Creuto is now an OpenAI Select Partner Read More
Every four-tier table for the Dubai AI Act traces back to blogs, not a law. What the UAE actually publishes, and what to record regardless.

We could not find the primary instrument for the Dubai AI Act. Not on the UAE legislation portal, not in the Cabinet's own announcements, not in any law-firm alert we were able to read. Every four-tier table, self-assessment deadline and dirham penalty figure now circulating traces back to commercial blogs that cite no decree number.
That matters more than it sounds. If you are about to appoint an AI Ethics Officer, budget for an annual third-party algorithm audit, or tell your board you have a September deadline, you are acting on a document nobody has produced. This post separates what is published from what is claimed, names the outlet behind each number, and then does the part that survives either way: working out which of your AI features would plausibly fall inside a risk-tiered regime, and what evidence an audit would want.
Search the UAE's official legislation portal for artificial intelligence and you get two things. One is a policy: the UAE Charter for the Development and Use of Artificial Intelligence, issued 10 June 2024, which sets principles on ethical use, privacy, transparency and accountability. The other is a statute, Federal Decree-Law No. 25 of 2018 on Projects of Future Nature, which lets the Cabinet grant interim licences to projects using AI where no law yet regulates them. A charter of principles and a mechanism for licensing the unregulated are the opposite of a risk-tier conformity regime.
The CMS expert guide to AI regulation in the UAE, last updated 17 February 2026, puts it flatly: the UAE does not yet have a standalone, comprehensive AI statute. Against the heading for forthcoming AI legislation it records two words — "Not at present." The instruments it does list are the ones already in force and already reaching AI: Federal Decree-Law No. 45 of 2021 on Personal Data Protection, Federal Decree-Law No. 34 of 2021 on cybercrime, and DIFC Data Protection Law No. 5 of 2020 as amended in 2023.
Several of the tier tables name a "UAE AI Authority" as enforcer, described as an independent regulator headquartered in Dubai. A federal AI body was in fact created this year, and it is not that. On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum approved establishing the Artificial Intelligence and Data Authority, reporting directly to the Cabinet and chaired by Omar Sultan Al Olama. It absorbs three existing bodies: the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector at the TDRA, and the UAE Data Office.
Read its published functions and the mismatch is obvious. It proposes national policies, legislation and strategies, sets standards and guidelines for data and AI management, manages government data, and ensures compliance across federal entities. There is no mention of risk tiers, registration, self-assessment, audits or penalties anywhere in the announcement. Morgan Lewis's note on the same development gives no decree number for it and mentions neither tiers nor fines; it also observes that the Personal Data Protection Law's implementing regulations have still not been issued. A body whose job description includes proposing legislation is a body for which the legislation does not yet exist.
It is also worth settling the naming question, because the sources use "Dubai AI Act" and "UAE AI Act" interchangeably and those are different things. Dubai is an emirate with its own legislative machinery; the UAE is the federation. One instrument cannot be both. Neither phrase appears in any primary source we could reach.
Here is the compliance picture as published, with attribution rather than endorsement. We are not restating any of it as law.
| Claim | Who published it | What they cite |
|---|---|---|
| Act effective March 2026; four tiers Minimal, Limited, High, Critical; six-month self-assessment; registration June 2026; enforcement September 2026; first annual audits December 2026 | digitaldubai.ai, 6 February 2026, by Daniel Hayes, "Founder & Editor" | A line reading "Original reporting by UAE AI Office / Dubai Digital Authority" and a link to the ai.gov.ae homepage. No law number. |
| Tier 3 duties: annual third-party audit by an accredited auditor, quarterly bias testing with public disclosure, an AI Ethics Officer reporting directly to the board, 72-hour incident notification, model cards and training-data documentation, a right to explanation | digitaldubai.ai, same article | As above. The minister quoted in the piece is unnamed. |
| Penalties: AED 500,000 registration failure, AED 2 million audit non-compliance, AED 5 million incident concealment, AED 10 million prohibited deployment | digitaldubai.ai, same article | As above. |
| Same March 2026 date, same four tier names, September 2026 self-assessment, penalties up to AED 10 million, enforcer "UAE AI Authority" | 6clicks, 10 April 2026, by Anthony Stevens, CEO and founder of a compliance software vendor | "UAE AI Authority, 2026", unlinked. No decree, gazette or primary URL. |
| Tier 4 described as prohibited or approval-only; penalties up to AED 500,000 minor, AED 3 million significant, AED 10 million severe plus shutdown orders | NomadX, 2 July 2026, a Dubai AI consultancy selling governance services | 6clicks, "Digital Dubai", TFSF Ventures, SilentGuard and MIT Sloan ME. No primary source. |
Two things about that first row deserve underlining. digitaldubai.ai is not Digital Dubai. Its own disclaimer says it is an independent news resource "not affiliated with, endorsed by, or connected to the Digital Dubai Office, Dubai Government, or any UAE government entity." Digital Dubai's actual site is digitaldubai.ae, whose homepage carries no AI act. The near-identical domain is doing a great deal of unearned work in this story.
If these accounts described a real document, they would converge on it. They do not. digitaldubai.ai calls the top tier "Critical"; NomadX calls it prohibited or approval-only. The penalty ladder is AED 500,000 / 2m / 5m / 10m in one and AED 500,000 / 3m / 10m in the other. 6clicks names an enforcer that does not exist under that name; NomadX names no enforcer at all. And the January 2027 date that has attached itself to this story in some briefings is, in NomadX's own text, a Personal Data Protection Law milestone, not an AI Act transition deadline. Four tiers is a familiar shape because the EU AI Act has that shape — which is the simplest explanation for why the shape travelled without the document.
Give that case its best form, because it is not weak. Risk tiering is now the default template for AI regulation worldwide, so whatever the UAE eventually legislates will probably rhyme with it. Dubai already operates a classification scheme for AI companies: the Dubai AI Seal, run by the Dubai Centre for Artificial Intelligence, issues certified companies a serial number and a classification tier with Tier S at the top, and had drawn 325 applications representing 77 international offices as of 15 May 2025. The Seal is voluntary and free to apply for, but it is described as a prerequisite for upcoming government-led AI initiatives — which is commercial pressure with real teeth. Add the Personal Data Protection Law, sector rules from financial and health regulators, and a new federal authority whose remit includes setting AI standards, and the direction of travel is not in doubt.
So the case for preparing is strong. The case for preparing to the specifics in the table is not, and the difference is money. An AI Ethics Officer with a board reporting line, quarterly bias testing published externally, and an annual third-party algorithm audit are three of the most expensive controls in AI governance. Buying them against a deadline no instrument sets is how a compliance budget gets spent twice: once on the wrong control, and again on the real one when it arrives. The honest position is that nobody knows the obligations yet, so you build the evidence that any version of them would demand, and you defer the org-chart changes and the external attestations until a duty-holder is named.
Under every risk-tiered AI regime we have read, two variables do almost all the sorting, and neither is the model you chose. The first is whether the system's output decides something about an identifiable person. The second is whether a human can review that output before it takes effect.
Run your feature list against those two axes and the answers are usually unambiguous:
If your human-in-the-loop cannot be shown to have changed outcomes, assume an auditor will treat the system as automated. That is the one design conclusion here we would act on today regardless of what the instrument eventually says.
Evidence is the part you cannot retrofit. A tier assessment, an audit or a data-protection enquiry all ask for the same substrate, and none of it can be reconstructed after the fact. The pattern is the same one we described in the context of India's consent manager rules, where the engineering work is logging the decision rather than announcing the policy.
| Record | Why an assessment asks for it | Where it lives |
|---|---|---|
| Model, version, provider and inference region per feature | Establishes what the system is and whether data left the jurisdiction | A checked-in inventory, not a slide |
| The decision the feature makes, and who can override it | Decides the tier under any person-affecting test | Feature spec, with the override path named |
| Override and disagreement rate | Proves the human in the loop is real rather than nominal | Application telemetry |
| Personal data categories entering the prompt | The Personal Data Protection Law applies today, tiers or no tiers | Data map keyed to the feature |
| Evaluation set, results and date per release | Stands in for bias testing if testing is ever required | CI artefacts kept per release, not overwritten |
| Prompt and output logs with a stated retention period | The only way to answer "what did it say on 3 March" | Log store with retention configured deliberately |
| Incident log with detection and notification timestamps | Any 72-hour clock is unanswerable without it | Incident tooling, not a shared inbox |
Most teams can produce the first two rows and almost none can produce the third and the fifth. Override rate and dated evaluation results are cheap to start capturing and impossible to backfill, which makes them the two we would start with this quarter. If you want help deciding what belongs in that inventory for a system already in production, that is ordinary AI engineering work rather than a compliance exercise.
Be clear about what we are and are not telling you. Creuto has no first-hand delivery experience in the UAE; this is a reading of public documents, not a report from the field, and we are not your counsel. Our Dubai practice page sets out what we do, which is build software, not advise on UAE law. For the regulatory position on a specific product, the only reliable answer comes from licensed counsel in the emirate you are shipping into.
The practical consequence, as of 8 October 2026: do not budget against the September deadline, do not appoint an ethics officer to satisfy a tier nobody can cite, and do not quote the dirham penalties to your board as law. Do build the record. We reached the same conclusion from the opposite direction when we looked at what the Dubai agentic AI programme actually binds: the announcements aimed at government get read as obligations on private companies, and the gap between those two readings is where compliance money goes to die. When the instrument appears, the teams who kept the logs will spend a fortnight on their tier assessment. The teams who bought the controls will still be looking for the evidence.
We could not find a primary instrument for a Dubai AI Act or a UAE AI Act. The UAE legislation portal lists an AI Charter issued in June 2024 and Federal Decree-Law No. 25 of 2018, and the CMS expert guide updated in February 2026 records no comprehensive AI statute and no forthcoming AI legislation.
No single AI enforcer is published. The Artificial Intelligence and Data Authority, approved on 14 June 2026, reports to the Cabinet and sets standards and ensures compliance across federal entities. Its announced functions include proposing legislation but mention no penalties, registration or risk tiers for private companies.
That penalty ladder originates with the site digitaldubai.ai, which is an independent publisher unaffiliated with Digital Dubai, and was repeated by the vendor blog 6clicks and the consultancy NomadX. None of the three cites a decree number, a gazette reference or an official document, and their figures do not agree.
Features whose output decides something about an identifiable person without meaningful human review are the most exposed under every risk-tiered regime we have read. CV screening, credit and eligibility scoring, access decisions, medical triage and biometric identification sit in that group; internal code assistants and summarisation generally do not.
Record the model, version, provider and inference region per feature, the decision each feature makes and who can override it, the override rate, personal data categories entering prompts, dated evaluation results per release, prompt and output logs with a retention period, and an incident log with detection timestamps.
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.
11th Floor, O-Hub, Chandaka Industrial Estate, Infocity, Bhubaneswar, Odisha 751024
Level 4, 11 York Street Sydney Startup Hub Sydney, NSW – 2000
30 N. Đinh Nghệ, Phước Mỹ Sơn Trà, Đà Nẵng / Da Nang City – 550000
Level 25, AIDP Business Tower, Dubai Marina, United Arab Emirates
50 Beauchamp Street, Wellington, WGN 5028, New Zealand