AI
Oct 1, 2026


Microsoft, the UAE Cyber Security Council, and G42’s Core42 will roll out MDASH, Microsoft’s AI system for finding software vulnerabilities, across UAE government entities, starting with pilots and workshops. The system, which found 16 Windows flaws that Microsoft fixed in May, will run on Core42’s sovereign cloud and be vetted through the council’s national AI testing lab.
[For more news, click here]
In May 2026, Microsoft said an AI system it had been building in-house had found 16 previously unknown flaws in Windows networking and authentication code with four of them rated critical, in time for them to be fixed in that month’s security updates. The system, called MDASH, coordinates more than 100 specialized AI agents running on a mix of large and smaller models and so far, Microsoft has offered it only to a small group of customers in a private preview.
This week Microsoft, the UAE Cyber Security Council, and Core42, part of Abu Dhabi’s G42, said they would bring that system to government entities across the UAE. The rollout starts with awareness sessions, pilots, technical workshops, and onboarding for the departments that take part.
MDASH, short for multi-model agentic scanning harness, does not lean on a single AI model. It splits the job into stages, preparing the code, scanning it, checking whether a suspected flaw is real, removing duplicates, and proving the bug can be triggered, with separate agents handling each step. On CyberGym, an industry benchmark made up of 1,507 real-world vulnerability tasks, Microsoft says MDASH scored 88.45% when it was announced, about five points ahead of the next entry. The company also said it caught all 21 bugs its engineers had planted in test code, with no false alarms.
In the UAE, the tool will be used to find weaknesses in government software, rank the risks, and help security teams respond faster. Microsoft will provide technical expertise and implementation guidance, Core42 will handle onboarding and training through its Sovereign Public Cloud, and the council will run the tool through its National AI Test and Validation Lab before departments put it to work. Microsoft and the council have worked together before, signing an agreement in 2023 to share threat information and build cybersecurity skills in the country.
“Code safety is a national priority and a cornerstone of cyber resilience,” said HE Dr. Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government. “As AI becomes integral to government and critical services, securing the code that underpins these systems must be built in from the outset, not treated as an afterthought. Bringing MDASH capabilities to the UAE is a major catalyst for wider adoption of AI-powered code security across government and our national digital ecosystem.”
“Governments around the world are increasingly looking to AI as a force multiplier to protect the nation, its critical assets, and people,” said Hayete Gallot, who returned to Microsoft from Google earlier this year and is now its Executive Vice President, Security and Emerging Technologies. “AI can be a powerful tool for cybersecurity. Together with the UAE Cyber Security Council and Core42, we will help government organisations strengthen resilience, improve cyber readiness and build capacity for emerging threats.”
MDASH has to read the source code of the systems it checks, and governments are wary of letting that code leave the country. Running the tool on Core42’s sovereign cloud keeps both the data and the work inside the UAE.
“The UAE has made a deliberate choice to lead in AI adoption,” said Talal M. Al Kaissi, chief executive of Core42. “That leadership brings a responsibility to ensure our digital infrastructure is secure, resilient and trusted. This collaboration combines world-class AI security capabilities with sovereign infrastructure and local expertise, giving government entities access to advanced cyber defense capabilities while keeping security, privacy and operational control at the centre. Core42, along with the wider G42 ecosystem are well positioned to help amplify the benefits of this partnership to our customers.”
The project also builds on a relationship that Washington has watched closely, since Microsoft invested $1.5 billion in G42 in 2024 under an agreement backed by security assurances between the US and UAE governments, after G42 had pledged to stop using Chinese hardware.
CloudSEK, a threat intelligence firm, recorded 2,588 threat activity indicators involving UAE government, finance, maritime, and industrial targets between April 2025 and August 2026. That figure counts signs of hostile activity rather than successful attacks, and government and financial services were the sectors targeted most often, according to the report.
Tools like MDASH are built for defenders, but OpenAI and Anthropic both disclosed this year that AI models under testing had broken into other companies’ systems. On Tuesday, the largest US AI developers signed a voluntary pledge at the White House to keep their tools from accessing technical systems in unintended ways.
The UAE rollout begins with pilots and workshops for the government entities that sign up, and the three organizations have not said how many departments will take part or when MDASH will move beyond that first phase.
The Middle East’s Next Battle May Be Fought in Code
Nozomi Compass Targets OT Security as AI Speeds Vulnerability Discovery
Microsoft’s $10 Billion Gulf Deal Extends Beyond Data Centers
Related Articles