AI Regulations in DMCC: Complete Guide
Adding an activity to the licence is administrative; carrying it on without adding it is not.
A DMCC company stays inside federal UAE law, which is what separates it from a DIFC or ADGM affiliate and makes a borrowed group compliance framework unreliable. The guide covers when an AI feature pushes a business past the activities on its DMCC licence, how the federal Personal Data Protection Law treats model training, cross-border transfers and automated decisions about people, the vendor and back-to-back terms that decide who carries the risk, and ownership of code and models in commissioned development work.
A company in the Dubai Multi Commodities Centre that has just added an AI feature to its trading platform, its screening process or its customer service usually wants to know which regulator it now answers to. There is no separate AI code sitting above DMCC companies. What applies is the law that already governs the activity the system performs, the personal data it uses, and the licence the company holds from the DMCC Authority.
This guide works through those obligations in the order they tend to bite, and flags where a DMCC entity's position differs from a company in one of the financial free zones.
Where a DMCC company sits in the UAE legal system
DMCC is a free zone. Companies there are registered and licensed by the DMCC Authority under the free zone's own company rules, but they are not outside federal UAE law. Federal legislation on data protection, criminal liability, commercial dealings and employment applies. That distinguishes DMCC from the DIFC and ADGM, which are common-law jurisdictions with their own courts, their own regulators and their own data protection regimes.
The practical consequence is that a DMCC entity cannot borrow a compliance framework written for a DIFC affiliate. The two entities are answering different questions, and the mismatch tends to surface at the worst time, during a financing round or a customer's security review.
Check the licence before the launch
A DMCC licence lists the activities the company is permitted to carry on. AI features have a way of moving a business past that description. A commodities trading company that starts selling its internal pricing model as a subscription product is now a software business. A platform that adds automated recommendations may be doing something the original activity code never contemplated.
Adding an activity is an administrative step; carrying it on without adding it is not. Before a new AI product is offered externally, confirm that the licence covers it, and check whether any element of the offering falls under a separate regulatory regime rather than free zone licensing alone.
Personal data and model training
Personal data handled by a DMCC company falls under the federal personal data protection law, Federal Decree-Law No. 45 of 2021. DIFC and ADGM run their own regimes, so a policy imported from a group company in either centre does not answer the DMCC entity's obligations.
Where AI is involved, the recurring issues are these:
- Basis for training. Data gathered to deliver a service is not automatically available to train a model. Reusing it for training needs its own justification, decided before the training run, not after it.
- What customers were told. A privacy notice describing the original service does not cover model development. If the notice is silent, the practice is exposed.
- Automated decisions about people. Systems that score, rank or reject individuals attract obligations around explanation and human review.
- Cross-border processing. Sending data to a model provider, a group company or a cloud region abroad is a regulated transfer, and the contract with the recipient does part of the compliance work.
- Retention. Training datasets need a retention position. Keeping everything indefinitely because it might be useful is not one.
The vendor contract carries most of the risk
Very few DMCC companies build their own models. They license them, and the terms are usually accepted online without review. The clauses that matter most are predictable:
- Use of your inputs. Whether the provider may train on your prompts, documents and customer data, and whether that setting can be turned off.
- Ownership of output. What the company actually owns in what the system generates, particularly where the output goes into a product sold to customers.
- Infringement risk. What the provider says about the material behind the model, and whether any indemnity survives the liability cap.
- Confidentiality. Whether client or counterparty information may be entered into the tool at all.
- Continuity. What happens when a model version is retired, an interface changes or a service is withdrawn while the business depends on it.
Where the company resells or embeds an AI capability, the terms it gives its own customers should not promise more than the upstream provider gives it. Back-to-back review of the two contracts is the cheapest protection available.
Intellectual property in development work
Trading, logistics and commodity businesses in DMCC often commission development work from contractors abroad. Ownership of code, models and training data should be dealt with expressly in the development agreement rather than assumed from payment. Where a contractor reuses a common framework across clients, the company needs to know what it owns outright, what it holds under licence, and what it cannot prevent the contractor from reusing elsewhere.
Accountability for what the system produces
A DMCC company remains answerable to its customers and counterparties for the decisions it takes, whether or not a model produced them. Contracts, statements to customers and regulatory obligations attach to the company, not to the software.
Making that defensible means keeping ordinary records: which version of a system was used, what data it worked from, who reviewed the result and what they were entitled to change. Where a decision affects a customer or an employee, human review should be genuine, not a signature added afterwards.
Employment and internal tools
Employment relationships in DMCC are governed by the federal employment law, Federal Decree-Law No. 33 of 2021, which replaced Federal Law No. 8 of 1980. Systems that screen applicants, monitor productivity or feed into decisions about staff process personal data about identifiable people and should be assessed before they are switched on. Staff use of external AI tools also needs a stated position: without one, confidential material reaches third-party systems the company has never reviewed.
Disputes
Disputes about AI systems look like ordinary commercial disputes: a product that does not perform as demonstrated, data used beyond the agreed scope, arguments over ownership of output, and claims following a decision the system got wrong. The forum should be settled in the contract rather than argued later. Arbitration in the UAE is governed by Federal Law No. 6 of 2018, as amended in 2023. Clause drafting deserves attention because institutional options changed: the DIFC-LCIA Arbitration Centre was abolished by Dubai Decree No. 34 of 2021 and its caseload moved to the Dubai International Arbitration Centre, so older templates naming it need correcting. Sound drafting at signature avoids most technology dispute resolution work afterwards.
Conclusion
For a DMCC company, AI compliance is a set of specific checks rather than a single filing. Does the licence cover what the product now does? Is there a lawful basis for the data behind the model under the federal data protection law? Do the vendor terms allocate risk in a way the business would defend to a customer? Can the company show who was accountable for a given output?
Companies that answer those questions before launch, and keep the answers on file, are in a far stronger position than those that reconstruct them under pressure.
For guidance on AI projects, data protection or technology contracts in DMCC, contact the Nour Attorneys team.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Related Resources
Explore more of our insights on related topics:
- AI Regulations Compliance Requirements in the UAE
- Blockchain Legal Defense Strategies for Dubai Businesses
- Cryptocurrency Compliance Guidelines for UAE Operators
- Data Privacy Laws for Multinational Entities