Three Standards, One Country: What UAE and GCC AI Rules Actually Require

Three Standards, One Country: What UAE and GCC AI Rules Actually Require

A company, three standards

A bank headquartered in Dubai with a DIFC subsidiary, an ADGM entity and Saudi operations is subject to four different sets of rules on automated decision-making. They are not variations on a theme. They impose materially different obligations, and one of them has no enforcement regulations at all.

This is not a compliance footnote. It determines where a model can run, whether a decision can be made without a human, and what you have to be able to show a supervisor afterwards. Most AI programmes in the region are designed without anyone having read them.


1. The federal layer: a right to object, and a five-year gap

UAE Federal Decree-Law No. 45 of 2021 has been in force since 2 January 2022. Article 51 required Executive Regulations within six months.

As of September 2026 they have still not been issued.

The practical consequences are specific. There is no published adequacy list for cross-border transfers, because that list was to come through the regulations — so in practice most transfers run on the Article 23 contractual-safeguards or explicit-consent limbs. And the administrative penalty regime was deferred to a Cabinet decision that has not arrived, which is why enforcement to date has been, in the words of one practitioner guide, cautious.

On automated processing, Article 18 gives the data subject the right to object to decisions resulting from automated processing, including profiling, particularly where those decisions have legal effect or adversely affect them. Note the structure carefully: this is a right to object, not the general prohibition on solely automated decisions that GDPR Article 22 imposes. It is a weaker instrument, and it is disapplied where the processing is contractually agreed, legally required, or covered by prior written consent.

One institutional change is worth watching. On 14 June 2026 the UAE approved a Federal Artificial Intelligence and Data Authority, chaired by Omar Sultan Al Olama, consolidating the Office of AI, the UAE Data Office and TDRA’s digital government portfolio. Its published mandate is primarily federal-government-facing, and it should not be assumed to exercise direct enforcement powers over the private sector today. Whether folding in the Data Office finally unblocks the Executive Regulations is the open question of the next twelve months.

A warning, because it keeps appearing in board papers: there is no Dubai AI Act. Several sites asserting one are AI-generated content farms. The UAE has no general binding AI law. What it has is a voluntary Charter (June 2024, twelve principles), the National AI Strategy 2031, and the Dubai AI Seal verification scheme — all non-binding.


2. The financial sector: advisory in form, supervisory in effect

On 11 February 2026 the Central Bank of the UAE issued its Guidance Note on the Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions, announcing it publicly on 23 February.

It is written in should language and states that it supplements rather than replaces existing rules. That leads some institutions to file it as advisory. This is a mistake in judgement rather than in law: the Guidance Note interprets the Consumer Protection Standards, which are binding. It is, in practice, the yardstick a supervisor will use.

What it asks for:

  • Board accountability. Senior management and the board are responsible for AI systems and their outcomes. Not the vendor. Not the data science team.
  • Model inventory and periodic testing under the existing Model Management Standards — annually, or on every model upgrade.
  • Disclosure. Customers should be told when AI is used in high-impact decisions, and when they are interacting with an AI application rather than a person.
  • Graduated human oversight. Human-in-the-loop, human-on-the-loop and human-out-of-the-loop are all permitted — but full autonomy is confined to low-risk processes.
  • Third-party due diligence. Where an institution relies on a vendor or cloud provider, it must diligence that provider’s governance, security and data-protection practices, and secure audit rights including CBUAE access.

That last point is the one that reaches procurement. A contract that does not give your regulator a path to the vendor is a contract that will not survive review.

No effective date or compliance deadline is stated on the Rulebook entry. Treat that as a reason to move, not a reason to wait.


3. DIFC: the only purpose-built AI rules in the region

DIFC amended its Data Protection Regulations on 7 September 2023 to add Regulation 10, covering personal data processed through autonomous and semi-autonomous systems. It remains the most AI-specific binding instrument in the Gulf, and it is genuinely different in kind.

It creates two new roles. A Deployer authorises or benefits from the operation of the system and is accountable for how that system processes personal data. An Operator is a technical service provider acting on the Deployer’s instructions. It also contemplates an Autonomous Systems Officer, functionally parallel to a Data Protection Officer.

The obligations are design-level rather than paperwork-level. Systems must meet standards of fairness, ethical compliance, transparency, security of operation and accountability. Human-defined purposes must be hard-coded; where a system defines its own sub-purposes, those must sit inside human-established principles. Notice to individuals must be sufficient for them to assess the risk, and must tell them what they can and cannot control.

Regulation 10 contemplates certification requirements and enhanced obligations for high-risk systems, but no licences or registrations are currently mandated; the general certification guidance has been expected during 2026 and we have seen no evidence it has landed.

ADGM does not have an equivalent. Its Data Protection Regulations 2021 handle automated decision-making at section 22 in a straight GDPR Article 22 style: a right not to be subject to solely automated decisions with legal or similarly significant effects, with rights to human intervention, to express a view and to contest. Sound, familiar, and not AI-specific.

So inside one country: DIFC has purpose-built rules for autonomous systems, ADGM has GDPR-style automated-decision rights, and the federal regime has a narrower right to object with no enforcement regulations behind it. Where an entity sits determines what it must do.


4. Saudi Arabia: mature data law, no AI law, and an approval gate

Saudi Arabia is the mirror image of the UAE. Its PDPL (Royal Decree M/19, 2021, amended 2023) has been fully enforceable since 14 September 2024, and its secondary legislation exists — Implementing Regulations, transfer regulations reissued in September 2024, standard contractual clauses, binding common rules, DPO rules, controller registration. Transfers out of the Kingdom are restrictive by default and require a risk assessment.

On AI itself there is nothing binding. SDAIA has issued AI Ethics Principles (2023) and Generative AI Guidelines (2024), both explicitly non-obligatory. A draft Responsible AI Policy went to public consultation via Istitlaa, closing 3 May 2026, proposing a four-tier risk classification — critical, high, limited, low — with registration and audit duties for high-risk systems. We have found no evidence it has been adopted. Treat it as a consultation draft.

On residency, the common shorthand is wrong. People say data must stay in the Kingdom. What SAMA’s Rules on Outsourcing actually impose is an approval gate: written no-objection is required for material outsourcing, and separately for any outsourcing to a provider located overseas. SAMA’s stated concerns are customer confidentiality, access to customer data by foreign authorities, and preservation of its own right of access.

Blanket in-Kingdom hosting obligations do exist, but they come from the National Cybersecurity Authority’s Essential Cybersecurity Controls, and they bind government entities and critical national infrastructure — not every regulated firm. The CST Cloud Computing Regulatory Framework adds a content-classification regime in which Level 3 content may not leave the Kingdom absent specific permission.

The distinction matters commercially. Prohibited ends a conversation. Requires no-objection is a timeline and a document set.


5. The EU AI Act still reaches you — and its timeline changed in July

Any assessment written before August 2026 is now out of date. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and amended the phase-in.

  • Prohibited practices and AI literacy: in force since February 2025.
  • General-purpose model obligations: in force since August 2025.
  • Article 50 transparency obligations: in force since 2 August 2026. These proceeded as scheduled.
  • High-risk obligations for Annex III standalone systems: deferred to 2 December 2027.
  • High-risk obligations for Annex I products: deferred to 2 August 2028.

The headline for a Gulf audience is that the obligations which were deferred are the heavy ones, and the obligation that bit this year is disclosure.

On reach: Article 2(1)(c) catches providers and deployers located in a third country where the output produced by the AI system is used in the Union. A Gulf institution that never sells into Europe can still be in scope if its model’s outputs are consumed there — scoring or screening EU-resident customers, or decisions passed to an EU affiliate. Annex III covers biometrics, critical infrastructure, employment, education and creditworthiness, which is a near-overlap with the banking use cases the CBUAE note addresses.


What this means for how you build

Read together, these five regimes point to the same short list of architectural decisions — and they are decisions, not documents.

  1. Deployment locus is a compliance choice, not an infrastructure preference. If a workload may need to move in-country, or into an account you control, that has to be true of the platform on day one. It is not something you retrofit.
  2. Every consequential decision needs a traceable record — what the system saw, what it produced, who reviewed it. Regulation 10 asks for it by design; the CBUAE asks for it through model management; a supervisor will ask for it after the fact.
  3. Autonomy should be scoped deliberately. The CBUAE’s three tiers are a useful default even outside financial services: fully autonomous only where the downside is genuinely low.
  4. Vendor contracts have to carry regulator access. Audit rights, named sub-processors, and a training boundary written into the agreement rather than asserted in a sales deck.
  5. Where the entity sits changes the answer. A group with DIFC, ADGM, mainland and Saudi entities cannot run one AI governance policy and assume it covers everything.

None of this requires waiting for the UAE’s Executive Regulations, and we would not advise waiting. The direction across every instrument here is consistent: accountability at board level, traceability by construction, and a human wherever the decision matters.


Sources: CBUAE Rulebook, Guidance Note (issued 11 February 2026); UAE Federal Decree-Law No. 45 of 2021; Mayer Brown on DIFC Regulation 10 (January 2026); CMS AI Regulation Scanner, Saudi Arabia; White & Case on Regulation (EU) 2026/1744. This article is general information, not legal advice; positions change and should be confirmed with counsel before you rely on them.

Leave a Reply

Your email address will not be published. Required fields are marked *