The Dubai Financial Services Authority has introduced a package of regulatory and technology measures covering updated crypto token rules, expanded digital asset oversight, and a significant widening of how the regulator itself uses agentic artificial intelligence.
Chief Executive Mark Steward framed the work as building on a 21-year foundation through a risk-based approach focused on flexibility, transparency and regulatory certainty. That framing matters, because the substance of these changes is not liberalisation or tightening as much as relocation: deciding where responsibility sits.
Tokens: the burden moves to firms
The updated crypto token rules, effective January 2026, give licensed firms greater responsibility for assessing tokens under strict risk management requirements. In parallel, the DFSA has recognised three fiat-backed stablecoins for use in financial services within the Dubai International Financial Centre, and signed a memorandum of understanding with the Virtual Assets Regulatory Authority.
The shift from regulator pre-clearance toward firm-level assessment is a scalability decision. A regulator cannot meaningfully vet every token that might touch a licensed firm; a principles-based regime asks whether the firm had a defensible methodology, applied it consistently, and documented it.
The cost of that approach shows up in supervision. "The firm assessed it" is only adequate if the assessment survives challenge, so firms should expect examiners to test the framework itself — what criteria were applied, what evidence was obtained, who reviewed the conclusion, and how a token already admitted would be reassessed if circumstances changed. A self-assessment that exists only in principle is a finding waiting to happen.
Recognising fiat-backed stablecoins is the infrastructural half of the same policy. Stablecoins that settle tokenised funds, margin and secondary-market trades need a recognised instrument; limiting the list to three suggests a deliberately high bar around reserve quality, attestation and redemption rather than an attempt to admit the whole market.
Securities: narrowing reach, not reducing protection
The DFSA has revised its securities regulations to limit offering rules to issuances based within the DIFC, aiming to reduce operational overlap while maintaining investor protection.
Where a regulator previously applied offering rules to anything reaching persons in its jurisdiction, narrowing to DIFC-based issuance removes a layer of duplicated compliance for cross-border business, particularly in a country where federal and free-zone regulators overlap. The stated purpose is to cut overlap rather than to lower standards. The seam this creates is the practical issue: if an issuance is structured outside the zone, firms need to establish clearly which regime governs, because ambiguity is where enforcement disputes begin.
The funds review is the substantive item
The authority began its largest review of the collective investment funds framework since 2010. Fifteen years is a long interval for a funds rulebook.
When that framework was written, private credit was not a mainstream product, tokenised fund units did not exist, and umbrella structures, master-feeder arrangements and delegated portfolio management were considerably less common. A framework drafted for an earlier product set tends to answer today's questions by analogy, which produces inconsistent treatment and friction for managers.
A parallel consultation to update the Islamic finance framework addresses the same problem from a different angle: structures not contemplated when the rules were drafted, assessed through processes designed for paper-based workflows.
Enforcement is the credibility test
The DFSA signed an agreement with the Ministry of Economy and Tourism to strengthen information sharing, and continued enforcement action against regulatory breaches including misleading conduct and failures to comply with suspicious transaction reporting requirements.
Reporting failures deserve more attention than their framing suggests. Suspicious transaction reporting is the point at which financial crime regulation becomes operational rather than documentary, and it is also the most commonly deficient area across jurisdictions. If the firm is where the rules now bite most — on token assessment — then STR quality is where the failure will surface first.
AI inside the regulator
The DFSA is integrating agentic AI across its own operations to streamline procedures and strengthen regulatory efficiency. That is a notable step: most supervisors are still running contained pilots, and moving to agentic systems inside a regulator raises different questions than using them internally at a firm.
It is also contextual. The authority's second annual AI survey, published in November 2025, found 52% of DIFC firms using AI technologies, up from 33% in 2024, with 60% planning to expand AI use in 2026. A regulator deploying these tools is regulating a population already using them at scale.
That concentration is why the DFSA's work on third-party technology risk management and expanded cyber threat intelligence sharing is the more consequential piece. When most firms use the same small set of models, vendors and cloud providers, duplicated third-party failures become correlated rather than idiosyncratic — the defining characteristic of a systemic risk rather than an operational one.
What it is aimed at
The measures are positioned as supporting Dubai Economic Agenda D33 and DIFC Strategy 2030, advancing the centre's position through digital asset rules, AI adoption and regulatory modernisation. Read practically, the strategy is to build credibility in the areas that attract international capital: a functioning token regime, a modern funds framework, and enforcement that is applied rather than announced.
What to watch
- Whether the recognised stablecoin list expands, which would indicate confidence in reserve and attestation standards.
- How the token assessment requirement is examined in practice — specifically whether firms are expected to produce documented, reviewable methodologies.
- The outcome of the collective investment funds consultation, particularly on tokenised fund units and private credit.
- Clarity on jurisdictional boundaries following the narrowing of offering rules; boundary ambiguity tends to surface before the next enforcement cycle.
Sources
- DFSA announcements and statements covered in this article: updated crypto token rules effective January 2026; recognition of three fiat-backed stablecoins in the DIFC; MoU with the Virtual Assets Regulatory Authority; revision of securities offering rules to DIFC-based issuances; consultation on the Islamic finance framework; the largest collective investment funds review since 2010; the agreement with the Ministry of Economy and Tourism; and continued enforcement including misleading conduct and suspicious transaction reporting failures.
- DFSA second annual AI survey, November 2025: 52% of DIFC firms using AI (33% in 2024), 60% planning expansion in 2026.
- Chief Executive Mark Steward's remarks on the 21-year foundation and a risk-based approach centred on flexibility, transparency and regulatory certainty.
- Secondary reporting, February 2025, indicating Circle's USDC and EURC were the first stablecoins recognised under the DFSA crypto regime; whether those two are among the three currently recognised has not been independently confirmed here.
- Note: analysis of self-assessment regimes, jurisdictional seams, third-party concentration risk and the items listed under "what to watch" is the author's.
