Home » Blog » Regulating Artificial Intelligence and Personal Data in the UAE: Is a Fragmented Framework Fit for Purpose?

Regulating Artificial Intelligence and Personal Data in the UAE: Is a Fragmented Framework Fit for Purpose?

Sargam Purohit

Authored By: Middlesex University

ABSTRACT

The United Arab Emirates has adopted an innovation-led approach to artificial intelligence while building a multi-layered data-protection regime. Federal Decree-Law No 45 of 2021 supplies a national baseline; the Dubai International Financial Centre and Abu Dhabi Global Market apply separate, more detailed regimes; and recent regulatory instruments increasingly address autonomous systems directly. This article argues that the framework contains strong substantive building blocks, particularly rights against harmful automated decisions, impact assessment duties and the DIFC’s system-specific governance model. Nevertheless, protection still depends too heavily on geography, sector and regulatory maturity. Fragmented scope, uncertain operational detail, opaque algorithmic decision-making and uneven enforcement can undermine both individual rights and commercial certainty. The UAE should preserve regulatory experimentation but establish a coordinated federal minimum for high-risk AI, supported by mandatory assessments, meaningful human review, auditable documentation and interoperable certification.

Keywords: United Arab Emirates; artificial intelligence; personal data; automated decision-making; DIFC; ADGM; AI governance

1. Introduction

Artificial intelligence is already embedded in the UAE’s financial services, recruitment, retail, healthcare, mobility and public administration. Its commercial appeal is obvious: automated systems can detect fraud, personalise services and process information at a speed unavailable to human decision-makers. Yet the same systems may infer intimate characteristics, reproduce bias, obscure responsibility and make consequential decisions about employment, credit or access to services. The central legal issue is therefore no longer whether AI should be used, but under what conditions its use remains lawful, explainable and contestable.

The UAE’s response is deliberately pro-innovation. The national policy direction is expressed through the UAE Charter for the Development and Use of Artificial Intelligence, which promotes safety, fairness, privacy and accountability while supporting the country’s AI ambitions.1 Binding protection, however, is dispersed across federal legislation, the two financial free-zone regimes and sector-specific supervision. Federal Decree-Law No 45 of 2021 concerning the Protection of Personal Data (the PDPL) is the principal national statute, while DIFC Law No 5 of 2020 and the ADGM Data Protection Regulations 2021 govern within their respective jurisdictions.2

This plural structure has advantages. Specialist regulators can respond quickly, test international models and tailor obligations to sophisticated markets. The DIFC’s Regulation 10, for example, moves beyond traditional privacy language by regulating personal data processed through autonomous and semi-autonomous systems. The weakness is that substantially similar AI activity may attract different duties depending on where an entity is established and which sector it serves. This article argues that the present regime is a credible foundation but not yet a complete national architecture for high-risk AI. A coordinated minimum standard is required to convert ethical ambition into consistent and enforceable protection.

2. The Federal Baseline: Rights Without a Complete AI Code

The PDPL was an important shift from scattered confidentiality rules to a general framework governing personal data. Its territorial reach captures processing by controllers or processors established in the UAE and, in specified circumstances, processing outside the State concerning persons in the UAE. At the same time, article 2 excludes government data and authorities, health and banking data governed by sectoral legislation, and entities in financial free zones with their own data-protection laws.3 These exclusions are understandable in a federal and specialised regulatory system, but they are also the legal source of fragmentation.

For AI, the PDPL’s strongest provisions are technology-neutral. Article 5 requires fair, transparent and lawful processing, purpose limitation, data minimisation, accuracy, security and limited retention. Articles 13 to 18 give individuals rights to information, portability, correction, erasure, restriction and objection. Most importantly, article 18 permits a data subject to object to automated decisions, including profiling, where they have legal consequences or seriously affect the person. Contractual necessity, statutory authority and prior consent qualify that right, but article 18(4) requires the controller to include a human element in reviewing an automated decision when requested.4 This is a valuable safeguard because it recognises that a technically accurate model may still produce a legally or contextually unfair result.

The PDPL also places preventive obligations on organisations. Article 10 requires a data protection officer in circumstances involving high privacy risk, systematic and comprehensive evaluation through profiling or automated processing, or large-scale sensitive data. Article 21 requires an impact assessment before processing that uses modern technology and is likely to create a high risk to personal-data privacy and confidentiality. Articles 22 and 23 regulate transfers outside the UAE through adequacy, agreements and defined derogations.5 Taken together, these provisions can govern many AI risks without naming a particular model or technique.

The difficulty lies in operational precision. A right to human review is meaningful only if the reviewer has authority, competence and access to sufficient reasons to change the result. Consent is weak where a person cannot realistically refuse a job-screening platform, credit-scoring tool or essential digital service. Likewise, a general impact-assessment duty does not by itself settle how risk should be classified, what testing is sufficient, whether affected groups must be consulted, or when an assessment should be disclosed to a regulator. The PDPL therefore supplies principles, but high-risk AI requires more detailed procedures than conventional data processing.

3. Regulatory Laboratories: DIFC and ADGM

The DIFC has developed the UAE’s most explicit legal response to AI-related personal-data processing. Regulation 10 of the DIFC Data Protection Regulations, effective from 1 September 2023, applies to autonomous and semi-autonomous systems. It identifies deployers and operators, connects them respectively to controller- and processor-like responsibility, and requires clear notice where such a system processes personal data. The notice must explain relevant purposes, design principles, safeguards and outputs. The regime also requires systems to be ethical, fair, transparent, secure and accountable.6 This is more concrete than relying only on broad processing principles because it connects transparency to the system’s operation and assigns responsibility to the actors who authorise, operate or benefit from it.

Regulation 10 is especially significant for high-risk processing. Commercial use may depend on applicable audit or certification requirements, human-defined or human-approved purposes and appointment of an Autonomous Systems Officer. The model is innovative because it treats governance as an engineering and organisational obligation, not merely a privacy notice drafted after deployment. It also addresses the recurring accountability problem in AI supply chains: a business cannot evade responsibility simply because a third-party vendor built the model.

ADGM’s Data Protection Regulations 2021 follow a GDPR-influenced model. They contain principles of lawfulness, fairness, transparency and accountability; rights relating to automated decision-making and profiling; data-protection-by-design obligations; and mandatory impact assessments for processing likely to result in high risk. ADGM guidance identifies profiling, automated decisions affecting access to services or benefits, large-scale special-category processing and the combination of multiple data sources as activities likely to require an assessment.7 In May 2025, the ADGM Office of Data Protection further clarified that nominal human involvement is insufficient: a reviewer must exercise meaningful influence and possess the authority and competence to overturn a system’s recommendation.8

These free-zone regimes demonstrate the benefit of regulatory experimentation. They can translate broad rights into practical expectations concerning model oversight, explainability and human intervention. Yet their sophistication also exposes the unevenness of the wider landscape. A person affected by an automated credit or recruitment decision should not receive materially stronger procedural protection merely because the relevant controller happens to sit in one financial centre rather than elsewhere in the UAE.

4. Why Fragmentation Matters

First, fragmented scope creates compliance uncertainty. A corporate group may have an onshore operating company, a DIFC financial entity, an ADGM service provider and overseas cloud or model vendors. The same dataset may pass through several legal regimes. Each regime is broadly compatible with international principles, but differences in terminology, exemptions, notification practice, transfer rules and supervisory expectations increase the cost of identifying the applicable law. For large businesses this becomes a compliance exercise; for smaller organisations it may produce under-compliance or excessive caution.

Secondly, AI challenges the idea that transparency can be satisfied by disclosure alone. A notice stating that an algorithm is used does not explain why a candidate was rejected or a customer was assigned a higher risk score. Complex models may not yield a simple causal account, and proprietary claims may discourage meaningful disclosure. The legal standard should therefore focus on useful explanation: the principal factors, data categories, logic at an appropriate level, foreseeable consequences and route to challenge. A human reviewer who merely confirms the machine’s answer creates an appearance of due process while leaving automation bias untouched.

Thirdly, regulatory capacity must match market adoption. The DFSA’s 2025 survey found that 52 per cent of responding authorised firms used AI, compared with 33 per cent in 2024, while 21 per cent lacked clear accountability or oversight even where AI was operationally critical.9 In June 2026, the DFSA accordingly stated that existing duties concerning governance, competence, risk management, cyber risk and third-party arrangements apply fully to AI. It emphasised that firms remain responsible when using external model providers, data vendors, cloud services or software suppliers.10 This is a sound supervisory position, but it also shows that rapid deployment can outpace internal governance before formal AI-specific rules mature.

Fourthly, cross-border processing complicates enforcement. Generative and predictive systems are often trained, hosted or supported outside the UAE. Personal data may be transferred to a cloud environment, transformed into embeddings, retained in logs or used to improve a vendor’s model. Contractual safeguards are essential, but contracts cannot remedy a controller’s failure to understand where data travels or whether a vendor can honour deletion, access and objection rights. Effective regulation therefore requires technical mapping of data flows, vendor audit rights and controls against secondary use, not only standard contractual language.

Finally, the regime risks protecting privacy more clearly than other AI-related interests. Biased automated decisions can implicate equality, consumer protection, employment fairness, safety and access to essential services even when the underlying personal-data processing is technically lawful. Data-protection law is indispensable, but it is not a complete AI law. A model may use lawfully obtained data and still be unsafe, discriminatory or unreliable. High-risk governance must therefore evaluate the use and outcome of the system, not merely the legality of collecting its inputs.

5. Comparative Lessons Without Mechanical Transplantation

The European framework illustrates two useful ideas. Article 22 of the General Data Protection Regulation protects individuals against solely automated decisions producing legal or similarly significant effects and requires safeguards where exceptions apply.11 The EU Artificial Intelligence Act adds a product- and use-based regime: certain practices are prohibited, while high-risk systems face obligations concerning risk management, data governance, documentation, logging, transparency, human oversight, accuracy and cybersecurity.12 The combination addresses both personal-data processing and systemic AI risk.

The UAE should not copy the EU model wholesale. The AI Act is extensive, complex and costly, and its institutional design reflects the EU internal market. The UAE can adopt a more agile approach suited to its federal structure and innovation strategy. Nevertheless, the comparative lesson is that principles become effective only when connected to risk classification, evidence and accountable actors. The DIFC has already moved in this direction. Its June 2026 consultation proposed strengthening safety, clarifying the role of the Autonomous Systems Officer and enabling recognition of accreditation and certification frameworks.13 That approach could inform a national minimum standard while allowing financial and sectoral regulators to impose additional requirements.

6. A Reform Roadmap for the UAE

A proportionate reform programme should begin with a federal high-risk AI standard rather than an immediate comprehensive code. It should apply across mainland commercial activity and operate as a floor where sectoral or free-zone law is stricter. High-risk uses should include automated decisions materially affecting employment, credit, insurance, healthcare, education, essential services, biometric identification and access to public benefits. The classification should depend on context and effect, not merely the technology’s label.

For those uses, five duties should be mandatory. First, an AI impact assessment should identify the purpose, lawful basis, affected groups, data provenance, foreseeable harms, bias testing, security measures, human-oversight design and residual risk. Secondly, deployers should maintain a register of high-risk systems and material third-party dependencies. Thirdly, affected individuals should receive concise notice and an intelligible explanation of a consequential decision, together with a prompt route to meaningful human reconsideration. Fourthly, systems should be tested before deployment and monitored for drift, unequal error rates, incidents and vendor changes. Fifthly, serious incidents and unmitigated high risks should be reportable to the competent regulator.

Institutionally, the UAE Data Office should coordinate a standing forum with DIFC, ADGM, the Central Bank, DFSA and relevant health, employment, consumer and digital authorities. The forum should publish common terminology, model assessment templates, standard contractual clauses and a jurisdictional referral protocol. Mutual recognition of credible audits and certifications would reduce duplication while preserving regulator access to evidence. Regulatory sandboxes could remain available, but participation should not dilute basic rights or accountability.

Enforcement should also be transparent enough to create precedent. Published anonymised decisions, thematic reviews and guidance would help organisations understand what counts as meaningful human intervention, adequate explainability and proportionate testing. Individuals require accessible complaint mechanisms, while regulators need technical expertise and power to obtain model documentation, logs and assessment records. The objective is not to demand disclosure of source code in every case, but to ensure that claims of complexity or trade secrecy do not defeat accountability.

7. Conclusion

The UAE has moved beyond a policy vacuum. The PDPL establishes nationally important rights and preventive duties; ADGM supplies a mature data-protection model; and DIFC Regulation 10 is a regionally significant attempt to govern autonomous systems through notice, design principles, accountable roles and certification. Recent DFSA supervision and the 2026 DIFC consultation show that regulators are continuing to adapt.

The remaining problem is coherence. High-risk AI can affect a person as seriously outside a financial free zone as within it, and cross-border systems do not respect jurisdictional boundaries. The UAE should therefore retain specialised regulation but connect it through a federal minimum standard for consequential AI. Mandatory impact assessment, meaningful human review, auditable governance, incident reporting and interoperable certification would protect individuals while giving businesses clearer rules. On that basis, the present fragmented framework should be understood not as a finished solution, but as the foundation of a coordinated and innovation-compatible system of AI accountability.

Note(S):

  1. UAE Government, ‘UAE Charter for the Development and Use of Artificial Intelligence’ (10 June 2024).

  2. Federal Decree-Law No 45 of 2021 Concerning the Protection of Personal Data (UAE); DIFC Law No 5 of 2020 Data Protection Law; ADGM Data Protection Regulations 2021.

  3. Federal Decree-Law No 45 of 2021 Concerning the Protection of Personal Data (UAE), art 2.

  4. ibid arts 5 and 13-18, especially art 18(1)-(4).

  5. ibid arts 10, 21-23. See also Federal Decree-Law No 44 of 2021 Establishing the UAE Data Office.

  6. DIFC Data Protection Regulations 2020, reg 10 (as amended 1 September 2023).

  7. ADGM Data Protection Regulations 2021, ss 4, 20 and 34; ADGM Office of Data Protection, ‘Guidance on the Data Protection Regulations 2021, Part 4: Data Protection Impact Assessments’ (11 August 2021).

  8. ADGM Office of Data Protection, ‘Data Subject Rights: Automated Individual Decision-Making, Including Profiling’ (May 2025).

  9. Dubai Financial Services Authority, ‘New DFSA AI Survey’ (12 November 2025).

  10. Dubai Financial Services Authority, ‘DFSA Regulatory Expectations on Artificial Intelligence Risk Management in the DIFC’ (4 June 2026).

  11. Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L119/1, art 22.

  12. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence [2024] OJ L, 2024/1689, arts 5-6, 9-15 and 26.

  13. Dubai International Financial Centre, ‘DIFC Announces Consultation of Amended DIFC Data Protection Regulations’ (18 June 2026).

Bibliography

ADGM Data Protection Regulations 2021.

ADGM Office of Data Protection, ‘Data Subject Rights: Automated Individual Decision-Making, Including Profiling’ (May 2025) <https://assets.adgm.com/download/assets/ADGM%2B-%2BData%2BSubject%2BRights%2BAutomated%2BIndividual%2BDecision-Making%2B%28Brochure%29.pdf/698e462858a511ef9face27828504259> accessed 22 August 2026.

ADGM Office of Data Protection, ‘Guidance on the Data Protection Regulations 2021, Part 4: Data Protection Impact Assessments’ (11 August 2021) <https://assets.adgm.com/download/assets/ADGM%2BDPR%2B2021%2BGuidance%2BPart%2B4.pdf/63de087e595611ef8e065eb4feb71eb0> accessed 22 August 2026.

DIFC Data Protection Regulations 2020, regulation 10 (as amended 1 September 2023).

DIFC Law No 5 of 2020 Data Protection Law.

Dubai International Financial Centre, ‘DIFC Announces Consultation of Amended DIFC Data Protection Regulations’ (18 June 2026) <https://www.difc.com/whats-on/news/difc-consultation-amended-data-protection-regulations> accessed 22 August 2026.

Dubai Financial Services Authority, ‘DFSA Regulatory Expectations on Artificial Intelligence Risk Management in the DIFC’ (4 June 2026) <https://www.dfsa.ae/download_file/4222/0> accessed 22 August 2026.

Dubai Financial Services Authority, ‘New DFSA AI Survey’ (12 November 2025) <https://www.dfsa.ae/news/new-dfsa-ai-survey-generative-ai-adoption-has-nearly-tripled-within-difc-last-12-months-governance-continues-develop> accessed 22 August 2026.

Federal Decree-Law No 44 of 2021 Establishing the UAE Data Office.

Federal Decree-Law No 45 of 2021 Concerning the Protection of Personal Data (UAE).

Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L119/1.

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence [2024] OJ L, 2024/1689.

UAE Government, ‘UAE Charter for the Development and Use of Artificial Intelligence’ (10 June 2024) <https://uaelegislation.gov.ae/en/policy/details/the-uae-charter-for-the-development-and-use-of-artificial-intelligence> accessed 22 August 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top