
UAE Plans MDASH Rollout—Sovereign Cloud Keeps Control Local

Microsoft’s September 30, 2026, release listing records its announcement with the UAE Cyber Security Council and Core42 on a government cyber defense initiative. The partners’ MDASH deployment plan would bring Microsoft’s AI-powered vulnerability analysis to UAE government entities in phases, with Core42 providing onboarding and implementation through its Sovereign Public Cloud. Government-wide deployment remains a plan, not a completed rollout.
Computer Weekly’s October 1 report quotes Dr. Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government: “Code safety is a national priority and a cornerstone of cyber resilience.” The planned path starts with awareness sessions and pilots, followed by technical workshops and onboarding. The partners have named UAE government entities as the intended recipients without identifying the initial pilot participants or giving a date for wider deployment.
What MDASH would do for government security teams
MDASH is designed to identify vulnerabilities and help security teams decide which risks to address first. It combines advanced AI models with automated analysis to find weaknesses and prioritize them, giving participating entities a way to focus their security work. The announcement describes this capability and its intended deployment, but gives no measured result from a participating UAE government entity.
Al Kuwaiti’s emphasis on code safety places software used by government and critical services at the center of the initiative. A prioritized finding can help a team decide where to investigate, but the published plan does not say that MDASH will automatically repair the underlying weakness. The practical value for each entity will depend on how its security teams examine findings and incorporate them into their existing work during the pilots.
Microsoft, the council and Core42 have distinct roles
The division of responsibility separates the security capability from government adoption and local delivery. Microsoft supplies MDASH and technical guidance; the UAE Cyber Security Council supports responsible government use; Core42 handles the implementation work for participating organizations. That distinction matters because a sovereign cloud delivery route describes who supports the rollout locally, while each entity’s operating arrangements still have to be established.
- Microsoft: Provides the MDASH capability, technical expertise, and guidance for onboarding and implementation. Its role covers the product and support for introducing it to participating government entities.
- UAE Cyber Security Council: Supports government adoption and responsible use of AI for cybersecurity through the National AI Test and Validation Lab. The stated role is to guide adoption; the plan does not assign the council the day-to-day operation of MDASH for individual entities.
- Core42: Provides local expertise, onboarding, implementation and capacity building through its Sovereign Public Cloud offering in partnership with Microsoft. It will also support integration with its sovereign controls platform and provide implementation services to participating organizations.
The matrix gives government buyers a boundary between what the software does and who makes it usable in their environment. Microsoft’s vulnerability analysis does not itself define an agency’s local controls, while Core42’s implementation role does not make it the developer of MDASH. The council’s involvement gives the initiative a government adoption channel through its validation lab.
The rollout begins with awareness sessions and pilots
The phased plan begins by introducing MDASH to government entities through awareness sessions. Pilots then provide an initial setting for participating organizations to examine the capability, with technical workshops and onboarding supporting implementation. These are the stages the partners have named; they have not attached completion dates or a list of entities to them.
That sequence makes the status of the initiative important. A pilot can show how vulnerability analysis fits a participating entity’s systems and security processes, but it is a different stage from routine use across government. The announced scope is broad, while the first deployments will be limited to the entities that enter the early stages.
Nor does the plan specify a single installation pattern for every agency. Onboarding and integration are part of Core42’s stated work, which means the details will be settled as participating organizations move through the rollout. The first pilots are therefore the next point at which readers can expect evidence about how MDASH is being applied in UAE government settings.
What sovereign delivery means in this plan
Core42’s Sovereign Public Cloud is the specified route for onboarding, implementation and capacity building, supported by its sovereign controls platform. This gives local operational control a defined delivery partner and a set of implementation responsibilities. Security, privacy and operational resilience are stated priorities for that work, alongside Microsoft’s technical guidance and the council’s adoption role.
The announcement does not spell out where every category of data processed by a future MDASH deployment will reside or how every agency will divide operational access. Those details will depend on the controls and arrangements established for participating entities. For now, the concrete next step is the planned awareness and pilot phase, where the partners’ division of responsibilities will begin to take shape in actual government deployments.
Also read:
Related articles


Amaani Raises $5M—Ninefold Growth Must Travel Beyond the UAE

Freelancing in the UAE with Quasa Connect: Effortless Crypto Work Despite Licensing Requirements

Gemini 3.8 Flash Keeps Its Low Price—but Cyber Access Is Gated

ESA and Mistral Want Sovereign Space AI—the Agreement Sets No Delivery Date

Microsoft’s Salesforce Converter Is Public—but It Starts With Discovery
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.