§ 01UAE

UAE

AI governance under DIFC Regulation 10 and the CBUAE guidance note

The UAE has no single AI statute, and reading that as "no AI regulation" is the mistake that costs a board its next examination. What the UAE has is a layered regime, and two of its layers moved within the last eight months.

DIFC Regulation 10 reached full enforcement on 1 January 2026. The CBUAE issued its guidance note on artificial intelligence and machine learning on 23 February 2026. An institution operating in both onshore UAE and the DIFC is now answering to two different instruments with two different characters, one binding and one supervisory, and the governance record has to satisfy both.

Written by Nabeel Khan, author of AI Governance & Compliance Frameworks for the Middle East · seven years in Kuwait government, the Council of Ministers and the Ministry of Planning · author of the MESA Framework · engagements are taken personally through iSystematic, not staffed to a bench
§ 02What applies

What is actually in force.

Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.

1 Jan 2026
DIFC Regulation 10, autonomous and semi-autonomous systemsEnacted 1 September 2023 with the updated DIFC Data Protection Regulations and in full enforcement since 1 January 2026. It governs personal data processed by autonomous and semi-autonomous systems on principles of ethics, fairness, transparency, security and accountability. The operative requirements are concrete: clear notices, a maintained AI register, certification of systems, and an Autonomous Systems Officer appointed where processing is high risk. Certification guidance is expected to develop through 2026.
23 Feb 2026
CBUAE guidance note on AI and machine learningIssued to all licensed financial institutions, covering consumer protection and responsible adoption. Its expectations run across governance and accountability, fairness and non-discrimination, transparency and explainability, data quality and privacy, continuous monitoring, human oversight, integration with existing risk frameworks, and third-party and outsourcing risk. For high-impact decisions it expects meaningful human oversight and a route for the customer to have the decision reviewed. It is not legally binding. Treating a supervisor’s stated expectations as optional is a different kind of risk from a legal one, and usually a more expensive one.
1 Jan 2027
Federal Personal Data Protection LawApplies to processing on the UAE mainland, and extraterritorially where the personal data of UAE residents is processed outside the country. Full compliance is required by 1 January 2027. For an AI system the binding questions are the ordinary ones asked in a harder setting: what is the lawful basis, what was disclosed, and can a decision be explained to the person it was made about.
June 2024
UAE Charter for the Development and Use of AIA national statement of principles rather than an enforceable instrument. It matters for direction and for tone at the top, and it is not what an examiner will hold you to. Abu Dhabi Global Market operates its own regime, so a group spanning ADGM and the DIFC is spanning two free-zone rulebooks as well as the federal layer.
§ 03What does not apply

The rule that does not exist.

There is no unified federal AI act in the UAE, and no announced date for one. Anyone selling readiness for a UAE AI law is selling something that does not exist, which is the same error as selling AIDA readiness in Canada. The exposure that is real comes from Regulation 10 inside the DIFC, the CBUAE’s supervisory expectations for licensed financial institutions, the federal PDPL, and the extraterritorial reach of the EU AI Act wherever output touches Europe.

§ 04Questions

The questions a board actually asks.

Is DIFC Regulation 10 in force, and what does it require?

Yes. It was enacted on 1 September 2023 as part of the updated DIFC Data Protection Regulations, and moved to full enforcement on 1 January 2026. It applies to personal data processed through autonomous and semi-autonomous systems, which in practice means most operational AI. The requirements that create work are the register of AI systems, the notices, the certification of systems, and the appointment of an Autonomous Systems Officer where processing is high risk. The register is the item most firms underestimate, for the same reason model inventories are underestimated everywhere: the model is not the only thing that changes, and a register blind to prompt, retrieval corpus and routing policy describes a system that no longer exists.

What did the CBUAE guidance note of February 2026 actually say?

It was issued on 23 February 2026 to all licensed financial institutions, on consumer protection and the responsible adoption of artificial intelligence and machine learning. It sets supervisory expectations across governance and accountability, fairness and non-discrimination, transparency and explainability, data quality and privacy, continuous monitoring, human oversight, integration with existing risk frameworks, and third-party and outsourcing risk. Where an AI system drives a high-impact decision it expects meaningful human oversight and a review mechanism the customer can actually use. It is not legally binding, and that is the point most often misread: a guidance note tells you what the supervisor will ask about at the next examination.

Does the UAE have an AI law?

No. There is no unified federal AI act, and no announced timetable for one. The UAE governs AI through a layered regime instead: the federal Personal Data Protection Law, free-zone instruments such as DIFC Regulation 10 and the separate ADGM regime, sectoral supervision such as the CBUAE guidance note, and the UAE Charter for the Development and Use of AI from June 2024 as a statement of principle. Being precise about this matters, because a governance programme designed against an imaginary statute will be aimed at the wrong evidence.

We operate onshore and in the DIFC. What changes?

You are inside two rulebooks with different characters, and the honest answer is that the operating model has to satisfy the stricter of the two per control rather than be maintained twice. Regulation 10 is binding inside the DIFC and carries specific artefacts, the register, the notices, the certification and the Autonomous Systems Officer. The CBUAE note is supervisory and applies to your licensed activity. The federal PDPL sits underneath both. A single control plane that produces the evidence once, tagged by which instrument it answers to, is cheaper than two governance functions and is also the only version that survives a group-level examination.

Where do you fit into this?

Independent assessment and architecture, not a compliance filing. The Teardown scores the estate against the four MESA layers and produces a board-ready reading of where you actually are, which is the input to a Regulation 10 or CBUAE programme rather than a substitute for one. The other half is architecture: governance the platform enforces at runtime, because an AI register maintained by hand is stale by the next deployment. Engagements are taken personally rather than staffed to a bench, and the published book on Middle East AI governance is the method written down.

Governance an examiner can follow, in the jurisdiction that actually binds you.

Fin · UAE
Book the 30-minute Fit Call →