Find an AI & Technology Governance Lawyer
The honest starting point for artificial intelligence in the UAE is also the most useful one, and almost nobody leads with it: there is no UAE federal AI statute. A search of the federal legislation portal returns only policy documents on AI, filed under Public Policies rather than Legislations. What actually governs an AI deployment here today is a set of instruments that were not written for it — a data protection law whose executive regulations have never been issued, a child safety law that mandates AI rather than restricting it, a copyright law that does not mention AI at all, a cybercrime law with an offence about “e-robots”, one DIFC regulation, and a financial-sector guidance document whose own status is unclear. LEXNOVA is not a law firm. It is a lawyer-matching service, it gives no legal advice, and it does not review AI systems, policies or contracts. It connects founders, product teams, boards and in-house counsel with independent UAE lawyers who work in this area across Dubai mainland, DIFC, Abu Dhabi mainland and ADGM. Every match is reviewed by a person, and the professional relationship is always directly between you and the lawyer you choose.
LAST REVIEWED 22 SEPTEMBER 2026
Example AI & Technology Governance Matters
- Assessing whether an automated decision-making feature engages the data protection law’s objection right
- Preparing a data protection impact assessment before launching a profiling or scoring system
- Reviewing training-data provenance where UAE copyright law has no text-and-data-mining exception
- Advising a platform directed at UAE users on the Child Digital Safety Law’s detection and age-verification duties
- Working out which of the four jurisdictions a product sits in before choosing a compliance baseline
- Advising a DIFC business on the regulation covering autonomous and semi-autonomous systems
- Assessing criminal exposure for synthetic media, automated accounts or generated content
- Setting AI governance for a financial institution where the sector guidance is neither binding nor final
WHO MAY NEED THIS
This category is for anyone deploying, building or buying AI in the UAE who needs to know what actually applies rather than what a policy document aspires to: founders and product teams shipping AI features to UAE users, boards and in-house counsel writing an AI governance policy, HR teams using automated screening, financial institutions working out what the sector guidance obliges them to do, and platforms with UAE-directed services. It is also for anyone handed a compliance memorandum citing UAE AI “rules” who wants to know which of them are law.
There is no UAE federal AI statute — start there
The most valuable thing anyone can tell you about artificial intelligence and UAE law is the thing most content avoids saying: there is no federal AI statute. A search of the federal legislation portal returns only policy documents on AI, and the portal itself classifies them under Public Policies rather than Legislations. That classification is not a technicality — it is the clearest evidence available of what these instruments are and are not.
The federal government’s own AI-in-government material names a UAE Strategy for Artificial Intelligence, a National Program for Artificial Intelligence known as BRAIN, a Generative AI Guide, and an AI and Coding Licence issued by the DIFC with the UAE AI Office. A strategy, a programme, a guide and a licence — none of them binding legislation. So an AI governance exercise here cannot be run by finding the AI law and complying with it. It runs the other way round: identify what the system actually does, then work out which existing general laws reach each part of it.
The Artificial Intelligence and Data Authority: announced, named, not yet constituted on paper
The UAE Cabinet’s own page confirms the name is the Artificial Intelligence and Data Authority. It is not the “Federal Authority for Artificial Intelligence and Data”, a formulation that circulates widely and is wrong. It was announced in June 2026, consolidating three named bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector at the TDRA, and the UAE Data Office.
The important point is what the announcement does not contain. The Cabinet page cites no Federal Decree-Law, Federal Law, Cabinet Decision or Resolution, and no establishing instrument had been published as at 22 September 2026, three months after the announcement. You cannot build a compliance programme against an authority’s powers before those powers exist on paper. Comply with the laws actually in force, keep the governance documentation any future regime would expect, and have a lawyer watch for the establishing instrument.
The closest thing to a binding AI rule sits in the data protection law
Article 18(1) of Federal Decree-Law No. 45 of 2021 provides that a data subject has the right to object to decisions resulting from automated processing. That is the nearest thing UAE law has to a binding rule on automated decision-making, and it is the provision most AI deployments touching individuals will engage first. Article 17 sits beside it, giving a right to stop processing, including profiling for direct marketing.
Between them these two articles cover much of what commercial AI systems actually do to people: score them, segment them, rank them, and decide something about them with no human in the loop. The question a lawyer will ask is not whether you use AI, but where a decision with consequences for a person is produced without human involvement, and what happens when that person objects.
Impact assessments and data protection officers
Article 21 requires an impact assessment before processing that uses modern technologies posing a high privacy risk, expressly covering systematic assessment including profiling that has legal consequences, and large-scale processing of sensitive data. A great many AI deployments — recruitment screening, eligibility scoring, behavioural profiling — read naturally onto that description.
Article 10 deals with appointing a Data Protection Officer, triggered where processing carries a high confidentiality risk, involves systematic assessment of sensitive data, or involves large volumes of sensitive data. An AI system doing continuous automated evaluation can satisfy more than one trigger at once. Articles 22 and 23 address cross-border transfer; this page does not paraphrase their conditions, because they should be read in full against a specific architecture before data starts moving.
The executive regulations that never arrived
Article 28 required executive regulations to be issued within six months. Article 31 brought the law into force on 2 January 2022. The executive regulations have still not been issued — more than four years past the Article 28 deadline. This is the defining feature of the UAE data protection regime as it currently stands, and it is more consequential for AI than any policy document.
The effect is a statute with substantive rights and no implementing detail: the Article 18(1) right to object to an automated decision exists without the machinery that would normally specify how it is exercised and enforced. Two wrong conclusions get drawn. The first is that the law can be ignored because the regulations have not arrived — it has been in force since January 2022. The second is that a future commencement date is known, and it is not: this page publishes no date for regulations that have not been issued.
The one in-force statute that names AI — and it mandates it
Federal Decree-Law No. 26 of 2025, the Child Digital Safety Law, is the only in-force UAE federal statute that expressly mentions artificial intelligence. Article 10 requires blocking and filtering, immediate reporting of child sexual abuse material and harmful content, and expressly requires platforms to leverage artificial intelligence systems and machine-learning algorithms for proactive detection — alongside default privacy settings, parental controls, time limits, age-based restrictions and the disabling of engagement-maximising features. The single statutory reference to AI in UAE federal law is a requirement to use it, not a restriction on using it.
Scope comes from Article 3, reaching internet service providers and digital platforms operating in or directed at UAE users — websites, search engines, apps, gaming, social media, streaming and e-commerce — and child caregivers. Article 7 requires explicit parental consent for collecting data from children under 13, with restrictions on commercial use and targeted advertising and possible exemptions for education and health platforms. Article 8 requires effective and reasonable age verification calibrated to platform risk. Article 20 brought the law into force on 1 January 2026, Article 18 gives a one-year grace period to regularise which the Cabinet may extend, and Article 16 leaves the administrative penalties regulation to the Cabinet.
Copyright: no AI, and no training exception
Artificial intelligence is not mentioned anywhere in Federal Decree-Law No. 38 of 2021 on Copyright and Neighbouring Rights. There is no provision on AI authorship and none on computer-generated works. Article 1 defines an Author as a person who creates a work, whose name is mentioned on it or to whom it is ascribed, and a Work as any creative product in the field of letters, arts or science — definitions not drafted with generated output in mind.
On the input side there is no text-and-data-mining exception and no machine-learning training exception. The nearest provision, Article 22(8), permits copying short parts of a work for educational purposes, and it does not cover algorithmic training. So there is no lawful-training carve-out in UAE copyright law to rely on. Training-data provenance is therefore a legal question here, not only an ethical one, and ownership of generated output has to be settled in contract because the statute provides no default. The executive regulations sit in Cabinet Resolution No. 47 of 2022, whose contents were not read.
Cybercrime: Articles 44, 52 and the e-robot provision
Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes came into force on 2 January 2022 and repealed Decree-Law No. 5 of 2012. Article 44 covers using an information system or IT means to modify or process any record, photo or scene with intent to defame or insult, carrying imprisonment of at least one year and/or a fine of AED 250,000 to AED 500,000. That is the provision reaching deepfakes — but note how it is framed, around defamation and insult rather than around synthesis.
Article 52 covers disseminating false news, data or misleading rumours via information networks, with at least one year’s imprisonment plus a minimum fine of AED 100,000 and enhanced penalties during crises. Article 54 is the one worth knowing about: creating or modifying “e-robots” with intent to disseminate or circulate false data or news, carrying up to two years’ imprisonment and a fine of AED 100,000 to AED 1,000,000 — the nearest thing in UAE law to a bot or automated-agent offence. Across the whole decree-law, no article specifically addresses AI-generated synthetic media as such.
DIFC has one AI-adjacent instrument. ADGM has none.
DIFC Data Protection Regulation 10 was enacted on 7 September 2023 and governs the processing of personal data via autonomous and semi-autonomous systems such as artificial intelligence and generative or machine-learning technology. DIFC describes it as the first enacted regulation in the MEASA region addressing the point, and as outcomes-based rather than prescriptive, with guidance to follow. This page states that it exists and what it covers and deliberately stops there: its specific obligations were not read, and an outcomes-based instrument is exactly the kind that should not be paraphrased second-hand.
ADGM, by contrast, has no AI-specific rulebook module. That asymmetry is real and is usually reported the wrong way round, or not at all — the two centres are frequently described as though their positions mirror each other. For a business choosing between them for an AI-driven product, a binding AI-adjacent instrument in one and none in the other is a genuine difference.
The instruments that look like rules and are not
The Guidelines for Financial Institutions adopting Enabling Technologies were issued jointly by the Central Bank of the UAE, the Securities and Commodities Authority, the DFSA and the FSRA. Section 6 covers Big Data Analytics and AI and reads like a serious governance standard: documented governance and pre-launch validation with ongoing training, calibration and review; senior-leadership accountability for AI outcomes including autonomous ones; reliability, transparency and explainability proportionate to materiality; fair, objective, consistent and ethical outcomes with anti-discrimination compliance; plain-language customer disclosure of AI use and risks; five-year retention of audit logs, design documentation, model versions, datasets and performance tracking; and continuous monitoring of algorithm reliability, fairness, accuracy and relevance.
Their status, however, is genuinely ambiguous, and the honest thing is to report it that way rather than resolve it. The hosted copy is watermarked “Draft for Discussion Purposes Only” and states that the Guidelines are not to be considered Regulations or Standards issued by the supervisory authorities — while in the same document describing the Section 2 principles as binding on all institutions adopting enabling technologies, with Sections 3 to 7 as guidance institutions may adopt. No issue date appears. They should not be described as binding, and they should not be described as final.
The UAE Charter for the Development and Use of Artificial Intelligence sits in a clearer but often misrepresented category. Issued on 10 June 2024, it is published on the federal legislation portal under Public Policies rather than Legislations, and sets out thirteen principles covering ethical and responsible use, privacy and data security, balancing advancement with social values, innovation and economic growth, awareness and education, transparency and accountability, algorithmic bias, human oversight, governance and accountability frameworks, technological excellence, human-centred commitment, peaceful coexistence, and compliance with international treaties and local laws. It is a policy charter, not law: it creates no enforceable obligation and no regulator has power to enforce it.
START YOUR REQUEST
Tell Us About Your Matter.
The matter type is already set to AI & Technology Governance, so the form begins with your location. LEXNOVA is a lawyer-matching service, not a law firm — any legal advice comes directly from the independent legal professional you are connected with.
HOW LEXNOVA LEGAL CONNECT WORKS
Tell us what you need, we review your requirements against practice area, location, and language, and — where appropriate — help facilitate an introduction to a potentially suitable legal professional. The legal advice itself is always provided directly by that professional.
See the full processFAQ
RELATED LEGAL GUIDES
LEXNOVA is not a law firm and does not provide legal advice, legal opinions, legal representation, or legal services. Any legal advice or representation is provided directly by the independent legal professional engaged by the client.
A connection or introduction does not constitute a guarantee, endorsement, or assurance of outcome. Users should independently confirm the professional's qualifications, authorization, fees, scope of engagement, and suitability.