Connect with us

Financial

WHY THE MIDDLE EAST’S DIGITAL IDENTITY INFRASTRUCTURE NEEDS A DEEPER TRUST LAYER

Published

on

Stefan Deiss, CEO and Co-Founder, The Hashgraph Group

The Middle East has moved faster on digital identity than almost any other region in the world. The UAE Pass now connects residents to more than 5,000 government and private services. Saudi Arabia’s Absher platform has issued over 28 million unified digital IDs. Dubai has gone fully paperless across 45 government entities.

But these systems were built for a world where the main challenge was convenience: getting citizens online, reducing paperwork, speeding up access to services. The threats they were designed to handle were stolen passwords, forged documents and basic impersonation.

What they were not built for is an environment where artificial intelligence can generate a convincing human face in seconds, clone a voice from a few minutes of audio, and inject a synthetic video feed into a verification check in real time.

What distributed ledger technology actually adds

Most digital identity systems today are centralised. Your credentials sit in a government or enterprise database, and every time your identity needs to be checked, the system queries that database. Sometimes that means scanning your face against a stored biometric template. Sometimes it means pulling up your document records and cross-referencing them. Either way, the process depends on one central store of information being secure, accurate and available.

The model works until it doesn’t. A single database holding millions of identities is a high-value target. An attacker who gets in does not compromise one person. They compromise everyone. And the tools available to attackers are improving fast.

The GCC fraud detection market has reached $1.2 billion. Deepfake attacks on identity systems are surging globally. In May, the Saudi Data and Artificial Intelligence Authority published updated deepfake guidelines that explicitly recommend blockchain-based provenance systems to establish traceable records of original content. The guidelines identify identity impersonation through cloned voices and facial simulations as a major risk, and single out finance, politics and identity verification as sectors requiring priority monitoring.

This is the context in which distributed ledger technology becomes relevant. Decentralised identity flips the conventional model. Instead of credentials sitting in someone else’s database, you hold them yourself, in a digital wallet on your device. When you need to prove something, you present only the specific credential required. The verification is recorded on a distributed ledger, a shared record maintained across a network of independent computers rather than controlled by any single organisation. Nobody owns it, can alter it, and shut it down.

Then there are zero-knowledge proofs. This is a way of proving something is true without revealing the underlying information. You could prove you are over 18 without showing your date of birth. You could prove you hold a valid professional licence without disclosing your name or address. The verifier gets the confirmation they need. You keep everything else private.

There is no single database to breach. The individual controls what information is shared and with whom. And every verification event is recorded permanently, creating an audit trail that regulators, enterprises and individuals can each trust independently.

In Sharjah, decentralised identity infrastructure has been integrated across a smart city ecosystem, making it one of the first urban environments in the world where residents, buildings and services interact through digital credentials rather than centralised databases.

The physical presence problem

There is a further gap that even well-designed digital identity systems do not currently address: physical presence.

Identity verification today confirms who someone claims to be remotely. It checks documents, runs facial recognition, performs biometric matching. What it cannot confirm is that a real human being is actually sitting in front of the screen. A synthetic face, a cloned voice and an injected video feed can sail through remote checks that were designed for an era when faking a human was genuinely difficult. That era is over.

The technology to close this gap exists. Ultra-wideband radar, the same short-range spatial sensing found in consumer devices, can detect physical presence with sub-10-centimetre accuracy. It can pick up vital signs such as breathing and heartbeat as a liveness check. When that presence event is cryptographically bound to a decentralised identity credential and recorded on a distributed ledger, the result is a tamperproof record proving a specific individual was physically present at a given location at a given time, verifiable by any authorised party without exposing personal data.

The applications stretch across sectors. In transport, a traveller approaching a gate at an airport or train station could be verified instantly: identity confirmed, physical presence proven, the event recorded permanently. The same logic applies to stadiums, conferences, concert venues and any gated environment where ticket fraud is a problem.

Why the Middle East is the right place for this conversation

The UAE government has announced its intention to transition 50 per cent of federal sectors and services to agentic AI within two years. When AI agents begin autonomously processing licences, permits, compliance checks and cross-border transactions, the question of who authorised what, and whether a human was genuinely involved at the point of decision, becomes critical. Without a verifiable link between a physical person and a digital action, agentic AI systems become vulnerable to impersonation at a scale that manual fraud teams cannot monitor.

The region also has structural advantages that most other markets do not. Governments in the Gulf are bringing policy, investment and technology deployment together under unified national strategies. Saudi Arabia’s Vision 2030, the UAE’s digital economy strategy targeting 20 per cent of non-oil GDP by 2030, and the broader push toward smart city infrastructure all create an environment where new identity infrastructure can move from concept to deployment far faster than in markets weighed down by legacy systems and fragmented regulation.

What comes next

The digital identity systems the Middle East has built over the past decade are genuine achievements. But they were designed for a world where the person on the other end of a verification check was assumed to be real. That assumption is becoming less reliable every quarter.

The next generation of identity infrastructure needs to do three things. It needs to remove single points of compromise by decentralising how credentials are stored and verified. It needs to give individuals control over their own data through zero-knowledge proofs and selective disclosure. And it needs to prove physical presence at the moment of verification, closing the gap that synthetic media is already exploiting.

About the Author:
Stefan Deiss is Co-Founder and CEO of The Hashgraph Group (THG), a Swiss-based Web3 and AI technology engineering company specialising in enterprise solutions built on the Hedera network.

Stefan brings over two decades of experience in technology and business transformation. He spent 11 years at Orange Business Services before moving to Zurich Insurance Group, and went on to found his own consulting firm in 2013. In 2016, he co-founded The Hashgraph Group, which today operates globally with offices across Switzerland, Abu Dhabi, Hong Kong, and beyond.

Under his leadership, THG has developed a suite of enterprise products including TrackTrace for EU Digital Product Passport compliance, IDTrust for decentralised digital identity, and EcoGuard for sustainability and carbon markets. He is also co-inventor of CITI (Continuous Identity Trust Infrastructure), a patent-pending cryptographic framework that binds physical presence to digital identity.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Financial

The rights you think you have: five legal stress tests for a more resilient business

Published

on

Resilience is not only about cash reserves, backup servers or alternative suppliers. It also depends on whether a company’s legal rights and permissions still work when the business is under pressure.

By: Maroun Abou Harb, Associate at BSA LAW

Resilience is discussed as an operational or financial discipline. Businesses test liquidity, back up systems and diversify supply chains. Yet every continuity plan rests on legal infrastructure: licenses, delegated authorities, contracts, data permissions, employment arrangements, security rights and evidence.

That infrastructure can fail when needed most. The replacement supplier cannot be appointed without third-party consent. Customer data cannot lawfully be moved to the backup provider. An insurance claim is compromized by late notification. A guarantee was signed incorrectly. The company owns a platform, but not all of its intellectual property.

The most dangerous legal risk is not the missing clause. It is the right management assumes the business has, but cannot use.

In the UAE, the Central Bank’s 2026 Operational Risk Management Regulation now requires licensed financial institutions to implement a comprehensive operational risk and resilience proecedure. The principle is valuable for every company: identify what must continue, locate the legal points of failure and test them before disruption does.

  1. Can the business lawfully act?

Start with corporate authority, check that licenses match actual activities, constitutional documents reflect the ownership and governance structure, and beneficial-owner, shareholder and director records are accurate. Review reserved matters, signing matrices, powers of attorney and banking mandates.

A deal, borrowing or emergency payment can stall because the authorized signatory is unavailable, a power has expired or an approval threshold was misunderstood. Group companies should confirm which entity employs people, owns assets, contracts with customers and receives revenue.

Run this scenario: if the chief executive and chief financial officer were unreachable tomorrow, who could bind the company, access its accounts and appoint an alternative supplier? If the answer is uncertain, the business has a legal single point of failure.

  • Which contracts become dangerous under stress?

Most contract reviews examine value and liability. A resilience review asks a different question: what happens when performance is interrupted?

Build a heat map of critical customer and supplier contracts, ranked by operational importance and consequence of failure. For each, test termination and suspension rights, force majeure and change-in-law provisions, service levels, price-adjustment mechanisms, liability caps, indemnities, insurance, governing law and dispute forum, subcontracting, assignment and change-of-control restrictions. Check notice methods and cure periods; a valuable right can disappear if a notice is sent late or to the wrong address.

Then examine optionality, can the company use a replacement supplier, obtain transition assistance, retrieve its data in a usable format and continue using essential intellectual property? Is there a source-code escrow or step-in mechanism where appropriate?

The aim is not to renegotiate every contract. It is to know which five contracts could stop the business and to fix those first.

  • Can technology fail without the legal part failing too?

A technical recovery plan is incomplete if the contracts do not support it. Cloud, payment, telecommunications and managed-service arrangements should align promised recovery times with the company’s tolerance for disruption. Audit rights, incident cooperation, subcontractor controls, data-location commitments and exit assistance should be tested.

The incident playbook must allocate legal decisions. Who determines whether regulators, customers, insurers or affected individuals must be notified? Who preserves evidence and engages external advisers? How will legal privilege or professional confidentiality be preserved? A cyber incident moves quickly; ambiguity over decision-making wastes the hours that matter most.

Conduct an exercise with management, technology, legal, communications and finance. Introduce a realistic vendor outage or data breach and follow the contracts: who calls whom, what must be notified, and what can actually be recovered?

  • Does the company know what data and technology it is using?

Across the GCC, privacy and cybersecurity regimes increasingly regulate how data is collected, processed, retained, transferred and protected. A company cannot comply, or recover confidently, without knowing where its data goes.

Create a data map covering customers, employees, vendors and website users. Record the purpose and legal basis for processing, storage location, access rights, retention period, cross-border transfers and third-party processors.

The same exercise should include artificial intelligence, by identifying public and embedded AI tools, the information supplied to them, the outputs relied upon and the human review applied. Confidential information, personal data and third-party intellectual property should not enter a tool because an employee can access it. An approved-use policy, procurement review and output-verification process are proportionate safeguards.

  • Can the company protect value when conditions deteriorate?

Management should monitor covenant breaches, unpaid taxes, overdue receivables, expiring insurance, threatened claims and counterparties showing signs of insolvency. The legal team should know which rights permit suspension, security enforcement, contract termination or protective court relief, and whether exercising them could create risk.

People and intellectual property also require continuity planning. Confirm that employment and consultancy terms contain appropriate confidentiality, invention-assignment and post-termination protections, tailored to the governing law. Identify key-person dependencies, succession gaps and access held by departing staff. Register intellectual property where appropriate and maintain evidence of creation and ownership.

Business needs also to review insurance as a contract, not a certificate. Map material risks to coverage, exclusions, deductibles, notification deadlines and consent requirements. The policy is only useful if the company knows how to activate it.

In brief, the output should be that for every critical risk, record the business service affected, relevant entity and contract, responsible owner, required action, deadline and escalation threshold.

Report the highest exposures to the board and repeat the exercise after major acquisitions, restructurings, regulatory changes or technology deployments.

A focused review can produce four useful assets:

  1. an authority and obligations calendar;
  2. a critical-contract heat map;
  3. a data and AI inventory; and
  4. a tested incident playbook.

No company can remove disruption. It can, however, remove the uncertainty surrounding who may act, what must be done and which rights remain available.

Continue Reading

Financial

Tax Is Not a Strategy – Why Dubai’s Smartest Founders Think Beyond Zero Per Cent

Published

on

By Joe David, CEO of Nephos Group

“Move to Dubai for tax.”

I hear this constantly. From founders, investors, crypto-native operators – people building real businesses who reduce one of the biggest decisions of their professional lives to a single line on a spreadsheet.

And honestly, it is the wrong way to think about it.

Tax should rarely be the sole reason to relocate. When it is, it is usually where things go wrong. The corporate structure is not set up correctly. The banking relationships are not in place. The founder leaves within 18 months because the deeper rationale was never really there. I have seen this pattern play out dozens of times over the past decade, and it almost always traces back to the same root cause: a decision built on a tax rate rather than a strategy.

The tax-first trap

Dubai’s zero per cent personal income tax rate is real, and it is significant. But leading with tax creates a narrow frame that obscures the fuller picture. Founders who relocate purely for a rate often fail to consider the operational realities of building in a new jurisdiction. They underestimate the compliance infrastructure required to make the move defensible. They overlook the substance requirements that tax authorities in their home countries will scrutinise. When the expected savings do not materialise cleanly, because the structure was an afterthought, disillusionment sets in fast.

This does Dubai a disservice. It reduces a genuinely world-class business environment to a line in a tax planning brochure. The city deserves better than that, and so do the founders making life-altering decisions based on incomplete thinking.

What the successful ones actually optimise for

The founders and investors who get the most out of Dubai are not chasing a tax rate. They are making a broader strategic move.

Jurisdictional access is a major factor. Dubai sits at the crossroads of Europe, Africa and Asia, offering time zone coverage and travel connectivity that few cities can match. For businesses operating across multiple markets, particularly in digital assets, fintech and professional services, that geographic positioning is a genuine competitive edge.

Then there is the capital environment. Dubai has become a magnet for institutional and private capital, with fund structures, family offices and venture vehicles establishing a permanent presence. The banking infrastructure, while still maturing in certain areas, has improved significantly. For crypto-native businesses in particular, the regulatory clarity offered by frameworks like the Virtual Assets Regulatory Authority (VARA) provides something that many Western jurisdictions still cannot: a clear, codified path to operating legally with digital assets.

The business ecosystem itself is another draw. The speed at which you can incorporate, hire, open accounts and begin operating is remarkable compared to legacy jurisdictions. Free zones offer tailored licensing, and the government’s responsiveness to emerging sectors – AI, blockchain, tokenised finance – signals a jurisdiction that is building forward rather than regulating backward.

And then, yes, there is the lifestyle. Climate, safety, connectivity, quality of infrastructure. These are not trivial considerations when you are asking a founding team to commit to a base for the next five to ten years.

Tax is often the outcome of all of this. It is not the strategy itself.

The compliance landscape is shifting

There is another reason the tax-first mindset is increasingly risky. The global compliance environment is tightening rapidly. The Crypto-Asset Reporting Framework (CARF), developed by the OECD, will require automatic exchange of information on crypto transactions between jurisdictions. The EU’s DAC8 directive introduces similar obligations across member states. The days of relocating and assuming your home country’s tax authority will not follow are numbered.

This means that substance, genuine economic activity, real operational presence, defensible corporate structures, matters more than ever. A Dubai relocation that is purely cosmetic will not survive scrutiny. One that is built on genuine strategic foundations, with proper advisory support and compliant structures, will.

The conversation worth having

None of this is an argument against moving to Dubai. Quite the opposite. For the right founder, with the right business, at the right stage, it can be a transformative decision. But that decision needs to be grounded in strategy, not arithmetic.

Before you start calculating your tax savings, ask the harder questions. Does your business model benefit from being in this jurisdiction? Can you build genuine substance here? Are your corporate structures defensible under international reporting frameworks? Do you have the advisory infrastructure to get this right from day one?

That distinction – between tax as a tactic and strategy as a foundation – matters more than most people realise. And it is a conversation worth having before you make any decisions.

Continue Reading

Financial

Why Financial Firms Keep Losing the Messaging Battle

Published

on

By: Avi Pardo, Co-Founder & CBO, LeapXpert

Avi Pardo

Financial firms globally have similar playbooks for off-channel communications: ban the channel, run a training, and send attestations for signing. Yet, the conversations are still happening on personal phones. Calling that playbook ‘good enough’ only hides how little has changed.


More than 100 organisations have faced charges under the US Securities and Exchange Commission’s off-channel communications initiative, while other regulators have pursued similar failures. Yet the response is still another rule, another warning, another ban.


The missing piece is the psychology behind banning. Until firms understand what drives employees towards off-channel apps, even banned ones, the next record-keeping failure is already on its way.


Why employees find workarounds


These channels are already part of the client relationship. A banker may be chasing a decision, dealing with a concern or replying to a question that has come through on Signal, WeChat or WhatsApp. In that moment, getting back to the client takes priority.

If replying through the approved channel takes too long, creates operational friction, or disrupts the conversation flow, the employee is likely to answer somewhere else. The message gets sent, but the firm may never see the full exchange.

Psychologists have studied this response to bans for decades. Jack Brehm’s work on psychological reactance shows people can push back when they feel their freedom of choice has been restricted. Research into imposed workplace change points to the same response: people who feel pushed into a new way of working may quietly find another route. Someone reads the policy, completes the training and then uses a personal phone when a client needs an answer.

Daniel Wegner’s work on ironic rebound also helps explain why bans can misfire. Tell people often enough to avoid something and it can make it more appealing. The channel remains on the phone, the client is waiting and the approved route takes longer.


Once the conversation moves to a personal phone, the firm may never recover the full exchange. Employers also face legal limits on how far they can inspect a private device.


Governance beats the workaround


Governance should redirect behaviour instead of trying to suppress it. Employees need an approved route that works while the client conversation is happening, or the workaround will keep winning.


Financial firms still need clear rules and a complete record of business conversations. Regulators expect those messages to be kept, whether they were sent by email, text, WhatsApp or another service.


The problem usually shows up during an ordinary working day: between meetings, on a journey or while a client is waiting for an answer. If the approved channel holds things up, few people will pause the conversation to sort out the process. They will reply another way.


Businesses are losing valuable conversation data


Regulatory risk is obvious when messages go missing: a firm cannot supervise what it cannot see or produce records that were never captured.


Client conversations carry information a business would want to know: a concern raised weeks before a relationship starts to slip, pricing pushback that never reaches the CRM or a salesperson handling a difficult exchange in a way others could learn from. Repeated questions may also point to problems with onboarding, service or product design.


Governed communication creates a record the organisation can learn from. Applied responsibly, conversation data can support supervision, client service, dispute resolution, coaching and a clearer view of relationship risk.
That information is already being generated every day. The difference is whether it remains scattered across personal devices or becomes something the organisation can understand and act on.


Bring the conversation back into view


Plenty of companies have the basics in place: a policy, training and an approved tool. What is often missing is a setup that matches how people work and talk to clients.


The existence of a policy says very little about whether it works. ‘Good enough’ governance can leave a business with all the right paperwork while the same behaviour carries on underneath it.


A quick exchange can soon include a shared document, a follow-up question and another colleague joining the conversation. Messages, files, participants and timing all form part of the record, which needs to stay within the firm without someone rebuilding the exchange later.


If senior leaders use the same channels they have banned for everyone else, the policy is a sham. Employees follow what leaders do, rather than what the compliance manual says. Training can help, particularly when people understand the reason behind it. But explanations only go so far if the approved route slows down a live client conversation. Technology can capture the record, but leadership decides whether people take the rules seriously. No system can rescue a policy that senior figures ignore.


Keeping those exchanges within view gives the business more than a record for compliance. It can also pick up concerns, repeated questions and early signs that a client relationship is beginning to change.


More rules have not stopped the conversations. They have pushed them onto personal phones and out of sight. Calling that ‘good enough’ is no longer credible.

Continue Reading

Trending

Copyright © 2023 | The Integrator