Skip to content

UAE's AI Regulation and Dubai's AI Governance Framework

9 min read · updated August 11, 2026

Coverage of the UAE tends to describe a country with advanced AI regulation. It has advanced AI strategy, a large amount of published governance material, and—onshore—fewer binding AI rules than the volume of documents suggests. The binding AI-specific rule is in a financial free zone.

Four layers, only some of them law

The single most useful thing to know about the UAE is that it has four distinct regulatory layers, and a document from one of them says nothing about your obligations in another.

  • Federal law, applying across the Emirates onshore.
  • Emirate-level instruments, such as Dubai’s and Abu Dhabi’s, which range from binding local law to published policy.
  • Financial free zones with their own legal systems—the Dubai International Financial Centre and the Abu Dhabi Global Market—each with its own common-law-based civil and commercial law and its own regulator.
  • Federal strategy, including the National Strategy for Artificial Intelligence 2031 and the charter published alongside it, which set direction and create no obligations.

A great deal of the confusion in secondary coverage comes from quoting a layer-four document as though it were layer one.

The federal position

There is no comprehensive federal AI statute. The UAE appointed a Minister of State for Artificial Intelligence in 2017—the first such appointment anywhere—and published the National Strategy for Artificial Intelligence 2031, which sets objectives for adoption across sectors. A strategy is not a source of obligations.

The federal instrument that does reach AI is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, issued in September 2021. It contains the elements you would expect—consent, purpose limitation, data subject rights, security, breach notification, cross-border transfer rules—and one provision of direct AI relevance: a right for the data subject to object to processing based on automated processing, including profiling, where it produces legal consequences or seriously affects them, subject to exceptions.

The PDPL contemplated executive regulations that would supply operative detail and start a compliance grace period. Verify whether those regulations have been issued before assuming either that the PDPL’s detailed obligations are enforceable against you or that they are not. This page is not legal advice; take UAE advice on your own facts.

This is the genuinely unresolved part of the onshore picture, and it should be stated as unresolved rather than smoothed over. A decree-law is in force, its detailed implementation was left to executive regulations, and the length of the wait for those regulations has left practitioners differing on how much of the PDPL can be enforced in the meantime. What would settle it is publication of the regulations, which would also start the transition period the law contemplated for controllers to come into compliance.

Sectoral regulators operate regardless. The Central Bank supervises model risk in regulated financial institutions, the health authorities regulate clinical software, and telecommunications and cybersecurity authorities issue binding requirements within their remits. For most regulated businesses those are the rules that bite first.

The free zones regulate AI directly

The DIFC is a separate jurisdiction with its own courts and its own data protection law, DIFC Law No. 5 of 2020. In 2023 it added a regulation specifically addressing the processing of personal data through autonomous and semi-autonomous systems—one of the earliest binding, AI-specific data protection rules in any jurisdiction. It sets out principles for such processing, obligations around accountability, transparency, human oversight and the handling of automated decisions, and a mechanism through which operators can be certified against it. The DIFC’s Commissioner of Data Protection publishes the law and regulations: DIFC data protection law and regulations.

The ADGM has its own Data Protection Regulations 2021, closely modelled on the GDPR, including restrictions on solely automated decision-making with legal or similarly significant effects.

So the accurate statement is inverted from the usual one: an AI system deployed by a DIFC entity faces binding AI-specific data protection obligations, while the same system deployed onshore faces a general data protection law whose detailed rules are still awaited. Which regime applies is a question about the entity and where the processing sits, and it is worth answering before designing anything.

Dubai’s framework and what it is for

Dubai’s AI governance material—the AI principles and guidelines and the self-assessment tool published through Digital Dubai, and the emirate’s subsequent AI strategy work—is governance guidance rather than legislation. The principles cover ethics, security, humanity and inclusiveness, and the self-assessment tool converts them into a questionnaire an organisation can work through.

Its force is procurement. Dubai government entities are substantial buyers of AI systems, and alignment with the emirate’s framework is the expected form of answer in that context—the same mechanism by which Singapore’s voluntary framework acquires practical weight without a penalty attached. Treating it as optional in a public-sector bid is a commercial error, not a legal one.

Be careful with two claims that appear in secondary coverage. First, that Dubai “requires” AI ethics compliance: the guidance is not law, and a requirement that appears in a tender document is a contractual requirement arising from that tender. Second, that the UAE charter for the development and use of AI creates obligations: it is a statement of principles.

What to do about it

The sequence that produces the right answer, rather than the answer the volume of published material suggests, is short.

  1. Establish which layer you are in. Onshore federal, a specific emirate, DIFC or ADGM. The answer follows the contracting entity and where processing happens, and it is not always the same for two products from one company.
  2. Identify the binding instrument for that layer. The PDPL onshore, DIFC Law No. 5 of 2020 and its autonomous systems regulation in the DIFC, the ADGM Data Protection Regulations in the ADGM, plus any sectoral regulator with authority over you.
  3. Treat the frameworks as procurement requirements. Prepare a mapping of your governance to the Dubai principles and, where relevant, the national charter, and keep it with your bid material rather than with your legal register.
  4. Use a certifiable management system as the backbone. Across all four layers, the artefacts requested are the same ones an ISO/IEC 42001 management system produces. Building that once answers most of the questions from every layer.