There is no UAE AI Act. Companies searching for a single comprehensive law modelled on the EU AI Act will not find one, and none has been announced.
What exists is a layered regime. Federal data protection law under the PDPL applies to most AI processing personal data. Financial free zones operate independent legal systems with their own rules, including DIFC Regulation 10, the first AI-specific regulation in the wider Middle East, Africa, and South Asia region, which reached full enforcement on 1 January 2026. Abu Dhabi has a binding emirate-level AI council.
Sectoral regulators in financial services and healthcare impose their own requirements. Non-binding charters and strategy documents shape regulator expectations across all of it.
The practical consequence is that the same AI deployment can sit under different rules depending on whether it operates onshore in Dubai, in the DIFC, in ADGM, or onshore in Abu Dhabi. Compliance work in the UAE begins with a jurisdiction mapping exercise, not a gap analysis against a single statute.
Two dates matter. DIFC Regulation 10 has been fully enforceable since 1 January 2026. Full PDPL compliance is required by 1 January 2027.
Key Definitions
| Term | Definition |
|---|---|
| PDPL | Personal Data Protection Law. Federal Decree-Law No. 45 of 2021, in force since 2 January 2022 |
| DIFC | Dubai International Financial Centre. A financial free zone with its own legal system |
| ADGM | Abu Dhabi Global Market. A financial free zone with its own legal system |
| DIFC Regulation 10 | The DIFC regulation on autonomous and semi-autonomous systems, in full force since January 2026 |
| ADGM DPR 2021 | ADGM Data Protection Regulations 2021, broadly GDPR-aligned |
| AIATC | Artificial Intelligence and Advanced Technology Council. Abu Dhabi’s emirate-level AI body |
| UAE AI Charter | UAE Charter for the Development and Use of Artificial Intelligence, issued June 2024. Non-binding, twelve principles |
| AI Strategy 2031 | UAE National Strategy for Artificial Intelligence 2031, launched 2017 and updated 2023 |
| UAE Data Office | The federal body responsible for data protection policy |
| Onshore | UAE mainland, subject to federal law rather than free zone regimes |
| CBUAE | Central Bank of the UAE |
| DFSA | Dubai Financial Services Authority, the DIFC financial regulator |
| FSRA | Financial Services Regulatory Authority, the ADGM financial regulator |
Does the UAE Have an AI Act
No. The UAE has no single horizontal AI statute and none has been announced.
This is a deliberate policy choice rather than a gap awaiting legislation. The UAE appointed the world’s first Minister of State for Artificial Intelligence in 2017 and has consistently prioritised enabling AI adoption over constraining it. Binding rules are applied where a specific harm requires them rather than horizontally across all AI use.
The absence of an AI Act does not mean the absence of enforceable obligations. It means the obligations come from data protection law, free zone regulation, and sectoral supervision rather than from an AI-specific statute.
The Three Layers
| Layer | Instruments | Binding | Scope |
|---|---|---|---|
| Federal | PDPL (Federal Decree-Law 45/2021), Child Digital Safety Law, Federal Decree-Law 25/2018 | Yes | UAE mainland and extraterritorial for UAE residents’ data |
| Free zone | DIFC Data Protection Law No. 5 of 2020 and Regulation 10, ADGM DPR 2021 | Yes | Entities established in the respective free zone |
| Strategy, sectoral, and advisory | AI Strategy 2031, UAE AI Charter, International Stance on AI Policy, CBUAE, DFSA, FSRA, SCA, DHA, Abu Dhabi DoH guidance | Mixed | By sector and activity |
Determining which layers apply is the first compliance question and the one most often answered incorrectly. A company with a Dubai mainland trade licence, a DIFC subsidiary, and customers across the Emirates is subject to all three layers simultaneously, in different combinations for different activities.
Key Frameworks and Strategies
Three national instruments set the direction that binding rules operate within. None of them creates enforceable obligations directly. All three shape what regulators expect.
UAE National Strategy for Artificial Intelligence 2031
Launched in 2017 and updated in 2023, the Strategy is the national roadmap for integrating AI across healthcare, education, transport, mobility, energy, and government services. Its stated aim is to position the UAE as a global leader in AI by 2031.
The Strategy is a policy document rather than a legal instrument, but it matters for compliance in two ways. It explains why the UAE has resisted horizontal AI regulation: the policy objective is adoption, and a statute of the EU AI Act type is understood as working against that. And it identifies the priority sectors where sectoral regulation is most likely to arrive first, which is a useful signal for organisations planning multi-year deployments.
UAE Charter for the Development and Use of Artificial Intelligence
Issued in June 2024, the Charter sets out twelve principles covering safety, fairness, data privacy, transparency, human oversight, and accountability.
It is non-binding. Its practical function is to establish the vocabulary and expectations that regulators, sectoral supervisors, and government procurement apply when assessing AI deployments. An organisation whose AI governance documentation does not address the Charter’s principles will find itself explaining that omission in contexts where no legal obligation compelled it.
The Charter’s principles map closely onto the EU AI Act’s requirements around transparency, human oversight, and accountability. An organisation built to EU AI Act standards will satisfy the Charter comfortably.
UAE’s International Stance on Artificial Intelligence Policy
This document establishes the UAE’s guiding principles for international AI engagement, centred on ethics, safety, sustainability, and collaboration.
Its relevance to operational compliance is indirect but real. It signals the UAE’s intention to align with international norms rather than diverge from them, which reduces the likelihood of the UAE adopting requirements that conflict with EU, US, or Singapore frameworks. For multinational organisations, this makes the UAE a jurisdiction where a well-built global AI governance programme is likely to travel well.
Supporting Guidance
| Instrument | Issued | Function |
|---|---|---|
| AI Ethics Guide | December 2022, UAE AI Office | National framework for fairness, accountability, transparency, and explainability |
| AI Adoption Guideline in Government Services | 2023 | Practical manual for federal and local entities integrating AI, covering maturity models and risk assessments |
| Federal Decree-Law No. 25 of 2018 | 2018 | Enables interim licences and temporary exemptions for innovative projects in areas lacking regulation |
Federal Decree-Law No. 25 of 2018 deserves attention from AI developers specifically. It permits businesses developing innovative projects in areas without existing regulation to seek interim licences and temporary exemptions, enabling controlled research and development while formal regulation is drafted. This is the UAE’s equivalent of a regulatory sandbox and it is underused by foreign entrants.
DIFC Regulation 10: The Closest Thing to an AI Act
DIFC Regulation 10 is the most significant AI-specific development in the UAE. Introduced as an amendment to the DIFC Data Protection regime in late 2023, it reached full enforcement on 1 January 2026. It is the first AI-specific regulation in the MEASA region.
What It Covers
Regulation 10 sits inside DIFC Data Protection Law No. 5 of 2020 and imposes duties on entities deploying autonomous or semi-autonomous systems that process personal data. It applies to entities established in the DIFC, which given the free zone’s concentration of financial services firms means it principally affects financial sector AI.
The core obligations concern transparency about automated processing, human oversight of consequential decisions, accountability for outcomes, and the rights of individuals subject to autonomous decision-making. The structure is recognisably data protection law extended to address AI-specific concerns rather than a standalone AI regime.
Why It Matters Beyond the DIFC
Regulation 10 is the template other UAE jurisdictions are most likely to follow. It demonstrates that the UAE’s preferred route to AI regulation runs through data protection law rather than through a horizontal AI statute. Organisations expecting a UAE AI Act should instead expect further amendments to data protection regimes at federal and free zone level.
Federal Layer: The PDPL
Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law, is the UAE’s first federal data protection law. It came into force on 2 January 2022 and is modelled closely on the EU GDPR.
Where an AI system processes personal data of UAE residents, PDPL obligations apply. Its extraterritorial reach captures processing of UAE residents’ data outside the country, mirroring GDPR Article 3(2).
The Divergence That Catches People Out
Unlike GDPR, the PDPL does not recognise legitimate interests as a standalone lawful basis. Consent is the default.
This is a material difference for AI deployment. An organisation relying on legitimate interests to justify AI training on customer data under GDPR cannot transfer that reasoning to the UAE mainland. The lawful basis analysis has to be redone.
The January 2027 Deadline
Full PDPL compliance is required by 1 January 2027. The Executive Regulations needed for full enforcement were originally due in 2022 and their delayed publication has created uncertainty about operational detail, but the compliance deadline itself is fixed.
| Requirement | PDPL | EU GDPR |
|---|---|---|
| Legitimate interests as lawful basis | Not recognised | Article 6(1)(f) |
| Consent as default | Yes | One of six bases |
| Extraterritorial scope | Yes, for UAE residents’ data | Yes, Article 3(2) |
| Data subject rights | Access, rectification, erasure, restriction, portability, objection | Equivalent |
| Breach notification | Required | 72 hours, Article 33 |
| DPO requirement | Required in defined circumstances | Article 37 |
| Full compliance deadline | 1 January 2027 | In force since 2018 |
Free Zones: DIFC and ADGM
The financial free zones operate independent legal systems. Federal law does not apply within them for the matters they regulate.
| Feature | DIFC | ADGM |
|---|---|---|
| Data protection law | DIFC Data Protection Law No. 5 of 2020, amended 2023 | ADGM Data Protection Regulations 2021 |
| AI-specific regulation | Regulation 10, in force January 2026 | Addressed through DPR and FSRA guidance |
| Regulator | DIFC Commissioner of Data Protection | ADGM Office of Data Protection |
| Financial regulator | DFSA | FSRA |
| GDPR alignment | Broadly aligned | Broadly aligned |
| Legitimate interests | Recognised | Recognised |
Note the divergence on legitimate interests. The free zone regimes recognise it. The federal PDPL does not. An organisation operating across both mainland and free zone will have different lawful basis analyses for the same processing depending on which entity carries it out.
Abu Dhabi and the AIATC
Abu Dhabi operates its own emirate-level AI governance through the Artificial Intelligence and Advanced Technology Council. The AIATC has binding authority within Abu Dhabi and issues implementation guidance for AI deployment in the emirate.
This creates a fourth relevant jurisdiction alongside federal, DIFC, and ADGM. An organisation deploying AI in Abu Dhabi onshore is subject to federal law and AIATC oversight simultaneously.
Sectoral Regulation
Financial services is the most heavily regulated sector for AI in the UAE, with multiple regulators operating in parallel.
| Regulator | Jurisdiction | AI focus |
|---|---|---|
| CBUAE | Banking, payments, insurance | Model risk management, fairness in credit decisioning, generative AI in customer channels |
| SCA | Onshore securities and commodities | Algorithmic trading, robo-advice, AI-driven market surveillance |
| DFSA | DIFC-licensed financial firms | Fintech and innovation guidance covering AI use |
| FSRA | ADGM-licensed financial firms | Regulatory laboratory, AI deployment guidance, virtual asset framework |
Healthcare AI requires authorisation from the Abu Dhabi Department of Health or the Dubai Health Authority depending on where it is deployed. The Central Bank Law of 2025 embeds cybersecurity requirements into fintech AI regulation.
For regulated financial institutions, sectoral guidance operates as effectively binding through the supervisory relationship even where it is framed as guidance.
Governance Bodies: Who Enforces What
There is no single AI enforcement body in the UAE. Responsibility is distributed.
| Body | Level | Responsibility |
|---|---|---|
| UAE Data Office | Federal | Data protection policy and PDPL oversight |
| AI Office and AI Council | Federal | AI policy and strategy coordination |
| AIATC | Abu Dhabi | Emirate-level AI governance |
| DIFC Commissioner of Data Protection | DIFC | Data protection and Regulation 10 enforcement |
| ADGM Office of Data Protection | ADGM | Data protection enforcement |
| Sectoral regulators | Various | Sector-specific AI supervision |
For an organisation facing a compliance question, the first task is identifying which of these bodies has jurisdiction over the specific activity in the specific location.
UAE Compared to the EU AI Act
| Feature | UAE | EU |
|---|---|---|
| Horizontal AI statute | None | EU AI Act, Regulation (EU) 2024/1689 |
| AI-specific binding regulation | DIFC Regulation 10 only, free zone scope | Full framework, EU-wide |
| Risk classification | Not mandated | Mandatory under Article 6 |
| Prohibited practices | None in AI-specific law | Eight categories under Article 5 |
| Conformity assessment | Not required | Required for high-risk systems |
| Technical documentation | Not required as an AI obligation | Annex IV, mandatory |
| Human oversight | Charter principle, Regulation 10 within DIFC | Required by design under Article 14 |
| Data protection basis | PDPL, no legitimate interests | GDPR, six lawful bases |
| Penalties for AI-specific breach | Via data protection law | Up to €35m or 7% of worldwide turnover |
| Enforcement architecture | Distributed across federal, emirate, free zone | AI Office and national market surveillance authorities |
For organisations operating in both, the EU framework is the binding constraint. A system built to EU AI Act requirements will satisfy UAE expectations, with one exception: the PDPL’s rejection of legitimate interests requires a separate lawful basis analysis that EU compliance does not supply.
A Compliance Checklist for the UAE
| Step | Action |
|---|---|
| 1 | Map every entity and determine its jurisdiction: mainland, DIFC, ADGM, or Abu Dhabi onshore |
| 2 | Identify which AI systems each entity deploys and which jurisdiction’s rules govern them |
| 3 | For DIFC entities, gap-assess against Regulation 10 for autonomous and semi-autonomous systems |
| 4 | For mainland processing, redo the lawful basis analysis without legitimate interests |
| 5 | Confirm PDPL readiness against the 1 January 2027 deadline |
| 6 | For regulated financial entities, map CBUAE, SCA, DFSA, or FSRA guidance as applicable |
| 7 | For healthcare AI, confirm DoH Abu Dhabi or DHA authorisation requirements |
| 8 | Assess AI governance documentation against the twelve UAE AI Charter principles |
| 9 | For innovative deployments in unregulated areas, consider an interim licence under Federal Decree-Law 25/2018 |
| 10 | Reconcile with EU AI Act, GDPR, and other applicable frameworks where the organisation operates internationally |
FAQ
Is there a UAE AI Act?
Not at the moment. The UAE has not enacted a comprehensive AI law and none has been announced. AI is regulated through federal data protection law, free zone regulations, sectoral supervision, and non-binding charters and strategies.
What is DIFC Regulation 10?
The DIFC regulation on autonomous and semi-autonomous systems, sitting within the DIFC Data Protection regime. It imposes duties on entities deploying such systems where they process personal data. It reached full enforcement on 1 January 2026 and is the first AI-specific regulation in the MEASA region.
When is the PDPL compliance deadline?
Full compliance with Federal Decree-Law No. 45 of 2021 is required by 1 January 2027. The law itself came into force on 2 January 2022, but the Executive Regulations needed for full enforcement were delayed.
Does the PDPL recognise legitimate interests?
No. Unlike the GDPR, the PDPL does not recognise legitimate interests as a standalone lawful basis. Consent is the default. This is one of the most consequential divergences for AI deployment, because it means an organisation cannot transfer its GDPR legitimate interests reasoning to UAE mainland processing.
What is the UAE AI Charter?
The UAE Charter for the Development and Use of Artificial Intelligence, issued in June 2024. It sets out twelve principles covering safety, fairness, data privacy, transparency, human oversight, and accountability. It is non-binding but shapes regulator and procurement expectations.
What is the UAE National Strategy for AI 2031?
The national roadmap for AI adoption across healthcare, education, transport, energy, and government services, launched in 2017 and updated in 2023. It is a policy document rather than a legal instrument, but it explains the UAE’s regulatory posture and signals which sectors will see binding rules first.
Which body enforces AI regulation in the UAE?
There is no single enforcement body. The UAE Data Office handles federal data protection, the AI Office and AI Council handle policy, the AIATC governs Abu Dhabi, the DIFC Commissioner of Data Protection enforces within the DIFC, the ADGM Office of Data Protection enforces within ADGM, and sectoral regulators supervise their sectors.
Do the free zones follow federal law?
No, not for the matters they regulate. The DIFC and ADGM operate independent legal systems with their own data protection regimes. This produces genuine divergence: the free zone regimes recognise legitimate interests as a lawful basis, and the federal PDPL does not.
Does the EU AI Act apply to UAE companies?
Yes, where a UAE company places an AI system on the EU market, puts it into service in the EU, or where the output of the system is used in the EU. The AI Act applies extraterritorially under Article 2(1). UAE establishment does not remove a company from its scope, and non-EU providers of high-risk AI systems or GPAI models must appoint an EU-established authorised representative.
Can we test AI in the UAE before regulation arrives?
Yes. Federal Decree-Law No. 25 of 2018 permits businesses developing innovative projects in areas lacking existing regulation to seek interim licences and temporary exemptions. This enables controlled development while formal regulation is drafted and is underused by foreign entrants.
Will the UAE enact an AI Act?
There is no announced legislative programme for a horizontal AI statute. The pattern established by DIFC Regulation 10 suggests the more likely route is further AI-specific amendments to data protection regimes at federal and free zone level, rather than a standalone AI law.
Disclaimer
This guide reflects UAE federal law, DIFC and ADGM regulations, and applicable strategy and charter documents as at September 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations deploying AI in the UAE should obtain advice specific to their entity structure, jurisdictions of operation, and sector.