The UAE has no single AI statute, and reading that as "no AI regulation" is the mistake that costs a board its next examination. What the UAE has is a layered regime, and two of its layers moved within the last eight months.
DIFC Regulation 10 reached full enforcement on 1 January 2026. The CBUAE issued its guidance note on artificial intelligence and machine learning on 23 February 2026. An institution operating in both onshore UAE and the DIFC is now answering to two different instruments with two different characters, one binding and one supervisory, and the governance record has to satisfy both.
Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.
There is no unified federal AI act in the UAE, and no announced date for one. Anyone selling readiness for a UAE AI law is selling something that does not exist, which is the same error as selling AIDA readiness in Canada. The exposure that is real comes from Regulation 10 inside the DIFC, the CBUAE’s supervisory expectations for licensed financial institutions, the federal PDPL, and the extraterritorial reach of the EU AI Act wherever output touches Europe.
Yes. It was enacted on 1 September 2023 as part of the updated DIFC Data Protection Regulations, and moved to full enforcement on 1 January 2026. It applies to personal data processed through autonomous and semi-autonomous systems, which in practice means most operational AI. The requirements that create work are the register of AI systems, the notices, the certification of systems, and the appointment of an Autonomous Systems Officer where processing is high risk. The register is the item most firms underestimate, for the same reason model inventories are underestimated everywhere: the model is not the only thing that changes, and a register blind to prompt, retrieval corpus and routing policy describes a system that no longer exists.
It was issued on 23 February 2026 to all licensed financial institutions, on consumer protection and the responsible adoption of artificial intelligence and machine learning. It sets supervisory expectations across governance and accountability, fairness and non-discrimination, transparency and explainability, data quality and privacy, continuous monitoring, human oversight, integration with existing risk frameworks, and third-party and outsourcing risk. Where an AI system drives a high-impact decision it expects meaningful human oversight and a review mechanism the customer can actually use. It is not legally binding, and that is the point most often misread: a guidance note tells you what the supervisor will ask about at the next examination.
No. There is no unified federal AI act, and no announced timetable for one. The UAE governs AI through a layered regime instead: the federal Personal Data Protection Law, free-zone instruments such as DIFC Regulation 10 and the separate ADGM regime, sectoral supervision such as the CBUAE guidance note, and the UAE Charter for the Development and Use of AI from June 2024 as a statement of principle. Being precise about this matters, because a governance programme designed against an imaginary statute will be aimed at the wrong evidence.
You are inside two rulebooks with different characters, and the honest answer is that the operating model has to satisfy the stricter of the two per control rather than be maintained twice. Regulation 10 is binding inside the DIFC and carries specific artefacts, the register, the notices, the certification and the Autonomous Systems Officer. The CBUAE note is supervisory and applies to your licensed activity. The federal PDPL sits underneath both. A single control plane that produces the evidence once, tagged by which instrument it answers to, is cheaper than two governance functions and is also the only version that survives a group-level examination.
Independent assessment and architecture, not a compliance filing. The Teardown scores the estate against the four MESA layers and produces a board-ready reading of where you actually are, which is the input to a Regulation 10 or CBUAE programme rather than a substitute for one. The other half is architecture: governance the platform enforces at runtime, because an AI register maintained by hand is stale by the next deployment. Engagements are taken personally rather than staffed to a bench, and the published book on Middle East AI governance is the method written down.
Governance an examiner can follow, in the jurisdiction that actually binds you.