DIFC Regulation 10 Enforcement Reshapes AI Compliance
For years, AI governance in the Middle East was largely a story of ambition — national strategies, ethics principles, and framework consultations that set direction without yet imposing hard obligations. That period is over. Across the UAE, Saudi Arabia, and Qatar, the regulatory architecture has sh
Middle East AI Compliance Enters Enforcement Phase: What Professional Services Must Do Now
For years, AI governance in the Middle East was largely a story of ambition — national strategies, ethics principles, and framework consultations that set direction without yet imposing hard obligations. That period is over. Across the UAE, Saudi Arabia, and Qatar, the regulatory architecture has shifted decisively towards enforcement, supervisory action, and binding legal requirements. For international professional services businesses and global enterprises operating in or with these markets, the window for preparation is closing fast.
The UAE: Consolidation and Sector-Specific Enforcement
The UAE's regulatory approach has never relied on a single horizontal AI statute, and that remains the case. What is changing is the coherence of oversight. From 14 June 2026, a new Cabinet-level body — the Federal Authority for Artificial Intelligence and Data — will consolidate the federal AI Office, the Telecommunications and Digital Government Regulatory Authority's digital-government functions, and the Emirates Data Office into a single regulatory entity. For businesses accustomed to navigating multiple federal touchpoints on AI and data matters, this consolidation is a meaningful structural improvement, though it does not eliminate the layered complexity that characterises the UAE's regulatory environment.
More immediately pressing for firms operating within the Dubai International Financial Centre is the full enforcement of DIFC Regulation 10 from January 2026. This regulation — one of the first AI-specific frameworks in the broader MEASA region — imposes direct obligations on organisations deploying AI systems that process personal data within the free zone. Compliance is not optional, and the DIFC's active supervisory posture means that gap assessments, documentation, and operational controls need to be in place now, not in response to a supervisory enquiry.
For licensed financial institutions, the Central Bank of the UAE issued a Guidance Note on AI and machine learning in February 2026, addressing governance structures, bias testing, transparency obligations, and requirements for meaningful human oversight. Firms in the financial sector face compounding obligations across both entity-level and sectoral frameworks, requiring a coordinated compliance approach rather than siloed responses.
Saudi Arabia: Enforcement Is Already Under Way
Saudi Arabia's trajectory is the clearest indicator of what regional AI compliance maturation looks like in practice. The Personal Data Protection Law (PDPL) became fully enforceable on 14 September 2024, and SDAIA — the Saudi Data and Artificial Intelligence Authority — has not treated that date as a formality. By January 2026, SDAIA had confirmed 48 decisions finding PDPL violations, a figure that signals active supervisory engagement rather than a grace-period approach.
The financial exposure is real. Penalties can reach SAR 5 million per violation, with the potential to double for repeat infringements. Certain categories of sensitive data disclosure carry criminal liability. For international businesses processing personal data belonging to Saudi citizens or residents — which includes a significant proportion of professional services activity — these are not theoretical risks.
There is also a notable development on the AI development side. A new copyright law, effective 12 August 2026, permits the reproduction of lawfully published works for AI training and development purposes, without requiring individual author permission, subject to defined limits on source and purpose. This positions Saudi Arabia as an early regional adopter of text-and-data-mining exceptions comparable to those seen in the EU's AI Act ecosystem. For businesses developing or fine-tuning AI models using content derived from Saudi sources, understanding the scope of this exception — and its boundaries — will be legally consequential.
Qatar: Binding Financial Sector Rules and a Phased Cross-Sector Approach
Qatar has pursued a sector-led model, beginning with financial services before extending governance principles more broadly. The Qatar Central Bank's AI Guidelines became legally binding for all licensed financial institutions in September 2024, requiring institutions to establish documented AI strategies, conduct formal risk assessments, disclose AI usage appropriately, and seek approval before deploying high-risk AI systems. The binding nature of these requirements is not incidental — the QCB has made clear that AI governance is a supervisory expectation, not a recommendation.
Alongside this, the Qatar Financial Markets Authority published draft AI regulations in May 2025 targeting capital markets participants, with transparency, accountability, and data protection as core pillars. Combined with the National Cyber Security Agency's guidelines on secure AI adoption and the Ministry of Communications and Information Technology's ethical AI principles, Qatar's governance landscape is layered even within a structured phased timeline. Cross-sector harmonisation is expected through 2026 and 2027, meaning the current period represents both the establishment of hard obligations and the anticipation of further requirements to follow.
What This Means for International Businesses
The combined picture across these three jurisdictions presents a clear operational reality: AI compliance in the Middle East now demands the same rigour applied to data protection obligations in Europe or financial regulation in the UK and US. Several implications follow directly.
Regulatory mapping is no longer optional. Businesses with AI deployments touching UAE free zones, Saudi data subjects, or Qatari financial services clients face obligations under distinct frameworks that do not fully align with one another. Organisations need a clear, jurisdiction-specific map of which AI systems fall under which requirements — and that map needs to be kept current as new regulations come into force.
Enforcement timelines are immediate. Saudi Arabia's PDPL is already generating formal violation decisions. DIFC Regulation 10 is in full force. The QCB's AI guidelines have been binding since late 2024. The CBUAE's guidance note was issued in February 2026. Businesses that are still treating Middle East AI compliance as a horizon issue are already behind.
Documentation and governance architecture matter. Across all three jurisdictions, regulators are looking for evidence of structured AI governance: risk assessments, disclosure frameworks, bias testing records, human oversight mechanisms, and defined accountability. These are not merely procedural requirements — they are the substance of what supervisors will examine. Absence of documentation is itself a compliance failure.
The copyright and data training dimension is emerging. Saudi Arabia's text-and-data-mining exception creates a specific legal basis for AI development activity, but one with defined conditions. Businesses developing AI systems that draw on regional content sources need legal clarity on whether their activity falls within or outside that exception, and what obligations apply in either case.
Convergence with global frameworks is incomplete. The Middle East regulatory picture does not simply mirror the EU AI Act or comparable global instruments. Businesses that have invested in EU AI Act compliance should not assume that framework transfers cleanly to Gulf jurisdictions. Local specificity — particularly around free zone structures, sector-specific regulators, and PDPL obligations — requires dedicated attention.
Act Now, Not Later
The Middle East AI compliance environment has entered its enforcement phase. The structural signals — a new federal regulator in the UAE, active SDAIA enforcement in Saudi Arabia, binding QCB obligations in Qatar — point in one direction. Organisations that are still assessing rather than acting carry both legal and reputational risk.
Ops Intel works with international professional services businesses and global enterprises to navigate AI compliance obligations across multiple jurisdictions, including the UAE, Saudi Arabia, and Qatar. If your organisation needs a clear-eyed assessment of your current exposure or a structured plan to achieve compliance across these markets, speak to our team today.
Work with Ops Intel
Need help navigating AI compliance?
We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.