Company logo
About usExpertiseOur peopleFrameworksInsightsContactsالعربية
About usAbout usExpertiseExpertiseOur peopleOur peopleFrameworksFrameworksInsightsInsightsContactsContactsالعربيةالعربية
← InsightsArticles

AI Regulations in UAE Federal: Complete Guide

Delegating a decision to software does not delegate responsibility for it.

Relief at the absence of a dedicated federal AI law is misplaced: the obligations are spread across the general law, and it falls to the business to work out which ones bite. This guide maps them — what the Personal Data Protection Law requires on purpose, offshore hosting and individual requests, which vendor contract terms actually allocate the risk, how an employment decision supported by a model has to be justified, what a board should be able to show it asked before approving a system, and where a sector regulator's rulebook comes ahead of the general position.

By Nour Attorneys / 24 August 2026

There is no single AI statute, and that is the point

Companies putting artificial intelligence to work in the UAE often ask which AI law they need to comply with, and are relieved to hear there is no dedicated federal AI statute. That relief is misplaced. The absence of one specific law does not mean the activity is unregulated; it means the obligations are spread across the general law, and the burden of working out which ones bite falls on the business. A model that screens job applicants, prices insurance, scores credit, moderates content or answers customers is doing something the law already has views about, whether or not the word "algorithm" appears anywhere in the text.

The useful question is therefore not "is AI regulated" but "what is this system deciding, about whom, using what data, and who is accountable when it is wrong". Every obligation described below follows from the answer.

Personal data is the main constraint

Federal Decree-Law No. 45 of 2021, the Personal Data Protection Law, is where most AI compliance work actually lands, because most useful models are trained on or applied to personal data. The federal regime governs how personal data may be processed and imposes duties on those who determine the purpose of processing and on those who process on their behalf. DIFC and ADGM operate their own data regimes under their own regulators, the DFSA and the FSRA, so a group with entities inside and outside those jurisdictions is complying with more than one rulebook and should not assume a single privacy notice covers all of them.

Three points are worth settling before a model goes live.

  • Purpose. Data collected for one purpose is not automatically available to train a model for another. If customer support transcripts were gathered to resolve tickets, using them to build a product is a separate question that needs its own answer.
  • Transfers. Most AI infrastructure is hosted abroad. Know where the data physically goes, including logs, prompts, fine-tuning sets and backups, and address transfers explicitly rather than by silence.
  • Individual requests. If a person asks what you hold about them, you need to be able to answer. Design that capability in; retrofitting it into a training pipeline is far harder than building it.

Contracts with model vendors

Federal Decree-Law No. 50 of 2022 on Commercial Transactions replaced Federal Law No. 18 of 1993 and governs commercial contracts under UAE law. AI vendor agreements are usually drafted by the vendor and allocate risk accordingly. Read them for the following, and negotiate where the exposure is real:

  • Whether your inputs may be used to train the vendor's models, and whether you can switch that off.
  • Who owns the outputs, and what warranty if any is given that outputs do not infringe third-party rights.
  • What the vendor promises about accuracy. Usually nothing, which means the accuracy risk sits with you and should be managed in how you use the system rather than in the contract.
  • Whether the vendor may change or withdraw the model, and what notice you get. A model that is silently updated can change the behaviour of a product you are responsible for.
  • Sub-processing and hosting locations, which connect straight back to the data analysis above.

AI in employment decisions

Federal Decree-Law No. 33 of 2021 replaced Federal Law No. 8 of 1980 and governs the employment relationship. Where AI is used to shortlist candidates, monitor performance or support a decision to dismiss, the legal exposure is not really about the model. It is about whether the decision can be explained and justified on grounds the law recognises. A manager who cannot say why an employee was selected, beyond pointing at a score, is in a weak position. Keep a human decision-maker who reviews the recommendation, records reasons in their own words, and can produce the underlying facts. Tell employees what monitoring is in place rather than letting them discover it.

Accountability inside the company

Federal Decree-Law No. 32 of 2021 on Commercial Companies, in force 2 January 2022, replaced Federal Law No. 2 of 2015 and sets the framework for how companies are managed and how directors answer for that management. Delegating a decision to software does not delegate responsibility for it. Boards approving AI systems that affect customers, pricing or safety should be able to show they asked what the system does, what it might get wrong, and who monitors it in production.

In practice that means keeping a short, current record for each system in use: its purpose, the data it relies on, who owns it internally, what human review applies, what testing was done before launch, and what happens when it fails. That record is unglamorous and it is the first thing anyone will ask for, whether the questioner is a regulator, an insurer, an acquirer or a claimant.

Sector regulators come first

Where an activity is already regulated, its regulator's rules apply to the AI used in it. Financial services, healthcare, insurance and telecommunications each have supervisory authorities whose existing requirements on suitability, record-keeping, outsourcing and customer treatment do not pause because a model is involved. DIFC and ADGM firms answer to the DFSA and the FSRA respectively under common-law frameworks. Check the sector rulebook before assuming general law is the whole picture.

Claims about what your AI can do

Marketing copy becomes a contractual and regulatory problem when it overstates capability. Statements that a system is accurate, unbiased, compliant or approved should be ones you could evidence if challenged. This is the cheapest exposure to remove: make the product page say what the system does, with its limits, and keep the testing that supports it.

When it goes wrong

Disputes about AI systems tend to turn on ordinary contract questions: what was promised, what was delivered, who bore which risk, and where the argument is heard. Federal Law No. 6 of 2018, amended in 2023, governs arbitration seated in the UAE. The DIFC-LCIA was abolished by Dubai Decree No. 34 of 2021 and its caseload moved to DIAC, while DIFC remains available as a seat; ADCCAC was restructured as arbitrateAD from 2024. Contracts that still name the abolished institution should be corrected by agreement now. A clear, consistent dispute clause across your vendor and customer contracts is the single most effective preparation for technology dispute resolution, and it is the clause most often left to whatever the template said.

Where to start

  1. List the AI systems actually in use, including the ones a team adopted without telling anyone.
  2. For each, record its purpose, its data, its owner and the human review that applies.
  3. Map personal data against the PDPL, including transfers outside the UAE.
  4. Review vendor terms on training, ownership, model changes and hosting.
  5. Check the sector rulebook where the activity is separately regulated.
  6. Align the dispute clause across the contract stack.

For advice on AI use in your organisation, or on vendor terms you have been asked to sign, contact the Nour Attorneys team.

Schedule Your Consultation

Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.

Nour Attorneys Team

Related Resources

Explore more of our insights on related topics:

  • AI Regulations Compliance Requirements in the UAE
  • Blockchain Legal Defense Strategies for Dubai Businesses
  • Cryptocurrency Compliance Guidelines for UAE Operators
  • Data Privacy Laws for Multinational Entities
Contact Us

Location

Silver Tower Floor 20, Office 2003 Business Bay Dubai, United Arab Emirates (UAE)
Working hours
Mon–Fri: 9am — 6pm

Navigation

  • About Us
  • Expertise
  • Our People
  • ESG & Sustainability
  • Insights
  • Contacts

Social Media

  • LinkedIn
  • Instagram

Contacts

  • Telephone: +971 58 555 2999
  • WhatsApp: +971 58 555 2999
  • Chatbot
Founding Member - SKP Business Federation
INFO@NOURATTORNEYS.COM
Copyright © 2025 Nour Attorneys. All Rights Reserved
Privacy Policy
Call Us NowChat With Our Team On WhatsApp