Creuto is now an OpenAI Select Partner Read More

AI & Machine Learning

DIFC Regulation 10: the UAE's only binding AI rulebook

DIFC Regulation 10 is the only AI-specific instrument we could verify in force in the UAE. What it requires, who it binds, and who actually enforces it.

DIFC Regulation 10: the UAE's only binding AI rulebook

Under DIFC Regulation 10, you can be asked to produce evidence of the algorithm that makes your AI system stop and call a human — and the person asking need not be the regulator. Regulation 10.2.2(c) to (f) says that evidence must be provided "upon request by any affected party". If you run an AI system touching personal data inside the Dubai International Financial Centre, that phrase is the one to take to your architects, and it is the one most commentary skips.

This is a reading of the instrument rather than of the alerts about it. Three things came out of it we did not expect: what the operative text says, how far its boundary reaches, and who holds the power to fine you.

What DIFC Regulation 10 actually requires

Regulation 10 sits inside the DIFC Data Protection Regulations, which implement the Data Protection Law, DIFC Law No. 5 of 2020. It is headed "Personal Data Processed Through Autonomous and Semi-Autonomous Systems" and was enacted on 1 September 2023 — a date confirmed inside the Commissioner's own certification framework, not only in the press release. DIFC called it the first enacted regulation in the MEASA region covering this kind of processing.

It creates three distinct groups of obligation, and they trigger at different moments.

Obligation groupWhat it requiresWhat triggers it
Notice, 10.2.2(a)-(b)One notice at first use carrying six disclosures: that some processing is not human-initiated, the human-defined purposes, the limits within which the system may define its own, the outputs and their use, the design safeguards, and the codes relied onAny system processing personal data through an app or website service
Evidence and register, 10.2.2(c)-(h)Evidence of certification compliance, of the algorithms forcing human intervention in three named scenarios, and of the matching risk and impact assessments — plus a register of use cases, lawful bases and export safeguardsThe same systems, on request, with no notice period
Design and certification, 10.3.1-10.3.3Five design concepts — ethical, fair, transparent, secure, accountable — and purposes confined to what humans defined or approved; high-risk processing adds certification and an Autonomous Systems OfficerCommercial use; the high-risk tier adds two further conditions

Source: DIFC Data Protection Regulations, Consolidated Version No. 2, Regulation 10.

One reported detail needs correcting. The repeated line is that Regulation 10 draws on OECD guidance and UK and EU data protection concepts. The footnotes are more specific: "System" in 10.1.1(a) was "adapted on the basis of the OECD guidelines and the Regulation of the European Union on harmonized rules on AI" — the EU AI Act, which is product-safety law, not data protection law. "Deployer" in 10.1.1(b) was adapted from the EU AI Act plus the concept of "user" in China's Management Measures for Generative AI Services. The UK and EU data protection lineage is real but sits in the Commissioner's guidance, which cites DIFC's "historical reliance on UK and EU data protection and privacy principles".

Regulation 10.3.4 then makes a Deployer a Controller and an Operator a Processor, and the guidance explains why in a line worth repeating to a board: a System operating under a Deployer's authority is "substantially similar to that of an employee within the Deployer organisation".

Who is inside the boundary, and who is not

DIFC is a separate jurisdiction with its own data protection statute, which is why Regulation 10 can exist at all. Article 6 of the Law sets the perimeter in two parts, and the second is wider than "firms in the DIFC": it covers processing by a Controller or Processor incorporated in the DIFC wherever the processing happens, and processing in the DIFC by a Controller, Processor or sub-processor "regardless of its place of incorporation as part of stable arrangements".

Read that against the Operator definition — a provider that operates or supervises a System for a Deployer's benefit, "without regard to whether or not that Provider exercises any control over the Processing". A vendor in London, Bengaluru or Singapore running an AI system under a standing contract for a DIFC-licensed client can hold Operator obligations without holding a DIFC licence. That is the boundary question a build partner should be asking, and almost nobody frames it that way.

Mainland UAE firms are outside Regulation 10 and are not unregulated. Federal Decree-Law No. 45 of 2021 on personal data protection has been in force since 2 January 2022. What a mainland firm lacks is the AI-specific layer on top: no certification condition, no Autonomous Systems Officer, no evidence-on-demand regime for human-intervention algorithms. The difference is that layer, not the existence of privacy law.

We went looking for a competing instrument and found none. Abu Dhabi Global Market, the other financial free zone, governs AI through its 2021 data protection regulations and guidance rather than a dedicated AI rule. Our reading — offered as a reading, not a legal opinion — is that Regulation 10 is the only binding AI-specific instrument in force anywhere in the UAE as of October 2026. Everything else we could verify is a charter, a survey or sector guidance, and DIFC's own MEASA-first claim points the same way. A counter-example would change this post.

The obligation most likely to catch a firm by surprise

Of the three groups, the evidence requirements break builds, because they are architectural rather than documentary. Regulation 10.2.2(d), (e) and (f) each require evidence of an algorithm that causes the System to seek human intervention — when processing may have an unfair or discriminatory impact on a data subject, when personal data must be accessed by government or law enforcement, and when processing may breach Regulation 9 on marketing and communications. Each carries a matching risk and impact assessment.

You cannot retrofit that from a policy document. A human-in-the-loop trigger on a bias condition is a code path, a threshold and an audit record; if it does not exist at design time it will not appear in a compliance review. The AI engineering consequence is specific: your escalation logic becomes a regulated artefact that must be describable to a non-technical reader, because 10.3.1(c) requires processing to be explainable to data subjects "in non-technical terms, with appropriate supporting evidence".

The strongest objection is that "upon request by any affected party" reads like an invitation to harassment — a competitor could paper you with requests. Regulation 10.2.2(h) answers it narrowly. You may redact or summarise the 10.2.2(c)-(f) material, but "solely to the minimum extent necessary" to protect intellectual property or comply with legal restrictions, and you must hand the full unredacted version to the Commissioner on request and implement any revisions required. The protection is real but thin: you can withhold detail from a competitor, not from the regulator.

High-risk AI: certified by an accredited body, not by the Commissioner

Regulation 10.3.3 prohibits commercial use of a System for High Risk Processing Activities unless four conditions hold together: the Commissioner has established audit and certification requirements, the System complies with them, it processes personal data solely for human-defined or human-approved purposes, and the Deployer or Operator has appointed an Autonomous Systems Officer with competencies substantially similar to a Data Protection Officer under Articles 17 and 18.

The trap is the definition of high-risk. Schedule 1 of the Law treats processing as a High Risk Processing Activity if any one of four limbs applies, and the first is "the adoption of new or different technologies or methods, which creates a materially increased risk to the security or rights of a Data Subject or renders it more difficult for a Data Subject to exercise his rights". Adopting the AI can itself be what makes the processing high-risk. The others cover large volumes of personal data, systematic automated evaluation producing legal effects, and a material amount of special category data.

Here we part company with the commentary. The guidance note to 10.3.3 states the intent that "no System may be used for any High Risk Processing Activities until the Commissioner has promulgated these certification and other requirements", which several advisories read as freezing high-risk AI in DIFC. It is not frozen. The Commissioner has published the Regulation 10 Accreditation and Certification Framework, implementing Articles 50 and 51 of the Law and Regulation 10.3.3(a), and the Commissioner's FAQ answers "Is there such an audit and certification framework?" with "Yes".

What makes it operational is that the Commissioner does not grant the certification. An Accredited Certification Body does, accredited under Article 51 — and DIFC's Regulation 10 page names four: Eversheds Sutherland, Middle East Privacy, White Label Consultancy and Standard Chartered Bank. Standard Chartered carries an asterisk — internal systems certifications only, not available for external Regulation 10 certifications. So the market is three bodies as of October 2026.

Two durations are easy to confuse: accreditation of a body lasts five years under the Framework, while a certification issued to you lasts a maximum of three under Article 50(4). Certification is also per-System rather than per-entity. If you have done EU work, the overlap is deliberate — the FAQ states the Framework "aligns with the EU AI Act Article 16 and Article 43 Obligations and Conformity Assessment criteria" and for high-risk systems "effectively acts as a conformity assessment". That is not mutual recognition, but the evidence you assembled for an EU AI Act conformity assessment is not wasted.

Who enforces DIFC Regulation 10, and what the exposure is

The Commissioner of Data Protection enforces it. Not the Dubai Financial Services Authority. That matters, because the DFSA is the body a DIFC-licensed financial firm hears from most, so the instinct is to hunt for AI rules in the DFSA rulebook. The DFSA appears in Regulation 10 exactly once, at 10.2.2(b)(v), as one of the authorities — with the Central Bank of the UAE, the Securities and Commodities Authority and the FSRA — whose Guidelines for Financial Institutions adopting Enabling Technologies a System may cite as the code it was designed against. Here the DFSA is a source of principles, not the enforcer.

Enforcement runs through the Law: directions under Article 59, fines under Article 62, appeal and recovery through the DIFC Courts under Article 63, and a private right of action under Article 64A. Regulation 6.2 on unfair or deceptive practices bites directly, because the Commissioner treats misleading notices of processing activities and false public claims about certifications as enforceable conduct.

The quantum is the part worth knowing. Schedule 2 sets maximum administrative fines against numbered Articles — 50,000 US dollars for an Article 9 contravention, 100,000 for several of the data subject rights Articles. We could find no Schedule 2 line item for Regulation 10. What applies instead is Article 62(3), under which the Commissioner may issue a general fine "in an amount, not limited to the amounts specified in Schedule 2, which he considers appropriate and proportionate". The headline exposure for a Regulation 10 breach is an uncapped discretionary fine, not a tariff — the opposite of how most summaries present it.

The sandbox, and what is proposed but not yet law

DIFC announced on 21 April 2026 that it intends to become the world's first AI-native financial centre, projecting a 3.5 billion US dollar contribution to Dubai's economy and 25,000 jobs, and saying its ethics and governance frameworks will cover AI agents and robotics rather than human activity alone. That is an intention, not an instrument.

The testing posture is already documented. The Commissioner publishes a Regulation 10 Accelerator — explicitly the sandbox concept — for testing a System for privacy by design against available or bespoke standards. Participation is open to DIFC entities, to non-DIFC entities with operations in DIFC, and to others that can give a reasonable purpose. It names the UAE Reg Lab, the UK ICO sandbox and the EU AI Act Article 57 sandbox as parallel options.

Not law yet: Consultation Paper No. 3 of June 2026 proposes adding "Safety" as a design concept, replacing "principles" with the broader "policy frameworks" in 10.2.2(b), spelling out ASO obligations in 10.3.3, and adding a Regulation 11 letting the Commissioner recognise accreditation and certification schemes by publication. Comments closed on 18 July 2026 and the paper says the proposals are "in draft form only" and "you should not act on them until they are formally enacted". We found no enactment notice as of 8 October 2026.

What this changes for a build

Adoption is running ahead of governance, and the numbers come from the financial regulator rather than from DIFC. The DFSA Artificial Intelligence Survey 2025, published 12 November 2025, found AI adoption among DIFC firms rose from 33% in 2024 to 52% in 2025 — 345 firms against 177 — with generative AI up 166%. Be precise about the denominator: 661 responding Authorised Firms at an 88% response rate, not every entity registered in DIFC. The same survey found 60% of firms have some AI governance structure while 21% lack clear accountability or oversight even where AI is critical to operations.

Three design decisions follow from the text rather than the commentary. Build the human-intervention triggers as first-class code paths with their own audit trail, because 10.2.2(d)-(f) make them evidence. Build the use-case register as a system of record rather than a spreadsheet, because 10.2.2(g) wants recipients, lawful bases, locations and export safeguards per use case. And decide early whether any use case is high-risk under Schedule 1, because that answer determines whether you need a certification body and an Autonomous Systems Officer before launch rather than after — a timeline question, not a paperwork one. Where personal data must stay inside a boundary, the same reasoning as model and data residency choices in the UAE applies to where the System runs.

This is the wrong framework to worry about if your system has no autonomy. The guidance to 10.1.1(a) is explicit that "purely automated systems — systems which have no degree of autonomy in their operation and whose operation is deterministically controlled by humans" are not meant to be caught, because the Law already governs automated processing. A deterministic rules engine is not a System here, however much the marketing calls it AI.

We should be straight about our own standing. We exhibit at GITEX Global and run a Dubai practice, but we have not taken a System through Regulation 10 certification, and nothing above is reported from a DIFC project of ours — it is read off the published instruments. Take the compliance call to DIFC counsel. The same separation applies federally: we looked at what actually binds a private firm on the mainland in our note on the Dubai agentic AI mandate, and the answer was much less than the coverage implied.

The decision this changes is where a System gets built and evidenced, not where a company incorporates. If your Deployer is DIFC-licensed, your Operator inherits Processor obligations wherever it sits — so the certification question belongs in the architecture review, before the first model call, not in the legal review after the demo.

Frequently asked questions

DIFC Regulation 10 is the part of the DIFC Data Protection Regulations governing personal data processed through autonomous and semi-autonomous systems, meaning AI. Enacted on 1 September 2023, it adds notice, evidence, design and certification duties on top of the DIFC Data Protection Law, DIFC Law No. 5 of 2020.

The DIFC Commissioner of Data Protection enforces Regulation 10, using directions under Article 59 and fines under Article 62 of the Data Protection Law, with appeals to the DIFC Courts. The Dubai Financial Services Authority does not enforce it; Regulation 10 cites DFSA guidance only as a design code a system may reference.

Regulation 10 can reach beyond DIFC-licensed firms. Article 6 of the DIFC Data Protection Law covers processing in the DIFC by any controller, processor or sub-processor as part of stable arrangements, regardless of where it is incorporated, so an overseas vendor operating an AI system for a DIFC client can hold Operator obligations.

For high-risk processing, Regulation 10.3.3 requires certification of the system against the Commissioner's framework, processing confined to human-defined or human-approved purposes, and an appointed Autonomous Systems Officer. Certification is granted per system by an Accredited Certification Body, not by the Commissioner, and lasts a maximum of three years.

There is no UAE AI Act. DIFC is a separate jurisdiction with its own data protection statute, which is why Regulation 10 exists there and has no mainland equivalent. Mainland firms fall under Federal Decree-Law No. 45 of 2021 on personal data protection, which is general privacy law rather than an AI-specific instrument.

Schedule 1 of the DIFC Data Protection Law treats processing as a High Risk Processing Activity if any one of four limbs applies, including the adoption of new or different technologies that materially increase risk to a data subject's rights. Adopting AI can itself satisfy that limb, which catches firms expecting a narrower test.

Written by

Akash Mohapatra

Akash Mohapatra

Co Founder & Director

8 Oct 2026

·

13 min read

Share

LET'S CONNECT

Connect with Creuto!

Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.

We don't just aim to fit in – we strive to stand out. Experience the perfect blend of innovation, excellence, and trust that makes us truly unforgettable. Discover the difference with Creuto.

© 2026 Creuto All Rights Reserved