In most organisations, a contract is being summarised in a public AI tool. A financial model is being analysed in a free platform. An employee directory is being uploaded to a public chatbot because someone needed a quick answer, and nothing approved was available. The organisation did not sanction it. It has no record of it. And the platform processing it has no obligation to keep it private.
This is not hypothetical; this is a real problem. Shadow AI in an enterprise does not wait for governance frameworks to catch up. It fills the gap between what employees need and what the organisation has sanctioned faster, without any guardrails.
Bukhatir Group, a 50-year UAE conglomerate with 16 companies spanning construction, education, real estate, retail, and sports, chose not to let that gap widen. They built a private and secured AI assistant inside their own infrastructure and made it live across the Group in weeks.
This blog walks through how Bukhatir Group, one of the UAE's oldest conglomerates, designed shadow AI out and put a private, governed AI in employees' hands across 16 companies - and the AI adoption playbook any diversified enterprise can use.
What Is Shadow AI, and Why Your Organisation Already Has It
Shadow AI is the use of public AI tools by employees without organisational approval or visibility. Sensitive data - contracts, financial records, HR files, client information - flows into platforms the organisation neither controls nor sees, processed on infrastructure it has no audit trail over and cannot recall. It is not a policy violation driven by carelessness. It is what happens when capable tools exist publicly, and no sanctioned alternative exists internally.
With shadow IT, blocking tools without providing a better and sanctioned alternative pushes the behaviour underground - the underlying need remains unmet. Shadow AI risk follows the same logic. Employees who find tools that make their work faster will keep using them and keep plugging in internal data. The question is not whether or how data gets used with AI, it is whether it securely happens inside the perimeter or outside it.
For AI in conglomerates, the exposure does not stay in one team or one entity. It multiplies across every company in the group, every function, every geography. The larger and more diversified the organisation, the wider the gap between what is sanctioned and what is happening at a desk level - and the harder it becomes to detect how AI is being used across it.
Solving Shadow AI Is How the UAE's National AI Vision Actually Gets Built
The UAE was the first nation to appoint a Minister of State for Artificial Intelligence. Its UAE National AI Strategy 2031 sets a clear ambition: intelligence embedded across every sector of the economy.
Every instance of shadow AI moves in the opposite direction. Enterprise data processed on platforms abroad is UAE enterprise knowledge leaving the country, unaudited and ungoverned. Every organisation that replaces shadow AI with a sovereign, governed alternative is not just solving an internal risk - it is delivering on the national direction.
Bukhatir Group's deployment is the private sector answering that call. A homegrown UAE conglomerate, partnering with a UAE-headquartered AI company, deploying a sovereign AI capability on UAE soil - not AI as a showcase, but AI as working infrastructure across the sectors UAE businesses and families touch daily.
For enterprises asking what the UAE National AI Strategy 2031 and the UAE AI Charter mean in practice: a sovereign, governed AI deployment on UAE soil, owned by the enterprise and auditable by design, is what both ask for.
For financial institutions navigating the CBUAE AI expectations, see how a CBUAE-licensed bank answered the regulator's responsible AI expectations in production.
For a deeper walkthrough of what UAE regulators expect of enterprise AI, our UAE AI Governance & Complaince Guide unpacks it.
The Three Bad Options Every Enterprise Is Offered
When shadow AI surfaces as a board-level risk, the response usually comes down to one of three options.
Rent AI from a hyperscaler. Fast to deploy, but the data sovereignty question is answered in someone else's favour. Processing happens outside the organisation's perimeter; switching costs run high, and the terms are the vendor's.
Stitch together open-source frameworks. Looks like control - until it reaches production. Falls short in practice - no governance, no audit trail, no enterprise security built in. The gap between a working prototype and a tool the business can rely on is wider than it looks.
Build a sovereign AI capability from scratch. Commission the engineers, scope the architecture, manage the infrastructure. Full control in principle, but the timeline stretches into years on a good run. The best engineers spend that time building plumbing, not building products. The shadow AI exposure keeps compounding throughout.
None of these closes the gap. In the meantime, shadow AI risk compounds. Employees reach for public AI tools because nothing sanctioned and capable exists inside the perimeter.
Bukhatir Group refused all three options.
The fourth option is to own the AI platform.
Not rent it on someone else's terms. Not stitch the open-source frameworks together and wait for production to expose the gaps. Not spend years building it from scratch while the shadow AI exposure compounds. Own your AI - sovereign deployment on the organisation's own infrastructure, governance built in from day one, data that never leaves your perimeter.
That is what MagOneAI is built for - an enterprise agentic AI orchestration platform that deploys on the organisation's own infrastructure. Governance, audit trails, access controls, and human oversight sit at the platform level, applying automatically to every capability built on it. No per-execution fees. No vendor lock-in. The organisation owns the environment, the models, and every AI capability it builds on top. Bukhatir Group chose this path. They built DIWAN on MagOneAI - a private AI assistant, live across 16 companies, inside infrastructure the Group owns entirely.
Case Study: DIWAN, a Private Enterprise AI Assistant for All 16 Companies
Bukhatir Group is one of the UAE's oldest and most diversified business houses - founded in 1974, headquartered in Sharjah, with 16 companies across construction, education, real estate, retail, commercial development, sports, and services. For a conglomerate of this scale, the shadow AI risk is not contained to one team. It exists across every company, every function, every seniority level - and a solution that works for one entity has to work for all sixteen simultaneously.
"Artificial intelligence represents the next chapter in our journey, strengthening how we make decisions, serve our communities and create lasting value. As we embrace its potential, we will remain guided by our values and our responsibility to our people."
Bukhatir Group built DIWAN on MagOneAI, Magure's enterprise agentic AI platform. The Group's own private enterprise AI assistant, running inside their cloud, governed end to end, with every byte of enterprise data staying in the UAE.
What Every Employee Got on Day One
DIWAN launched with 17 capabilities live from day one - one entry point across all 16 Group companies. Knowledge search, document intelligence, HR assistance, content generation, and writing assistance - all inside the Group's own perimeter, with Microsoft Single Sign-On, role-based access control, and audit logging on every interaction. 100% of AI is auditable by design.
What Changed After Rollout
The first rollout wave covered business users across three Group companies, with expansion underway Group-wide. 4 in 5 rollout members are actively using DIWAN, and 52% made it part of their working week from the outset. Employees are spending approximately 96% less hands-on time on work routed through DIWAN. The full production numbers are in the case study.
Platform activity from DIWAN's first rollout wave: 25 business users across 3 Group companies, expanding Group-wide. Usage figures are measured; time-saved figures are estimates, rounded and directional.
Why "DIWAN"
For centuries, the Diwan was the heart of governance and knowledge - the chamber where records were kept, counsel was given, and decisions were made. DIWAN carries that legacy into the AI era: one intelligent place where the Group's knowledge lives, questions are answered, and work gets done.
How MagOneAI Made It Sovereign
Bukhatir evaluated its options the way a diversified enterprise must: sovereignty first, governance second, speed third. MagOneAI answered all three by design.
"In partnership with Magure, everything that matters to us - our cloud, our data, our governance - stayed inside the Group, and we still moved fast. The risk of staff reaching for unsanctioned public tools is no longer something we manage day to day; we've designed it out."
Sovereign by Default
DIWAN runs on a privately deployed model inside the Group's own cloud, served through a sovereign AI UAE model endpoint. 100% UAE data residency. Zero enterprise data leaves the Group's own environment. The Group retains full control over its AI capability, including the immediate ability to cease any system it runs.
Governed Once, Enforced Everywhere
The enterprise AI governance layer was established before the first capability went live. Microsoft SSO, RBAC, centralised monitoring, cost attribution, and audit logging apply automatically to every interaction and every future use case built on the platform. Human task nodes pause any consequential workflow for human review and sign-off. AI assists and accelerates; people decide. When the next capability ships, these controls are already in place - none of them have to be rebuilt.
From Decision to Live Tool in Weeks
From decision to live tool in weeks - that is the timeline DIWAN delivered on. Because the platform, governance layer, and sovereign deployment were established first, each new capability that follows configures on infrastructure that already exists. Guardrails and integrations are reused. Each new use case ships faster and costs less than the one before.
From One Assistant to an AI-Driven Enterprise
DIWAN is the first step, not the destination. Bukhatir Group is establishing its own Group AI Centre of Excellence with Magure - each new capability built on the same governed foundation, reaching production in weeks rather than quarters.
The roadmap spans an intelligent inbox that summarises emails and flags priorities; Spark Plug, the Group's ideation platform, rebuilt with AI; conversational analytics over the Group's own data; intelligent document analysis for contracts and tenders at scale; finance automation with human sign-off; and AI assistants across the Group's customer-facing brands. Because guardrails and integrations are reused, each new use case ships faster and costs less than the one before. The destination is a cognitively connected enterprise - intelligence flowing across every Bukhatir business, under the Group's full control.
"Bukhatir understood early what most enterprises learn the hard way: ungoverned AI is a liability, and rented AI is a ceiling. DIWAN is live today on a sovereign stack the Group fully owns, and behind it sits a platform that can carry AI into every corner of the business, governed, auditable and private by design. That is the difference between adopting AI and becoming an AI-driven enterprise."
The Playbook: Five Moves for Enterprises That Want AI Without the Leak
1. Give employees a sanctioned alternative before blocking anything.
Blocking public AI tools without providing a better option pushes the behaviour underground. The most effective response to shadow AI is a faster, more capable sanctioned alternative employees are permitted to trust with real work. Adoption follows when the tool is better than the public option, not just approved.
2. Deploy the model inside the organisation's own perimeter.
Sovereign AI UAE deployment is the baseline for any organisation that cannot afford its data on someone else's infrastructure. Data stays in the environment by architecture, not policy.
3. Govern once at the platform layer, not per tool.
Every tool governed separately is enterprise AI governance that fails to scale. Build Microsoft SSO, RBAC, audit logging, centralised monitoring, and human task nodes at the platform level before the first capability goes live. Every use case that follows inherits those controls automatically.
4. Launch with everyday capabilities employees use daily.
Knowledge search, document intelligence, HR assistance - high-frequency, daily use cases that produce immediate results and build trust in the platform before moving to higher-stakes applications.
5. Treat the assistant as foundation, not destination.
DIWAN is a private AI assistant built on a governed platform the Group owns entirely. Because the platform beneath it - MagOneAI - comes with guardrails and integrations already in place, each new capability the Group builds ships faster and costs less than the last. This is the difference between renting AI capability and owning it.
Shadow AI in the enterprise is not solved by policy. It is solved by architecture - by giving employees a better, governed alternative before they ever need to reach for a public tool. Bukhatir Group proved that across 16 companies, on sovereign infrastructure, in weeks. The decision framework, the governance model, and the full production numbers are in the case study.
About Magure
Magure is a Dubai-headquartered enterprise AI company helping organisations move AI from pilot to production. Its flagship platform, MagOneAI, is an Enterprise AI Agent Operating Platform that lets enterprises build, deploy, govern, and scale AI agents on their own infrastructure, with enterprise-grade security and control from day one.
Magure is triple ISO certified (9001, 27001, and 42001), SOC 2 Type II compliant, GDPR compliant and a holder of the Dubai AI Seal.
Found this useful? Share it with your team.

Medha Ganti
Senior Content Writer
FAQ
Frequently Asked Questions
- What is shadow AI in enterprises?
- Shadow AI in enterprises is the use of public AI tools by employees without organisational approval or visibility. Sensitive data - contracts, financial records, HR files, client information - flows into platforms the organisation neither controls nor sees, processed on infrastructure it has no audit trail over and cannot recall. It is not driven by carelessness. It is what happens when capable tools exist publicly and no sanctioned alternative exists internally.
- How do enterprises stop shadow AI without blocking productivity?
- Blocking public tools without providing a better alternative does not work - it pushes the behaviour underground while the underlying need remains unmet. The effective response is a sanctioned alternative that is at least as fast and capable as the public option, deployed inside the organisation's own perimeter, with every interaction governed and auditable. When employees have a tool they are permitted to trust with real work, the incentive to reach for public tools disappears.
- What is a sovereign enterprise AI assistant?
- A sovereign enterprise AI assistant is an AI tool that runs entirely within the organisation's own infrastructure - its own cloud, its own compute, its own governance controls. No data is processed by a third-party provider. No queries or documents leave the organisation's perimeter. The organisation retains full ownership of its AI capability, including the ability to audit every interaction and cease any system it runs. DIWAN is exactly this - built on MagOneAI, running on a privately deployed model inside Bukhatir's own cloud, with 100% UAE data residency.
- How does the UAE National AI Strategy 2031 affect enterprise AI decisions?
- The UAE National AI Strategy 2031 calls for intelligence embedded across every sector of the economy. The UAE AI Charter calls for that intelligence to be safe, fair, transparent, and accountable - with data privacy and human oversight built in. For enterprises, this means AI that runs on infrastructure outside the UAE, without governance or audit trails, moves against the national direction. Sovereign, governed AI deployed on UAE soil - with data residency in the country and accountability owned by the enterprise - is what both ask for.
- What platform did Bukhatir Group use to build DIWAN?
- Bukhatir Group built DIWAN on MagOneAI, Magure's enterprise agentic AI platform. MagOneAI runs on a privately deployed model inside Bukhatir's own cloud tenancy, served through a sovereign AI UAE model endpoint. The platform provides the enterprise AI governance layer beneath every DIWAN interaction - Microsoft SSO, RBAC, centralised monitoring, audit logging, and human task nodes for consequential workflows. Every capability Bukhatir builds from here inherits those controls automatically.




