The UAE has a national AI strategy and a Minister of State for AI, but most binding duties still flow from data-protection law. On the mainland the Federal Decree-Law 45 of 2021 (PDPL) supplies the hooks - automated processing, impact assessment, security and breach - while its executive regulations remain unissued. The DIFC goes furthest, with Regulation 10 treating autonomous and semi-autonomous systems as hard law. ADGM applies a GDPR-modelled regime.
All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.
Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). PDPL Article 21 impact assessment for high-risk processing.
Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. PDPL Articles 4-5 lawful basis and data principles govern AI data.
Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. PDPL Article 18 is the de-facto AI hook - rights around automated processing.
AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. PDPL Article 20 security of processing.
Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. PDPL Article 9 breach notification (exact clock pending executive regulations).
Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence. Expected under general accountability; no AI-specific assurance rule federally.
Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Vendor and foundation-model diligence expected under processor duties.
A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI policy is prudent; the AI Charter and Ethics principles are soft law.
A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.
Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. No federal AI-labelling duty; disclosure is prudent (DIFC Reg 10 requires it in-zone).
An internal policy governing employees' use of generative AI: approved tools, data rules, output review.
Keeping the logs, technical documentation and conformity evidence regulators expect. Record-keeping is prudent federally; DIFC requires an AI-activities register.
PrivMatrix works out whether the federal PDPL, DIFC Regulation 10 or ADGM applies to you, then generates the AI notices, registers and assessments each regime expects - and flags where federal thresholds still await the executive regulations.