The UAE is preparing to put artificial intelligence deeper inside its government cybersecurity operations, this time with an AI system designed to hunt vulnerabilities in software before attackers can exploit them.
The UAE Cyber Security Council, Microsoft and Core42 have announced plans to deploy MDASH, Microsoft’s multi-model agentic security system, across UAE government entities.
This is not simply another AI assistant being added to government software.
MDASH is built around more than 100 specialised AI agents that examine code, investigate potential vulnerabilities, challenge findings and attempt to prove whether identified weaknesses can actually be exploited. Microsoft developed the system through its Autonomous Code Security team as a way of moving AI-assisted vulnerability research closer to production security operations.
For the UAE, the deployment also carries another requirement: sovereignty.
Core42, part of Abu Dhabi-based G42, will support implementation through its Sovereign Public Cloud infrastructure, keeping security, privacy and operational control at the centre of the government rollout.
MDASH Brings AI Agents Into Vulnerability Hunting
Traditional vulnerability scanners can produce long lists of potential problems. Security teams still have to work out which findings matter, whether they are genuinely exploitable and what deserves attention first.
Microsoft is trying to push AI further into that process.
MDASH uses an orchestrated collection of specialised agents rather than depending on a single large language model. Different agents can search for possible vulnerabilities, debate findings, remove duplicates and construct proof-of-concept inputs designed to confirm whether a suspected weakness is real.
That distinction matters. A security team does not necessarily need another system producing thousands of theoretical warnings. It needs a way to surface vulnerabilities that deserve human attention.
Microsoft initially reported an 88.45% success rate on CyberGym, a public benchmark containing 1,507 real-world vulnerability reproduction tasks across 188 open-source projects. In a controlled test containing 21 planted vulnerabilities, Microsoft said MDASH detected all 21 without a false positive.
The technology has moved quickly since then.
Microsoft reported in June that an updated MDASH system had reached approximately 96.5% on CyberGym. The company has also cautioned that benchmark performance does not capture every difficulty found in real-world vulnerability discovery, where incomplete information and constantly changing software environments make the problem considerably messier.
Core42 Adds the Sovereign Cloud Layer
The UAE deployment is as much about where AI operates as what the AI can do.
Core42 will provide onboarding, implementation and capacity-building support using its Sovereign Public Cloud offering. The platform combines Microsoft Azure capabilities with UAE-focused sovereign and security controls.
Core42 describes the infrastructure as designed for workloads where data residency, jurisdictional control and regulatory compliance are central requirements. Its sovereign cloud portfolio is aimed particularly at governments, regulated industries and other organisations handling sensitive workloads.
That makes the MDASH arrangement a familiar pattern in the UAE’s growing AI infrastructure strategy: use global AI and cloud technology, but pair it with domestic controls over sensitive data and operations.
The government rollout will not happen all at once. The programme is expected to begin with awareness sessions, pilot programmes, technical workshops and onboarding for participating entities. The UAE Cyber Security Council will support responsible adoption through the country’s National AI Test and Validation Lab.
UAE Government AI Is Moving Beyond Productivity Tools
The cybersecurity agreement lands inside a much bigger government AI push.
Abu Dhabi has already deployed Microsoft 365 Copilot to 35,000 civil servants across 27 government entities through its Frontier Employee Programme. The deployment includes Advanced Data Residency, with AI processing taking place inside the UAE.
Microsoft and Core42 are also involved in the sovereign cloud foundation behind Abu Dhabi’s ambition to become an AI-native government by 2027.
An agreement announced in March 2025 established plans for a unified sovereign cloud environment capable of processing more than 11 million daily digital interactions between government entities, citizens, residents and businesses. Abu Dhabi has allocated AED13 billion ($3.54 billion) to its 2025–2027 digital strategy and plans to introduce more than 200 AI-driven government solutions.
The direction is becoming clearer.
AI is moving from chat interfaces and employee productivity software into the underlying machinery of government — workflows, infrastructure, citizen services and now software security.
Cybersecurity Becomes Part of the UAE’s Sovereign AI Push
There is an obvious tension in the current AI race.
The same class of models that can help defenders inspect millions of lines of code can also lower the barrier for attackers searching for weaknesses.
Microsoft has increasingly positioned agentic security systems as one answer. Instead of asking a model to inspect code once and return a result, MDASH creates a structured pipeline where multiple agents investigate and challenge potential findings before vulnerabilities reach security teams.
The UAE deployment adds the sovereignty question on top of that.
Government source code, vulnerability information and security findings can be exceptionally sensitive. Running AI-powered cybersecurity at national scale therefore requires more than access to a capable model. Governments also have to decide where the data is processed, who controls the infrastructure and how security policies are enforced.
That is where Core42 becomes central to the arrangement.
The UAE is effectively combining Microsoft’s agentic cybersecurity technology with locally controlled sovereign infrastructure. If the phased rollout expands as planned, MDASH could become another piece of the AI stack being built underneath UAE digital government — not something citizens necessarily see, but something designed to protect the software they increasingly depend on.
Sources
Middle East AI News — UAE taps Microsoft, Core42 for AI cyber defence
Read the original report
Microsoft Security — Defense at AI speed: Microsoft’s multi-model agentic security system
Read Microsoft’s MDASH technical announcement

