The position
The Abu Dhabi Global Market has no standalone artificial-intelligence law.
The Abu Dhabi Global Market has no standalone artificial-intelligence law. Its Data Protection Regulations 2021 are a GDPR-modelled data-protection regime, and they reach AI the way that family of laws reaches it: through the rules on automated decisions and through the general obligations that apply whenever an AI system processes personal data. The regulations are current in a consolidated version dated August 2025 and have been in force since 2021 (Data Protection Regulations 2021, section 64). They do two things with AI that are worth stating at the outset.
First, section 20 gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects (Data Protection Regulations 2021, section 20(1)). The wording mirrors the automated-decision provision of the GDPR, and it is drawn more strongly than the federal equivalent: where the federal Personal Data Protection Law gives an objection right, examined in the companion article on the federal law, the ADGM provision is framed as a right not to be subject to the decision at all, subject to defined exceptions.
Second, and distinctively, the ADGM regulations are the only one of the three UAE data regimes this series examines to use the words “artificial intelligence” in their operative text. Section 31(4)(c) carves a dataset used to lawfully train or refine an artificial intelligence system out of the duty to delete personal data once its processing basis has ended, provided the use does not present risks to a data subject’s rights and a data protection impact assessment has been carried out (Data Protection Regulations 2021, sections 31(4)(c) and 31(5)). That express hook sits inside the cessation-of-processing machinery, not the rights chapter, which is why it is easy to miss and worth foregrounding.
One structural divergence governs how all of this plays out for AI, and it should be flagged now. ADGM has a legitimate-interests lawful basis (section 5(1)(f)). The federal regime, as the companion article sets out, does not. Because legitimate interests is the basis most often relied on for training data and analytics, the choice of free zone changes the lawful-basis analysis for an AI build before any AI-specific provision is reached. That is a consequence this article draws from the two regimes’ lawful-basis architectures, marked as such, not a statement either regulation makes about AI.
The material scope is the GDPR shape: the regulations apply to processing of personal data wholly or partly by automated means, and to non-automated processing of personal data that forms part of a filing system (Data Protection Regulations 2021, section 2(1)). Automated processing is squarely within scope, so an AI system processing personal data is caught on the same footing as any other automated processing. The territorial scope turns on establishment: the regulations apply to processing in the context of the activities of an establishment of a controller or processor in ADGM, wherever the processing physically occurs, and reach a processor outside ADGM acting for an ADGM controller to the extent possible (sections 3(1) and 3(2)).
One scope provision on the face of the consolidated text is spent and should be read as such. Section 3(4) exempts persons operating from Al Reem Island, but only for a window that commenced with Cabinet Resolution No. 41 of 2023 and ended on 31 December 2024 (section 3(4)). As at the date of this article that window has closed, so the exemption no longer removes anyone from the regulations; the provision remains printed in the consolidated text but is spent by its own terms. This is a reading of the dated window against the current date, not a change the register has made to the wording.
The scope provision matters for the map this series draws. An establishment in ADGM is governed by the ADGM regulations, not the federal Personal Data Protection Law, because the federal law carves out free zones with their own data legislation, a point the companion article on the federal law develops. Which of the three regimes governs an AI deployer therefore follows from where it is incorporated.
Processing is lawful under ADGM only on one of six bases: consent, contract necessity, compliance with a legal obligation, protection of vital interests, performance of a public-interest or official-authority task, and the legitimate interests of the controller or a third party except where overridden by the data subject’s interests, in particular where the data subject is a child (Data Protection Regulations 2021, sections 5(1)(a) to 5(1)(f)). The legitimate-interests basis does not apply to processing by a public authority performing its tasks (section 5(2)).
The presence of section 5(1)(f) is the pivotal divergence from the mainland. Training an AI model on personal data, running analytics, and profiling for risk or personalisation are activities that a GDPR-lineage controller typically grounds in legitimate interests, subject to a balancing test. An ADGM controller has that basis available; a mainland controller, on the companion article’s reading of the federal law, does not and must fit the activity into contract necessity or a legal obligation instead. The practical consequence for an AI build is that the same processing may be lawful in ADGM on a basis that is simply absent federally. That consequence is drawn from the two lawful-basis regimes read together and is marked as an inference; the direct side-by-side comparison should be run with both primary texts loaded, which this article has not done for the federal side this turn.
Special categories of personal data, which include the biometric and health data that many AI systems ingest, are prohibited from processing unless one of the conditions in section 7(2) applies, several of which require an appropriate policy document to be in place (sections 7(1) and 7(2)). This is the ordinary GDPR-style special-categories gate, and it bites on AI systems that process such data just as it bites on any other processing.
Section 20 is the provision that most directly governs AI decision-making, and it repays a structural read. The right is that a data subject shall not be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them (Data Protection Regulations 2021, section 20(1)). Two features of the trigger matter: the decision must be based solely on automated processing, so a decision with genuine human involvement falls outside it, and it must have legal or similarly significant effect, so a trivial automated output does not engage it.
The exceptions are three, and they are narrower than they first appear. The right does not apply where the decision is necessary for entering into or performing a contract between the data subject and a controller, is based on the data subject’s explicit consent, or is required or authorised by applicable law, including for fraud prevention, anti-money laundering and security and integrity purposes (section 20(2)). The third exception carries its own procedure: the controller must notify the data subject in writing that a solely-automated decision has been taken, and the data subject then has one month to request that the decision be reconsidered or retaken other than on a solely-automated basis (section 20(2)(c)). For the contract and consent exceptions, the controller must implement safeguards including at least the right to obtain human intervention, to express a point of view, and to contest the decision (section 20(3)). And a solely-automated decision must not be based on special categories of personal data unless a specific condition and safeguards apply (section 20(4)).
Whether section 20(1) operates as a general prohibition on solely-automated decisions or as a right the data subject must invoke is the live interpretive question, and it is not resolved on the operative words alone. The wording mirrors the GDPR provision, and the Commissioner’s published guidance on data subject rights addresses how the right is to be read; that guidance has not been loaded in full this turn, so this article states the text and flags the prohibition-versus-right question as one to resolve against the guidance rather than asserting an answer. What is clear is that the transparency obligations require the controller to tell data subjects that automated decision-making, including profiling, exists and to give meaningful information about the logic involved and the envisaged consequences (sections 11(2)(g), 12(2)(g) and 13(1)(h)). An AI system making consequential decisions in ADGM therefore carries an explanation duty on the face of the regulations.
Set against the other two regimes, section 20 is a third distinct mechanism. The federal law objects; the DIFC deems the deployer into controllership and gates high-risk systems behind certification, as the companion articles set out; ADGM grants a right against the solely-automated decision itself, with a human-review safeguard. Same technology, three architectures.
The distinctive ADGM provision is not in the rights chapter but in the rules on stopping processing. When the basis for processing ends, or a data subject exercises the erasure right, the controller must delete, anonymise, pseudonymise or securely encrypt the personal data (Data Protection Regulations 2021, section 31(1)). Section 31(4) then carves out three cases where that duty does not bite, and the third names AI expressly: personal data that is part of a dataset used to lawfully train or refine an artificial intelligence system, in a manner that does not present risks to a data subject’s rights (section 31(4)(c)). The carve-out is not free-standing. A controller relying on it must first conduct a data protection impact assessment under section 34, and must limit the processing to what is necessary for the purpose (section 31(5)), and must hold a policy to delete the data once the grounds no longer apply (section 31(6)).
Read structurally, this is operative content sitting in a proviso: the AI-training permission is an exception to a deletion duty, gated by an assessment. It is also the only place across the three UAE data regimes where the black-letter text uses the term “artificial intelligence,” and the term is not defined anywhere in the regulations, including the definitions section (section 62). That the regulations impose a concrete obligation keyed to an “artificial intelligence system” without defining the phrase is a genuine gap, named here as an open question rather than filled: the boundary of what counts as an AI system for section 31(4)(c) is left to be worked out.
The assessment framework that gates the carve-out is the general one. A controller must carry out a data protection impact assessment before processing likely to result in a high risk to the rights of natural persons (section 34(1)), and the Commissioner must publish a list of processing operations that require one (section 34(4)). The defined term High Risk Processing Activities reaches, among other things, systematic and extensive automated evaluation including profiling on which decisions with legal or significant effect are based, and the adoption of new or different technologies creating a materially increased risk (section 62). Both limbs are AI-shaped, so a consequential AI deployment will commonly sit inside the high-risk category and its assessment and officer obligations.
The enforcement architecture is complete on the text, which distinguishes it from the federal regime’s deferred tariff. The Commissioner may impose an administrative fine not exceeding USD 28 million for a contravention (Data Protection Regulations 2021, section 55(1), a figure set by the amendment of 28 February 2024), with a separate fixed penalty of up to 150 per cent of the unpaid fee for non-payment of the data protection fee (section 56(1)). A personal data breach must be notified to the Commissioner without undue delay and, where feasible, within 72 hours (section 32(1)), a hard timeframe that exists on the face of the ADGM text where the federal equivalent is deferred to unissued regulations. Data subjects may complain to the Commissioner (section 57) and refer matters to the Court (section 58), and controllers and processors carry joint and several liability for damage from non-compliant processing (section 59(6)).
Transfers of the personal data an AI system uses run through the GDPR-style Part V: adequacy decisions by the Commissioner, which may rest on a European Commission adequacy decision (sections 41(3)(a) and 41(3)(b)), standard contractual clauses that may adopt the European Commission’s clauses by reference (section 42(2)), binding corporate rules (section 43), and specific derogations (section 44). The GDPR lineage is not inferred here; it is written into the instrument, which defines the GDPR as a term and builds EU mechanisms into the transfer regime (section 62; sections 41(3)(b) and 42(2)).
The practical hooks for an AI deployer are two, and neither is an AI licence. There is no AI-specific authorisation in the ADGM regime; there is a data protection fee and notification obligation on any controller that starts processing (section 24), and a data protection officer requirement where core activities involve large-scale regular monitoring or large-scale special-categories processing (section 35(1)). The regime governs the AI deployer as a controller, not as the operator of a licensed AI product.
Everything set out above binds on the current consolidated text: the lawful bases including legitimate interests, the section 20 automated-decision right, the section 31(4)(c) AI-training carve-out and its assessment gate, the impact-assessment framework, the USD 28 million fine ceiling, the 72-hour breach rule, and the GDPR-style transfer regime. What remains open is narrower and specific: the term “artificial intelligence system” is used but undefined (section 31(4)(c) against section 62); whether section 20(1) is a prohibition or an invokable right is a guidance-level question this article has flagged rather than answered; and the content of the Commissioner’s section 34(4) list of assessment-triggering operations is a separate publication to be checked.
The three-regime map is now complete, and the divergences are material rather than cosmetic. The federal Personal Data Protection Law reaches AI through an objection-shaped automated-processing right, has no legitimate-interests basis, and awaits its Executive Regulations. The DIFC deems the deployer of an autonomous system into controllership and gates high-risk deployment behind a certification regime and a dedicated officer. ADGM grants a right against solely-automated decisions with a human-review safeguard, is the only regime to name AI in its text, and offers a legitimate-interests basis that the mainland lacks. Which regime governs an AI deployer is decided by incorporation, and the answer changes the lawful basis, the deployment gate and the enforcement exposure. A substantive comparison against the GDPR and the EU AI Act, which the ADGM regime’s GDPR lineage would make illuminating, is reserved for a piece that loads those instruments; the GDPR is named and incorporated in the ADGM text, but the EU AI Act (in force with phased application) is not loaded this turn and is not relied on here.
The refresh triggers follow from the regime’s own habits. The ADGM regulations have been amended in 2022, 2023, 2024 and 2025, so a compliance position keyed to a specific section number should be re-checked against the current consolidation; the consolidated text loaded here is titled August 2025 yet carries a footnote referencing a 9 September 2025 amendment, so its exact consolidation date should be confirmed against the ADGM register. The Commissioner’s section 34(4) assessment list and the published adequacy list are separate instruments to track. The answer to the question in the title is therefore precise: ADGM treats artificial intelligence not through an AI statute but through a GDPR-modelled data law that grants a right against solely-automated decisions, expressly permits AI-training retention subject to an impact assessment, and supplies the legitimate-interests basis on which much AI processing is built.
For your facts, in confidence, put the question to the firm.





The bench stands behind it