← Global AI Policy Radar · Methodology
Jurisdiction baseline

AI regulation in United Arab Emirates.

The UAE does not currently have a single comprehensive federal AI statute. Its framework combines binding federal personal data and cyber law, national AI policy instruments, emirate and free-zone rules, and sector supervision. The UAE Charter and National AI Security Policy set important governance expectations, while regulated firms may face more specific requirements in jurisdictions such as the DIFC.

Sources checked and position verified through 2026-08-11. Proposals are kept separate from binding law and adopted policy.

Rules and policy in force today

Federal Decree-Law 45 of 2021 on Personal Data Protection

in force

The federal privacy law governs electronic personal data processing inside and outside the UAE, including lawful processing, data security, individual rights, transfers, and controller and processor duties. Some free zones maintain separate data regimes.

UAE Charter for the Development and Use of Artificial Intelligence

adopted charter

The charter establishes national principles for safety, privacy, fairness, transparency, human oversight, accountability, accessibility, and compliance with applicable law.

National Cyber Security Policy for Artificial Intelligence

national policy

The policy defines minimum AI security requirements across governance, inventories, secure development, model and data protection, operational safety, adversarial attacks, monitoring, incident response, and performance evaluation.

DIFC Data Protection Law 5 of 2020

in force in DIFC

Organizations operating in the DIFC must assess its separate data protection regime, including accountability, lawful processing, rights, transfers, security, and requirements relevant to automated processing.

Pending and emerging AI measures

passed

UAE National AI Security Policy

The policy sets minimum security expectations for AI adoption, covering governance, inventories, secure development, model and data protection, human oversight, resilience, monitoring, incident response, and adversarial attacks.

passed

DFSA AI Risk Management Expectations

The DFSA has set out supervisory expectations for how authorized financial firms in the DIFC identify, govern, test, monitor, and control AI risks.

passed

UAE Charter for AI Development and Use

The charter establishes national principles for safe, fair, transparent, privacy-respecting, human-centered, and accountable AI development and deployment.

UAE AI Charter 2024 ↗Updated 2024-07-01

What a business should know

Is there a federal AI Act?

No comprehensive federal AI statute is in force. Binding obligations arise from federal privacy, cyber, consumer, employment, and sector law, plus emirate and free-zone regimes. National AI instruments provide policy and security benchmarks.

Does one UAE data law apply everywhere?

No. Federal law is central, but financial free zones such as the DIFC and ADGM maintain separate data protection and regulatory frameworks. Scope depends on establishment, activity, customers, and data flows.

Which AI rules matter most for financial firms?

A firm should identify its regulator and legal jurisdiction first. The DFSA has published AI risk-management expectations for DIFC firms, while other federal, emirate, free-zone, and sector requirements may apply elsewhere.

Need a company-specific assessment?

Nomos maps rules and changes to a specific business profile.

Explore Nomos →