Whose framing is this? The five-part map below is the platform's own, designed to be easy to explain to a board or a family business. Its central loop (sense, interpret, decide, act, learn) is adapted from OpenExO's Intelligence Stack in The Organizational Singularity (OpenExO), which in turn builds on John Boyd's OODA loop. See exo-3-agentic.md for OpenExO's own version.
Why a map helps
"Agentic" is a new word for many people, and new words can make change feel bigger and stranger than it is. In practice, an agentic organisation is still made of familiar things: a purpose, people, information, tools and rules. What changes is that some tools can now carry out several steps on their own. A map shows where those tools sit, who they answer to, and where the safety catches are.
The five parts
1. Purpose and guardrails (the "why" and the "never")
Everything starts with a clear statement of what the organisation is for, what it will never do, and how it chooses when goals conflict (for example, "customer safety before speed"). OpenExO calls this writing the MTP as a "protocol" with constraint, decision and identity layers (MTP page). In plain terms: if an agent, or a new employee, read only this page, would they make the choices your leaders would?
Gulf note: guardrails should include the legal lines that apply to you, such as data residency and consent rules, written in words an engineer can turn into system settings.
2. People above the loop
People set direction, own outcomes, handle exceptions, look after relationships and improve the system. Every agent has a named human owner. This is the idea OpenExO calls the Fiduciary Wedge, and it matches what the Central Bank of the UAE expects of financial firms: boards and senior management are "responsible and accountable for AI and ML systems and outcomes" (CBUAE Guidance Note, 11 Feb 2026) [F].
The CBUAE describes three levels of human involvement, a helpful vocabulary for any sector:
| Model | What it means (CBUAE wording, shortened) | Suitable for (platform's suggestion) |
|---|---|---|
| Human-in-the-loop | AI recommends; a person "retains full authority to approve or reject". | Decisions that significantly affect a customer, employee or citizen: credit, claims, hiring, medical triage. |
| Human-on-the-loop | AI works autonomously on routine tasks; a person monitors and "can intervene where necessary". | High-volume, reversible work: scheduling, document checks, stock reorders within limits. |
| Human-out-of-the-loop | AI operates without direct human involvement, "only... for low-risk, non-material processes with appropriate controls". | Internal housekeeping: tagging files, formatting reports. |
3. The agent loop (how work gets done)
| Stage | What happens | Everyday example: a Dubai distributor's delivery desk (illustrative) |
|---|---|---|
| Sense | Collect signals: orders, emails, sensor data, shipping updates. | An agent reads a carrier notice that a vessel will discharge at a different port. |
| Interpret | Add context and history; work out what it means. | It checks which customer orders are on that vessel and how much later they may arrive. |
| Decide | Choose an action within set limits ("permission envelope"). | It proposes new delivery dates; anything that changes a contract price goes to a person. |
| Act | Carry it out through systems, messages or other agents. | It updates the order system and drafts bilingual messages to customers for approval. |
| Learn | Check results and improve next time. | It records which customers accepted the new dates and refines its estimates. |
(The scenario is invented for illustration. Real 2026 carrier re-routing in the region is described in Maersk's operational updates [F].)
4. Data and systems of record (what the agents stand on)
Agents are only as good as the information they can reach. This layer covers the records the business relies on (customers, stock, finance, HR), who may access what, and where the data physically lives. OpenExO's v25 update argues that "most enterprise AI fails at the data layer, not the model" (OpenExO); that is their view, but it matches common experience.
Gulf notes (verified):
- UAE health information generally may not be stored or processed outside the UAE except where the health authorities allow it (Federal Law No. 2 of 2019, Art. 13) (DLA Piper) [F].
- UAE e-invoicing records must be stored in the UAE (KPMG) [F].
- Saudi Arabia's PDPL allows transfers abroad only on specified grounds and with safeguards such as SDAIA's standard contractual clauses (Clyde & Co; HFW) [F].
- Resilience: after the March 2026 strikes, AWS said it could not restore data held only in its Bahrain region or one UAE availability zone [fact base A3]. Keep copies in more than one location.
5. The governance layer (always on)
A layer that watches everything above and can stop it. OpenExO calls this GOVERN/ASSURE and names four pillars: trusted evaluations, searchable logs, granular rollback and a human review queue (OpenExO). The table maps those ideas to public, non-proprietary standards and Gulf rules, so organisations can build on sources they can cite.
| Governance element | What it means | Where it appears in public standards and Gulf rules |
|---|---|---|
| Inventory | A list of every AI system, its purpose and risk rating. | CBUAE: maintain "an inventory of all AI models" with at least name, purpose and risk rating [F]. DIFC Regulation 10: a register of system use cases [F]. |
| Named owner | One accountable person per agent. | CBUAE board and senior-management accountability [F]; DIFC Autonomous Systems Officer for some high-risk cases [F]. |
| Testing and monitoring | Test before launch and keep testing; watch for drift and bias. | CBUAE: periodic bias testing "once a year or each time a model is upgraded", and continuous monitoring [F]. NIST AI RMF (released 26 Jan 2023; being revised in 2026) (NIST) [F]. |
| Logs and explanations | Be able to reconstruct and explain what happened. | CBUAE: clear provenance and audit trails; ability to explain decisions [F]. DIFC Reg. 10: explain processing "in non-technical terms" [F]. |
| Stop and undo | A reliable way to pause, stop or roll back. | CBUAE: "the clear and immediate ability, with human intervention, to cease use" [F]. |
| Human review and redress | People can ask for a human and challenge a decision. | CBUAE: customers can request human review [F]. UAE PDPL: right to object to automated processing [F]. Saudi PDPL: consent needed for decisions based solely on automated processing, per HFW [F]. |
| Management system | A repeatable way to run all of the above. | ISO/IEC 42001:2023, the AI management system standard (ISO) [S]. |
The boundary with the outside world
More and more, your agents will deal with other organisations' systems: suppliers, banks, government portals. OpenExO's "Ecosystem Trust" covers this (page). Practical steps: give external connections only the access they need, log every exchange, and agree in writing who is responsible if an automated exchange goes wrong, before it goes live.
The map in one picture
Alt text: A diagram with five labelled parts. At the top, "Purpose and guardrails" feeds into a central loop of Sense, Interpret, Decide within limits, Act and Learn, which returns to Sense. "People above the loop" set limits for the loop, approve and handle exceptions. The loop reads from and writes to "Data and systems of record". A "Governance layer, always on" watches the loop, can stop it and reports to the people. The loop connects to the outside world through controlled, logged connections.
What this looks like at different sizes
| A 10-person SME | A 300-person company | A government entity | |
|---|---|---|---|
| Purpose and guardrails | One page, written by the owner. | Board-approved, with a legal review of the "never" list. | Linked to the entity's mandate and national policy. |
| People above the loop | The owner and one "AI champion". | A named owner per agent, an AI risk lead, a regular management review. | A named accountable official; alignment with national frameworks (e.g. the UAE's April 2026 agentic government framework [F, see exo-3-agentic.md]). |
| Agents | Two or three, bought as services (email triage, bookkeeping assistance, bilingual customer replies). | Ten to thirty across functions, some built in-house. | Many, introduced in phases with performance assessment. |
| Data | Clean customer and stock lists; cloud backups in two regions. | A governed data layer; data-residency map. | Sovereign or in-country hosting as required. |
| Governance | A simple register, a monthly check and an off switch. | Inventory, testing, logs and rollback; alignment with NIST AI RMF or ISO/IEC 42001. | Formal assurance, audit and public transparency. |
(The numbers of agents are illustrative, not benchmarks.)
Common worries, answered calmly
- "Will the agents take over?" Not in a well-designed organisation. Agents act within limits people set, every action is logged, and there is always a way to stop them. That is the point of parts 2 and 5.
- "We're too small for this." Small firms often find it easier: fewer systems and shorter chains of approval. OpenExO itself suggests applying its playbook directly to firms of 50 or fewer people (OpenExO).
- "What about our staff?" The best results come from lifting people into more interesting work and training them, not from cutting first. The UAE government's own agentic framework commits to training every federal employee [F, see exo-3-agentic.md].
Next steps
- Score yourself with the AI readiness checklist.
- Follow the stages in the digitisation roadmap.
- See the map applied in the illustrative archetypes.
Attribution and permissions
The central loop on this page is adapted from the Intelligence Stack and its GOVERN/ASSURE control plane in OpenExO's ExO 3.0 framework, set out by Salim Ismail with contributors in The Organizational Singularity (OpenExO, v25, June 2026) (OpenExO). The terms Intelligence Stack, GOVERN/ASSURE, Fiduciary Wedge, Ecosystem Trust and ExO 3.0 belong to their authors and to OpenExO. The five-part map, the size table and the Gulf notes are the platform's own. We do not reproduce OpenExO's diagrams.