# The UAE central bank took WhatsApp away from its banks. Customer memory cannot live in the channel

> In April 2026, the CBUAE gave banks, insurers and exchange houses thirteen days to stop serving customers over WhatsApp. What the directive says, what it teaches any market where WhatsApp comes first, and where customer memory has to live to outlast the channel.

URL: https://niadra.com/en/blog/the-uae-central-bank-took-whatsapp-away-from-its-banks
Published on: 2026-10-01 · Regulation · Niadra team

On April 17, 2026, the Central Bank of the United Arab Emirates (CBUAE) directed every licensed financial institution in the country to stop using WhatsApp and similar apps to request or share customer data, initiate or confirm transactions, send passwords and one-time codes, and exchange documents containing personal or financial information. The deadline to confirm compliance and describe the corrective actions was April 30: thirteen days ([the Dubai daily, April 26, 2026](https://www.khaleejtimes.com/life-and-living/banking-in-uae/uae-banks-banned-from-seeking-documents-via-whatsapp-what-it-means-for-customers); [Gulf News, April 29, 2026](https://gulfnews.com/business/banking/uae-central-bank-bans-whatsapp-messaging-apps-in-financial-customer-communications-1.500522809)). In a market where WhatsApp is the first channel for almost everything, years of customer conversations lived inside an app the regulator had just withdrawn. The question it leaves for any company, in the Emirates, in Brazil or in India, is where the customer's memory lives when the channel goes.

This post is for the people who decide channels and vendors in markets where WhatsApp comes first. Every source was read on October 1, 2026.

## What the directive says

The directive covers banks, finance companies, exchange houses, payment service providers, insurers and brokers. As reported by the Dubai daily, it prohibits using instant messaging platforms to:

- request or share customer data;
- initiate or confirm transactions;
- send authentication details, such as passwords and one-time codes;
- exchange documents containing personal or financial information.

The regulator's stated reasons: fraud, impersonation, account takeovers and social engineering; data confidentiality; and the possibility of customer information being processed and stored outside the UAE ([the Dubai daily](https://www.khaleejtimes.com/life-and-living/banking-in-uae/uae-banks-banned-from-seeking-documents-via-whatsapp-what-it-means-for-customers); [Gulf News](https://gulfnews.com/business/banking/uae-central-bank-bans-whatsapp-messaging-apps-in-financial-customer-communications-1.500522809)). The directive, in the words Gulf News reports, aims "to safeguard customers and protect the reputation of the UAE's financial sector". The channels that remain: the bank's app, online banking, the call center and the branch. Before the directive, according to the Dubai daily, banks offered balance checks, transaction alerts and support over WhatsApp.

Two months earlier, on February 23, 2026, the same regulator had published a guidance note on the use of artificial intelligence by financial institutions ([Zawya, February 23, 2026](https://www.zawya.com/en/business/banking-and-insurance/uae-central-bank-issues-guidance-for-responsible-use-of-ai-in-finance-fp1n3i0c)). As read by the law firm Hadef & Partners, it asks that "customers should be informed when they are interacting with AI systems" and receive explanations where decisions are AI-driven, that there be "meaningful human oversight" in high-impact decisions, that the institution keep an inventory of its models, and that "institutions remain accountable for third-party AI systems", with audit and information rights secured contractually ([Hadef & Partners, 2026](https://hadefpartners.com/news-insights/insights/ai-in-banking-finance-in-the-uae-2026-legal-regulatory-considerations/)).

Together, the two pieces tell a bank in the Emirates: the channel where you spoke to customers most no longer serves for what matters, and you answer for the AI agent that speaks for you, whoever built it.

## What happens to the memory when the channel goes

Think of how a bank served customers over WhatsApp until April: an AI agent from a WhatsApp vendor, with the customer's memory kept inside that vendor's platform, or inside WhatsApp Business itself. In thirteen days, three things had to happen at once:

1. **The customer was pushed to the app and the call center.** The conversation that was mid-way on WhatsApp had to continue on the phone or in the app's chat. If the memory lived with the WhatsApp vendor, the call center's voice agent started from zero, and the customer told the story again.
2. **Identity changed shape.** On WhatsApp the customer was a `wa_id` or a number; in the app, a login; on the phone, a caller number the carrier attests or does not. Without an identity resolved outside the channel, the WhatsApp history does not find the customer in the app.
3. **The record of what the agent said stayed behind.** The CBUAE's AI note asks the institution to answer for the third-party agent and keep an audit trail. If the record of what the WhatsApp agent stated and promised stayed on the vendor's platform, the bank lost the proof on the same day it lost the channel.

None of the three problems belongs to WhatsApp. They are problems of a memory that lives in the channel. The same would happen if the regulator withdrew SMS, if Meta changed a policy or if the bank switched WhatsApp vendors on its own. The UAE regulator only made the switch happen in thirteen days, for a whole sector at once.

## What it teaches any market where WhatsApp comes first

The lesson holds for Brazil, India, Indonesia and the rest of the Gulf, where the conversation with a company starts on WhatsApp and becomes a call when it matters ([WhatsApp-first customer service with AI agents](/en/blog/whatsapp-first-customer-service-with-ai-agents)). Three design rules:

- **The channel is a source, not the home of the memory.** Every WhatsApp message, every call and every app session comes in as an event of a memory that sits outside all of them. The channel can go; the memory stays.
- **Identity is resolved before storing.** The `wa_id`, the phone number, the app login and the CRM identifier are clues to the same person, each weighted by what it proves. When the channel changes, the person stays the same.
- **The record of what the agent said belongs to the company.** What each agent read, stated and promised, with the time, the channel and the vendor, lives in the company's record, not on the platform that served the customer. That is what the regulator asks for when it says the institution answers for the third party.

Data residency, the CBUAE's third reason, calls for one direct question to every agent and memory vendor: in which region does the data live, and is it written in the contract?

## What we don't know

- How many customers the Emirates' banks served over WhatsApp and how many conversations were open on April 17. None of the reports gives a volume.
- What each bank did with the WhatsApp history: whether it exported it, discarded it or linked it to the customer record. We found no public statement on this.
- Whether other Gulf regulators will follow. As of the reading date, no equivalent directive has been published.
- The original text of the CBUAE directive. We worked from the Dubai daily and Gulf News reports, which agree on the content and the deadline; the February AI note was read through the Zawya summary and the Hadef & Partners analysis.

## How Niadra solves it

Niadra is the memory layer that sits outside every channel, platform and vendor. Messages from the [WhatsApp Cloud API](/en/integracoes/whatsapp) or [Twilio](/en/integracoes/twilio), calls on the voice platforms, app sessions and CRM and ERP events come in as events of one memory, and Niadra recognizes the same person by `wa_id`, phone number, email, app login and each system's identifier, with a verification level per conversation that decides what the agent may read ([Identity](/en/produtos/identidade)). When a channel goes, the memory does not go with it: the call center's voice agent receives, before the first word, what was handled on WhatsApp, with its source and time, and a webhook alert calls your system when a source stops sending events ([Alerts](/en/produtos/avisos)). The [turn record](/en/produtos/registro) keeps what each agent, from each vendor, read, stated and promised, and the receipt of every read is chained by SHA-256 and exported to your SIEM.

Data stays in a single region, named in the contract, and the Regulated plan comes with a dedicated environment, with its own servers, database and keys ([Enterprise](/en/enterprise)). In the [benchmark of September 30, 2026](/en/benchmark), with the same agent and the same judge for every system, Niadra answered 98.8% of the 338 cases where the customer changes channel correctly, and no sensitive data was delivered to a conversation that had not proven who it was.

## Frequently asked questions

### Does Niadra meet the UAE's data residency requirements?

Niadra runs in a single region, named in the contract, and does not move data between regions. If your rule requires data to stay inside the country, the early-access conversation starts there: the region is a contract decision, and we state in writing where the data lives before any integration.

### Does the WhatsApp history left with the old vendor enter the memory?

It enters by file: Niadra takes history as NDJSON and identities as CSV, and links each conversation to the right customer by the identifiers it carries ([Systems](/en/produtos/sistemas)). What carries no recognizable identifier is kept as unowned history until evidence links it to someone.

### Does this apply outside financial services?

It applies to any company whose main channel can change by decision of a regulator, a platform or itself. The question is the same: if WhatsApp went away tomorrow, would your voice agent know what the customer said yesterday?
