AI and the Law in the UAE: What’s Actually Regulated
UAE AI governance today is not run by a dedicated AI statute — it is the combined effect of general laws on data protection, child safety, copyright and cybercrime, plus one binding DIFC regulation, applied to whatever a given AI system actually does; everything else published on AI at federal level is policy, not law.
Ask what UAE law says about artificial intelligence and most answers reach for a list of AI-sounding instruments — a Strategy, a Charter, a National Programme, a newly announced Authority. Almost none of that list is law. The UAE’s federal legislation portal files every AI-related instrument it holds under Public Policies, separate from Legislations, and that filing choice is the most reliable evidence of what these documents are. This guide is written for anyone handed a memorandum citing UAE AI “law” who wants to know which parts a court or regulator would actually enforce, and which are policy nobody is bound to follow. It sits alongside LEXNOVA’s AI & Technology Governance category and goes deeper on the distinction that matters most: what is actually regulated, and what only reads that way. LEXNOVA is not a law firm. It is a lawyer-matching service, it gives no legal advice, and it does not review AI systems, policies or contracts — this guide explains a landscape, not your specific facts.
LAST REVIEWED 23 SEPTEMBER 2026
WHO THIS GUIDE IS FOR
This guide is for anyone who needs to separate binding obligation from published aspiration: in-house counsel and compliance leads drafting an AI governance policy, founders and product teams told their AI feature must comply with a “UAE AI law” that does not exist in that form, board members signing off on an AI risk framework, procurement teams checking a vendor’s AI compliance claims, and anyone reading a memorandum that cites a UAE AI Strategy, Charter or Authority and wants to know what it can be relied on for.
There Is No UAE Federal AI Statute — and the Portal Proves It
A search of the federal legislation portal for artificial intelligence returns instruments filed under Public Policies, not Legislations. That classification, made by the portal that hosts every Federal Law, Federal Decree-Law, Cabinet Decision and Cabinet Resolution in the country, is the best public evidence available of an instrument’s legal status. Where AI appears on that portal, it appears as policy.
This is not a claim that AI is unregulated in the UAE, or that no law touches an AI deployment. It is a claim about form: there is no single statute to find the way one might find a Companies Law or a Data Protection Law. Content that describes a “UAE AI Law” in that sense is describing something that does not exist, and it should be treated with the same suspicion as a fee figure or an outcome guarantee.
How to Tell a Law From a Policy on the UAE Legislation Portal
The portal separates Legislations — Federal Decree-Laws, Federal Laws, Cabinet Decisions and Cabinet Resolutions, each carrying articles, an issuing authority and typically a commencement provision — from Public Policies, which cover strategies, charters, programmes and guides. A Federal Decree-Law or Federal Law is primary legislation. A Cabinet Decision or Resolution implements or supplements one. A strategy, charter, programme or guide is neither: it is a statement of government direction, published for anyone to read, and not law in the sense a court would apply.
A usable diagnostic follows. Handed a document describing a UAE “AI rule”, ask whether it carries a law or decree-law number with articles, whether it sits under Legislations rather than Public Policies on the portal, and whether it names an enforcement mechanism or a regulator with power to act on it. An instrument that fails all three is functioning as policy, however law-like its language reads, and any governance document or vendor compliance claim should describe it that way.
An Authority Has Been Announced. It Has Not Yet Been Established in Law.
The UAE Cabinet’s own page names the body the Artificial Intelligence and Data Authority — not the “Federal Authority for Artificial Intelligence and Data”, a formulation that circulates widely and is wrong. It was announced in June 2026, consolidating three named bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications; the Digital Government Sector at the TDRA; and the UAE Data Office.
What the announcement does not contain matters more than what it does. The Cabinet page cites no Federal Decree-Law, Federal Law, Cabinet Decision or Resolution, and no establishing instrument had been published as at 22 September 2026 — three months after the announcement. An announced consolidation is not a constituted body with published legal personality and defined powers. The sound position for now is to keep complying with the laws already in force and have a lawyer watch for the establishing instrument, rather than building a compliance programme against powers that do not yet exist on paper.
The Law That Actually Binds an AI System Today: the Data Protection Law
Article 18(1) of Federal Decree-Law No. 45 of 2021, the data protection law, gives a data subject the right to object to decisions resulting from automated processing. That is the closest thing UAE law has to a binding rule on automated decision-making, and it is the provision most AI deployments touching individuals will engage first. Article 17 sits beside it, giving a right to stop processing, including profiling used for direct marketing.
Article 21 requires an impact assessment before processing that uses modern technologies posing a high privacy risk, expressly covering systematic assessment including profiling with legal consequences, and large-scale processing of sensitive data — a description many AI deployments that score, rank or decide about people fit naturally. Article 10 requires a Data Protection Officer where processing carries a high confidentiality risk, involves systematic assessment of sensitive data, or involves large volumes of it. Articles 22 and 23 govern cross-border transfer — a live question for any model or vendor sitting outside the UAE — and this guide does not paraphrase what they require, because those conditions should be read in full against a specific architecture.
A Right Without Machinery: the Missing Executive Regulations
Article 28 of the data protection law required executive regulations to be issued within six months. Article 31 brought the law into force on 2 January 2022. The executive regulations have still not been issued — more than four years past the Article 28 deadline. That gap, not any AI-specific policy document, is the single most consequential fact about how AI is actually governed in the UAE today, because it means the law’s substantive rights exist without the implementing detail that would normally set out how they are exercised and enforced.
Two wrong conclusions tend to follow from that gap. The first is that the law can be treated as inactive because the regulations never arrived — it has been binding since January 2022 regardless. The second is that a future date for the regulations is known and can be planned around; none has been published, and this guide gives none. The right to object to an automated decision is real and current, and how it will be enforced in practice is genuinely open.
The Only Statute That Names AI — and It Mandates Use, Not Restriction
Article 10 of Federal Decree-Law No. 26 of 2025, the Child Digital Safety Law, expressly requires platforms to leverage artificial intelligence systems and machine-learning algorithms for proactive detection, alongside blocking and filtering, immediate reporting of child sexual abuse material and harmful content, default privacy settings, parental controls, time limits and age-based restrictions. It is the only in-force UAE federal statute that expressly mentions artificial intelligence, and the mention is an obligation to deploy the technology rather than a restriction on using it.
Article 3 reaches internet service providers and digital platforms operating in or directed at UAE users, and child caregivers. Article 7 requires explicit parental consent for collecting data from children under 13. Article 8 requires age-verification mechanisms calibrated to platform risk. Article 20 brought the law into force on 1 January 2026, with a one-year grace period to regularise under Article 18, extendable by Cabinet Resolution, and Article 16 leaves the administrative penalties regulation to the Cabinet. The methodological point matters as much as any one article: where UAE legislators have reached artificial intelligence so far, they have done it through a general child-safety statute, not a dedicated AI law — reinforcing that the portal’s Public Policies/Legislations split is the right place to keep checking, not the last place.
Cybercrime Law Reaches Conduct, Not Technology
Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes came into force on 2 January 2022 and repealed Decree-Law No. 5 of 2012. Article 44 covers using an information system to modify or process any record, photo or scene with intent to defame or insult, carrying imprisonment of at least one year and/or a fine of AED 250,000 to 500,000 — the provision that reaches deepfakes, framed around defamation and insult rather than synthesis. Article 52 covers disseminating false news, data or misleading rumours via information networks, carrying at least one year’s imprisonment plus a minimum fine of AED 100,000, with enhanced penalties during crises.
Article 54 is the one worth knowing specifically: creating or modifying “e-robots” with intent to disseminate or circulate false data or news, carrying up to two years’ imprisonment and a fine of AED 100,000 to AED 1,000,000 — the nearest thing in UAE law to a bot or automated-agent offence, though narrow and intent-based rather than a general regulation of automated agents. No article addresses AI-generated synthetic media as such; exposure turns on what the content does and what was intended, not on how it was produced.
Copyright’s Silence Is Itself the Answer
Artificial intelligence is not mentioned anywhere in Federal Decree-Law No. 38 of 2021 on Copyright and Neighbouring Rights. Article 1 defines an Author as a person who creates a work, whose name is mentioned on it or to whom it is ascribed, and a Work as any creative product in the field of letters, arts or science — definitions built for human creation, with no provision addressing AI authorship or computer-generated works.
On the input side there is no text-and-data-mining exception and no machine-learning training exception. The nearest provision, Article 22(8), permits copying short parts of a work for educational purposes, and it does not cover algorithmic training. There is, in short, no lawful-training carve-out in UAE copyright law to point to. Training-data provenance is therefore a legal question here and not only an ethical one, and ownership of an AI system’s output has to be settled in contract, because the statute supplies no default. Executive regulations sit in Cabinet Resolution No. 47 of 2022; that instrument was located for this project but not read, so its contents are not described here.
DIFC’s Regulation 10: the One Binding, AI-Specific Instrument in the UAE
DIFC Data Protection Regulation 10, enacted 7 September 2023, governs the processing of personal data via autonomous and semi-autonomous systems such as artificial intelligence, generative or machine-learning technology. DIFC describes it as the first enacted regulation in the MEASA region addressing the point — a genuine distinction from the federal picture, where nothing comparable exists as binding law.
DIFC describes the regulation as outcomes-based rather than prescriptive, with guidance to follow — a real design choice worth understanding: it sets a result an institution must achieve rather than dictating a specific technical method, which generally means more judgment and more documentation of how the outcome was met. This guide states that Regulation 10 exists and what it covers, and deliberately stops there — its specific obligations were not read for this project. Read the regulation itself with a lawyer before relying on any summary of what it requires.
ADGM’s Gap, and a Financial-Sector Guidance Document That Is Neither Law Nor Final
ADGM has no AI-specific rulebook module. That asymmetry — DIFC holding one binding AI-adjacent instrument, ADGM holding none — is real, and it is usually reported the other way round or not mentioned at all. For a business choosing between the two centres for an AI-driven product, it is a genuine structural difference to weigh, not a detail.
A different kind of document sits at federal level, and it needs equal care. The Guidelines for Financial Institutions adopting Enabling Technologies, issued jointly by the Central Bank of the UAE, the Securities and Commodities Authority, the DFSA and the FSRA, devote Section 6 to Big Data Analytics and AI — documented governance with pre-launch validation, senior-leadership accountability for AI outcomes including autonomous ones, explainability proportionate to materiality, fair and anti-discriminatory outcomes, plain-language customer disclosure, five-year retention of audit logs, and continuous monitoring. It reads like a serious standard. Its status is genuinely ambiguous: the hosted copy is watermarked “Draft for Discussion Purposes Only” and states the Guidelines are not Regulations or Standards issued by the supervisory authorities — while the same document describes the Section 2 principles as binding on all institutions adopting enabling technologies, with Sections 3 to 7 as guidance institutions “may adopt”. No issue date appears. Do not describe these Guidelines as binding, and do not describe them as final.
Policy Documents That Read Like Law and Are Not
The UAE Charter for the Development and Use of Artificial Intelligence, issued 10 June 2024, is published on the federal legislation portal under Public Policies rather than Legislations. Its thirteen principles cover ethical and responsible use, privacy and data security, balancing advancement with social values, innovation and economic growth, awareness and education, transparency and accountability, algorithmic bias, human oversight, governance and accountability frameworks, technological excellence, human-centred commitment, peaceful coexistence, and compliance with international treaties and local laws. It is a policy charter, not law: it creates no enforceable obligation, and no regulator has power to enforce it.
The federal government’s own AI-in-government material names further instruments in the same category: a UAE Strategy for Artificial Intelligence, a National Program for Artificial Intelligence known as BRAIN, a Generative AI Guide, and an AI and Coding Licence issued by the DIFC with the UAE AI Office. A strategy, a programme, a guide and a licence — legitimate government instruments, and none of them binding legislation. Reading any of the four as a compliance obligation is the same category error as reading the Charter that way.
Building a Defensible Position Without a Dedicated Statute
The practical method follows directly from everything above. Start from what the system actually does to people, not from the label “AI”: does it make or materially shape a decision, profile someone, moderate or generate content, or process personal data at scale? Then map each of those functions against the general laws that actually reach it — the data protection law’s objection right, impact-assessment and DPO triggers; the Child Digital Safety Law where the platform reaches under-18 users; the copyright law’s silence on training and on ownership of output; the cybercrime law’s general offences; and, for a DIFC entity, Regulation 10.
Where no binding instrument reaches a function, document the decision against the non-binding material anyway — the Charter’s principles, the Enabling Technologies guidelines for a financial institution — not because it is enforceable today, but because that record is what a regulator would expect from a business that acted responsibly before a binding regime arrived. Then watch for the Authority’s establishing instrument and revisit the mapping when it is published.
What This Guide Deliberately Does Not Resolve
Several things are left open here on purpose. This guide does not state what DIFC Data Protection Regulation 10 requires in substance — only that it exists and what it covers — because its obligations were not read for this project. It does not set out the conditions in Articles 22 and 23 of the data protection law on cross-border transfer; those should be read in full against a specific architecture. It gives no date for the Authority’s establishing instrument or for the data protection law’s executive regulations, because none has been published for either, and it does not resolve the Enabling Technologies guidelines’ status as binding or non-binding, because the source material genuinely supports neither conclusion.
Nor does it state how these general laws interact when an AI system spans more than one UAE jurisdiction — trained by a Dubai mainland entity and deployed through a DIFC subsidiary, for instance — because that analysis is fact-specific. And it does not tell you whether a particular system is compliant with any law described here; that depends on facts this guide cannot know. What it gives is the classification method and a current inventory of what actually binds and what only reads that way, so a conversation with a lawyer starts from an accurate map rather than a list of AI-sounding names.
FAQ
LEXNOVA is not a law firm and does not provide legal advice, legal opinions, legal representation, or legal services. Any legal advice or representation is provided directly by the independent legal professional engaged by the client.
A connection or introduction does not constitute a guarantee, endorsement, or assurance of outcome. Users should independently confirm the professional's qualifications, authorization, fees, scope of engagement, and suitability.