hoot.
Position
← Positions · the record

Does the UAE’s federal data protection law regulate artificial intelligence?

The position

The federal Personal Data Protection Law, Federal Decree-Law No.

The opening · read the position in full

01 Section I

The short answer

The federal Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, contains no artificial-intelligence regime. It reaches an AI system only where that system processes personal data, and where it does, it governs it through provisions written before generative AI reached the market: the automated-processing right in Article 18, the impact-assessment duty in Article 21, and the Article 1 definitions on which both depend. The law has been in force since 2 January 2022 (Federal Decree-Law No. 45 of 2021, Article 31).

Its shape, for AI, is the opposite of what the word “regulation” tends to imply, and the point is worth stating at the outset. Article 18 does not prohibit automated decision-making. It gives the data subject a right to object to it, and a right to have a human involved in reviewing it. The provision is objection-shaped, not prohibition-shaped, and that distinction governs how a mainland deployer should read its position: the default is that the system may run, subject to a right the individual may exercise against it, not that the system is barred until cleared.

Two consequences follow, and the rest of this article develops them. First, on the UAE mainland there is today no AI-specific statute. What is called AI regulation is data-protection regulation applied to AI, and its enforcement consequences are the general consequences of the PDPL, not a dedicated AI code. Second, the operative detail that would give Articles 18 and 21 hard edges, the thresholds, the assessment mechanics, the penalty measure, sits in Executive Regulations that are not confirmed issued on the official federal register as at the date of this article, more than four years past the deadline the law set for itself (Article 28). The principles bind now. The mechanics wait. A firm that reads the missing mechanics as a missing obligation has misread the law.

One boundary belongs in the short answer. The AI-specific instrument in this jurisdiction does not sit in the federal law at all. It sits one border away, in the Dubai International Financial Centre, in Regulation 10 of the DIFC Data Protection framework, and it binds only firms in that free zone. Which regime reaches a given deployer is decided by where the deployer is incorporated, a point Section II sets out and a separate article in this series takes up in full.

02 Section II

When does the law reach an AI system at all?

The threshold is personal data, not autonomy. The PDPL applies to the processing of personal data by a controller or processor inside the State, whatever the data subject’s location, and to a controller or processor outside the State processing the personal data of data subjects inside it (Federal Decree-Law No. 45 of 2021, Article 2(1)). Its reach is therefore extraterritorial in the same way the rest of the framework is: a model trained or run abroad on the personal data of people in the UAE is within scope. But a system that processes no personal data is outside the law entirely, however advanced. The first question in any mainland AI matter is not whether the tool is artificial intelligence; it is whether it processes personal data. Everything in Sections III and IV depends on a yes to that question.

The exclusions then decide who is governed by this law and who by another. The PDPL does not apply to, among other categories, health personal data and banking and credit personal data each governed by their own legislation, and companies and institutions in the free zones of the State that are subject to their own personal-data-protection legislation (Article 2(2)). That last carve-out is the one that builds the map. A firm in the DIFC or the ADGM is not lifted out of data-protection law; it is placed under that free zone’s own regime, which is where the DIFC’s Regulation 10 lives. So a deployer running the same model faces a different AI-data rule depending on incorporation: the federal PDPL on the mainland, the DIFC framework inside the DIFC, the ADGM framework inside the ADGM. Reading the health and banking carve-outs onto an AI deployer is a narrower and less certain exercise, and is flagged as such: whether a given system’s data falls inside a sectoral regime that displaces the PDPL is a facts question on that regime’s own scope, not a conclusion this law states for AI.

03 Section III

What does Article 18 actually give the data subject?

Article 18 is the provision the federal layer uses to govern the category of activity AI systems mostly perform: decisions produced without a person making them. The data subject has the right to object to, and not to be subject to, a decision issued through automated processing that produces legal consequences or seriously affects the data subject, including profiling (Federal Decree-Law No. 45 of 2021, Article 18). The right is triggered by two features of the decision together: it must be automated, and it must have legal or serious effect. A low-stakes automated output does not engage it; a consequential one does.

The definitions the right runs on sit in Article 1, and their exact wording is where the interpretive weight falls. “Automated Processing” is defined to reach processing carried out by a system operating without human intervention or with only limited human oversight, and “Profiling” to reach the automated use of personal data to evaluate or predict aspects of a person. The precise formulation of these two definitions is the load-bearing text for every AI question under this law, and this article marks the exact wording as requiring confirmation against the register’s English text before reliance. What is clear on the sources is the structural point: Article 18 does not reach only fully autonomous systems. Its trigger is the effect of the automated decision on the person, not the degree of the machine’s independence, so a system with a human nominally in the loop is not outside the provision if the decision is in substance automated and consequential.

Two further features complete the mechanism, and each is stated here at the calibration the loaded text supports. The right is not absolute; the law provides for cases in which an automated decision may stand, understood to include where it is necessary for a contract, permitted by other legislation, or made with the data subject’s prior consent. The exact list and wording of these exceptions is flagged for register confirmation and should not be relied on as settled from this article alone. And where an automated decision is made, the controller is required to provide for human involvement in reviewing it on the data subject’s request, the “human element” the provision preserves against a purely machine-run outcome. The direction of the provision is therefore consistent: the machine may decide, but the person retains a route to object and a route to a human review. That is the federal layer’s answer to automated decision-making, and it was drafted before the systems now deployed under it existed.

04 Section IV

When must a deployer assess the system before running it?

The second AI-relevant obligation is preventive, and it attaches to deployment rather than to any individual decision. Before beginning processing that poses a high risk to the privacy and confidentiality of personal data through the use of modern technologies, the controller must carry out a documented assessment of the impact of that processing (Federal Decree-Law No. 45 of 2021, Article 21). The triggers reach the situations AI deployment typically creates: processing that carries a high risk to data subjects through new technologies, and processing involving a systematic and comprehensive evaluation of sensitive personal data including profiling and automated processing. That an onboarding model, a behavioural-analytics layer or a profiling engine can meet these triggers is a reading of the trigger onto an AI use case, stated as such and not as a rule the law writes for AI; whether a specific system crosses the threshold is a facts question.

The same cluster of features drives the governance requirement. A controller must appoint a data protection officer where its processing involves a high risk to data subjects through new technologies or the volume of data processed, or a systematic and comprehensive assessment of sensitive personal data including profiling and automated processing, or a large volume of sensitive data (Article 10). The criteria for what counts as the relevant volume of data are themselves deferred to the Executive Regulations (Article 10(4)), which is the first place the assessment and governance duties meet the unfinished machinery: the duty to assess and to appoint binds now, but one of the tests for when it bites is not yet fixed on the official sources.

The consequence for a deployer is where the risk actually sits, and it sits at the irreversible step. An assessment run after a model is live, on data already ingested and decisions already issued, is a record of exposure rather than a control on it. The load-bearing discipline Article 21 imposes is to run the assessment before deployment, because deployment is the point past which the processing cannot be undone and the individual effects begin to accrue. The security controls of Article 5 and the encryption and pseudonymisation expectations of Article 20 apply across that processing throughout, but they mitigate a live system; the impact assessment is the one duty that is meant to bite before the system runs.

05 Section V

What binds now, and what waits?

The AI-relevant obligations of the PDPL divide cleanly into what is complete on the law’s own words and what is a shell around deferred content, and a deployer should hold the two apart. Binding now, on the text alone: the Article 18 objection right and human-review duty; the Article 21 duty to assess high-risk processing before it begins; the Article 10 duty to appoint a data protection officer where the triggers are met; the Article 5 and Article 20 controls on any processing. Waiting on Executive Regulations not confirmed issued: the volume criteria that partly set when the DPO and assessment duties bite (Article 10(4)); the administrative penalty measure, which the law defers entirely to a Cabinet decision (Article 26); and the compliance clock, which runs six months from the day those regulations issue (Article 29). The principles are enforceable; the tariff and some of the thresholds are not yet located.

The refresh triggers for this article follow from that split. The single largest is the issuance of the PDPL Executive Regulations, which would fix the deferred criteria and start the six-month regularisation clock. The second is any Cabinet decision issued under Article 26 setting the penalty measure, which is what would give these duties a quantified consequence. Institutional change at the regulator, reported through 2026, is watched but is not itself an instrument and does not alter the duties above. And the AI-specific rule for firms in the DIFC, Regulation 10, is a separate regime governed by a separate article; nothing in this piece reaches a DIFC or ADGM deployer, whose obligations run under their own free zone’s law.

The answer to the question in the title is therefore precise rather than clean. The federal data protection law does regulate artificial intelligence, but only where AI processes personal data, only through a provision that gives the individual a right to object rather than a ban on the system, and only with the enforcement measure that the general law supplies, because no AI-specific federal code exists and the operative detail of the one that governs automated processing has not yet been issued.

This is our published view

For your facts, in confidence, put the question to the firm.

makkikairisbabikerhowdariziayuki The bench stands behind it
Put it to a partner