AI Compliance · Middle East

Dubai already has binding AI rules. Most firms working there have never read them.

The Gulf is usually described as having no AI law. For the Dubai International Financial Centre that is simply wrong, and has been for years: Regulation 10 of the DIFC Data Protection Regulations governs personal data processed through autonomous and semi-autonomous systems, and it binds.

What makes it bite for ordinary firms is who it names. The duty falls on the deployer — the business operating the system or getting the benefit of it — whether or not that business built the tool, hosts it, or controls what it does. Buying software off the shelf does not move the obligation to the vendor.

Across the wider UAE there is no single AI statute. Personal data is governed federally, and Abu Dhabi Global Market and the DIFC each run their own regime, so where you are registered decides which rules you are under.

What actually governs AI in United Arab Emirates and Dubai International Financial Centre.

No summaries of summaries. Each of these was read at the publisher's own site, and the obligation is stated as the thing you have to do rather than the clause it comes from.

United Arab Emirates

The law

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, which is in force. There is no federal AI statute.

What you have to do

Handle personal data lawfully across the whole business, and know which of the country's regimes you sit under — the federal law, the DIFC or ADGM — because they are not the same and registration decides it.

Dubai International Financial Centre

The law

DIFC Data Protection Regulation 10, on personal data processed through autonomous and semi-autonomous systems.

What you have to do

Tell people, on first use, that they are dealing with a system that acts on its own — what it was built to do, where it is allowed to decide things for itself, what it produces and what you do with the output. High-risk uses need an Autonomous Systems Officer and certification under the Commissioner's framework.

14 dates that decide whether you are compliant.
8 of them have already passed.

United Arab Emirates is one line of 6. Yours is marked, and it is the oldest line on this chart — the DIFC was binding while most of Europe was still consulting. If you also have customers or staff elsewhere, you are on more than one of these.

Europe

  • in force Obligations for general-purpose AI models.
  • in force Article 50 transparency duties, deployer obligations, and enforcement powers for national regulators.
  • coming New prohibitions, and Article 50(2) marking of synthetic content.
  • coming Every Member State must have an AI regulatory sandbox running.
  • coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
  • coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.

United Kingdom

  • in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
  • in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.

United States

  • in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
  • in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
  • coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect.

Canada

  • in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.

Australia

  • coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are.

United Arab Emirates this page

  • in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.

Does this apply to you?

Most firms read a page like this and conclude it is about somebody bigger. These are the three things that decide it, and the first one catches almost everybody.

  1. You are registered in the DIFC and run anything that answers customers, screens applicants or scores risk.
  2. You bought the system in. Regulation 10 names the deployer, not just the developer.
  3. Your customer-facing notices describe your data handling but say nothing about what the system decides on its own.

What we would do about it.

We build AI compliance frameworks — the policy, the register of where AI touches your business, the record that shows a regulator you thought about it before something went wrong. Fixed price, plain English, written for a business owner rather than a lawyer.

We sell fixed-price frameworks off the shelf for the UK, the EU, the US and Canada. Middle East is not one of them yet, so this starts as a conversation rather than a checkout: tell us where your people and your customers are, and we will tell you honestly which of these obligations reaches you and what it takes to meet them. If the answer is that you are covered by a framework we already build, we will say so.

Find out where you stand in Middle East.

A free call, no pitch deck. We will tell you which of the obligations above reach your business and which do not — including if the answer is none of them.

Call Now Claim Your Free Audit