Skip to content
Is there an AI for this?

Jurisdiction

United Arab Emirates

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

The UAE runs three parallel data-protection regimes, not one. Onshore, Federal Decree-Law 45 of 2021 has been in force since January 2022, but its Executive Regulations still cannot be found on any official source, leaving breach windows, transfer controls and penalties undefined. The DIFC and ADGM are separate, GDPR-shaped and fully operative, and the DIFC has the only bespoke AI rule in the country — Regulation 10 on autonomous and semi-autonomous systems, which requires notice at first use and an Autonomous Systems Officer for high-risk activities. The Central Bank issued AI expectations for financial institutions in February 2026. Health data is effectively localised by separate federal law.

Region
Middle East
ISO code
AE
Privacy framework
Onshore: Federal Decree-Law No. 45 of 2021, in force since 2 January 2022, supervised by the Emirates Data Office. Its scope provision carves out government data, health data with its own legislation, banking and credit data with its own legislation, and free-zone companies with special personal-data legislation — which is why the DIFC and ADGM sit outside it entirely. The DIFC applies Data Protection Law No. 5 of 2020 together with the DIFC Data Protection Regulations, including Regulation 10 on autonomous and semi-autonomous systems. ADGM applies the Data Protection Regulations 2021 and designates adequate jurisdictions on the European Commission’s model. Onshore, automated decisions engage a right to object and a right to have the human element included in the review, and an impact assessment is mandatory for systematic comprehensive automated evaluation with legal or serious effects.
AI-specific rules
No general-purpose UAE AI statute was found. The AI-specific instruments are DIFC Regulation 10 on processing personal data through autonomous and semi-autonomous systems, in force since September 2023 and now under amendment, and the Central Bank’s February 2026 guidance note on the responsible adoption and use of artificial intelligence and machine learning by licensed financial institutions. That guidance note is unusually operational: a documented governance framework, a model inventory, annual bias testing, plain-language disclosure in Arabic and English, an explicit choice about where the human sits relative to the loop, a consumer opt-out from high-impact AI decisions, and a retained ability to stop the system by human intervention. Everything else — the UAE AI Charter, the National Strategy for AI 2031, the Dubai Universal Blueprint and Dubai’s AI Ethics toolkit — is policy or recommended practice. In Dubai, Law 24 of 2023 gives the data and statistics regulator an express remit over AI applications.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

Three regimes, three answers. Onshore, the PDPL permits transfer where the destination has adequate personal-data legislation in cases approved by the Bureau, or under an agreement, with derogations and the controls delegated to Executive Regulations that have not been issued — and no UAE federal adequacy list was found on any official source. The DIFC publishes an adequacy list that does not include the United States as a whole, only California, and its Commissioner has been re-assessing the European framework; note also that the list in the Regulations and the list on the DIFC website do not match, so the Regulations appendix is the one to rely on. ADGM follows the European Commission’s approach, admits Canada only where the recipient is subject to PIPEDA and the United States only for EU-US Data Privacy Framework participants, and its guidance confirms that onshore UAE is a non-ADGM jurisdiction, that there is no de-minimis rule, and that granting access to a portal from another jurisdiction is itself a transfer. Health data is separately barred from leaving the country.

Primary sources

  1. Official faqUAE Government portal — Personal Data Protection Law
  2. LegislationDIFC Data Protection Regulations, consolidated text including Regulation 10
  3. Regulator guidanceADGM Office of Data Protection — adequate jurisdictions
  4. LegislationADGM Data Protection Regulations 2021 (updated)
  5. Regulator guidanceADGM Guidance on the Data Protection Regulations 2021, Part 6 — international transfers
  6. Regulator guidanceCBUAE — guidance note on the responsible adoption and use of artificial intelligence
  7. Regulator pageCBUAE Rulebook — market conduct and consumer protection
  8. Regulator guidanceDigital Dubai — AI ethics
  9. Regulator guidanceDigital Dubai — AI ethics self-assessment toolkit
  10. LegislationDubai Law No. (24) of 2023 — Dubai Data and Statistics Establishment
  11. LegislationDubai Resolution No. (2) of 2017 — data classification policy
  12. Regulator pageDFSA — AI survey and thematic reviews

02Regulations and guidance

11 instruments
InstrumentStatus
ADGM DPR 2021Abu Dhabi Global Market’s data protection regime. It follows the European Commission’s approach of designating adequate jurisdictions, and permits transfer to a recipient outside ADGM only where the laws applicable to that recipient ensure an adequate level of protection for the specific personal data.In force
CBUAE Consumer Protection RegulationThe Central Bank’s conduct regulation for licensed financial institutions. It is the framework the 2026 AI guidance note sits inside, which is why an AI consumer-facing deployment in a UAE financial institution engages conduct rules before it engages anything AI-specific.In force
CBUAE AI/ML Guidance NoteThe Central Bank’s AI expectations for licensed financial institutions: a documented governance framework, a model inventory, annual bias testing, plain-language disclosure in Arabic and English, an explicit choice about where the human sits relative to the loop, consumer opt-out from high-impact decisions, and a retained ability to stop the system.In force
CBUAE Telemarketing RegulationThe Central Bank’s telemarketing rules for licensed financial institutions, in force from March 2026. It reaches AI-driven outbound contact — synthetic voice, automated calling and generated messaging — because the regulation attaches to the marketing activity rather than to the technology used.In force
DIFC DP Regulations / Reg 10The DIFC’s data protection regulations, and the only bespoke AI rule in the UAE. Regulation 10 defines Provider, Operator and Deployer, requires notice at first use, and for high-risk activities requires an appointed Autonomous Systems Officer with competencies substantially similar to a data protection officer.In force
Dubai AI EthicsDigital Dubai’s AI ethics principles, guidelines and self-assessment toolkit, overseen by an AI Ethics Advisory Board. The Executive Council has advised that the toolkit is to be used by all public entities implementing AI systems, which makes it a procurement expectation rather than a law.In force
Dubai Law 24/2023Establishes the Dubai Data and Statistics Establishment with an express remit over data, statistics, artificial intelligence applications, advanced analytics and data science, including proposing and reviewing the legislation that governs them.In force
Dubai Data Classification PolicyDubai’s data classification, dissemination, exchange and protection policy. It is the instrument that decides what a Dubai government entity may put into a system at all, and therefore what any AI deployment serving one is allowed to ingest.In force
Dubai AI BlueprintDubai’s plan to accelerate adoption of AI applications in service of its economic agenda. Like the federal strategy it is direction rather than regulation, and it explains why a Dubai public-sector buyer will expect an AI proposal rather than resist one.In force
UAE PDPLThe onshore federal data protection law, in force since January 2022. Breach-notification windows, data protection officer thresholds, transfer controls and the penalty schedule are all delegated to Executive Regulations that could not be found on any official source, so the regime is in force with its detail missing.Partly in force
UAE AI Strategy 2031The federal AI strategy. It sets national ambition and investment direction and creates no obligations, which is worth stating explicitly because the UAE’s prominence in AI policy leads readers to assume a regulatory framework behind it.In force

03Common enterprise issues

6
  • Personal data

    Onshore, the law is in force and the detail is missing

    The PDPL applies, but its Executive Regulations could not be found on any official source. Breach-notification windows, data protection officer thresholds, transfer controls and the penalty schedule are all delegated to instruments that have not surfaced, and the regularisation clock has not started. Plan to a moving target, and do not read "no regulations" as "no obligations".

  • Cross-border transfers

    Pick the right regime before picking the region

    A DIFC-licensed entity and an onshore Dubai company face different transfer tests for the same model endpoint. Both free zones publish adequacy lists and both treat the United States restrictively — the DIFC recognising only California, ADGM only Data Privacy Framework participants — so a default US-region model API is not automatically covered.

  • Data residency

    Health data is a hard localisation blocker, free zones included

    Federal law forbids storing, processing, generating or transforming health data outside the UAE where it relates to health services provided inside it, absent a Health Authority resolution, and it applies including in the free zones. DIFC or ADGM status is no escape, so clinical AI needs in-country inference or a specific approval.

  • Automated decision-making

    Automated decisions carry a human-review right onshore

    The PDPL lets a data subject object to decisions produced by automated processing including profiling, and requires the controller to include the human element in reviewing those decisions at the data subject’s request. An impact assessment is mandatory for systematic comprehensive automated evaluation with legal or serious effects.

  • High-risk AI

    DIFC high-risk AI needs a named officer, and a certification that may not exist yet

    Regulation 10 bars commercial use of a system for high-risk processing unless the Commissioner has established audit and certification requirements for that activity, the system complies with them, and an Autonomous Systems Officer has been appointed with competencies substantially similar to a data protection officer. Scope that appointment early.

  • Sector rules

    The Central Bank now has concrete AI expectations

    Licensed financial institutions are asked for a documented AI governance framework, a model inventory, annual bias testing, plain-language disclosure in Arabic and English, an explicit human-in, on or out-of-the-loop choice proportionate to risk, a consumer opt-out from high-impact AI decisions, and a retained ability to stop the system by human intervention at any time.


04Vendor restrictions

0

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

No vendor restriction has been recorded for this jurisdiction.


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 11 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.