DIFC Regulation 10: the GCC's first AI rulebook, and who it binds
Regulation 10 has been the leading AI-specific regulation in the MEASA region since 2023 and reached full enforcement in January 2026. If you are a DIFC entity running anything autonomous over personal data, it already applies.
Most of the AI-regulation conversation in the Gulf is still framed as something coming. In the DIFC it is not coming. It arrived.
DIFC Data Protection Regulation 10 has been the leading AI-specific regulation in the MEASA region since 2023, and it reached full enforcement in January 2026. If you are a DIFC-registered entity deploying anything autonomous over personal data, you are inside it now.
This is written for operators. It is informational, not legal advice — where a question is legal rather than technical, take it to counsel.
Who it actually binds
This is where most of the confusion sits, so it is worth being blunt.
Regulation 10 binds entities registered in the DIFC. It does not bind onshore UAE businesses. The DIFC regime applies instead of the federal PDPL for entities incorporated in the zone, not in addition to it.
So before reading further, establish which of these you are:
| Registration | Regime | Status |
|---|---|---|
| Onshore (mainland) | Federal PDPL | Full compliance required by 1 January 2027 |
| DIFC | DIFC DP Law + Regulation 10 | Already enforced |
| ADGM | ADGM Data Protection Regulations | Separate regime again |
A great many businesses assume the 2027 federal date is theirs. For DIFC entities it is not, and the applicable deadline has already passed.
What it covers
Regulation 10 sits inside the DIFC’s data-protection regime and imposes specific duties on entities deploying autonomous or semi-autonomous systems that process personal data.
That phrasing matters more than it might appear. It is not scoped to “artificial intelligence” as a marketing category — it is scoped to systems that act with some degree of independence over personal data. In our world that captures most of what people actually deploy:
- A voice agent that qualifies a caller and books them in
- A chat agent that looks up an order and issues a refund
- A scoring system that ranks or routes leads
- An automated triage or eligibility step
- Anything that takes an action rather than merely returning text
If your system reads personal data and then does something on the basis of it, assume you are in scope and work backwards from there.
What it asks of you
The obligations reduce, in practice, to four questions you must be able to answer about any autonomous system you run.
1. Can you explain what it did?
Not “how do transformers work”. Can you account for a specific decision affecting a specific person, on a specific date? That means logging inputs, tool calls, actions taken and outcomes — retained long enough to answer a complaint months later.
This is the single most common gap. Plenty of deployments produce good outcomes and keep no usable record of how.
2. Is there meaningful human oversight?
Meaningful is the operative word. A human who technically could intervene but has no practical route to, no visibility, and no authority is not oversight — they are decoration.
In design terms: a defined escalation path, a person who owns it, and the ability to override or reverse an action the system took.
3. Have you assessed the risk before deploying, not after?
An assessment done before go-live, proportionate to what the system can do to somebody. An agent that answers opening hours and an agent that decides eligibility are not the same risk and should not receive the same treatment.
4. Do the people affected know?
Transparency about automated processing to the data subjects it touches. For a voice agent this is straightforward and, in our experience, entirely uncontroversial: the agent identifies itself at the start of the call. Customers mind that far less than they mind being trapped on hold.
Why it is easier to comply with when you build properly
The awkward truth is that Regulation 10 mostly asks for things a well-built system has anyway.
Logging, defined escalation, a risk assessment sized to the system’s authority, disclosure to the user — these are not compliance overhead bolted onto a good deployment. They are what distinguishes a good deployment from a demo. The engagements that struggle with Regulation 10 are the ones where an agent was shipped with no logging, no owner and no defined boundary, and the regulation simply surfaced that.
This is why our builds settle what the agent may do, what it must never do, and what triggers a handover before conversation design. Those become enforced guardrails outside the model rather than polite suggestions inside a prompt — and they happen to be exactly what you need to evidence afterwards.
What to do if you are a DIFC entity today
- Inventory your autonomous systems. Not your AI tools — the systems that take actions. These are frequently not the ones IT knows about.
- For each, check you can answer the four questions above. Where you cannot, that is your gap list.
- Fix logging first. It is the cheapest to add, the hardest to retrofit as history, and the one you will be asked for.
- Name an owner per system. Accountability that is not assigned to a person is not accountability.
- Write the risk assessments down. An assessment you did but did not record does not exist for these purposes.
If you are expanding across the Gulf
Worth knowing early: Saudi Arabia’s PDPL introduces data-residency and cross-border transfer restrictions that constrain how international AI providers can serve Saudi customers, and SDAIA has layered an AI Adoption Framework, Generative AI Guidelines and AI Ethics Principles on top — the most comprehensive regulatory overlay in the GCC.
Which is to say: a design that satisfies the DIFC does not automatically satisfy Riyadh. If KSA expansion is on your roadmap, bring it into the architecture conversation now rather than rebuilding later.
If you are running an agent in the DIFC and are not certain you could evidence any of this, that is a normal position to be in and a fixable one. Our governance engagement exists for exactly that, and the readiness scorecard will tell you in about five minutes how large the gap is.