No Gulf state has a binding AI statute, and the UAE's federal data protection law is less operative than it looks: its executive regulations have not been issued, and the compliance grace period runs from the day they are. The one binding, AI-specific, deployer-facing instrument anywhere in the region is Regulation 10 of the DIFC Data Protection Regulations, which builds a Deployer, Operator and Provider framework precisely because controller and processor break down when no human directs the processing. For anyone deploying AI agents in the Gulf, that is where to start.
Key takeaways
- No Gulf state has a binding AI statute. A search of the UAE's official legislation portal for artificial intelligence returns only unrelated statutes that mention it in passing, and u.ae's own regulatory framework index lists no AI instrument.
- DIFC Regulation 10, on personal data processed through autonomous and semi-autonomous systems, has been in force since 1 September 2023. It is the most operationally specific AI provision in the Gulf and possibly the most agent-specific anywhere. It defines System, Deployer, Operator and Provider, requires explicit notice of non-human-initiated processing, a register of use cases, and evidence of algorithms that force human intervention, and it prohibits commercial use of a non-compliant System. High Risk Processing additionally requires an Autonomous Systems Officer.
- The UAE PDPL, Federal Decree-Law No. 45 of 2021, came into force on 2 January 2022, but its Executive Regulations have not been issued. Article 28 leaves them to the Cabinet, and Article 29's grace period for controllers and processors runs from that issuance. The UAE Data Office is still described on u.ae in the future tense.
- The UAE PDPL also has extensive exclusions in Article 2, including government data, health data governed by its own legislation, banking and credit data governed by its own legislation, and companies in free zones with their own data protection legislation. The banking and credit exclusion matters directly to anyone modelling credit-eligibility decisions.
- The UAE PDPL contains no fine amount. Article 26 provides that the Cabinet shall issue a resolution determining the violations and the administrative penalties, and no such resolution was found on the official portal. An earlier version of this guide stated a ceiling of AED 20 million; it is unsupported and has been removed.
- Saudi Arabia's AI material is guidance, current and worth reading: AI Ethics Principles, May 2025, document number SDAIA-P114E, seven principles; Generative AI for Government Guidelines, May 2025, SDAIA-P116E, with a separate public-facing edition; plus deepfakes guidelines and an AI Adoption Framework. The Saudi PDPL itself contains no automated-decision provision; those rules are in its Implementing Regulation and the operative trigger is explicit consent where a decision is made solely by automated processing.
Why Gulf AI governance matters for international operators
Three factors make the Gulf relevant to a wider set of operators than those with physical Gulf operations. First, extraterritorial scope. Article 2 of the UAE PDPL reaches controllers and processors outside the State processing the data of data subjects in the State. Saudi Arabia's PDPL likewise reaches processing of Saudi residents' personal data by entities inside or outside the Kingdom. Second, the scale of Gulf enterprise contracts for European service providers, many of which now run through AI agents. Third, the Gulf's role as an AI infrastructure node for the Middle East and Africa region.
Understanding the landscape does not require a full compliance programme for every operator with incidental Gulf exposure. It requires knowing which specific provisions apply to your deployment and whether they differ from what your EU AI Act programme already delivers. In the Gulf's case the answer is that most of them do not add much, and one of them adds a great deal.
The UAE framework: federal and free-zone layers
The UAE's regulatory architecture is multi-layered because its jurisdictional structure is. The federal government, the Emirate of Dubai, the Emirate of Abu Dhabi, and the two major financial free zones each exercise distinct authority.
At federal level, the UAE appointed a Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications, His Excellency Omar bin Sultan Al Olama. Note the office: the UAE Cabinet listing on u.ae contains no entry for a Ministry of Artificial Intelligence, and an earlier version of this guide described one three times, including in its structured data. There is a Minister of State and a UAE Artificial Intelligence Office. The national strategy is published by u.ae as the UAE Strategy for Artificial Intelligence, also referred to as the Artificial Intelligence Strategy 2031, which the UAE Council for Artificial Intelligence works to implement. u.ae's own link to the dedicated strategy page returns a 404, so its launch date and adopting body could not be read at source and are not asserted here. ai.gov.ae could not be read at source at all, so nothing is attributed to it.
The binding federal instrument for AI agents is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. It was issued on 20 September 2021 and came into force on 2 January 2022, and the official legislation portal records no amendments.
What the PDPL does not yet do
This is the most important practical point in the UAE section and the earlier version of this guide had it backwards. Article 28 of the Decree-Law provides that the Cabinet shall issue the Executive Regulations on the proposal of the Director-General. Article 29 gives controllers and processors a grace period to align their position, running from that issuance. No executive regulations exist at any official source: the portal record for the Decree-Law shows an empty related-legislations section and a last update of 20 September 2021, and a portal-wide search for personal data surfaces none. u.ae's own data protection page, last updated 4 December 2025, does not mention executive regulations and still describes the UAE Data Office in the future tense as the body that will act as the federal data regulator.
An operator should plan on the basis that the UAE federal regime is in force as a statute but not yet fully operative in practice, and that the clock on its grace period has not started.
Article 18, and what it actually grants
The automated processing provision is Article 18, headed the right of processing and automated processing. Article 17 is the right to stop processing, and an earlier version of this guide cited it for automated processing in error.
Article 18 gives the data subject a right to object to decisions issued by automated processing that carry legal consequences or seriously affect them, including profiling. That right does not apply where the automated processing falls within the terms of a contract, is required by other legislation in force, or is covered by prior consent. The controller must apply appropriate measures, and must introduce a human element into the review of automated-processing decisions on the data subject's request.
What Article 18 does not contain is a duty to notify the individual that such a decision was made, or a duty to provide meaningful information about the logic involved. Those are GDPR formulations, and an earlier version of this guide imported them into a law that does not have them.
The exclusions that shape scope
Article 2 applies the law to data subjects residing or having a place of business in the State, to controllers and processors inside the State, and to controllers and processors outside the State processing the data of data subjects in the State. It then excludes government data and government entities; personal data held by security and judicial authorities; a data subject processing their own data personally; health data governed by its own legislation; banking and credit data and information governed by its own legislation; and companies in free zones that have their own personal data protection legislation.
Two consequences. The free-zone exclusion is the legal basis for the DIFC and ADGM carve-out that this guide previously asserted without one. And the banking and credit exclusion means that a credit-eligibility decision, which an earlier version of this guide used as its worked example of Article 18 in action, may well sit outside the federal PDPL entirely.
Penalties
The Decree-Law sets no fine amount. The words million and dirham do not appear in it. Article 26 provides that the Cabinet shall issue a resolution, on the Director-General's proposal, determining the acts constituting violations and the administrative penalties to be imposed. No such resolution was found on the official legislation portal. An earlier version of this guide stated administrative fines reaching AED 20 million, approximately EUR 5 million, in two places including its structured data. That figure is unsupported and has been removed.
DIFC Regulation 10: the instrument that actually addresses AI agents
The DIFC Data Protection Law, DIFC Law No. 5 of 2020, came into force on 1 July 2020, with a current consolidated version of July 2025 following amendments in 2022 and 2025. Automated individual decision-making, including profiling, is Article 38, within the Part 6 data subject rights. There is no Chapter X, and an earlier version of this guide cited one.
An earlier version also asserted that the DIFC law applies more broadly than the federal PDPL because it is not limited to individuals who are significantly affected. That is not right either. DIFC Article 38(1) uses legal consequences or other seriously impactful consequences; UAE Article 18 uses legal consequences or seriously affect. The tests are materially the same.
The instrument that genuinely distinguishes the DIFC is Regulation 10 of the DIFC Data Protection Regulations, in force from 1 September 2023 in consolidated version 2, headed personal data processed through autonomous and semi-autonomous systems. Its own guidance records that its definitions were adapted from the OECD guidelines and the EU AI Act. It defines System, Deployer, Operator and Provider, which is a deliberate departure from controller and processor for the case where no human initiates the processing.
Regulation 10.2 requires Deployers and Operators to give explicit notice of non-human-initiated processing; a plain description of the human-defined purposes, the limits of self-definition, the outputs, the design safeguards, and the codes or certifications relied on; evidence of compliance with audit or certification requirements; evidence of algorithms that force human intervention where processing may be unfair, discriminatory, accessed by law enforcement, or non-compliant; and a register of use cases.
Regulation 10.3 imposes five design concepts, Ethical, Fairness, Transparent, Secure and Accountability, and prohibits commercial use of a System that does not comply. Where the processing is High Risk Processing, an Autonomous Systems Officer is required.
For a publication about AI agent liability, this is the single most relevant provision in the Gulf, and arguably the most agent-specific regulatory text in force anywhere. An operator running agents through a DIFC entity should treat Regulation 10 as its primary compliance document.
Note also that the DIFC regime is administered by the Commissioner of Data Protection, not by the DFSA and not by the DIFC Authority in this respect. Appendix 3 to the Regulations lists every EU member state, the United Kingdom, Switzerland and ADGM as adequate jurisdictions, which materially changes the cross-border analysis for a DIFC entity.
ADGM
ADGM operates under the Data Protection Regulations 2021, which repealed the 2015 Regulations. All ADGM-registered entities that process personal data are required to register as a Data Controller with the Office of Data Protection, and official guidance is issued by the Commissioner of Data Protection. The Commissioner can impose fines of up to USD 28 million. ADGM publishes no AI-specific regulation. An earlier version of this guide attributed data protection enforcement in both free zones to the DFSA and the FSRA; neither enforces data protection in either centre.
Saudi Arabia
SDAIA, the Saudi Data and AI Authority, was established by Council of Ministers Resolution No. 292 dated 27/4/1441H, as amended by Resolution No. 195 dated 15/3/1444H. Saudi Arabia has no binding AI statute, no AI licensing regime and no AI registration duty. Everything SDAIA has published on AI is guidance.
The current documents are worth naming precisely, because dates and versions have moved. AI Ethics Principles is cover-dated 2025, with a colophon of May 2025, document number SDAIA-P114E, version 1, and it sets seven principles: Fairness; Privacy and Security; Humanity; Social and Environmental Benefits; Reliability and Safety; Transparency and Explainability; and Accountability and Responsibility. SDAIA itself labels it a draft. An earlier version of this guide dated the principles to 2022. Generative Artificial Intelligence for Government Guidelines is dated May 2025, version 1, SDAIA-P116E, with a separate public-facing edition. Deepfakes guidelines and an AI Adoption Framework sit alongside them.
An earlier version of this guide described a draft National AI Governance Framework released for consultation in late 2025, risk-tiered, with mandatory impact assessments for high-risk applications and a penalty structure tracking the EU AI Act, and called it the most significant Saudi development for international operators. Nothing of the kind appears in SDAIA's own laws and regulations index, and the claim has been removed.
On data protection, the Saudi PDPL was issued by Royal Decree M/19 dated 9/2/1443H and amended by Royal Decree M/148 dated 5/9/1444H. Article 43 provides that it comes into force 720 days after publication in the Official Gazette, and the Implementing Regulation takes effect from the same date. SDAIA's data protection page confirms that compliance is evaluated through the National Data Governance Platform after the grace period ends but states no calendar date, so no enforcement date is asserted here.
The Law itself contains no automated-decision provision: the word automated appears only in the definition of processing, and the Article 4 data subject rights are to be informed, to access, to obtain a copy in a readable format, to correct, complete or update, and to request destruction. There is no right to object. The automated-decision requirements sit in the Implementing Regulation, and they are different in kind: the privacy notice must disclose whether decisions are made solely by automated processing under Article 5(5)(c); explicit consent is required where decisions are made solely on automated processing under Article 11(2)(c); and making automated decisions triggers impact-assessment and data protection officer requirements. Explicit consent is a materially different compliance action from a right to object, and an operator that built to the latter has built the wrong thing.
On penalties, Article 36 provides for a warning or a fine not exceeding SAR 5 million, doubled on repetition. Article 35 provides that disclosing or publishing sensitive data with intent to harm or for personal benefit carries imprisonment of up to two years and a fine not exceeding SAR 3 million, doubled on recidivism. Note that the criminal figure is lower than the administrative ceiling, not higher as an earlier version of this guide stated, and that there is no automated-processing offence in the Law.
Claims that the National Data Management Office publishes AI guidance, and that SAMA and the Capital Market Authority already require explainability for AI models in credit and investment decisions, could not be confirmed at source. SDAIA describes the NDMO as its legislative arm for data management and governance, and all the AI documents above are SDAIA's. A search of the SAMA Rulebook for artificial intelligence returned no results.
Qatar
Qatar's binding instrument is the Personal Data Privacy Protection Law, Law No. 13 of 2016. Its text could not be read at source in this pass: the Ministry of Communications and Information Technology page for it returns a server error, and the ministry's laws index lists only the Telecommunications Law and the e-Commerce Law. No penalty figures are asserted here.
What is verifiable is where Qatar stands on AI. MCIT's own policies page lists a National Artificial Intelligence Policy with the status Upcoming, meaning it has not been issued. An earlier version of this guide described a Qatar AI Committee established under the ministry, a QCSC framework with cybersecurity standards applying to AI in critical infrastructure, a National Artificial Intelligence Initiative, and discussions with the EU on digital governance alignment. None could be confirmed at a Qatari government source, and the acronym QCSC does not expand to the body the guide named. All of it has been removed.
Cross-border transfers, not data localisation
An earlier version of this guide said three times that Gulf compliance adds data localisation requirements. It does not. Neither the UAE PDPL, the Saudi PDPL nor the DIFC and ADGM regimes impose data localisation. What they impose are cross-border transfer conditions: adequacy, safeguards, and risk assessment. Localisation and transfer restriction are different obligations and conflating them sends operators to the wrong solution.
Articles 22 and 23 of the UAE PDPL govern transfer and sharing outside the State, with Article 22 covering cases where an adequate level of protection exists and Article 23 the remainder. u.ae publishes no adequacy list. Saudi Arabia's Regulation on Personal Data Transfer Outside the Kingdom requires SDAIA to publish an adequacy list; the published list could not be read in this pass, so the EU's status on it is not asserted. For a DIFC entity the position is different and better: Appendix 3 to the DIFC Data Protection Regulations lists every EU member state, the United Kingdom, Switzerland and ADGM as adequate.
The practical task is to map data flows between the Gulf jurisdiction and the processing infrastructure, and identify the transfer mechanism applying to each flow.
What operators should prepare for
First, determine which Gulf jurisdictions your deployments touch, and specifically whether you are inside DIFC or ADGM, because that changes the applicable regime entirely rather than adding to it.
Second, if you are in the DIFC, work through Regulation 10 line by line. It is the only instrument in the region written for autonomous systems, it imposes a register of use cases and a human-intervention requirement, and it bars commercial use of a non-compliant System. If your processing is High Risk Processing, appoint an Autonomous Systems Officer.
Third, for the UAE federal regime, check the Article 2 exclusions before building anything. If you are in health, banking or credit, or in a free zone with its own data protection law, the federal PDPL may not apply to you at all. If it does, build the Article 18 objection and human-review route, and do not build to a notification or logic-disclosure duty the law does not impose. Watch for the Executive Regulations, because the grace period starts when they issue.
Fourth, in Saudi Arabia, note that the operative automated-decision requirement is explicit consent under the Implementing Regulation, not a right to object, and that the current guidance documents are the May 2025 editions.
Fifth, map cross-border transfers as transfers rather than as a localisation problem, and check the DIFC adequacy list if you are working through a DIFC entity.
For operators already maintaining EU AI Act programmes, most Gulf requirements are incremental. The exception is DIFC Regulation 10, which asks for things no EU instrument asks for in the same form. For the broader global comparison see the US, EU and UK three-framework comparison, and for the EU baseline see EU AI Act Article 26 deployer obligations.
Frequently asked questions
Does the UAE have a binding AI law?
No. A search of the UAE's official legislation portal for artificial intelligence returns only unrelated statutes that mention it in passing, and u.ae's own regulatory framework index lists no AI instrument. The UAE has a Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications and a UAE Artificial Intelligence Office, but no Ministry of Artificial Intelligence appears in the Cabinet listing. The national strategy is published by u.ae as the UAE Strategy for Artificial Intelligence, also referred to as the Artificial Intelligence Strategy 2031; its dedicated page returns a 404, so its launch date and adopting body could not be read at source.
What is DIFC Regulation 10 and why does it matter for AI agents?
Regulation 10 of the DIFC Data Protection Regulations, in force since 1 September 2023, governs personal data processed through autonomous and semi-autonomous systems. It is the only binding, AI-specific, deployer-facing instrument in the Gulf. It defines System, Deployer, Operator and Provider, a deliberate departure from controller and processor for cases where no human initiates the processing. Regulation 10.2 requires explicit notice of non-human-initiated processing, a plain description of human-defined purposes and the limits of self-definition, evidence of audit or certification compliance, evidence of algorithms forcing human intervention where processing may be unfair or discriminatory, and a register of use cases. Regulation 10.3 imposes five design concepts and prohibits commercial use of a non-compliant System, and High Risk Processing requires an Autonomous Systems Officer.
How does UAE data protection law apply to AI agents?
Federal Decree-Law No. 45 of 2021 came into force on 2 January 2022, but its Executive Regulations have not been issued: Article 28 leaves them to the Cabinet and Article 29's compliance grace period runs from that issuance, so much of the law is not yet operative. The automated processing provision is Article 18, not Article 17. It gives a right to object to decisions issued by automated processing that carry legal consequences or seriously affect the individual, including profiling, and requires the controller to introduce a human element into review on request. It does not require notification that such a decision was made, and it does not require meaningful information about the logic involved. Article 2 excludes government data, health data and banking and credit data governed by their own legislation, and free-zone companies with their own data protection legislation.
What penalties apply under Gulf data protection and AI rules?
The UAE PDPL sets no fine amount at all. Article 26 provides that the Cabinet shall issue a resolution determining the violations and the administrative penalties, and no such resolution was found on the official legislation portal. In Saudi Arabia, Article 36 of the PDPL provides for a warning or a fine not exceeding SAR 5 million, doubled on repetition, and Article 35 provides that disclosing or publishing sensitive data with intent to harm or for personal benefit carries imprisonment of up to two years and a fine not exceeding SAR 3 million. In ADGM, the Commissioner of Data Protection can impose fines of up to USD 28 million. Qatar's Law No. 13 of 2016 could not be read at source, so no Qatari figure is stated.
What has Saudi Arabia actually published on AI?
Guidance, not law. SDAIA's current documents are AI Ethics Principles, cover-dated 2025 with a colophon of May 2025, document number SDAIA-P114E, version 1, setting seven principles; Generative Artificial Intelligence for Government Guidelines of May 2025, SDAIA-P116E, with a separate public-facing edition; deepfakes guidelines; and an AI Adoption Framework. Saudi Arabia has no binding AI statute, no AI licensing regime and no AI registration duty. The Saudi PDPL itself contains no automated-decision provision; those requirements sit in its Implementing Regulation, where the operative trigger is explicit consent where a decision is made solely by automated processing, not a right to object.
How do Gulf AI governance frameworks compare to the EU AI Act?
Gulf frameworks are far less prescriptive. The EU AI Act imposes conformity assessment, documentation and technical obligations for high-risk AI with penalties up to EUR 35 million or 7 per cent of worldwide turnover. Gulf frameworks are principles and national strategy, with data protection legislation as the binding layer, and the EU AI Act remains the primary compliance burden for an operator with European exposure. The one exception runs the other way: DIFC Regulation 10 asks for things no EU instrument asks for in the same form, including a register of autonomous system use cases, evidence of algorithms that force human intervention, and an Autonomous Systems Officer for High Risk Processing. Note also that Gulf regimes impose cross-border transfer conditions rather than data localisation; the two are different obligations.