Onshore, DIFC or ADGM: which AI rules actually apply to you
There is no single UAE AI act. Obligations are split across the federal PDPL, two free-zone regimes and a stack of sectoral regulators. This is how to work out, in an afternoon, which of them binds your business.
We are regularly shown compliance work that was done carefully, thoroughly, and against the wrong regime.
It is an easy mistake. The UAE operates a layered regime — federal data protection law, financial-free-zone-specific rules, sectoral regulators and high-level ethical charters — rather than one horizontal AI statute. Compliance requirements vary significantly by sector and by where you are registered.
So the first question is never “what does the law require”. It is “which law”.
Here is how to settle it. It takes an afternoon.
Step 1 — Where are you registered?
This determines your base regime, and the three answers are mutually exclusive.
Onshore (mainland UAE)
Federal Decree-Law No. 45 of 2021 — the PDPL.
Applies to any controller or processor established in the UAE processing personal data of subjects inside or outside the country, and to organisations outside the UAE processing data of people residing in the Emirates.
Full compliance is required by 1 January 2027. If you are onshore, that is your date.
DIFC
DIFC Data Protection Law, including Regulation 10.
Regulation 10 has been the leading AI-specific regulation in the MEASA region since 2023 and reached full enforcement in January 2026. It imposes specific duties on entities deploying autonomous or semi-autonomous systems that process personal data.
If you are a DIFC entity, the federal 2027 date is not your deadline — and your actual one has already passed.
ADGM
ADGM Data Protection Regulations.
A separate regime again. As with the DIFC, it applies instead of the federal PDPL for entities incorporated in the zone.
The rule that catches everyone: free-zone regimes apply instead of the federal PDPL for entities incorporated in those zones — not in addition. Plenty of businesses build a PDPL programme they were never subject to, while missing the one they were.
Step 2 — What sector are you in?
Whatever your base regime, sectoral rules stack on top. You comply with both.
| Regulator | Applies to |
|---|---|
| NESA | Government entities and critical national infrastructure |
| CBUAE | Banks and financial institutions |
| DHA | Healthcare in Dubai |
| HAAD | Healthcare in Abu Dhabi |
This is why our clinics work starts with governance and not with a build. A patient-facing agent sits under a base data-protection regime and a health regulator, and the combination genuinely constrains what can be deployed. Better to know that in week one than to discover it after the agent is written.
Step 3 — Are you multi-entity?
Groups frequently have an onshore trading company and a DIFC or ADGM holding or advisory entity. Those are different regimes, and a shared tool estate spanning both is the most common source of genuine mess we encounter.
If a single AI tool is used by staff across two entities under two regimes, you need to know which entity’s data is in it. Usually nobody does.
Step 4 — Where does your data actually go?
Once you know the regime, the constraint that most often changes an architecture is cross-border transfer.
And if the Gulf beyond the UAE is on your roadmap, note this now rather than later: Saudi Arabia’s PDPL introduces data-residency and cross-border transfer restrictions that limit how international AI providers can serve Saudi customers. SDAIA has also published an AI Adoption Framework, Generative AI Guidelines and AI Ethics Principles — layered on top of the PDPL and sectoral regulators, this is the most comprehensive regulatory overlay in the GCC.
The practical implication: a design that is fine for a Dubai onshore business may not be deployable for the same group’s Riyadh operation. That is an architecture decision, and it is far cheaper made at the start.
The one-page version
Answer these four and you know where you stand:
- Registered where? → Onshore = federal PDPL (2027). DIFC = DIFC DP Law + Reg 10 (already enforced). ADGM = ADGM regs.
- Sector? → Add NESA / CBUAE / DHA / HAAD as applicable.
- How many entities? → Each may sit under a different regime. Map the tool estate against them.
- Data crossing borders? → Especially into or out of KSA. Settle it at design time.
Why we lead with this
We are a technology firm, not a law firm, and this article is informational rather than legal advice. Where a question is legal we say so and work alongside whoever advises you.
But we start every governance engagement here, because the regime determines everything downstream: which controls matter, what evidence looks like, what we can build, and what we will decline to build. Skipping it is how businesses end up with a thorough programme pointed at the wrong target and a deadline they did not know they had already missed.
Two minutes on the AI Readiness Scorecard will show you where the gaps are. If you would rather talk it through, the readiness call is thirty minutes and free — and if the answer is that you need counsel rather than us, we will say so.