Wise Hustlers — Digital Product & App Development Studio Logo
Get Consultation
By Wise Hustler Admin9/20/20267 min read

There is no "UAE AI Act": what actually regulates AI in the UAE right now

There is no "UAE AI Act": what actually regulates AI in the UAE right now

If you searched for UAE AI regulation in the last few months, you were probably told that a "UAE AI Act 2026" took effect in March 2026, that it sorts AI systems into Minimal, Limited, High and Critical risk tiers, that it requires you to appoint an AI governance officer, and that every organisation had to complete a mandatory self-assessment by September 2026.

We went looking for that law, because several clients asked us to build against it. We could not find it.

What we found instead is a set of pages — mostly on commercial sites with no official standing — repeating each other's summary of an instrument that none of them cite by decree number, gazette date or official link. Meanwhile the regulatory trackers maintained by international law firms say something close to the opposite.

This article lays out what we could actually verify, what is genuinely new in 2026, and what a team shipping AI into the UAE should build against in the meantime. It is not legal advice, and if you can point us at an official gazette citation for a Dubai or federal AI Act we will update this post and say so.

What the tier-one sources say

CMS's AI regulation scanner for the UAE states plainly that "there is currently no dedicated AI law in force in the United Arab Emirates." Latham & Watkins' overview of the UAE AI regulatory landscape reaches the same conclusion: no binding federal AI statute, with governance delivered by adapting existing law rather than by dedicated legislation.

That is the important distinction. "The UAE has no AI law" and "AI is unregulated in the UAE" are completely different claims, and only the first one is true. There is a great deal of binding law that applies to an AI system — it simply is not AI-specific legislation.

What is actually binding

These are real instruments with real numbers, and they are what your AI feature is measured against today:

Federal

  • Federal Decree-Law No. 45 of 2021 — Personal Data Protection Law (PDPL). The centre of gravity for anything involving personal data, which is most AI products.
  • Federal Decree-Law No. 34 of 2021 — Countering Rumours and Cybercrimes. Covers unauthorised access and misuse of data.
  • Federal Decree-Law No. 38 of 2021 — Copyright and Neighbouring Rights. Relevant to training data and generated output.
  • Federal Decree-Law No. 25 of 2018 — Projects of Future Nature, which enables pilot licensing for innovative solutions, including AI.

Emirate level

  • Dubai Law No. 9 of 2023 — autonomous vehicles.
  • Abu Dhabi Law No. 3 of 2024 — establishing the AI and Advanced Technology Council.

Financial free zone

  • DIFC Data Protection Law No. 5 of 2020 (amended 2023), which reaches autonomous and semi-autonomous systems operating within the DIFC.

Not binding, but not irrelevant

  • The UAE Charter for the Development and Use of Artificial Intelligence (June 2024), the National Strategy for AI 2031, and the AI Ethics Guide. These are principles and direction of travel, not obligations. Regulators do, however, quote them — and financial-sector guidance that is formally non-binding is routinely adopted by regulated entities as though it were not.

Notice what is missing from that list: risk tiers, a self-assessment deadline, and a statutory AI governance officer. Those specifics appear to originate in secondary commentary, not in a cited instrument.

The thing that genuinely changed in 2026

Here is the development worth actually paying attention to, and it is not a statute.

On 14 June 2026, the UAE established a Federal Authority for Artificial Intelligence and Data, announced by His Highness Sheikh Mohammed bin Rashid Al Maktoum. It consolidates three bodies that previously split this remit: the UAE Artificial Intelligence Office, the Information and Digital Government Sector of the TDRA, and the Emirates Data Office.

Its stated mandate includes setting unified national AI and data policy, proposing legislation, setting standards for data and AI management, driving compliance across government entities, and building national R&D capacity.

Two things follow from that, per Morgan Lewis's analysis:

1. The jurisdictional ambiguity that made UAE AI and data governance hard to plan around is being deliberately resolved by consolidating it into one body.

2. That body is the natural home for finalising the long-pending PDPL implementing regulations — the executive regulations that would give the 2021 data protection law meaningful private-sector enforcement machinery.

That last point is the real compliance event on the horizon. Not a hypothetical AI Act — the PDPL executive regulations, from a regulator that now has the authority to enforce them.

Alongside this, the UAE Cabinet has set out a framework to deploy agentic AI across 50% of government sectors and operations within two years. If you sell software into UAE government or government-adjacent buyers, that is a procurement signal worth more than any compliance checklist.

What this changes for a team shipping AI in the UAE

Do not build a compliance programme around a statute you cannot cite. If a vendor, consultant or content site tells you a UAE AI Act obliges you to do something, ask for the decree number and the gazette date. That request resolves the question in about thirty seconds.

Build against what exists instead, which for most products means:

  • Treat PDPL as the binding constraint, and assume the implementing regulations will tighten rather than loosen it. Lawful basis, purpose limitation, data subject rights, cross-border transfer and breach notification are the areas to get right.
  • Check your sector regulator before your general counsel. A fintech in the DIFC answers to the DFSA and DIFC data protection law; one in ADGM answers to the FSRA; a bank answers to the CBUAE. Sector rules are where concrete AI expectations are appearing first, and they bind you regardless of whether a general AI act ever arrives.
  • Keep the documentation anyway. Model inventory, training data provenance, human-review paths for consequential decisions, and an audit trail of automated decisions are not currently a UAE statutory requirement as far as we can verify — but they are cheap while you are building and expensive to reconstruct afterwards. Every jurisdiction that has legislated AI has asked for some version of them.
  • If you are in the DIFC or ADGM, read your free zone's rules directly. The free zones move faster than the federal level and their rules genuinely do reach autonomous systems.

We build and run AI features for clients in the UAE and we track this because our own delivery depends on it — if that is useful to you, our services are here. If you want the surrounding context, we have also written on UAE PASS digital identity integration and enterprise AI agent development in the UAE.

One caveat, stated plainly

UAE regulation moves quickly, and emirate-level instruments are not always easy to find in English on the day they are issued. It is entirely possible that something has been issued that the law firm trackers have not yet reflected. What is not reasonable is planning engineering work around a described law that no source will cite. Verify with UAE-qualified counsel before making a compliance decision — this post is engineering context, not legal advice.

Sources

Related articles