Creuto is now an OpenAI Select Partner Read More

AI & Machine Learning

Dubai AI Act: the tier table nobody can source

Every four-tier table for the Dubai AI Act traces back to blogs, not a law. What the UAE actually publishes, and what to record regardless.

Dubai AI Act: the tier table nobody can source

We could not find the primary instrument for the Dubai AI Act. Not on the UAE legislation portal, not in the Cabinet's own announcements, not in any law-firm alert we were able to read. Every four-tier table, self-assessment deadline and dirham penalty figure now circulating traces back to commercial blogs that cite no decree number.

That matters more than it sounds. If you are about to appoint an AI Ethics Officer, budget for an annual third-party algorithm audit, or tell your board you have a September deadline, you are acting on a document nobody has produced. This post separates what is published from what is claimed, names the outlet behind each number, and then does the part that survives either way: working out which of your AI features would plausibly fall inside a risk-tiered regime, and what evidence an audit would want.

What the UAE actually publishes, and what it does not

Search the UAE's official legislation portal for artificial intelligence and you get two things. One is a policy: the UAE Charter for the Development and Use of Artificial Intelligence, issued 10 June 2024, which sets principles on ethical use, privacy, transparency and accountability. The other is a statute, Federal Decree-Law No. 25 of 2018 on Projects of Future Nature, which lets the Cabinet grant interim licences to projects using AI where no law yet regulates them. A charter of principles and a mechanism for licensing the unregulated are the opposite of a risk-tier conformity regime.

The CMS expert guide to AI regulation in the UAE, last updated 17 February 2026, puts it flatly: the UAE does not yet have a standalone, comprehensive AI statute. Against the heading for forthcoming AI legislation it records two words — "Not at present." The instruments it does list are the ones already in force and already reaching AI: Federal Decree-Law No. 45 of 2021 on Personal Data Protection, Federal Decree-Law No. 34 of 2021 on cybercrime, and DIFC Data Protection Law No. 5 of 2020 as amended in 2023.

The authority that exists is not the authority being named

Several of the tier tables name a "UAE AI Authority" as enforcer, described as an independent regulator headquartered in Dubai. A federal AI body was in fact created this year, and it is not that. On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum approved establishing the Artificial Intelligence and Data Authority, reporting directly to the Cabinet and chaired by Omar Sultan Al Olama. It absorbs three existing bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector at the TDRA, and the UAE Data Office.

Read its published functions and the mismatch is obvious. It proposes national policies, legislation and strategies, sets standards and guidelines for data and AI management, manages government data, and ensures compliance across federal entities. There is no mention of risk tiers, registration, self-assessment, audits or penalties anywhere in the announcement. Morgan Lewis's note on the same development gives no decree number for it and mentions neither tiers nor fines; it also observes that the Personal Data Protection Law's implementing regulations have still not been issued. A body whose job description includes proposing legislation is a body for which the legislation does not yet exist.

It is also worth settling the naming question, because the sources use "Dubai AI Act" and "UAE AI Act" interchangeably and those are different things. Dubai is an emirate with its own legislative machinery; the UAE is the federation. One instrument cannot be both. Neither phrase appears in any primary source we could reach.

The claimed Dubai AI Act tier table, and the outlet behind each number

Here is the compliance picture as published, with attribution rather than endorsement. We are not restating any of it as law.

ClaimWho published itWhat they cite
Act effective March 2026; four tiers Minimal, Limited, High, Critical; six-month self-assessment; registration June 2026; enforcement September 2026; first annual audits December 2026digitaldubai.ai, 6 February 2026, by Daniel Hayes, "Founder & Editor"A line reading "Original reporting by UAE AI Office / Dubai Digital Authority" and a link to the ai.gov.ae homepage. No law number.
Tier 3 duties: annual third-party audit by an accredited auditor, quarterly bias testing with public disclosure, an AI Ethics Officer reporting directly to the board, 72-hour incident notification, model cards and training-data documentation, a right to explanationdigitaldubai.ai, same articleAs above. The minister quoted in the piece is unnamed.
Penalties: AED 500,000 registration failure, AED 2 million audit non-compliance, AED 5 million incident concealment, AED 10 million prohibited deploymentdigitaldubai.ai, same articleAs above.
Same March 2026 date, same four tier names, September 2026 self-assessment, penalties up to AED 10 million, enforcer "UAE AI Authority"6clicks, 10 April 2026, by Anthony Stevens, CEO and founder of a compliance software vendor"UAE AI Authority, 2026", unlinked. No decree, gazette or primary URL.
Tier 4 described as prohibited or approval-only; penalties up to AED 500,000 minor, AED 3 million significant, AED 10 million severe plus shutdown ordersNomadX, 2 July 2026, a Dubai AI consultancy selling governance services6clicks, "Digital Dubai", TFSF Ventures, SilentGuard and MIT Sloan ME. No primary source.

Two things about that first row deserve underlining. digitaldubai.ai is not Digital Dubai. Its own disclaimer says it is an independent news resource "not affiliated with, endorsed by, or connected to the Digital Dubai Office, Dubai Government, or any UAE government entity." Digital Dubai's actual site is digitaldubai.ae, whose homepage carries no AI act. The near-identical domain is doing a great deal of unearned work in this story.

Where the secondary sources contradict each other

If these accounts described a real document, they would converge on it. They do not. digitaldubai.ai calls the top tier "Critical"; NomadX calls it prohibited or approval-only. The penalty ladder is AED 500,000 / 2m / 5m / 10m in one and AED 500,000 / 3m / 10m in the other. 6clicks names an enforcer that does not exist under that name; NomadX names no enforcer at all. And the January 2027 date that has attached itself to this story in some briefings is, in NomadX's own text, a Personal Data Protection Law milestone, not an AI Act transition deadline. Four tiers is a familiar shape because the EU AI Act has that shape — which is the simplest explanation for why the shape travelled without the document.

The strongest case for acting as if the tiers were real

Give that case its best form, because it is not weak. Risk tiering is now the default template for AI regulation worldwide, so whatever the UAE eventually legislates will probably rhyme with it. Dubai already operates a classification scheme for AI companies: the Dubai AI Seal, run by the Dubai Centre for Artificial Intelligence, issues certified companies a serial number and a classification tier with Tier S at the top, and had drawn 325 applications representing 77 international offices as of 15 May 2025. The Seal is voluntary and free to apply for, but it is described as a prerequisite for upcoming government-led AI initiatives — which is commercial pressure with real teeth. Add the Personal Data Protection Law, sector rules from financial and health regulators, and a new federal authority whose remit includes setting AI standards, and the direction of travel is not in doubt.

So the case for preparing is strong. The case for preparing to the specifics in the table is not, and the difference is money. An AI Ethics Officer with a board reporting line, quarterly bias testing published externally, and an annual third-party algorithm audit are three of the most expensive controls in AI governance. Buying them against a deadline no instrument sets is how a compliance budget gets spent twice: once on the wrong control, and again on the real one when it arrives. The honest position is that nobody knows the obligations yet, so you build the evidence that any version of them would demand, and you defer the org-chart changes and the external attestations until a duty-holder is named.

Which of your AI features would plausibly fall in scope

Under every risk-tiered AI regime we have read, two variables do almost all the sorting, and neither is the model you chose. The first is whether the system's output decides something about an identifiable person. The second is whether a human can review that output before it takes effect.

Run your feature list against those two axes and the answers are usually unambiguous:

  • Likely in scope. Anything that screens CVs or ranks candidates, scores creditworthiness or eligibility, prices a policy per customer, grants or denies access, triages a medical or safety case, or identifies someone biometrically.
  • Probably out of scope. An internal code assistant, autocomplete, summarising your own documents, a support-ticket auto-tagger that only routes work, or a drafting tool whose output a person edits before anyone sees it.
  • The ambiguous middle, which is where most teams actually sit. A model flags a claim, a transaction or an application and a human decides. That human review is the single feature most likely to pull a system down a tier — and the thing most likely to be nominal in practice, because the reviewer approves 99% of flags without reading them.

If your human-in-the-loop cannot be shown to have changed outcomes, assume an auditor will treat the system as automated. That is the one design conclusion here we would act on today regardless of what the instrument eventually says.

What to record from today, whatever the tier turns out to be

Evidence is the part you cannot retrofit. A tier assessment, an audit or a data-protection enquiry all ask for the same substrate, and none of it can be reconstructed after the fact. The pattern is the same one we described in the context of India's consent manager rules, where the engineering work is logging the decision rather than announcing the policy.

RecordWhy an assessment asks for itWhere it lives
Model, version, provider and inference region per featureEstablishes what the system is and whether data left the jurisdictionA checked-in inventory, not a slide
The decision the feature makes, and who can override itDecides the tier under any person-affecting testFeature spec, with the override path named
Override and disagreement rateProves the human in the loop is real rather than nominalApplication telemetry
Personal data categories entering the promptThe Personal Data Protection Law applies today, tiers or no tiersData map keyed to the feature
Evaluation set, results and date per releaseStands in for bias testing if testing is ever requiredCI artefacts kept per release, not overwritten
Prompt and output logs with a stated retention periodThe only way to answer "what did it say on 3 March"Log store with retention configured deliberately
Incident log with detection and notification timestampsAny 72-hour clock is unanswerable without itIncident tooling, not a shared inbox

Most teams can produce the first two rows and almost none can produce the third and the fifth. Override rate and dated evaluation results are cheap to start capturing and impossible to backfill, which makes them the two we would start with this quarter. If you want help deciding what belongs in that inventory for a system already in production, that is ordinary AI engineering work rather than a compliance exercise.

Where this leaves a product decision

Be clear about what we are and are not telling you. Creuto has no first-hand delivery experience in the UAE; this is a reading of public documents, not a report from the field, and we are not your counsel. Our Dubai practice page sets out what we do, which is build software, not advise on UAE law. For the regulatory position on a specific product, the only reliable answer comes from licensed counsel in the emirate you are shipping into.

The practical consequence, as of 8 October 2026: do not budget against the September deadline, do not appoint an ethics officer to satisfy a tier nobody can cite, and do not quote the dirham penalties to your board as law. Do build the record. We reached the same conclusion from the opposite direction when we looked at what the Dubai agentic AI programme actually binds: the announcements aimed at government get read as obligations on private companies, and the gap between those two readings is where compliance money goes to die. When the instrument appears, the teams who kept the logs will spend a fortnight on their tier assessment. The teams who bought the controls will still be looking for the evidence.

Frequently asked questions

We could not find a primary instrument for a Dubai AI Act or a UAE AI Act. The UAE legislation portal lists an AI Charter issued in June 2024 and Federal Decree-Law No. 25 of 2018, and the CMS expert guide updated in February 2026 records no comprehensive AI statute and no forthcoming AI legislation.

No single AI enforcer is published. The Artificial Intelligence and Data Authority, approved on 14 June 2026, reports to the Cabinet and sets standards and ensures compliance across federal entities. Its announced functions include proposing legislation but mention no penalties, registration or risk tiers for private companies.

That penalty ladder originates with the site digitaldubai.ai, which is an independent publisher unaffiliated with Digital Dubai, and was repeated by the vendor blog 6clicks and the consultancy NomadX. None of the three cites a decree number, a gazette reference or an official document, and their figures do not agree.

Features whose output decides something about an identifiable person without meaningful human review are the most exposed under every risk-tiered regime we have read. CV screening, credit and eligibility scoring, access decisions, medical triage and biometric identification sit in that group; internal code assistants and summarisation generally do not.

Record the model, version, provider and inference region per feature, the decision each feature makes and who can override it, the override rate, personal data categories entering prompts, dated evaluation results per release, prompt and output logs with a retention period, and an incident log with detection timestamps.

Written by

Akash Mohapatra

Akash Mohapatra

Co Founder & Director

8 Oct 2026

·

11 min read

Share

LET'S CONNECT

Connect with Creuto!

Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.

We don't just aim to fit in – we strive to stand out. Experience the perfect blend of innovation, excellence, and trust that makes us truly unforgettable. Discover the difference with Creuto.

© 2026 Creuto All Rights Reserved