
New KnowBe4 research warns UAE and Saudi Arabia firms face rising AI agent and deepfake threats in 2025. Here's what Gulf businesses need to know now.
Businesses across the UAE and Saudi Arabia are facing a rapidly escalating cybersecurity threat, as ungoverned artificial intelligence agents and increasingly convincing deepfakes emerge as top attack vectors in 2025. New research from cybersecurity awareness firm KnowBe4 flags both trends as critical risks for Gulf organisations that have moved fast on AI adoption without matching governance frameworks.

AI agents are software systems that act autonomously, making decisions and executing tasks without constant human oversight. The problem, according to KnowBe4’s findings, is that many organisations in the region are deploying these tools faster than they are setting rules around them. Without clear policies on what an AI agent can access, modify or share, a single compromised agent can become a serious internal liability.
The Gulf’s aggressive push toward digital transformation, driven by Saudi Vision 2030 and the UAE’s own AI strategy, means adoption rates are among the highest in the world. That speed is an asset economically but a vulnerability operationally.
Deepfake technology has moved well beyond viral social media tricks. Cybercriminals are now using AI-generated audio and video to impersonate senior executives, tricking finance teams into authorising transfers or leaking sensitive credentials. These attacks are sometimes called “CEO fraud” or business email compromise, but the deepfake layer makes them far harder to detect than a spoofed email.
KnowBe4’s research highlights that the sophistication of these fakes has reached a point where even trained employees struggle to spot them in real-time scenarios, particularly under time pressure.
The UAE and Saudi Arabia are not average targets. Both countries host high concentrations of financial services, government digitisation projects and large-scale infrastructure programmes that are attractive to state-sponsored and financially motivated threat actors alike.
Riyadh’s position as a growing financial hub and Dubai’s role as a global business gateway mean that successful attacks on firms here can have ripple effects far beyond the region. The stakes for getting AI governance right are unusually high.
There is also a cultural dimension. High-trust business environments, where decisions are sometimes made quickly based on a phone call or voice note, can be particularly vulnerable to voice-cloning attacks. An employee who trusts a familiar-sounding voice from a known number is exactly the profile attackers are targeting.
KnowBe4’s report points toward human-centred security as the primary defence layer. Technology controls matter, but an employee who can critically evaluate an unusual request, even one that appears to come from a trusted source, is the most reliable line of defence.
Practical steps include establishing verbal verification protocols for any financial instruction received digitally, auditing which AI tools have access to sensitive systems, and running regular simulated deepfake and phishing exercises so staff build recognition instincts before a real attack occurs.
Organisations should also push for AI governance policies that define acceptable use, data access limits and audit requirements before new tools go live, not after an incident forces the conversation.
The tension between AI opportunity and AI risk is not unique to the Gulf, but the region’s ambition makes the gap between adoption and governance unusually visible. Regulators in both the UAE and Saudi Arabia have signalled increased focus on AI oversight, yet formal frameworks that specifically address agentic AI risks remain in early stages.
For a full breakdown of the findings, see the original report from KnowBe4.
As AI tools become standard equipment across Gulf boardrooms and back offices, the question is not whether your organisation uses AI, but whether you know exactly what your AI is doing when no one is watching. What steps has your company taken to govern its AI tools? Share your thoughts in the comments below.
Disclaimer: This article covers cybersecurity research and does not constitute professional IT or legal advice. Organisations should consult qualified security professionals for guidance specific to their operations.






