PRACTICE AREA

Find an AI & Technology Governance Lawyer

The honest starting point for artificial intelligence in the UAE is also the most useful one, and almost nobody leads with it: there is no UAE federal AI statute. A search of the federal legislation portal returns only policy documents on AI, filed under Public Policies rather than Legislations. What actually governs an AI deployment here today is a set of instruments that were not written for it — a data protection law whose executive regulations have never been issued, a child safety law that mandates AI rather than restricting it, a copyright law that does not mention AI at all, a cybercrime law with an offence about “e-robots”, one DIFC regulation, and a financial-sector guidance document whose own status is unclear. LEXNOVA is not a law firm. It is a lawyer-matching service, it gives no legal advice, and it does not review AI systems, policies or contracts. It connects founders, product teams, boards and in-house counsel with independent UAE lawyers who work in this area across Dubai mainland, DIFC, Abu Dhabi mainland and ADGM. Every match is reviewed by a person, and the professional relationship is always directly between you and the lawyer you choose.

LAST REVIEWED 22 SEPTEMBER 2026

Example AI & Technology Governance Matters

  • Assessing whether an automated decision-making feature engages the data protection law’s objection right
  • Preparing a data protection impact assessment before launching a profiling or scoring system
  • Reviewing training-data provenance where UAE copyright law has no text-and-data-mining exception
  • Advising a platform directed at UAE users on the Child Digital Safety Law’s detection and age-verification duties
  • Working out which of the four jurisdictions a product sits in before choosing a compliance baseline
  • Advising a DIFC business on the regulation covering autonomous and semi-autonomous systems
  • Assessing criminal exposure for synthetic media, automated accounts or generated content
  • Setting AI governance for a financial institution where the sector guidance is neither binding nor final

WHO MAY NEED THIS

This category is for anyone deploying, building or buying AI in the UAE who needs to know what actually applies rather than what a policy document aspires to: founders and product teams shipping AI features to UAE users, boards and in-house counsel writing an AI governance policy, HR teams using automated screening, financial institutions working out what the sector guidance obliges them to do, and platforms with UAE-directed services. It is also for anyone handed a compliance memorandum citing UAE AI “rules” who wants to know which of them are law.

There is no UAE federal AI statute — start there

The most valuable thing anyone can tell you about artificial intelligence and UAE law is the thing most content avoids saying: there is no federal AI statute. A search of the federal legislation portal returns only policy documents on AI, and the portal itself classifies them under Public Policies rather than Legislations. That classification is not a technicality — it is the clearest evidence available of what these instruments are and are not.

The federal government’s own AI-in-government material names a UAE Strategy for Artificial Intelligence, a National Program for Artificial Intelligence known as BRAIN, a Generative AI Guide, and an AI and Coding Licence issued by the DIFC with the UAE AI Office. A strategy, a programme, a guide and a licence — none of them binding legislation. So an AI governance exercise here cannot be run by finding the AI law and complying with it. It runs the other way round: identify what the system actually does, then work out which existing general laws reach each part of it.

The Artificial Intelligence and Data Authority: announced, named, not yet constituted on paper

The UAE Cabinet’s own page confirms the name is the Artificial Intelligence and Data Authority. It is not the “Federal Authority for Artificial Intelligence and Data”, a formulation that circulates widely and is wrong. It was announced in June 2026, consolidating three named bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector at the TDRA, and the UAE Data Office.

The important point is what the announcement does not contain. The Cabinet page cites no Federal Decree-Law, Federal Law, Cabinet Decision or Resolution, and no establishing instrument had been published as at 22 September 2026, three months after the announcement. You cannot build a compliance programme against an authority’s powers before those powers exist on paper. Comply with the laws actually in force, keep the governance documentation any future regime would expect, and have a lawyer watch for the establishing instrument.

The closest thing to a binding AI rule sits in the data protection law

Article 18(1) of Federal Decree-Law No. 45 of 2021 provides that a data subject has the right to object to decisions resulting from automated processing. That is the nearest thing UAE law has to a binding rule on automated decision-making, and it is the provision most AI deployments touching individuals will engage first. Article 17 sits beside it, giving a right to stop processing, including profiling for direct marketing.

Between them these two articles cover much of what commercial AI systems actually do to people: score them, segment them, rank them, and decide something about them with no human in the loop. The question a lawyer will ask is not whether you use AI, but where a decision with consequences for a person is produced without human involvement, and what happens when that person objects.

Impact assessments and data protection officers

Article 21 requires an impact assessment before processing that uses modern technologies posing a high privacy risk, expressly covering systematic assessment including profiling that has legal consequences, and large-scale processing of sensitive data. A great many AI deployments — recruitment screening, eligibility scoring, behavioural profiling — read naturally onto that description.

Article 10 deals with appointing a Data Protection Officer, triggered where processing carries a high confidentiality risk, involves systematic assessment of sensitive data, or involves large volumes of sensitive data. An AI system doing continuous automated evaluation can satisfy more than one trigger at once. Articles 22 and 23 address cross-border transfer; this page does not paraphrase their conditions, because they should be read in full against a specific architecture before data starts moving.

The executive regulations that never arrived

Article 28 required executive regulations to be issued within six months. Article 31 brought the law into force on 2 January 2022. The executive regulations have still not been issued — more than four years past the Article 28 deadline. This is the defining feature of the UAE data protection regime as it currently stands, and it is more consequential for AI than any policy document.

The effect is a statute with substantive rights and no implementing detail: the Article 18(1) right to object to an automated decision exists without the machinery that would normally specify how it is exercised and enforced. Two wrong conclusions get drawn. The first is that the law can be ignored because the regulations have not arrived — it has been in force since January 2022. The second is that a future commencement date is known, and it is not: this page publishes no date for regulations that have not been issued.

The one in-force statute that names AI — and it mandates it

Federal Decree-Law No. 26 of 2025, the Child Digital Safety Law, is the only in-force UAE federal statute that expressly mentions artificial intelligence. Article 10 requires blocking and filtering, immediate reporting of child sexual abuse material and harmful content, and expressly requires platforms to leverage artificial intelligence systems and machine-learning algorithms for proactive detection — alongside default privacy settings, parental controls, time limits, age-based restrictions and the disabling of engagement-maximising features. The single statutory reference to AI in UAE federal law is a requirement to use it, not a restriction on using it.

Scope comes from Article 3, reaching internet service providers and digital platforms operating in or directed at UAE users — websites, search engines, apps, gaming, social media, streaming and e-commerce — and child caregivers. Article 7 requires explicit parental consent for collecting data from children under 13, with restrictions on commercial use and targeted advertising and possible exemptions for education and health platforms. Article 8 requires effective and reasonable age verification calibrated to platform risk. Article 20 brought the law into force on 1 January 2026, Article 18 gives a one-year grace period to regularise which the Cabinet may extend, and Article 16 leaves the administrative penalties regulation to the Cabinet.

Artificial intelligence is not mentioned anywhere in Federal Decree-Law No. 38 of 2021 on Copyright and Neighbouring Rights. There is no provision on AI authorship and none on computer-generated works. Article 1 defines an Author as a person who creates a work, whose name is mentioned on it or to whom it is ascribed, and a Work as any creative product in the field of letters, arts or science — definitions not drafted with generated output in mind.

On the input side there is no text-and-data-mining exception and no machine-learning training exception. The nearest provision, Article 22(8), permits copying short parts of a work for educational purposes, and it does not cover algorithmic training. So there is no lawful-training carve-out in UAE copyright law to rely on. Training-data provenance is therefore a legal question here, not only an ethical one, and ownership of generated output has to be settled in contract because the statute provides no default. The executive regulations sit in Cabinet Resolution No. 47 of 2022, whose contents were not read.

Cybercrime: Articles 44, 52 and the e-robot provision

Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes came into force on 2 January 2022 and repealed Decree-Law No. 5 of 2012. Article 44 covers using an information system or IT means to modify or process any record, photo or scene with intent to defame or insult, carrying imprisonment of at least one year and/or a fine of AED 250,000 to AED 500,000. That is the provision reaching deepfakes — but note how it is framed, around defamation and insult rather than around synthesis.

Article 52 covers disseminating false news, data or misleading rumours via information networks, with at least one year’s imprisonment plus a minimum fine of AED 100,000 and enhanced penalties during crises. Article 54 is the one worth knowing about: creating or modifying “e-robots” with intent to disseminate or circulate false data or news, carrying up to two years’ imprisonment and a fine of AED 100,000 to AED 1,000,000 — the nearest thing in UAE law to a bot or automated-agent offence. Across the whole decree-law, no article specifically addresses AI-generated synthetic media as such.

DIFC has one AI-adjacent instrument. ADGM has none.

DIFC Data Protection Regulation 10 was enacted on 7 September 2023 and governs the processing of personal data via autonomous and semi-autonomous systems such as artificial intelligence and generative or machine-learning technology. DIFC describes it as the first enacted regulation in the MEASA region addressing the point, and as outcomes-based rather than prescriptive, with guidance to follow. This page states that it exists and what it covers and deliberately stops there: its specific obligations were not read, and an outcomes-based instrument is exactly the kind that should not be paraphrased second-hand.

ADGM, by contrast, has no AI-specific rulebook module. That asymmetry is real and is usually reported the wrong way round, or not at all — the two centres are frequently described as though their positions mirror each other. For a business choosing between them for an AI-driven product, a binding AI-adjacent instrument in one and none in the other is a genuine difference.

The instruments that look like rules and are not

The Guidelines for Financial Institutions adopting Enabling Technologies were issued jointly by the Central Bank of the UAE, the Securities and Commodities Authority, the DFSA and the FSRA. Section 6 covers Big Data Analytics and AI and reads like a serious governance standard: documented governance and pre-launch validation with ongoing training, calibration and review; senior-leadership accountability for AI outcomes including autonomous ones; reliability, transparency and explainability proportionate to materiality; fair, objective, consistent and ethical outcomes with anti-discrimination compliance; plain-language customer disclosure of AI use and risks; five-year retention of audit logs, design documentation, model versions, datasets and performance tracking; and continuous monitoring of algorithm reliability, fairness, accuracy and relevance.

Their status, however, is genuinely ambiguous, and the honest thing is to report it that way rather than resolve it. The hosted copy is watermarked “Draft for Discussion Purposes Only” and states that the Guidelines are not to be considered Regulations or Standards issued by the supervisory authorities — while in the same document describing the Section 2 principles as binding on all institutions adopting enabling technologies, with Sections 3 to 7 as guidance institutions may adopt. No issue date appears. They should not be described as binding, and they should not be described as final.

The UAE Charter for the Development and Use of Artificial Intelligence sits in a clearer but often misrepresented category. Issued on 10 June 2024, it is published on the federal legislation portal under Public Policies rather than Legislations, and sets out thirteen principles covering ethical and responsible use, privacy and data security, balancing advancement with social values, innovation and economic growth, awareness and education, transparency and accountability, algorithmic bias, human oversight, governance and accountability frameworks, technological excellence, human-centred commitment, peaceful coexistence, and compliance with international treaties and local laws. It is a policy charter, not law: it creates no enforceable obligation and no regulator has power to enforce it.

START YOUR REQUEST

Tell Us About Your Matter.

The matter type is already set to AI & Technology Governance, so the form begins with your location. LEXNOVA is a lawyer-matching service, not a law firm — any legal advice comes directly from the independent legal professional you are connected with.

Step 2 of 540%

Where is your matter located?

HOW LEXNOVA LEGAL CONNECT WORKS

Tell us what you need, we review your requirements against practice area, location, and language, and — where appropriate — help facilitate an introduction to a potentially suitable legal professional. The legal advice itself is always provided directly by that professional.

See the full process

FAQ

No federal AI statute exists. A search of the federal legislation portal returns only policy documents on AI, and they are filed under Public Policies rather than Legislations — the portal’s own classification being the clearest available evidence of their status. What applies to AI in the UAE today is a set of general laws written for other purposes, plus one DIFC regulation.

Not as far as the public record shows. The Cabinet page announcing it cites no Federal Decree-Law, Federal Law, Cabinet Decision or Resolution, and no establishing instrument had been published as at 22 September 2026 — three months after the announcement. So there is an announced authority without, so far, a published legal basis setting out its powers.

Three named bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector at the TDRA, and the UAE Data Office. That consolidation is the substance of what was announced. What powers the combined body will hold, and over whom, the announcement does not establish.

Article 18(1) of Federal Decree-Law No. 45 of 2021, the data protection law, provides that a data subject has the right to object to decisions resulting from automated processing. That is the closest thing UAE law has to a binding rule on automated decision-making, and the provision most likely to be engaged by an AI feature that makes or materially shapes decisions about people.

The right exists in the statute, but the enforcement machinery does not yet exist. Article 28 required executive regulations to be issued within six months, and they have still not been issued — more than four years past that deadline. So the right sits on the books without the machinery that would normally set out how it is exercised and enforced.

Article 31 of Federal Decree-Law No. 45 of 2021 brought it into force on 2 January 2022. It has been in force for years, a useful corrective to content describing it as new or forthcoming. What has not happened in that time is the issuing of its executive regulations, and that gap defines the regime as it stands.

Possibly. Article 21 of the data protection law requires an impact assessment before processing that uses modern technologies posing a high privacy risk, expressly covering systematic assessment including profiling having legal consequences, and large-scale sensitive data. Many AI deployments that score, rank or decide about people sit within that description, making this an early question for a lawyer.

Article 10 of the data protection law sets the triggers: processing that carries a high confidentiality risk, processing involving systematic assessment of sensitive data, or processing of large volumes of sensitive data. An AI system doing continuous automated assessment can meet more than one trigger at once, so settle the appointment question before launch.

Cross-border transfer is dealt with at Articles 22 and 23 of the data protection law. This page does not set out what those articles require, because those conditions should be read in full rather than paraphrased. If a model, vendor or cloud region sits outside the UAE, take it to a lawyer before data starts moving.

One does. Article 10 of Federal Decree-Law No. 26 of 2025, the Child Digital Safety Law, expressly requires platforms to leverage artificial intelligence systems and machine-learning algorithms for proactive detection. It is the only in-force UAE federal statute that expressly mentions AI, and that mention requires the technology rather than constraining it.

It requires it. Article 10 obliges in-scope platforms to use AI and machine learning for proactive detection, alongside blocking and filtering, immediate reporting of child sexual abuse material and harmful content, default privacy settings, parental controls, time limits and age-based restrictions. Anyone expecting the UAE’s first statutory reference to AI to be a restriction has it backwards.

Article 3 applies it to internet service providers and digital platforms operating in or directed at UAE users — websites, search engines, apps, gaming, social media, streaming and e-commerce — and to child caregivers. The “directed at UAE users” limb catches businesses without a UAE establishment, so a platform outside the country should not assume it is outside the law.

Article 7 requires explicit parental consent for the collection of data from children under 13, and imposes restrictions on commercial use and targeted advertising, with possible exemptions for education and health platforms. For a product with any realistic under-13 audience that is a design constraint, and it should be settled before the consent flow is built.

Article 8 requires effective and reasonable age-verification mechanisms calibrated to the platform’s risk. The calibration language matters: the obligation is not one prescribed method applied uniformly, but a mechanism proportionate to what the platform exposes a child to. How that applies to a product is a question for a lawyer who has seen it.

Article 20 brought it into force on 1 January 2026. Article 18 provides a one-year grace period to regularise, extendable by Cabinet Resolution, and Article 16 leaves the administrative penalties regulation to the Cabinet. A platform relying on the grace period should have a lawyer confirm how it applies rather than assuming a general amnesty.

There is no text-and-data-mining exception and no machine-learning training exception in Federal Decree-Law No. 38 of 2021 on Copyright and Neighbouring Rights. The nearest provision, Article 22(8), permits copying short parts of a work for educational purposes, and it does not cover algorithmic training. So there is no lawful-training carve-out to rely on, and anyone told otherwise should ask to see the provision.

The copyright law gives no statutory answer. Artificial intelligence is not mentioned anywhere in Federal Decree-Law No. 38 of 2021, and there is no provision on AI authorship or computer-generated works. Article 1 defines an Author as a person who creates a work and a Work as any creative product in letters, arts or science. Where ownership of generated output matters commercially, it has to be handled in contract, because the statute does not resolve it.

Article 44 of Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes covers using an information system or IT means to modify or process any record, photo or scene with intent to defame or insult, carrying imprisonment of at least one year and/or a fine of AED 250,000 to AED 500,000. That is the provision reaching deepfakes — but it is framed around defamation and insult rather than synthesis.

Article 52 of the cybercrime law covers disseminating false news, data or misleading rumours via information networks, carrying at least one year’s imprisonment plus a minimum fine of AED 100,000, with enhanced penalties during crises. It does not turn on how the content was produced, so generated material is assessed like anything else circulated on a network.

Article 54 of the cybercrime law is the nearest thing. It covers creating or modifying “e-robots” with intent to disseminate or circulate false data or news, carrying up to two years’ imprisonment and a fine of AED 100,000 to AED 1,000,000. It is narrow and intent-based rather than a general regulation of automated agents, but it is the closest UAE law comes to naming the thing.

No article of the cybercrime law addresses AI-generated synthetic media as such. Exposure arises through general offences — modification of a record, photo or scene with intent to defame or insult, dissemination of false news, and the e-robot provision. The analysis turns on what the content does and what was intended, not on how it was made.

Yes. DIFC Data Protection Regulation 10, enacted on 7 September 2023, governs the processing of personal data via autonomous and semi-autonomous systems such as artificial intelligence and generative or machine-learning technology. DIFC describes it as the first enacted regulation in the MEASA region on the point and as outcomes-based rather than prescriptive. This page does not state what it requires — its specific obligations were not read and should be read with a lawyer.

No. ADGM has no AI-specific rulebook module. That asymmetry — DIFC with one binding AI-adjacent instrument, ADGM with none — is usually reported the other way round or not at all, and it is a genuine structural difference between the two centres.

Their status is genuinely ambiguous. The Guidelines for Financial Institutions adopting Enabling Technologies were issued jointly by the Central Bank of the UAE, the Securities and Commodities Authority, the DFSA and the FSRA. The hosted copy is watermarked “Draft for Discussion Purposes Only” and says they are not Regulations or Standards issued by the supervisory authorities — while describing the Section 2 principles as binding on all institutions adopting enabling technologies. No issue date appears. They should not be described as binding, and should not be described as final.

No. The UAE Charter for the Development and Use of Artificial Intelligence, issued on 10 June 2024, is published on the federal legislation portal under Public Policies rather than Legislations. Its thirteen principles include human oversight, transparency and accountability, and algorithmic bias. It is a policy charter, not law: it creates no enforceable obligation, and no regulator has power to enforce it.

No. LEXNOVA is not a law firm — it is a lawyer-matching service. It does not advise on AI systems, write governance policies, conduct impact assessments or review training data, and nothing on this page is legal advice. Every enquiry is reviewed by a person, and the professional relationship sits directly between you and the independent lawyer you choose.

LEXNOVA is not a law firm and does not provide legal advice, legal opinions, legal representation, or legal services. Any legal advice or representation is provided directly by the independent legal professional engaged by the client.

A connection or introduction does not constitute a guarantee, endorsement, or assurance of outcome. Users should independently confirm the professional's qualifications, authorization, fees, scope of engagement, and suitability.