? For UAE companies, the opportunity is faster commercial coordination. The risk is a confident exchange that conceals different assumptions. This article proposes a Human Handshake Matrix to help leaders match oversight to delegated authority and the consequences of error.

 




A commercial misunderstanding at machine speed


Your next proposal to a Dubai client may be drafted by your AI and assessed by theirs. The exchange could look efficient: clear specifications, an attractive price and a delivery date. Yet neither business may have checked whether both systems understood the same commitment.

Consider an illustrative scenario, not a reported incident. A Dubai hospitality operator asks its procurement agent to source equipment for a new property. A UAE distributor’s sales agent returns an offer stating “delivery within ten days”. The buyer’s system interprets this as delivery to the property. The seller’s system means dispatch from its warehouse, subject to stock confirmation. If connected to ordering systems and given sufficient authority, the agents could move the transaction forward before either manager notices the difference.

No dramatic technical failure is necessary. Each system may follow its own instructions while the businesses remain commercially misaligned. The important question is where an exchange of information becomes permission to act.

Why this matters for businesses in the UAE

Dubai’s Universal Blueprint for Artificial Intelligence, launched in April 2024, explicitly promotes AI adoption and the development of AI governance. [1] The Dubai AI Seal, announced in January 2025, adds an initiative for assessing AI providers and strengthening confidence in them. [2] Together, these initiatives make trust a practical part of the local AI agenda.

For a UAE business coordinating buyers, suppliers and service partners across borders, that agenda has a further implication. Confidence in an AI provider should be complemented by agreement with the trading partner about how AI will participate in their relationship. A provider’s credentials cannot establish what a particular purchasing agent has permission to commit to.

When technical connection becomes commercial commitment

The underlying technology is taking shape. In June 2025, the Linux Foundation launched the Agent2Agent project, an open protocol designed to enable agents to communicate and collaborate across different platforms. [3] This is evidence of developing technical infrastructure, not proof that autonomous negotiation is routine across UAE businesses.

A protocol can help systems exchange messages. Businesses still need to agree what those messages mean. A request for availability, a provisional offer and an approved order should remain distinguishable throughout the workflow. The US National Institute of Standards and Technology is also exploring identity and authorisation for software and AI agents, illustrating the importance of controlling who an agent represents and what actions it may take. [4]

The Human Handshake Matrix

I propose assessing each interaction using two questions: how much authority has the AI been given, and how serious would an error be? The matrix below is a conceptual management tool, not an empirically validated scoring model or a regulatory standard.

Figure 1. Human Handshake Matrix. Concept and figure by Dr Ali Bagheri.

A routine reorder may suit bounded automation when the supplier, specification and cumulative spending limit are approved. Selecting a critical supplier requires expert review even if the AI only recommends. Allowing an agent to change consequential terms calls for explicit confirmation by authorised people on both sides before execution. Consequences include confidentiality, service disruption and reputational harm, as well as financial loss.

Make the handshake operational

The handshake is a recorded checkpoint, not a meeting for every transaction. Before connecting systems, trading partners should agree four practical controls.

Establish identity and authority. Each agent needs a verifiable business owner and a defined remit. Separate permission to request information from permission to negotiate or place an order. Verify authority through an approved channel rather than trusting an agent’s own claim.

Confirm shared meaning. Record the terms that matter: currency, taxes, delivery location, acceptance criteria and expiry dates. Where communications cross languages, preserve the agreed wording. In the equipment scenario, “dispatch” and “delivery” must be resolved before an order proceeds.

Limit action and information sharing. Specify permitted data, spending ceilings and exceptions that require review. Limits should apply to cumulative activity so multiple small orders cannot bypass them. Enforce restrictions in the connected business systems, rather than relying only on instructions written to the AI.

Keep evidence and a route to intervention. Retain the relevant messages, source documents, approvals and actions. Name someone on each side who can pause the workflow, investigate a mismatch and agree the response. A stop control prevents further action; it does not necessarily undo an order or recover disclosed information.

Start with one relationship

A practical first step is a limited pilot with a trusted supplier. Begin with a reversible task, such as checking availability or reconciling order status, and keep consequential actions subject to approval. Agree the scope with the partner and test ambiguous requests before expanding it.

Measure more than response time. Track clarification requests, unauthorised actions, human overrides and time spent resolving exceptions. If the systems exchange messages faster but employees spend longer repairing misunderstandings, the relationship has not become more efficient.

BCCD could provide a useful forum for members to compare these controls and develop a voluntary checklist for AI-assisted trading relationships. For individual businesses, the immediate leadership question is simple: when our AI meets a partner’s AI, can both sides show who authorised the action and what was actually agreed?

Author:

DR. Ali Bagheri
AI Governance, Leadership & Innovation Advisor

References

1. Protocol Department – Dubai. (29 April 2024). Hamdan bin Mohammed launches Dubai Universal Blueprint for Artificial Intelligence.

2. Protocol Department – Dubai. (20 January 2025). Dubai Centre for Artificial Intelligence launches “AI Seal” to certify trusted AI companies.

3. The Linux Foundation. (23 June 2025). Linux Foundation launches the Agent2Agent Protocol Project to enable secure, intelligent communication between AI agents.

4. NIST National Cybersecurity Center of Excellence. (n.d.). Software and AI Agent Identity and Authorization.

Sources accessed 27 September 2026. The scenario, matrix and recommended controls are the author’s analysis; the cited initiatives do not endorse this framework.