One company, three rulebooks: how AI compliance works in the UAE

By George Titus · 14 August 2026 · 4 min read

A Dubai business can sit under federal law, DIFC rules and ADGM rules at the same time. Which one applies depends on where the entity and the data sit. Companies looking for a single UAE AI law will not find one. What exists instead is a set of frameworks that operate side by side. Which of them applies to a given business depends on where it is registered and where its data is processed. For a group with entities in more than one place, several can apply at once. That is the practical starting point for anyone building an AI compliance programme in the Emirates.

A single national body now oversees AI and data

On 14 June, Sheikh Mohammed bin Rashid Al Maktoum approved the creation of the Federal Authority for Artificial Intelligence and Data. It reports directly to the Cabinet. Omar Sultan Al Olama, Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications, was appointed to lead it.

The Authority brings together three bodies that previously operated separately: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector at the Telecommunications and Digital Government Regulatory Authority, and the UAE Data Office. Its remit covers the national AI strategy, digital government services, government data platforms, and policies and standards for AI and data governance. For companies, the useful part is simple. Three points of contact became one.

The federal layer: PDPL

On the UAE mainland, the main instrument is the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021. It applies to controllers and processors established on the mainland. It also reaches outside the country, covering foreign entities that process the personal data of UAE residents. Full compliance is required by 1 January 2027. The PDPL is not an AI law. But because most AI systems process personal data, it is the layer that catches AI use on the mainland.

One point of caution. Advisers do not all describe the status of the executive regulations the same way. Some cite regulations published in November 2023. Others state they remain unpublished. Companies should confirm current requirements with the Authority directly rather than relying on secondary summaries, including this one.

The DIFC layer: Regulation 10

The Dubai International Financial Centre took a different route. Rather than write a separate AI law, it folded AI into its data protection regime. Regulation 10 was enacted on 1 September 2023 as part of the DIFC Data Protection Regulations. It covers personal data processed through autonomous and semi-autonomous systems, which in practice means AI. Enforcement began in January 2026.

Mayer Brown notes that Regulation 10 draws on international approaches, including OECD guidelines and data protection regimes in the UK and EU. The Commissioner has signalled a certification-based approach rather than licensing.

DIFC is also refining it. On 18 June the Centre opened a consultation on proposed amendments, set out in Consultation Paper No. 3 of 2026. Comments closed on 18 July. The proposals would strengthen Regulation 10 around safe, ethical and privacy-by-design development, clarify certification obligations and the role of the Autonomous Systems Officer, and add a new Regulation 11 giving the Commissioner power to recognise accreditation and certification schemes. Worth being precise here: a consultation is not a rule change. The obligations that apply today are the ones already in force.

Abu Dhabi Global Market runs its own regime under the Data Protection Regulations 2021, which closely follow the GDPR model. That includes a legitimate interests basis for processing and standard contractual clauses for transfers, both of which will be familiar to anyone who has done European compliance work. The PDPL does not cover processing carried out exclusively under the DIFC or ADGM regimes.

Saudi Arabia’s approach

Across the border, the Saudi Data and Artificial Intelligence Authority published a National AI Risk Management Framework in 2026. It gives public and private entities a single methodology for identifying, assessing, treating and monitoring AI risks. It runs through four phases: defining context and scope, identifying and assessing risks, treating risks, and continuous monitoring and review.

Risk levels are set using a matrix that combines the likelihood of a risk occurring with the scale of its impact. The framework is built on seven core principles, including integrity, privacy, transparency and accountability, and it sorts AI risks into seven categories. It applies across sectors and across different levels of digital maturity.

One note on sourcing. Gowling WLG dates publication to April 2026, while Saudi press reported the launch on 14 July. If the exact date matters to you, confirm it with SDAIA.

What this means in practice

Take a group with a mainland trading company, a DIFC-registered financial entity and an ADGM fund vehicle. That is an ordinary structure in the UAE. Deploy one AI system across all three and you are working under three sets of requirements at once.

The obligations are not identical. DIFC requires impact assessments and documentation for high-risk processing under Regulation 10. ADGM follows a GDPR-style model. The mainland PDPL has its own requirements and its own January 2027 date.

So the first task in any UAE AI compliance programme is not legal. It is a mapping exercise. Which entity runs the system, where the data physically sits, and which residents the data belongs to. Most groups discover the answer is messier than the org chart suggests. Shared services, group-wide platforms and cross-border transfers blur the lines that the rulebooks assume are clean. Get the map wrong and the rest of the programme is built on the wrong foundation.

Leave a reply