Guide

Distinguishing UAE AI Requirements, Policies and Good Practice

AI obligations in the UAE depend on the organisation, jurisdiction, sector, data and use case. Leaders should separate binding law and regulation from government policy directions, voluntary frameworks and internal good practice before designing an AI governance programme.

Why the distinction matters

A statement about AI can describe a law, regulatory rule, government programme, policy for public entities, voluntary standard or recommended practice. Treating all of them as identical creates two risks. An organisation may claim that a voluntary principle is legally mandatory, or it may overlook an actual obligation hidden inside data protection, consumer protection, financial regulation, employment or sector rules.

The correct question is not whether the UAE has one AI law that answers everything. It is which requirements apply to this organisation and this use case.

Binding law and regulation

Binding obligations can arise from legislation and regulatory instruments. The governs the processing and protection of personal data within its scope. Financial institutions face CBUAE rules and guidance relevant to enabling technologies, consumer protection, governance and outsourcing. Health, employment, telecommunications, free-zone and other regimes may add requirements.

A company should obtain legal advice where interpretation is needed. An AI governance exercise can organise evidence and controls, but it is not a substitute for a legal opinion.

Government directions and entity policies

The federal Agentic AI programme sets objectives, roles and implementation expectations for federal entities. Dubai's AI Policy provides a governance framework for Dubai government entities. These directions are highly relevant to the bodies they govern and to suppliers supporting those bodies. They should not automatically be presented as direct obligations on every private company.

A private supplier may still face contractual requirements that translate a public body's policy into procurement, security, data, evaluation and reporting conditions.

National principles and voluntary frameworks

The sets ethical principles for responsible, safe and inclusive development and use. ISO/IEC 42001 provides a certifiable management-system standard, but certification is not automatically required for every UAE organisation. The Dubai AI Seal is a specific programme for eligible AI providers and is required for technology companies wishing to participate in Dubai government AI projects, according to the official programme announcement.

These frameworks can be valuable even where they are not generally mandatory. Organisations should describe their status accurately.

Good AI hygiene

Good practice fills the operating gap between high-level principles and a particular system. It includes maintaining an AI inventory, defining intended use, classifying impact, controlling data and permissions, evaluating representative cases, preserving human authority, logging actions, monitoring change and preparing incident and retirement procedures.

These practices may support compliance, but their immediate purpose is to help management know what the organisation is using and whether it remains dependable.

Build a requirement map per use case

For each AI system, record the legal entity, jurisdiction, sector, affected people, data categories, decision or action, materiality, vendors, deployment location and contractual commitments. Map each applicable source to an owner, control and evidence record. Keep the map current when the model, data, workflow or law changes.

Do not copy a generic control library without explaining why each control applies. Equally, do not allow a team to label a use case low risk simply because the vendor describes it as an assistant.

Common mistakes

Organisations can overstate compliance by publishing broad principles without evidence of implementation. They can understate risk by treating an agent as a software feature even when it acts on customers or money. They can rely on vendor certification without testing the configured system in their workflow. They can also create committees that approve systems but lack authority to stop them.

A good programme keeps the distinction between policy, control, test evidence and management decision visible.

How Marketways supports the work

Marketways can help build the AI inventory, classify impacts, map operating requirements, design controls and test whether a particular model or agent is dependable enough for its intended use. AI Inventory and Shadow AI Audit establishes what is in use. AI Impact Assessment and Risk Classification determines proportionate review. ISO 42001 Readiness examines management-system gaps without implying certification. AI Governance and Model Risk connects requirements to operating evidence.

Independence and scope

Marketways provides independent management and technical advisory, including readiness assessment, workflow and system design, implementation planning, data and integration review, AI evaluation, governance design and management decision support. Marketways is not affiliated with, appointed by or representing any UAE or Dubai authority, regulator or public initiative mentioned on this page. It does not provide legal opinions, regulatory approvals or certification decisions. Readers should confirm current requirements with the responsible authority and obtain specialist advice where needed.

References

  1. UAE data protection laws
  2. UAE AI Charter
  3. Federal Agentic AI roles framework
  4. Dubai government AI Policy
  5. Dubai AI Seal announcement