A board here usually asks the question in one line. Are we compliant on AI?
There is no one-line answer, because there is no one law. There is a stack, and which layers apply depends on where each entity in the group is licensed and what business it is in.
This page is the map. It is not legal advice, and every item should be confirmed with counsel and, where relevant, with the regulator in writing.
Layer one, the federal data law
Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law, has applied since January 2022 to personal data of UAE residents outside the financial free zones.
It does not use the words artificial intelligence often, and it does not need to. Three of its provisions land directly on an AI programme.
Article 18 gives a data subject the right to object to a decision made by automated processing where that decision has legal consequences or seriously affects them, with exceptions where the processing is contractual, legally required or consented to.
Article 21 requires a data protection impact assessment before processing that uses modern technologies and poses a high risk to privacy, or that handles large volumes of sensitive data.
The law requires a Data Protection Officer where the controller or processor conducts high-risk processing using new technologies, systematic assessment of sensitive data including profiling and automated processing, or large-volume sensitive data processing. The officer may be a staff member or a contractor and need not be UAE-based.
The executive regulations were still not published as at August 2026. The market has been planning to 1 January 2027. That is the single most commonly quoted date in this market and the single most commonly quoted without a caveat.
Note that several commentaries published in 2026 state that the executive regulations have been issued. They have not. Clyde & Co and CMS both put the position as still pending, and the UAE legislation portal shows no related instrument. Plan for them, do not report them as law.
The supervisor changed in June 2026, and that is the development to watch. On 14 June 2026 the Federal Authority for Artificial Intelligence and Data was announced, consolidating the UAE Artificial Intelligence Office, the Emirates Data Office and the information and digital government sector of the TDRA into one body reporting to Cabinet, led by the Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. Finishing the PDPL executive regulations and standing up private-sector supervision is the first thing the market expects of it. The rules have not changed yet. The body that will write and enforce them has.
Layer six, the engagement itself
The five layers above bind the AI programme. None of them binds the arrangement under which the people doing the work are engaged, and in practice that arrangement is where the enforcement happens.
An operator engaged without a permit covering the work exposes the hiring company to a fine of AED 50,000, misclassification exposure between AED 100,000 and AED 1,000,000, retroactive gratuity, and refusal of new work permits. MOHRE weighs control over hours and methods, integration into the company structure, economic dependence on a single client, and whether the operator holds valid registration.
This layer is cheaper to get right than any of the five above it, and it is the one most often skipped. It is set out in full in the licence question.
Layer two, DIFC Regulation 10
If any entity in the group is in the DIFC, Regulation 10 applies to it. It was enacted in September 2023 within the DIFC Data Protection Regulations, with enforcement running from January 2026, and it addresses personal data processed through autonomous and semi-autonomous systems.
It binds the Deployer, which controls the system, and the Operator, which processes through it. It requires transparency about whether the system can define further purposes of its own, a register of use cases and processing activities including the necessity and proportionality of each, certification against applicable standards with stricter requirements where the system is high risk, human intervention where processing may produce unfair or discriminatory impact, impact assessments for high-risk processing, and an Autonomous Systems Officer where the processing is high risk.
ADGM operates its own Data Protection Regulations 2021. A group with an onshore company, a DIFC entity and an ADGM vehicle answers to three regimes with three sets of definitions.
Layer three, the financial regulators
Four authorities have moved, and they have moved together as well as separately.
The Central Bank of the UAE published its Guidance Note on the consumer protection and responsible adoption and use of artificial intelligence and machine learning by licensed financial institutions on 11 February 2026. It covers banks, insurers, exchange houses, finance companies and payment service providers. It expects a documented AI governance framework proportionate to size and complexity, AI risk integrated into enterprise risk management, clear roles across risk, compliance, internal audit and IT, a comprehensive model inventory, periodic stress testing for bias, third-party due diligence on vendors and cloud providers, disclosures to consumers in Arabic and English, explanations of AI-assisted decisions, a route for consumers to challenge and complain, human oversight described as in the loop, on the loop or out of the loop, and full retained responsibility for outcomes regardless of outsourcing.
The Central Bank, the Securities and Commodities Authority, the Dubai Financial Services Authority and the ADGM Financial Services Regulatory Authority have also jointly issued Guidelines for Financial Institutions Adopting Enabling Technologies, covering application programming interfaces, big data analytics and artificial intelligence, biometrics, cloud computing and distributed ledger technology.
The DFSA issued a letter to Senior Executive Officers on 4 June 2026 setting out its expectations for authorised firms using artificial intelligence in the DIFC. Its second annual AI survey, published in November 2025, found 52% of DIFC firms using AI, up from 33% in 2024, with 60% planning to expand use in 2026.
Layer four, sector rules
Health. Federal Law No. 2 of 2019 on the use of information and communication technology in health fields requires health data to be stored and processed inside the UAE, subject to exceptions under Ministerial Decision No. 51 of 2021, and applies across all UAE jurisdictions including the free zones. Abu Dhabi's Department of Health published a Responsible AI Standard in October 2025 and Dubai Health Authority has had an AI policy since August 2021.
Medical software. Federal Decree-Law No. 38 of 2024 on medical products, effective 2 January 2025, brings software as a medical device into a centralised approval regime.
Everything else. Most other sectors have no AI-specific rule yet. They have the data law, the consumer protection law, and whatever their own regulator asks for in an inspection.
Layer five, procurement
On 20 January 2025 the Dubai Centre for Artificial Intelligence launched the Dubai AI Seal, awarded in six tiers from E to S. Certification is voluntary in itself. It stops being voluntary the moment a company wants to be selected as a partner on Dubai and UAE government projects, where it is treated as a prerequisite. It is free for licensed Dubai technology companies providing AI products or services.
In a market where government and quasi-government work is a large share of the money, a procurement condition moves faster than a statute.
What this means for one company
| If you are | You are bound by | The first artefact |
|---|---|---|
| Onshore trading or services company | PDPL | The register and a DPIA process |
| DIFC entity | DIFC DP Law 2020 and Regulation 10 | The register, plus an ASO decision |
| ADGM entity | ADGM DP Regulations 2021 | The register |
| Bank, insurer, payments, exchange | CBUAE guidance and the joint guidelines | Documented framework and model inventory |
| DIFC authorised firm | DFSA expectations and Regulation 10 | Framework, inventory, SEO accountability |
| Healthcare provider | Federal Law 2 of 2019 and DoH or DHA policy | Data localisation check and AI risk register |
| Bidding for government work | Dubai AI Seal | The Seal application |
| Engaging anyone independent to do the work | Federal Decree-Law 33 of 2021 and MOHRE practice | The operator's permit, sighted and in date |
Every row but the last begins with the same artefact. The register. The last one begins with a permit, and it is the cheapest check on the page.
Where to go next
For the seat that owns all of this, read the AI Officer seat and DIFC Regulation 10 and the Chief AI Officer job description. For the order of work, read AI transformation in the UAE. For the licence that has to be in place before any of it starts, read the licence question.
If your group spans more than one row of that table, read the register.
