Explainer · Fraud

UAE banks retire SMS and email one-time passwords

Banks had until 31 March 2026 to phase out OTPs sent by SMS and email. Approval inside the bank's app replaces them.

Banks in the UAE had a deadline of 31 March 2026 to phase out one-time passwords sent by SMS and email, according to Khaleej Times. Since 2025, banks have been replacing them with transaction approvals inside their own apps (Khaleej Times).

Why the SMS code had to go

A code sent by text can be intercepted through SIM swaps, phished through fake websites or talked out of a customer over the phone. Once a fraudster has it, the bank sees a valid login.

The UAE central bank’s guidance on digital identification points banks towards “phishing-resistant authenticators”, where at least one factor relies on public key encryption, such as FIDO standards or PKI certificates (CBUAE).

Where AI comes in

Removing the SMS code does not remove fraud. It moves the fight to the signals around a payment: the device, the location, the beneficiary, how the customer types and swipes. Those signals are scored by machine learning models in real time, and that is where most banks’ fraud AI now sits.

A note on sourcing

The 31 March deadline has been widely reported, including by Khaleej Times, but we have not yet found the central bank’s notice published in its public rulebook. We will link it when we do.

GoodRollout desk · 31 March 2026 · 4 min readSpotted an error? Tell us
Newsletter

Every Gulf bank AI rollout, in one Sunday email