Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomeAI laws › Federal PDPL 45/2021 + DIFC + ADGM
AI governance law · the UAE

๐Ÿ‡ฆ๐Ÿ‡ช Federal PDPL 45/2021 + DIFC + ADGM

The UAE has a national AI strategy and a Minister of State for AI, but most binding duties still flow from data-protection law. On the mainland the Federal Decree-Law 45 of 2021 (PDPL) supplies the hooks - automated processing, impact assessment, security and breach - while its executive regulations remain unissued. The DIFC goes furthest, with Regulation 10 treating autonomous and semi-autonomous systems as hard law. ADGM applies a GDPR-modelled regime.

Cited to primary sources
Federal PDPL 45/2021
Governing framework
UAE Data Office (federal); DIFC Commissioner; ADGM
Supervisory authority
5
Controls this market requires
7
Required or strongly expected
Three regimes, not one. The UAE federal PDPL applies on the mainland, but the DIFC and ADGM financial free zones have their own laws. In the DIFC, Regulation 10 on Processing Personal Data via Autonomous and Semi-Autonomous Systems (in force since September 2023) is the region's only piece of hard AI law - it requires an AI-interaction notice, ethical and transparent design principles, a high-risk assessment and certification, and an Autonomous Systems Officer. ADGM applies its GDPR-modelled Data Protection Regulations 2021, with no AI-specific instrument. The grades below reflect the federal (mainland) position.
Good to know: the federal PDPL's Executive Regulations are still unissued, so exact DPO, DPIA and breach-notification thresholds cannot yet be stated as firm numbers - treat the federal duties below as directional until the regulations land. The AI Charter, National AI Strategy and AI Ethics principles are soft law, not binding rules.
Status: provisional overview (v0.1), reviewed against primary sources dated 24 Aug 2026; not legal advice.

What the UAE expects of you

All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.

Required mandated by binding law Expected near-mandatory / guidance-backed Prudent advisable Optional emerging n/a not applicable
AI RiskRequired

AI risk classification & impact assessment

Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). PDPL Article 21 impact assessment for high-risk processing.

Closes with: AI risk classification + impact assessment (AIA/FRIA)
AI DataRequired

Data governance for AI

Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. PDPL Articles 4-5 lawful basis and data principles govern AI data.

Closes with: AI data-governance standard
AI OversightRequired

Human oversight & automated decisions

Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. PDPL Article 18 is the de-facto AI hook - rights around automated processing.

Closes with: Human-oversight + automated-decision safeguards note
AI SecurityRequired

Security of AI systems

AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. PDPL Article 20 security of processing.

Closes with: AI security controls statement
AI IncidentRequired

AI incident response & serious-incident reporting

Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. PDPL Article 9 breach notification (exact clock pending executive regulations).

Closes with: AI incident-response plan + reporting templates
AI AssuranceExpected

Accuracy, robustness & drift monitoring

Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence. Expected under general accountability; no AI-specific assurance rule federally.

Closes with: Model monitoring + drift-review plan
AI Supply ChainExpected

Third-party / vendor AI & foundation models

Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Vendor and foundation-model diligence expected under processor duties.

Closes with: Vendor AI due-diligence + model cards
AI GovernancePrudent

AI governance ownership & policy

A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI policy is prudent; the AI Charter and Ethics principles are soft law.

Closes with: AI policy + governance charter
AI InventoryPrudent

AI system inventory / register

A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.

Closes with: AI system register
AI TransparencyPrudent

Transparency & disclosure

Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. No federal AI-labelling duty; disclosure is prudent (DIFC Reg 10 requires it in-zone).

Closes with: AI transparency + disclosure notices
AI UsePrudent

Acceptable use of AI by staff

An internal policy governing employees' use of generative AI: approved tools, data rules, output review.

Closes with: Acceptable-use policy for generative AI
AI AssurancePrudent

Record-keeping, logging & conformity

Keeping the logs, technical documentation and conformity evidence regulators expect. Record-keeping is prudent federally; DIFC requires an AI-activities register.

Closes with: AI logging + technical-documentation pack

Get UAE-ready across all three regimes

PrivMatrix works out whether the federal PDPL, DIFC Regulation 10 or ADGM applies to you, then generates the AI notices, registers and assessments each regime expects - and flags where federal thresholds still await the executive regulations.

Other markets

See all AI laws →
๐Ÿ‡ช๐Ÿ‡บ EU๐Ÿ‡ฌ๐Ÿ‡ง UK๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ฎ๐Ÿ‡ณ India๐Ÿ‡ถ๐Ÿ‡ฆ Qatar