UAE banks retire SMS and email one-time passwords
Banks had until 31 March 2026 to phase out OTPs sent by SMS and email. Approval inside the bank's app replaces them.
Banks in the UAE had a deadline of 31 March 2026 to phase out one-time passwords sent by SMS and email, according to Khaleej Times. Since 2025, banks have been replacing them with transaction approvals inside their own apps (Khaleej Times).
Why the SMS code had to go
A code sent by text can be intercepted through SIM swaps, phished through fake websites or talked out of a customer over the phone. Once a fraudster has it, the bank sees a valid login.
The UAE central bank’s guidance on digital identification points banks towards “phishing-resistant authenticators”, where at least one factor relies on public key encryption, such as FIDO standards or PKI certificates (CBUAE).
Where AI comes in
Removing the SMS code does not remove fraud. It moves the fight to the signals around a payment: the device, the location, the beneficiary, how the customer types and swipes. Those signals are scored by machine learning models in real time, and that is where most banks’ fraud AI now sits.
A note on sourcing
The 31 March deadline has been widely reported, including by Khaleej Times, but we have not yet found the central bank’s notice published in its public rulebook. We will link it when we do.
More rollouts
Bank Albilad scores every transaction in real time to hunt mule accounts
The Saudi bank uses machine learning and network analysis from SAS. The vendor reports half the false positives and 70% more fraud losses prevented.
Emirates NBD ranks first of 25 banks in the first Middle East and Africa AI index
Evident's new index puts Emirates NBD ahead of Standard Bank, with First Abu Dhabi Bank third. Two of the top three are in the UAE.
ADCB rebuilds its mobile app around a conversational AI assistant
Customers can check balances, move money and manage cards by voice or text. ADCB says biometrics and AI fraud detection sit underneath.