Launching soon

Atlas opens to its first companies this quarter. Leaders can list now.

List yourself

The AI Officer seat. Regulation 10, PDPL, and who signs.

Two UAE regimes now require a named accountable person for how a company uses AI. In most mid-market companies here, that person does not exist yet.

A tower seen from its base, the facade receding into mist.
Burst, stocksnap. Public domain, CC0.

Ask a mid-market company in Dubai who owns AI and you will usually get one of three answers. The CTO, in addition to everything else. A working group. Nobody, said with a shrug.

Two regulations have made the third answer expensive and the first one uncomfortable.

What Regulation 10 requires

DIFC Regulation 10 sits inside the DIFC Data Protection Regulations, enacted in September 2023, with enforcement running from January 2026. It governs personal data processed through autonomous and semi-autonomous systems, which is the regulation's language for artificial intelligence, generative models and machine learning tools.

It binds two parties: the Deployer, which controls the system, and the Operator, which processes through it.

The obligations are specific.

Transparency. The entity must tell people whether processing follows purposes a human defined, or whether the system can define further purposes of its own.

A register. Deployers and Operators maintain a record of system use cases and processing activities, including the necessity and proportionality of each.

Certification. Systems must meet applicable audit and certification requirements, with stricter standards where the system is high risk.

Human intervention. Processing that may produce unfair or discriminatory impacts, or unjust bias, must trigger a human in the loop.

Impact assessment. Risk and impact assessments are required for high-risk processing.

An officer. Where the processing is high risk, the entity appoints an Autonomous Systems Officer, a role that mirrors the Data Protection Officer applied to AI systems.

Read that list as an org chart question rather than a legal one. Every item requires a person who owns it, keeps it current, and answers for it when it is inspected.

What sits alongside it

What Regulation 10 asks somebody to own
01 Transparency Notice on whether the system can define its own purposes 02 The register Use cases and processing, with necessity and proportionality 03 Certification Audit and certification, stricter where the system is high risk 04 Human intervention Where processing may produce unfair or discriminatory outcomes 05 Impact assessment Required for high-risk processing 06 An officer An Autonomous Systems Officer where the processing is high risk
The obligations on Deployers and Operators of autonomous and semi-autonomous systems in the DIFC. DIFC Data Protection Regulations, Regulation 10, enacted September 2023, enforced from January 2026. Read this as an org chart question, not a legal opinion.

The UAE Federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, has been in effect since January 2022 and applies to personal data of UAE residents outside the financial free zones. It carries its own obligations on consent, cross-border transfer, breach notification and data subject rights. Full compliance across in-scope entities is understood to be required by 1 January 2027.

A group with an onshore trading company, a DIFC entity and an ADGM vehicle answers to more than one regime at the same time, with different definitions and different registers.

Two changes since Regulation 10 was enacted raise what is at stake inside the DIFC. Amendment Law No. 1 of 2025 came into force on 15 July 2025 and gave data subjects a private right of action in the DIFC Courts, so a claim no longer has to travel through the Commissioner. The same amendment raised the fine for failing to conduct a data protection impact assessment before high risk processing to up to USD 50,000, and introduced a fine of up to USD 25,000 for missing the annual assessment on whether a Data Protection Officer is required. The assessment that used to be a filing is now the thing a claimant asks for first.

At federal level the supervisor changed on 14 June 2026, when the Federal Authority for Artificial Intelligence and Data was announced. It consolidates the UAE Artificial Intelligence Office, the Emirates Data Office and the TDRA's information and digital government sector into a single body reporting to Cabinet. The PDPL executive regulations are still not issued, and finishing them is the first thing expected of the new Authority.

There is a third obligation that sits below all of this and catches companies more often than either. Whoever fills the seat has to hold a permit or licence that covers the work. That is set out in the licence question.

Why the CTO is not the answer, arithmetically

The CTO already runs infrastructure, security, the product roadmap and the vendor stack. Adding AI accountability to that seat adds a register, a set of impact assessments, a certification cycle and a board reporting line.

Something gets postponed, and it is always the register, because the register has no user complaining about it until the day someone asks to see it.

This is not a criticism of any CTO. It is the same arithmetic that produced the Data Protection Officer as a separate seat rather than an extra duty on the general counsel.

Why the seat exists at all, and where it came from

In June 2024 the Crown Prince of Dubai appointed 22 Chief AI Officers across Dubai government entities, including Dubai Police, the Roads and Transport Authority, DEWA and the Department of Economy and Tourism, under the Dubai Universal Blueprint for Artificial Intelligence.

The pattern after a government creates a seat is consistent and it has run before with the Chief Data Officer. Suppliers to that government are asked who holds the equivalent seat on their side. Joint venture partners are asked. Then banks are asked by their regulator and family businesses are asked by their board.

The UAE National AI Strategy 2031 sits above all of it as the stated national direction, which is why the question arrives in a board pack rather than in an IT review.

Why the first version of the seat is a shared one

A full-time Chief AI Officer is a senior technology package in a market where senior technology packages are already expensive, for a function the board cannot yet evaluate, reporting on a technology the company has not finished deciding about.

The shape that fits is two or three days a week, held by someone who has already taken AI from pilot into production somewhere real, owning four things:

  1. The register and the impact assessments, current and inspectable.
  2. One production use case that pays for itself, chosen for evidence rather than ambition.
  3. The board reporting line, so the question has a standing answer.
  4. The internal policy people actually follow, and the training that makes it true.

Twelve to eighteen months later, if the programme works, the company knows enough to write a full-time job description that is worth writing. That sequencing is the argument, and it is an argument about learning order rather than about cost.

One caution about named positions

A fractional leader can own an AI programme, a register, an assessment cycle and a board line. Whether they can hold a specific named regulatory position, including an Autonomous Systems Officer appointment, depends on that regulator's conditions on residency, approval and presence.

Confirm the specific requirement with the regulator, in writing, before the seat is scoped. Nothing on this page is legal advice, and a page that pretended otherwise would be the wrong page to trust on a compliance deadline.

Where Atlas stands

Atlas lists an AI Officer category, and that is the reason this register exists in the shape it does.

If you have already built an AI function inside a real company here, claim a page. If your board has asked the question and there is no name in the answer, read the register.

Questions

What is DIFC Regulation 10?
A regulation within the DIFC Data Protection Regulations, enacted in September 2023 and enforced from January 2026, governing personal data processed through autonomous and semi-autonomous systems. It binds Deployers and Operators of those systems in the DIFC.
What is an Autonomous Systems Officer?
The person a DIFC entity must appoint where it carries out high-risk processing through autonomous or semi-autonomous systems. The role mirrors that of a Data Protection Officer, applied to AI systems.
Does the UAE PDPL apply to companies outside DIFC?
The Federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, applies to the processing of personal data of UAE residents outside the financial free zones, which run their own regimes. A group operating onshore, in DIFC and in ADGM answers to more than one at the same time.
Can a fractional executive hold AI accountability?
A fractional leader can own the AI programme, the register, the impact assessments and the board reporting. Whether they can hold a specific named regulatory position depends on that regulator's conditions, which should be confirmed before the seat is scoped.
Why not give AI to the CTO?
Many companies do, and in a company where the CTO has capacity it is the right answer. The problem is arithmetic. A CTO already running infrastructure, security and the product roadmap acquires a regulatory register and a board reporting line, and the register is what gets postponed.

Sources

  1. DIFC, Regulation 10 on autonomous and semi-autonomous systems
  2. Mayer Brown, AI regulation in the DIFC
  3. Clyde & Co, DIFC enacts landmark regulation for autonomous systems
  4. Dubai Government Protocol, 22 Chief AI Officers appointed
  5. UAE AI Office, National AI Strategy 2031
  6. Bird & Bird, DIFC enacts amendments to the Data Protection Law
  7. Morgan Lewis, UAE establishes Federal Authority for Artificial Intelligence and Data

The Atlas letter

One leader added to the register, by name. One thing that changed in the rules. One number, with its geography on it.

Once a month. Atlas sends one email to confirm the address before adding it. Nothing arrives until that link is clicked.

Back to writing