Residents of the United Arab Emirates (UAE) were advised on Friday, August 28th, to exercise caution when using artificial intelligence tools found through internet search engines, as not all platforms are reliable or secure.
The UAE Cybersecurity Council reported that some AI tools may be designed to collect personal information and user data without their knowledge. Residents were advised to check the reliability of the website or AI service before use and carefully review requested permissions.
Furthermore, the authority strongly urged users not to grant unnecessary access to their camera or other device functions, especially when working with unfamiliar AI tools. As AI services become increasingly common, UAE residents were reminded of the need to protect privacy by using tools from verified and trusted sources and carefully considering before granting access to personal data or device functions.
Artificial intelligence has rapidly integrated into daily life. However, as AI capabilities grow, cybersecurity experts continue to warn users about the information they share with these platforms. Three types of data were highlighted that should never be uploaded to an AI chatbot:
Firstly, one should avoid entering financial and banking information, such as credit card numbers, bank account details, online banking credentials, or financial reports into AI tools. If the conversation accidentally becomes public, your account could be compromised or the information could fall into the wrong hands if you are using an AI service with insufficient privacy protection. Financial data must always be treated as strictly confidential.
Secondly, identity documents, including passports, Emirates IDs, driver's licenses, or visas, should not be uploaded, as they contain highly sensitive personal information. Unjustified uploading of such files increases the risk of personal data theft in case of a leak. If AI is required to analyze a document, it is recommended to remove personal details first.
Thirdly, medical records often contain the most private information about a person, such as diagnoses, prescriptions, test results, and insurance information. When using AI for better understanding of a medical report, names, identification numbers, and other personal information should be removed where possible.
In June, Dr. Mohammed Al Kuwaiti, head of the UAE Cybersecurity Council, warned that artificial intelligence is being used for much more than traditional phishing attacks and email attacks. He stated that AI is now being applied to a wider range of cyber threats, including data exfiltration, data wiping, and sophisticated cyber operations observed almost daily in recent months.
Al Kuwaiti noted that attackers are increasingly using AI in cyberattacks, moving beyond phishing and email to more diverse attacks related to theft, exfiltration, and destruction of data. He emphasized that AI is being used in cyberterrorism and cyberwarfare to organize attacks and overcome many traditional security measures previously relied upon.
He also pointed out that attacks are no longer limited to critical infrastructure but are increasingly targeting government institutions, operational technology systems, enterprises, supply chains, and individuals as digital ecosystems become more interconnected. The Head of UAE Cybersecurity stressed the growing threat posed by AI-generated deepfakes, as well as disinformation and misinformation campaigns, warning that such tools can be used to spread fear, confusion, and panic among the population.
