# UAE AI regulation for businesses: what you must do

> Source: <https://dev.to/azrty/uae-ai-regulation-for-businesses-what-you-must-do-3c2h>
> Published: 2026-10-07 05:07:27+00:00

The UAE has no single AI law, so business owners are left juggling the PDPL, DIFC Regulation 10, ADGM rules and sector regulators. This cuts the stack down to what a mainland or free zone SME must do before the 2027 compliance dates: know where personal data goes when staff use AI, document it, and keep a person accountable. You finish with a one-page checklist and a clear split between what needs a lawyer and what needs an IT decision.

UAE AI regulation for businesses is not a single federal statute. Instead, it is a stack of data protection laws and sector rules: the federal Personal Data Protection Law (PDPL) for mainland companies, dedicated regimes such as DIFC Regulation 10 and ADGM rules in financial free zones, and oversight from sector regulators. For any business deploying AI in the UAE, compliance comes down to three operational duties: inventorying every AI system, mapping and minimising personal data flows before prompts leave your boundary, and keeping a named human accountable for decisions that affect people.

Two things moved this year. Neither created a new compliance obligation on its own.

On 14 June 2026, Sheikh Mohammed bin Rashid approved the establishment of the Artificial Intelligence and Data Authority, a single body reporting directly to the Cabinet and chaired by Omar Sultan Al Olama. It merges three existing bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector within TDRA, and the UAE Data Office. Its mandate includes "proposing national public policies, legislation and strategies" and "setting standards and guidelines for data and AI management" ([Emirates News Agency, 14 June 2026](https://www.wam.ae/en/article/c0pz7ku-mohammed-bin-rashid-approves-establishing)). Creating an institutional authority is not the same as promulgating binding law, so treat it as a signal of regulatory direction, not as immediate new compliance obligations ([Legal500, on the AI and Data Authority](https://www.legal500.com/intelligence/united-arab-emirates/strategy/the-uae-artificial-intelligence-and-data-authority-what-it-means-for-ai-data-and-digital-governance)).

Second, DIFC's AI-specific machinery went live. [Regulation 10 on autonomous and semi-autonomous systems](https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection/regulation-10) has sat inside the DIFC Data Protection Regulations since they were enacted on 1 September 2023. What is new is that the Commissioner's portal now runs a Regulation 10 certification application, supported by an accreditation framework and three approved certification bodies (Middle East Privacy, Mission+, and Brave Governance, White Label Consultancy). If you are a DIFC entity running a high-risk AI system, certification is no longer a future concept. It is a form you can submit.

What did not change: the PDPL's Executive Regulations are still not published. The decree asked for them within six months of promulgation (Article 28). [DLA Piper's data protection tracker](https://www.dlapiperdataprotection.com/countries/uae-general/law.html) records that they had not appeared as of 6 January 2025; Legal500's 2026 analysis confirms they are still outstanding. Everything below therefore has a hard edge (the decree is in force) and a soft edge (the detailed procedures and penalty schedule the Executive Regulations will fill in).

Your obligations depend on where your legal entity is registered and whose data you process. The PDPL explicitly steps aside for "companies and establishments located in free zones in the Country and have special legislations regarding Personal Data protection" (Article 2(2)(g) of [Federal Decree-Law No. 45 of 2021](https://uaelegislation.gov.ae/en/legislations/1972/download)), which is why a mainland company and a DIFC company on the same street answer to different law.

|  | Mainland UAE (PDPL) | DIFC | ADGM | Sector overlays | 
|---|---|---|---|---|
| Instrument | Federal Decree-Law No. 45 of 2021, in force 2 January 2022 | DIFC Data Protection Law 2020 plus Regulation 10 (enacted 1 September 2023) | Data Protection Regulations 2021 | CBUAE consumer protection rules, ICT in Health Fields Law, DFSA and FSRA guidance | 
| Lawful bases | Consent is the rule, with 10 enumerated exceptions (Article 4). No GDPR-style "legitimate interests" basis | GDPR-style menu, including legitimate interests | Six GDPR-style bases, including legitimate interests | Sector rules add duties on top | 
| Automated decisions | Right to object to automated decisions with legal or adverse effect; exceptions for contract, law or prior consent; human review on request (Article 18) | Plus Regulation 10 notice at first use, design principles, and human-defined purposes | Right not to be subject to solely automated decisions, with human intervention safeguards ( [ADGM Rulebook, section 20](https://en.adgm.thomsonreuters.com/rulebook/20-automated-individual-decision-making-including-profiling) ) | Explainability, validation and audit trails for regulated models | 
| AI-specific duties | None beyond data protection duties that AI happens to trigger | Yes: Regulation 10, with certification and an Autonomous Systems Officer (ASO) for High Risk Processing | None specific; general duties apply | Model risk management expectations | 
| Records and people | Record of Personal Data (Article 7(4)); DPO in defined cases (Article 10) | DPO rules plus ASO for High Risk Processing | DPO where high risk | Designated senior accountability (CBUAE standards) | 
| Cross-border | Adequacy or contractual safeguards, explicit consent as a fallback (Articles 22 to 23) | DIFC transfer mechanism and adequacy list | Standard contractual clauses and an adequacy list that broadly tracks the EU's | Health data may not leave the UAE except in permitted cases | 
| Who enforces | The federal data regulator (functions to be absorbed into the new Authority) | Commissioner of Data Protection | ADGM Office of Data Protection | Your sector supervisor | 

If you hold entities in more than one zone, you satisfy all applicable regimes at once. An intra-group transfer between a mainland entity and a DIFC entity should be papered like any other transfer.

You will see "full PDPL compliance by 1 January 2027" in several 2026 guides, for example [WCR Legal's UAE AI regulation guide](https://wcr.legal/uae-ai-regulation-2026-compliance-guide/). Read the decree instead. Article 28 says the Executive Regulations were to be issued within six months of promulgation. Article 29 says controllers and processors "shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months as of the date on which its Executive Regulations are issued", with the Cabinet able to extend that by a similar period. The compliance clock starts when the Executive Regulations land, not on a fixed calendar date.

So where does 1 January 2027 come from? Two plausible sources. First, wishful rounding of a deadline that has not been set. Second, a real date from a different law: the Child Digital Safety Law (Federal Decree-Law No. 26 of 2025) took effect on 1 January 2026 with a one-year transition, so full compliance falls on 1 January 2027 ([AI Law Guide, 2026](https://ailawguide.org/blog/uae-artificial-intelligence-regulations-explained-2026-guide-3840828626886645338)). That one bites if your service is likely to be accessed by under 18s: age verification, content filtering, parental controls, and no behavioural profiling of children for marketing.

Three practical conclusions:

Strip the technology out and an AI system is just processing. Here is where the decree bites.

**Lawful basis and purpose (Articles 4 and 5).** Processing without consent is prohibited unless one of 10 exceptions applies, including performance of a contract, steps taken at the request of the data subject, employment obligations, legal claims and public interest. There is no legitimate interests safety valve. The practical effect on AI: reusing a support mailbox to fine-tune a sales model is a new purpose and needs its own basis. Purpose limitation and data minimisation (Article 5) decide whether your agent may read a full customer file at all.

**The record (Article 7(4)).** Controllers must maintain a "special record for Personal Data" covering categories of data, who is authorised to access it, processing times and scope, the erasure mechanism, purposes, "any data related to the cross-border movement and processing of such data", and the security measures. It must be produced to the regulator on request. This is your record of processing activities, and for AI it doubles as your use case register.

**Automated decisions (Articles 13 and 18).** A data subject can ask what "decisions made based on automated processing, including profiling" were made about them (Article 13(1)(c)), and can object to automated decisions with legal impact or adverse effect (Article 18(1)). The objection right does not apply where the processing is agreed in the contract, required by law, or consented to in advance (Article 18(2)), but the controller must still protect the person's rights. Article 18(4) is the sentence every AI team should memorise: the controller "shall include the human element in reviewing automated processing decisions at the request of the Data Subject." Human-in-the-loop is not good practice here. It is what you owe on request.

**Impact assessment (Article 21).** You must evaluate the impact of proposed processing before you start when you use "any of the modern technologies that would pose a high risk to the privacy and confidentiality of the Data Subject". It is mandatory in two cases: a systematic and comprehensive assessment of a person's characteristics using automated processing including profiling, where that has legal consequences or serious impact; and processing large volumes of Sensitive Personal Data. Article 21(3) lists the minimum contents, Article 21(4) lets you group similar processing into one assessment, and Article 21(5) says coordinate with the DPO.

**The DPO (Article 10).** Appoint one where processing creates high risk because of new technology or data volume, where processing involves a systematic and comprehensive assessment of Sensitive Personal Data including profiling, or where you process large volumes of Sensitive Personal Data (health, biometrics, religion, ethnicity, criminal record). The DPO can be an employee or external, and can sit inside or outside the UAE (Article 10(2)); you must give the regulator the contact details (Article 10(3)).

**Transfers (Articles 22 and 23).** Sending a prompt containing personal data to a model endpoint abroad is cross-border processing. You need either an adequate destination as approved by the regulator, or one of the Article 23 fallbacks: a contract binding the recipient to PDPL-equivalent measures, or explicit consent that does not contradict public or security interests. Health data is governed by its own statute, which restricts storing, processing or transferring health information outside the UAE except in permitted cases ([DLA Piper summary](https://www.dlapiperdataprotection.com/countries/uae-general/law.html)). Assume an LLM API call carrying clinical or claims data is in scope.

The scenario: a Dubai mainland trading company, 40 staff, no free zone entity. Three AI systems in production or near production: (1) a customer support assistant on a hosted LLM API that reads inbound email and CRM history and drafts replies; (2) a CV screening agent that ranks job applicants for two roles a quarter; (3) an invoice extraction agent feeding the ERP. Separately, staff use personal ChatGPT and Copilot accounts on work data. Here is the sequence, with realistic effort figures (our planning estimates for a first pass, not quotes).

| Step | Action | Trigger in the decree | Effort | Output | 
|---|---|---|---|---|
| 1 | Stop ungoverned use and inventory everything | Article 7(4) record | 1 to 2 person-days | Register of 3 systems plus 2 unapproved tools found in use | 
| 2 | Map data flows per system: fields sent, destination, retention | Articles 5 and 22 to 23 | 2 to 3 person-days | One flow table per system | 
| 3 | Assign a lawful basis per purpose | Article 4 | 1 person-day plus legal review | Basis per purpose, documented | 
| 4 | Run DPIAs | Article 21 | 2 to 3 person-days | 1 full DPIA (CV screening), 1 grouped light assessment | 
| 5 | Engineer human review and objection handling | Article 18 | 2 to 4 person-days | Rank-only agent, reviewer log, objection workflow | 
| 6 | Decide on a DPO and notify the regulator | Article 10 | 0.5 person-day | Appointment letter, contact details filed | 
| 7 | Fix the transfer position | Articles 22 to 23 | 2 to 5 person-days | Contract addendum or regional routing change | 

Step 1 in detail: the support assistant and the invoice agent are on the register. So are two findings nobody wanted: an intern using a personal ChatGPT account for supplier emails, and a sales manager uploading a customer spreadsheet to an online summariser. Both are stopped the same day, with a one-page interim rule: use only approved tools, never paste identity documents or health information, and never use customer data in free consumer tiers.

Step 2 in detail, for the support assistant alone:

| Agent step | Data involved | Transfer risk | Safer design | 
|---|---|---|---|
| Email intake | Name, email, phone, order history | Personal data enters the workflow | Allowlist fields; drop signatures and attachments | 
| LLM API call | Prompt with order context | Processing outside the UAE | Enterprise agreement with transfer clause, or UAE region endpoint | 
| Draft reply | Order status, apology text | Low | Human sends, never auto-send | 
| Logging | Prompt and response | Logs become a shadow CRM | Redact identifiers, set a 30-day retention | 

Step 3: the support assistant runs on contract performance (Article 4(9)). CV screening runs on steps at the request of the applicant to conclude a contract, plus employment obligations (Articles 4(8) and 4(9)). Invoice extraction runs on legal obligation for the tax data and contract for the rest. The moment anyone proposes reusing support transcripts to train a new model, that is a new purpose and it comes back here.

Step 4: the CV screening agent is a systematic, automated assessment of people that decides who reaches an interview. That has serious impact, so the DPIA is mandatory under Article 21(2)(a). The support and invoice agents get one grouped light assessment under Article 21(4), because their processing is similar and lower risk.

Step 5: the screening agent is configured to rank only and never to reject. The rejection button lives in the recruiter's screen, and the reviewer identity is stored with each decision. An applicant who objects triggers Article 18(4): a named human re-reviews with the model output as commentary only. Set your own service level, for example acknowledge within 7 days and resolve within 30, since the decree sets no response clock for objections.

Step 6: the screening agent routinely ingests CVs, and CVs routinely leak Sensitive Personal Data (a photo, a disability note, a career gap explained by illness). Treat that as a systematic assessment of Sensitive Personal Data and appoint a DPO under Article 10(1)(b). An external DPO is expressly permitted. File the contact details with the regulator.

Step 7: the support assistant's API endpoint sits outside the UAE. Either paper the transfer under Article 23(1)(a) with an enterprise agreement binding the provider to PDPL-equivalent measures and no training on your data, or move the workload to a UAE region or a self-hosted model. For anything health-related, assume the answer is "do not send it abroad".

Total: roughly 10 to 15 person-days of internal work, one legal review of the basis and transfer position, and two architecture decisions (log redaction and endpoint routing). That is the whole of the core job for an SME of this size.

Documentation is not enough. Three engineering controls do most of the compliance work.

**1. A machine-readable AI register.** One entry per system, kept in Git next to the code, so the Article 7(4) record regenerates from reality:

```
system: cv-screening-agent
owner: head-of-talent
data_controller: example-trading-llc
purposes:
  - purpose: rank applicants for open roles
    lawful_basis: article_4_9_contract_steps   # PDPL Art. 4(9)
data_categories: [name, email, employment_history, cv_text]
sensitive_data_incidental: true                # photos, health notes in CVs
profiling: true
automated_decision: rank_only_no_reject        # PDPL Art. 18
human_review: required
dpia: dpia-2026-002.md                         # PDPL Art. 21(2)(a)
dpo: external-dpo@example.com                  # PDPL Art. 10
transfers:
  - destination: llm-api-us-east
    mechanism: article_23_1_a_contract_clause
log_retention_days: 30
```

**2. Pre-flight minimisation before any model call.** Strip what the task does not need, and mask identity patterns, before data leaves your boundary:

``` python
import re

ALLOWLIST = {"order_id", "status", "amount", "query"}   # PDPL Art. 5(3)
EMIRATES_ID = re.compile(r"\b\d{3}-\d{4}-\d{7}-\d\b")

def prepare_prompt(record: dict, query: str) -> str:
    kept = {k: record[k] for k in ALLOWLIST if k in record}
    body = "\n".join(f"{k}: {v}" for k, v in kept.items())
    body = EMIRATES_ID.sub("[REDACTED-ID]", body)         # run the same over logs
    return f"{body}\nQuery: {query}"
```

**3. One gateway, one policy.** The Article 22 to 23 question ("where does personal data go?") is unanswerable if staff pick their own model endpoints. Route every model call through a single gateway you control, so approved providers, regions and budgets live in one place. This is exactly the job our [FastLLM Proxy](https://www.azrty.com/software/fastllm-proxy) does: an OpenAI-compatible gateway in front of your own model servers and hosted providers, with routing, budgets and access control in one place.

Now the split you were promised. Which decisions are legal and which are technical?

| Decision | Owner | Why | 
|---|---|---|
| Whether a stated purpose and lawful basis is defensible | Lawyer | Turns on Article 4 exceptions and contract wording | 
| Whether a workflow is "systematic assessment with serious impact" (DPIA mandatory) | Lawyer plus IT | Legal characterisation, technical facts | 
| Whether to appoint a DPO, and whether one person covers several entities | Lawyer | Article 10 thresholds, organisational fit | 
| Transfer mechanism wording for a vendor agreement | Lawyer | Articles 22 to 23 and vendor risk | 
| Which fields reach the model, and log redaction | IT | Architecture and code | 
| Endpoint routing, region choice, self-hosting | IT | Architecture and cost | 
| Human-in-the-loop design and reviewer logging | IT, with legal sign-off | Implements Article 18 | 
| Whether an AI use case goes live at all | Business owner | Risk appetite and the register entry | 

Print this. Twelve items, each with an owner and the evidence you keep.

If you do only one thing this week, do item 1 and item 2 together: get the register, and stop the ungoverned tool use. Everything else becomes easy once you know what you are running and can see where personal data goes.

Then pick your deadline. For most mainland SMEs the honest answer is "finish by 1 January 2027", because that is the date your board has already heard, the Child Digital Safety transition ends then, and the PDPL clock (six months from the Executive Regulations) could land inside that window. If you are in DIFC and running a High Risk Processing system, your deadline is now: Regulation 10 certification and an Autonomous Systems Officer are live questions, not future ones.

When you want the assessment done properly, that is the work we do in [AI strategy and readiness](https://www.azrty.com/services/ai-strategy): we look at how your business runs, from processes and systems to data, then tell you plainly where AI will pay off, what it takes and what to do first. A compliance register and an AI roadmap turn out to be the same document, written once.

This article is general information, not legal advice. Have qualified UAE counsel confirm your lawful basis, transfer position and free zone status before you rely on any of it.

*Originally published on [Azrty](https://www.azrty.com/blog/uae-ai-regulation-for-businesses-what-you-must-do).*
