writing/news/2026/08
NewsAug 9, 2026·6 min read

Dubai's DIFC Tightens AI Data Rules as Regulation 10 Enters Full Enforcement

The DIFC's public consultation on amended Data Protection Regulations has closed, sending changes to Regulation 10 toward enactment. The Gulf's most specific AI compliance regime now requires certification, AI registers and an Autonomous Systems Officer for high-risk processing — with fines from USD 25,000 per violation.

The Dubai International Financial Centre's 30-day public consultation on amendments to its Data Protection Regulations closed on 18 July 2026, moving the proposed changes toward the next stage of the legislative process. The amendments sharpen Regulation 10 — the rule governing personal data processed through autonomous and semi-autonomous systems — which moved to full enforcement on 1 January 2026 after a transition period of more than two years.

For companies running AI in the Gulf, this is the region's most specific set of binding obligations on AI systems to date. Saudi Arabia, by contrast, still has no AI-specific statute; it enforces AI through the Personal Data Protection Law instead.

Key Highlights

  • The DIFC consultation ran for 30 days from 18 June 2026 and closed on 18 July 2026, as Consultation Paper No. 3 of 2026.
  • Regulation 10 came into force on 1 September 2023 with a compliance deadline of 1 January 2026; enforcement is now live.
  • High-risk commercial AI processing requires an appointed Autonomous Systems Officer (ASO), system certification, AI registers and transparency notices.
  • A proposed new Regulation 11 would give the Commissioner of Data Protection power to formally recognise accreditation and certification schemes.
  • Following the July 2025 amendments, fines run from roughly USD 25,000 to USD 50,000 per violation, with no stated cap for repeated or flagrant breaches.

Details

Regulation 10 applies to any machine-based system that operates autonomously or semi-autonomously and can process personal data — a definition broad enough to cover LLM-backed assistants, scoring models, and virtual personas or avatars that identify individuals.

It allocates duties across three roles. Providers develop or procure the system. Operators run it on someone else's direction and are treated much like data processors. Deployers authorise the system and benefit from it, and are treated as data controllers. The obligations attach to the deployer even when the system is bought off the shelf rather than built in house — buying a vendor's agent does not transfer the accountability.

Certification becomes mandatory where two conditions hold together: the system is autonomous or semi-autonomous, and it performs high-risk processing for commercial use. The regulation's high-risk indicators include automated decisions affecting employment, credit, insurance or fraud detection; processing of special categories of personal data; large-scale operations; and the use of untested technologies.

Regulation 10.3.3 bars running a high-risk system commercially unless, among other conditions, an Autonomous Systems Officer is appointed. The ASO carries status, competencies and tasks substantially similar to a Data Protection Officer, but scoped to autonomous systems. Deployers must also maintain registers documenting system use cases, processing activities, data sharing and export safeguards, plus transparency documentation explaining each system's purpose, function and decision logic.

Jacques Visser, Chief Legal Officer at DIFC Authority, framed the amendments as a clarification exercise. "As the use of AI and data-driven systems continues to develop, it is important that the regulatory framework remains practical, clear and able to respond to the way these technologies are being used," he said. "These amendments are intended to help provide that clarity, while supporting high standards of accountability and governance across DIFC."

Impact

The practical burden lands on documentation and architecture, not on model choice. An organisation that cannot produce a register of which systems process personal data, on what legal basis, and with what export safeguards, cannot demonstrate compliance regardless of how well its models perform.

That is a familiar problem in a different costume. Most Gulf enterprises do not have a single inventory of where their data goes once it leaves a core system — and AI adoption has multiplied those exits, usually through API calls that nobody classified as data processing at the time they were written.

The proposed Regulation 11 matters more than its brevity suggests. By letting the Commissioner recognise external accreditation and certification schemes, DIFC opens a path where a recognised third-party certificate can carry regulatory weight, rather than every firm negotiating its own interpretation. That is the mechanism through which compliance costs eventually fall.

Background

The DIFC issued Regulation 10 in September 2023 as an addition to its Data Protection Law, well ahead of most jurisdictions. The long runway to 1 January 2026 was deliberate: it gave firms time to inventory their AI systems and prepare for certification before enforcement began.

The regional picture around it is uneven. Saudi Arabia has no binding AI-specific statute and no announced legislative process to create one, but SDAIA enforcement is real — its committees issued 48 decisions confirming PDPL violations across 2025 and 2026, with administrative fines reaching SAR 5 million and doubling for repeat violations. The Kingdom's new copyright law came into force on 1 August 2026 with an exception permitting reproduction of works for AI training. The EU AI Act's own enforcement milestones arrived the same month.

The result is that a Gulf business operating across Dubai and Riyadh now faces two different compliance shapes for the same AI system: a certification-and-officer regime in the DIFC, and a data-transfer-and-legal-basis regime in Saudi Arabia. Our breakdown of why every LLM API call is a cross-border transfer under PDPL covers the Saudi half of that.

What's Next

The amendments now proceed through the DIFC's legislative process following the close of consultation. Firms should expect the clarified certification obligations and the formal ASO definition to be the operative changes, alongside the Commissioner's new recognition powers under Regulation 11.

The Global Privacy Assembly is due to be hosted by Dubai and the DIFC in the fourth quarter of 2026 — a plausible venue for further alignment across Gulf data protection regimes.

For teams shipping AI features now, the sequence is unchanged by any of it: map the systems, classify the processing, then choose the architecture. If you need a second pair of eyes on where your AI systems touch personal data and what that obliges you to document, we can run that review with you.


Source: DIFC — Consultation of amended DIFC Data Protection Regulations