Launching soon

Atlas opens to its first companies this quarter. Leaders can list now.

List yourself

Every UAE rule that lands on your AI programme, in one place

The UAE has no single AI act. It has a federal data law, a DIFC regulation, four financial regulators, two health authorities and a procurement seal, and a group company can sit inside five of them at once.

A curved glass facade wrapping the corner of a building.
rawpixel. Public domain, CC0.

A board here usually asks the question in one line. Are we compliant on AI?

There is no one-line answer, because there is no one law. There is a stack, and which layers apply depends on where each entity in the group is licensed and what business it is in.

This page is the map. It is not legal advice, and every item should be confirmed with counsel and, where relevant, with the regulator in writing.

Layer one, the federal data law

Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law, has applied since January 2022 to personal data of UAE residents outside the financial free zones.

It does not use the words artificial intelligence often, and it does not need to. Three of its provisions land directly on an AI programme.

Article 18 gives a data subject the right to object to a decision made by automated processing where that decision has legal consequences or seriously affects them, with exceptions where the processing is contractual, legally required or consented to.

Article 21 requires a data protection impact assessment before processing that uses modern technologies and poses a high risk to privacy, or that handles large volumes of sensitive data.

The law requires a Data Protection Officer where the controller or processor conducts high-risk processing using new technologies, systematic assessment of sensitive data including profiling and automated processing, or large-volume sensitive data processing. The officer may be a staff member or a contractor and need not be UAE-based.

The executive regulations were still not published as at August 2026. The market has been planning to 1 January 2027. That is the single most commonly quoted date in this market and the single most commonly quoted without a caveat.

Note that several commentaries published in 2026 state that the executive regulations have been issued. They have not. Clyde & Co and CMS both put the position as still pending, and the UAE legislation portal shows no related instrument. Plan for them, do not report them as law.

The supervisor changed in June 2026, and that is the development to watch. On 14 June 2026 the Federal Authority for Artificial Intelligence and Data was announced, consolidating the UAE Artificial Intelligence Office, the Emirates Data Office and the information and digital government sector of the TDRA into one body reporting to Cabinet, led by the Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. Finishing the PDPL executive regulations and standing up private-sector supervision is the first thing the market expects of it. The rules have not changed yet. The body that will write and enforce them has.

Layer six, the engagement itself

The five layers above bind the AI programme. None of them binds the arrangement under which the people doing the work are engaged, and in practice that arrangement is where the enforcement happens.

An operator engaged without a permit covering the work exposes the hiring company to a fine of AED 50,000, misclassification exposure between AED 100,000 and AED 1,000,000, retroactive gratuity, and refusal of new work permits. MOHRE weighs control over hours and methods, integration into the company structure, economic dependence on a single client, and whether the operator holds valid registration.

This layer is cheaper to get right than any of the five above it, and it is the one most often skipped. It is set out in full in the licence question.

Layer two, DIFC Regulation 10

If any entity in the group is in the DIFC, Regulation 10 applies to it. It was enacted in September 2023 within the DIFC Data Protection Regulations, with enforcement running from January 2026, and it addresses personal data processed through autonomous and semi-autonomous systems.

It binds the Deployer, which controls the system, and the Operator, which processes through it. It requires transparency about whether the system can define further purposes of its own, a register of use cases and processing activities including the necessity and proportionality of each, certification against applicable standards with stricter requirements where the system is high risk, human intervention where processing may produce unfair or discriminatory impact, impact assessments for high-risk processing, and an Autonomous Systems Officer where the processing is high risk.

ADGM operates its own Data Protection Regulations 2021. A group with an onshore company, a DIFC entity and an ADGM vehicle answers to three regimes with three sets of definitions.

Layer three, the financial regulators

Four authorities have moved, and they have moved together as well as separately.

The Central Bank of the UAE published its Guidance Note on the consumer protection and responsible adoption and use of artificial intelligence and machine learning by licensed financial institutions on 11 February 2026. It covers banks, insurers, exchange houses, finance companies and payment service providers. It expects a documented AI governance framework proportionate to size and complexity, AI risk integrated into enterprise risk management, clear roles across risk, compliance, internal audit and IT, a comprehensive model inventory, periodic stress testing for bias, third-party due diligence on vendors and cloud providers, disclosures to consumers in Arabic and English, explanations of AI-assisted decisions, a route for consumers to challenge and complain, human oversight described as in the loop, on the loop or out of the loop, and full retained responsibility for outcomes regardless of outsourcing.

The Central Bank, the Securities and Commodities Authority, the Dubai Financial Services Authority and the ADGM Financial Services Regulatory Authority have also jointly issued Guidelines for Financial Institutions Adopting Enabling Technologies, covering application programming interfaces, big data analytics and artificial intelligence, biometrics, cloud computing and distributed ledger technology.

The DFSA issued a letter to Senior Executive Officers on 4 June 2026 setting out its expectations for authorised firms using artificial intelligence in the DIFC. Its second annual AI survey, published in November 2025, found 52% of DIFC firms using AI, up from 33% in 2024, with 60% planning to expand use in 2026.

Layer four, sector rules

Health. Federal Law No. 2 of 2019 on the use of information and communication technology in health fields requires health data to be stored and processed inside the UAE, subject to exceptions under Ministerial Decision No. 51 of 2021, and applies across all UAE jurisdictions including the free zones. Abu Dhabi's Department of Health published a Responsible AI Standard in October 2025 and Dubai Health Authority has had an AI policy since August 2021.

Medical software. Federal Decree-Law No. 38 of 2024 on medical products, effective 2 January 2025, brings software as a medical device into a centralised approval regime.

Everything else. Most other sectors have no AI-specific rule yet. They have the data law, the consumer protection law, and whatever their own regulator asks for in an inspection.

Layer five, procurement

On 20 January 2025 the Dubai Centre for Artificial Intelligence launched the Dubai AI Seal, awarded in six tiers from E to S. Certification is voluntary in itself. It stops being voluntary the moment a company wants to be selected as a partner on Dubai and UAE government projects, where it is treated as a prerequisite. It is free for licensed Dubai technology companies providing AI products or services.

In a market where government and quasi-government work is a large share of the money, a procurement condition moves faster than a statute.

What this means for one company

If you are You are bound by The first artefact
Onshore trading or services company PDPL The register and a DPIA process
DIFC entity DIFC DP Law 2020 and Regulation 10 The register, plus an ASO decision
ADGM entity ADGM DP Regulations 2021 The register
Bank, insurer, payments, exchange CBUAE guidance and the joint guidelines Documented framework and model inventory
DIFC authorised firm DFSA expectations and Regulation 10 Framework, inventory, SEO accountability
Healthcare provider Federal Law 2 of 2019 and DoH or DHA policy Data localisation check and AI risk register
Bidding for government work Dubai AI Seal The Seal application
Engaging anyone independent to do the work Federal Decree-Law 33 of 2021 and MOHRE practice The operator's permit, sighted and in date

Every row but the last begins with the same artefact. The register. The last one begins with a permit, and it is the cheapest check on the page.

Where to go next

For the seat that owns all of this, read the AI Officer seat and DIFC Regulation 10 and the Chief AI Officer job description. For the order of work, read AI transformation in the UAE. For the licence that has to be in place before any of it starts, read the licence question.

If your group spans more than one row of that table, read the register.

Questions

Does the UAE have an AI law?
Not a single one. As at August 2026 AI obligations arrive through the federal data protection law, the DIFC data protection regulations, financial regulator guidance, sector rules in health, and procurement conditions. A company is usually bound by more than one at the same time.
Is the Central Bank AI guidance binding?
It is issued as guidance rather than as a regulation. In practice a UAE licensed financial institution is examined against supervisory expectations, and a documented framework, a model inventory and board accountability are the expectations it sets out.
When does the UAE PDPL become enforceable in full?
The law has been in effect since January 2022. Its executive regulations were still not published as at August 2026, and the market has been working to 1 January 2027 as the date after which the UAE Data Office can act without a further transitional period. Confirm the current position with counsel before you plan around it.
Do free zone companies escape these rules?
No. The DIFC and ADGM have their own data protection regimes, which are additional rather than instead of sector law. A healthcare business inside DIFC still answers to Federal Law 2 of 2019.

Sources

  1. DIFC, Regulation 10 on autonomous and semi-autonomous systems
  2. CBUAE, Guidance Note on the responsible adoption of AI and machine learning by licensed financial institutions, 11 February 2026
  3. DFSA, UAE regulatory authorities jointly issue Guidelines for Financial Institutions Adopting Enabling Technologies
  4. MOHAP, Federal Law No. 2 of 2019 on the use of ICT in health fields
  5. Dubai Government Protocol, Dubai Centre for Artificial Intelligence launches the AI Seal
  6. DLA Piper, data protection laws of the world, United Arab Emirates
  7. Morgan Lewis, UAE establishes Federal Authority for Artificial Intelligence and Data
  8. Clyde & Co, data protection and privacy in the Middle East

The Atlas letter

One leader added to the register, by name. One thing that changed in the rules. One number, with its geography on it.

Once a month. Atlas sends one email to confirm the address before adding it. Nothing arrives until that link is clicked.

Back to writing