AI Governance9 min readAugust 13, 2026

The UAE's AI Compliance Map: PDPL, DIFC Regulation 10 and the New Federal Authority

M
Mohammed UsmanFounder & CEO

Mohammed Usman is the founder and CEO of Masarrati with 15+ years in product engineering. He has led the development of 10+ production AI, blockchain, and cybersecurity platforms for enterprise clients across UAE, MENA, and Europe.

AI/ML ArchitectureBlockchain SystemsEnterprise Security

TL;DR

The UAE regulates AI in layers rather than one act: consent-first PDPL, DIFC Regulation 10 enforced from January 2026 with impact-assessment and transparency duties, a child digital safety law prohibiting behavioural profiling of minors, and a new Federal Authority for AI and Data consolidating oversight since June 2026. Engineer to it with consent and withdrawal infrastructure, systems that generate their own assessment artefacts, decision-level explainability logging, and a deliberate residency posture.

Updated August 13, 2026

Teams arriving in the UAE from Europe often ask where the Emirati AI Act is. The answer is that there is not one — and that does not mean the obligations are lighter. The UAE regulates AI through layers: federal data protection law, AI-specific rules in the financial free zones, sectoral regulators, national charters, and, since June 2026, a single federal authority consolidating AI and data oversight. Each layer is individually manageable; the compliance risk lives in the seams. Here is the map as it stands, and what it means at the engineering level.

The layers

PDPL: consent-first by design. The federal Personal Data Protection Law (Federal Decree-Law 45 of 2021) is the base layer for any AI system touching personal data. The practical difference from GDPR that most teams miss: PDPL does not recognise legitimate interests as a standalone lawful basis — consent is the default posture. For an AI product, that shifes real weight onto consent capture, granular purpose records, and the ability to honour withdrawal across training corpora, feature stores and inference logs.

DIFC Regulation 10: AI rules with enforcement. The DIFC's Regulation 10 governs autonomous and semi-autonomous systems, with reporting through 2026 describing full enforcement from January 2026 — AI impact assessments, transparency obligations for AI-driven decisions, documentation of high-risk use cases, and fines reported in the tens of thousands of dollars per violation. If your entity or your data processing sits in the DIFC, this is the closest thing the region has to EU-style AI obligations, and it is live now. ADGM runs its own data protection regulations with the FSRA covering financial uses.

The Child Digital Safety Law. Effective 1 January 2026 with full compliance required by January 2027, it imposes age verification, content filtering and parental-control duties on digital platforms — and strictly prohibits behavioural profiling of children for marketing. Any AI-driven personalisation touching under-18 users in the UAE needs a designed answer to this, not an assumption of exemption.

The federal consolidation. On 14 June 2026 the UAE Cabinet approved the Federal Authority for Artificial Intelligence and Data, absorbing the previously separate AI office, digital government function and national data office. One counterparty now owns national AI and data policy, standards and compliance across federal entities. Expect the layered regime to become more coherent — and materially harder to route around — as the authority issues unified standards.

The soft layer that hardens through procurement. The UAE AI Charter and sectoral guidance are not statutes, but their principles — fairness, transparency, human oversight, accountability — surface as procurement requirements and regulator expectations long before they surface as law. Government-adjacent AI work in the UAE already gets evaluated against them in practice.

Engineering to the map

Reading regulation as a specification, four systems fall out.

Consent and purpose infrastructure. Purpose recorded at collection, consent state checked at use — including training use — and withdrawal that actually propagates: removal or exclusion across datasets, embeddings and caches, with records proving it happened.

Impact assessment as an artefact the system generates. DIFC-style AI impact assessments and the documentation duties that follow are far cheaper when the platform produces them — model versions, evaluation results, data lineage, human-oversight configuration — than when a compliance team reconstructs them quarterly.

Explainability at the decision surface. Transparency obligations for AI-driven decisions mean the system must retain, for each consequential output, what inputs and what logic produced it, in a form a regulator or affected person can be shown. That is a logging and design decision made at the start, or an archaeology project later.

Residency and deployment posture. Between PDPL transfer rules, free-zone regimes and government data expectations, where models run and where logs live is a compliance variable. Sovereign and in-country deployment options belong in the architecture conversation from day one.

Where Masarrati fits

Masarrati builds AI systems with this map designed in: AI and agentic platforms with consent-aware data pipelines, decision logging and human oversight configured as first-class features; GRC and compliance automation that generates the evidence — control monitoring, assessment artefacts, audit trails — regulators ask for; and sovereign AI deployments for the GCC where residency requirements shape the architecture. Legal interpretation always rests with your counsel; what we deliver is a system whose records make their job straightforward.

Frequently Asked Questions

Does the UAE have an AI law like the EU AI Act?

No single horizontal statute. The UAE regulates AI through layers: the federal PDPL for personal data, DIFC Regulation 10 for autonomous systems in that free zone with enforcement from January 2026, ADGM's own data protection regime, the Child Digital Safety Law from 2026, sectoral regulators, and the new Federal Authority for Artificial Intelligence and Data approved in June 2026 that consolidates national oversight.

How does PDPL differ from GDPR for AI systems?

The most consequential difference: PDPL does not recognise legitimate interests as a standalone lawful basis for processing, making consent the default. For AI products this puts real engineering weight on consent capture, purpose records, and withdrawal that propagates across training data, feature stores and inference logs.

What does DIFC Regulation 10 require for AI?

Reporting through 2026 describes AI impact assessments, transparency obligations for AI-driven decisions, and documentation of high-risk use cases, with full enforcement from January 2026 and fines reported in the tens of thousands of dollars per violation. If your entity or processing sits in the DIFC, these obligations are live now.

What changed with the UAE Federal Authority for AI and Data?

Approved by the UAE Cabinet on 14 June 2026, the authority consolidates the previously separate AI office, digital government function and national data office into one body owning national AI and data policy, standards and federal compliance. The practical expectation is a more unified — and less avoidable — standards regime over time.