العربية

Regulation · DIFC

DIFC Regulation 10: the Gulf’s first binding AI data rule, in practice

Regulation 10 of the DIFC Data Protection Regulations governs personal data processed through autonomous and semi-autonomous systems. It was enacted in September 2023 and revised in August 2024, and it binds across sectors rather than inside one.

Who it applies to

Organisations in the Dubai International Financial Centre that deploy or operate AI systems processing personal data. The regulation defines three roles: the deployer, who has authority over or benefits from the system and acts much like a controller; the operator, who runs the system on the deployer’s behalf, much like a processor; and the provider, who develops or procures systems for commercial use.

What it requires

All in-scope systems

Notice on first use

Transparency

Clear and explicit notice when a user first uses or accesses the system, flagging processing that is not human-initiated, controlled or directed, and its effect on the user’s rights.

OwnerDeployer
All in-scope systems

Registers

Accountability

Registers of use cases and of compliance with applicable audit and certification requirements.

OwnerDeployer and operator
High-risk processing

Certification

Commissioner scheme

Commercial systems engaged in high-risk processing are expected to need certification under a scheme established by the Commissioner. Accreditation of certifiers runs for five years; system certification for up to three.

StatusScheme being established; check current position
High-risk processing

Autonomous Systems Officer

Governance

Where high-risk systems are not restricted to human-defined purposes, an Autonomous Systems Officer is appointed, performing a role similar to a data protection officer.

OwnerDeployer

Enforcement

The Commissioner links Regulation 10 to the rules on unfair or deceptive practices, so misleading notices, false certification claims or misstatements about processing can be enforced against. The FAQs say violations are determined case by case.

How we help

  • An inventory of AI systems in the DIFC entity, and a view on which are in scope and which involve high-risk processing.
  • A review of user notices against the Regulation 10 requirements.
  • Use-case and compliance registers that an auditor or the Commissioner can follow.
  • Support for the Autonomous Systems Officer role, and readiness for certification when the scheme opens.
  • Alignment with ISO/IEC 42001, so one management system serves DIFC and other Gulf AI instruments; see our AI governance service.

Independence

We never assess work we have advised on, and we never sell the fix for anything we assess. Where a framework requires a licensed or accredited assessor, we say so and tell you who can sign it.

Questions we are asked

Does Regulation 10 apply to every automated system?

No. It covers autonomous and semi-autonomous systems that process personal data, including machine learning and natural language processing. Purely automated systems whose operation is deterministically controlled by humans are excluded.

What must users be told?

Clear and explicit notice on first use or access, including any processing that is not human-initiated, controlled or directed, and how that affects their rights to rectification, erasure or objection.

Can an EU AI Act certification help?

The Commissioner’s FAQs say existing certifications under the EU AI Act can fast-track approval through a short-form application.

Primary sources

Checked 30 September 2026. Nothing on this page is legal advice; the regulation as published by the DIFC is the authority.

Start with a scoping call

Tell us which AI systems your DIFC entity uses, who built them and whether any make decisions about people.