UAE Business Portal
Brent 82.4 ▲0.6% Gold $2 415 USD/AED 3.6725
Regulations

UAE Federal Authority for AI and Data: Business Guide

On 14 June 2026, Sheikh Mohammed bin Rashid approved a single federal regulator for AI and personal data — and private-sector enforcement scrutiny is starting this July.

UAE regulator symbol and data flows — Federal Authority for AI and Data

Common questions on this topic

Who in the UAE needs to prepare for enforcement by the new regulator?

Every company (mainland or free zone) that processes personal data of UAE residents — customers, employees, website visitors. Extra attention goes to businesses deploying AI systems that touch personal data: HR platforms, marketing tools, customer service bots. PDPL jurisdiction covers all UAE residents, regardless of company size.

What fines apply for violations?

As of 22 July 2026, the PDPL schedule of fines is not officially published (Morgan Lewis, AGBI). Secondary regulation from the new Authority is expected in the coming months. General consequences under Federal Decree-Law No. 45 of 2021 include investigations, enforcement actions and administrative penalties.

What should businesses do right now, before final rules land?

Six baseline steps, matching the checklist in the article: (1) map personal data flows across the company, (2) document the lawful basis for each processing category, (3) assign a data protection lead — a DPO where applicable, (4) refresh privacy notices on the website and in contracts under Federal Decree-Law No. 45 of 2021, (5) roll out technical and organisational safeguards, (6) build AI accountability by documenting model inputs and automated decisions. Public compliance guides are already out from Morgan Lewis (June 2026) and Ashurst Perkins Coie (July 2026).

How does this affect the use of AI in a company?

The new Authority explicitly oversees governance of AI deployment — how companies embed AI in operations. The key: show that AI models process personal data lawfully (valid legal basis, consent), with proper safeguards, and that AI-driven decisions are accountable and auditable. This applies to chatbots, HR scoring, marketing personalisation and customer analytics.

Who should you approach for a compliance consultation?

Corporate lawyers specialising in UAE data protection and compliance. At Garant Business Consultancy we cover the full cycle: audit of current processes, drafting policies and procedures, staff training, structured engagement with the regulator. Terms for the first meeting are on our contacts page.

Lead

The UAE now has a single federal regulator overseeing artificial intelligence and personal data. On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum — Vice President, Prime Minister and Ruler of Dubai — approved the establishment of the Federal Authority for Artificial Intelligence and Data, as announced by the UAE Cabinet and Dubai Media Office. The new body absorbs the functions of three existing entities and, for the first time, holds a full enforcement mandate over the PDPL for the private sector. Translation for business: the rules are getting sharper, and enforcement scrutiny for private companies is starting right now.

What was established: the Federal Authority for AI and Data

The Federal Authority for Artificial Intelligence and Data is a single federal body reporting directly to the UAE Cabinet. It is chaired by Omar Sultan Al Olama, Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. According to the primary source — the UAE Cabinet announcement — the regulator consolidates three existing structures:

  • UAE Artificial Intelligence Office;
  • Information and Digital Government Sector within TDRA (Telecommunications and Digital Government Regulatory Authority);
  • Emirates Data Office (referred to as the UAE Data Office in the founding Federal Decree-Law No. 44 of 2021).

The logic is straightforward. Until June 2026, responsibility for AI policy and data governance was spread across separate agencies. Now companies have one address for rules, standards and clarifications. Sheikh Mohammed framed the intent plainly: the government should be "more efficient, agile and proactive", relying on "data and AI-driven tools to accelerate decision-making" (Gulf News).

What the regulator can actually do

The Authority holds seven core functions — from rulemaking to international partnerships. As mapped by international law firm Morgan Lewis, powers break down as follows:

FunctionWhat it covers
National policyUnified federal course on AI and data handling
LegislationDrafting strategies and secondary regulation
Alignment of initiativesCoherence between federal and local digital programmes
Standards and guidelinesRules for data governance and AI adoption
ComplianceOversight of compliance, starting with federal bodies
R&DBuilding the national research and development base
International partnershipsExpanding AI cooperation with other jurisdictions

The practical takeaway: the mandate covers both the rulebook and its enforcement. Governance of AI deployment is now a distinct area of responsibility — meaning the regulator will look not only at the data you hold, but at how AI is actually woven into your workflows.

PDPL: the law existed, the enforcer did not — until now

The UAE's Personal Data Protection Law — Federal Decree-Law No. 45 of 2021, better known as the PDPL — has been in force since 2 January 2022. It carried one structural gap: no supervisory body with a full enforcement mandate over the private sector. The Emirates Data Office operated closer to a policy coordinator than an enforcer with real teeth.

That gap is now closed. Jurisdiction over PDPL sits with the new Authority, together with enforcement mechanisms for the private sector (per Morgan Lewis analysis). In plain terms: any breach in the handling of personal data now has an address — a place where regulator queries originate and where employee or customer complaints will land.

22 July: the enforcement wave begins

Enforcement scrutiny for the private sector starts this summer. According to Arabian Gulf Business Insight (AGBI) reporting on 22 July 2026, the regulator is ready to tighten the screws on compliance for private companies. Major law firms are already pushing compliance guidance to their UAE clients — Morgan Lewis in June 2026 and Ashurst Perkins Coie in Data Bytes 67 (July 2026). Gabriele Obino of Denodo summed up the mood in AGBI: "Compliance stops being purely a legal matter and becomes an operational one."

What that means on the ground. Legal opinions lose their weight the moment internal processes fail to match what the regulator expects: data processing logs, a working DPO function, incident response drills, staff training. One well-written policy document does not save you — the Authority will test whether the process actually runs in daily operations.

What UAE businesses should do right now

The right time to prepare is before the final schedule of fines drops, not after. Below is a baseline checklist drawn from AGBI reporting and Morgan Lewis recommendations:

  1. Audit your data flows. Map what personal data you collect, where it lives, and where it moves — including third-party vendors, cloud services and AI providers.
  2. Document the lawful basis for processing. Consent, contract, legitimate interest — for every category of customer and employee data.
  3. Assign a data protection lead. A Data Protection Officer or equivalent role, where the scale and nature of processing require it.
  4. Refresh privacy notices. On your website, in customer contracts, in HR documentation — aligned with Federal Decree-Law No. 45 of 2021.
  5. Deploy safeguards. Technical (encryption, access control, logging) and organisational (staff training, incident procedures, periodic review).
  6. Build AI accountability. Document what data feeds your models, which decisions are automated, and how they can be explained or contested.

What is still open

The schedule of fines is not published yet — confirmed by both Morgan Lewis and AGBI. Fixed amounts for specific PDPL breaches do not exist in official form. Secondary regulation from the new Authority is expected in the coming months.

A second open item is the jurisdictional boundary between the new Authority and TDRA on IoT regulation. Morgan Lewis notes that lines of responsibility have not been finalised. For companies running IoT stacks — retail, logistics, real estate with smart meters, healthcare devices — that means tracking both regulators until coordination documents appear.

The wider 2026 AI strategy

The Federal Authority for AI and Data is not a standalone move. It sits inside a sequenced 2026 AI agenda. Timeline according to the UAE Cabinet and Dubai Media Office:

  • 23 April 2026: Sheikh Mohammed unveiled a framework plan to deploy agentic AI across 50% of the government sector within two years.
  • 28 April 2026: The Ministerial Development Council was renamed Ministerial Council for Artificial Intelligence and Development, chaired by Sheikh Mansour bin Zayed.
  • 18 May 2026: The UAE Cabinet approved a federal framework for the Agentic AI Project.
  • 14 June 2026: Establishment of the Federal Authority for AI and Data was approved.

The frame is clear. The UAE is positioning itself as an AI hub with a unified rulebook — not a jurisdiction of prohibitions and barriers. For business, that means predictability: rules are shaped in one place, not across three parallel agencies with mismatched positions.

What this means for our clients

Practical implications — broken down for the three groups of companies we work with at Garant Business Consultancy.

Mainland companies. If you deal with UAE residents directly, you are on the hook for full PDPL compliance. Priority actions: audit data flows, appoint a DPO where applicable, refresh privacy policies and internal procedures. Getting there before the Authority's first investigations means engaging the regulator as a prepared party — not one playing catch-up.

Free zone residents. Free zones have long maintained their own data protection frameworks — DIFC DPL, ADGM DPR and others. Federal PDPL layers on top for operations touching mainland customers and specific cross-border scenarios. Draw a clear line on which regime applies where, and align policies so neither clients nor regulators end up looking at "two versions of the truth".

International entrepreneurs. If you process personal data of UAE residents from abroad, PDPL jurisdiction still reaches you. Review cross-border transfer mechanisms, contracts with local partners, and whether you need a data protection representative in the UAE. This matters most for SaaS platforms, e-commerce and marketing agencies holding databases of Emirati contacts.

At Garant Business Consultancy, we are already preparing clients for the new regulator: from process audits and policy drafting to staff training and structured engagement with the Authority. The rules are being written in real time — using this quiet window for preparation beats scrambling after the first inbound query. Initial consultation is complimentary.

Attribution and sources

Topics:RegulationsAIComplianceData Protection