Lead
The UAE now has a single federal regulator overseeing artificial intelligence and personal data. On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum — Vice President, Prime Minister and Ruler of Dubai — approved the establishment of the Federal Authority for Artificial Intelligence and Data, as announced by the UAE Cabinet and Dubai Media Office. The new body absorbs the functions of three existing entities and, for the first time, holds a full enforcement mandate over the PDPL for the private sector. Translation for business: the rules are getting sharper, and enforcement scrutiny for private companies is starting right now.
What was established: the Federal Authority for AI and Data
The Federal Authority for Artificial Intelligence and Data is a single federal body reporting directly to the UAE Cabinet. It is chaired by Omar Sultan Al Olama, Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. According to the primary source — the UAE Cabinet announcement — the regulator consolidates three existing structures:
- UAE Artificial Intelligence Office;
- Information and Digital Government Sector within TDRA (Telecommunications and Digital Government Regulatory Authority);
- Emirates Data Office (referred to as the UAE Data Office in the founding Federal Decree-Law No. 44 of 2021).
The logic is straightforward. Until June 2026, responsibility for AI policy and data governance was spread across separate agencies. Now companies have one address for rules, standards and clarifications. Sheikh Mohammed framed the intent plainly: the government should be "more efficient, agile and proactive", relying on "data and AI-driven tools to accelerate decision-making" (Gulf News).
What the regulator can actually do
The Authority holds seven core functions — from rulemaking to international partnerships. As mapped by international law firm Morgan Lewis, powers break down as follows:
| Function | What it covers |
|---|---|
| National policy | Unified federal course on AI and data handling |
| Legislation | Drafting strategies and secondary regulation |
| Alignment of initiatives | Coherence between federal and local digital programmes |
| Standards and guidelines | Rules for data governance and AI adoption |
| Compliance | Oversight of compliance, starting with federal bodies |
| R&D | Building the national research and development base |
| International partnerships | Expanding AI cooperation with other jurisdictions |
The practical takeaway: the mandate covers both the rulebook and its enforcement. Governance of AI deployment is now a distinct area of responsibility — meaning the regulator will look not only at the data you hold, but at how AI is actually woven into your workflows.
PDPL: the law existed, the enforcer did not — until now
The UAE's Personal Data Protection Law — Federal Decree-Law No. 45 of 2021, better known as the PDPL — has been in force since 2 January 2022. It carried one structural gap: no supervisory body with a full enforcement mandate over the private sector. The Emirates Data Office operated closer to a policy coordinator than an enforcer with real teeth.
That gap is now closed. Jurisdiction over PDPL sits with the new Authority, together with enforcement mechanisms for the private sector (per Morgan Lewis analysis). In plain terms: any breach in the handling of personal data now has an address — a place where regulator queries originate and where employee or customer complaints will land.
22 July: the enforcement wave begins
Enforcement scrutiny for the private sector starts this summer. According to Arabian Gulf Business Insight (AGBI) reporting on 22 July 2026, the regulator is ready to tighten the screws on compliance for private companies. Major law firms are already pushing compliance guidance to their UAE clients — Morgan Lewis in June 2026 and Ashurst Perkins Coie in Data Bytes 67 (July 2026). Gabriele Obino of Denodo summed up the mood in AGBI: "Compliance stops being purely a legal matter and becomes an operational one."
What that means on the ground. Legal opinions lose their weight the moment internal processes fail to match what the regulator expects: data processing logs, a working DPO function, incident response drills, staff training. One well-written policy document does not save you — the Authority will test whether the process actually runs in daily operations.
What UAE businesses should do right now
The right time to prepare is before the final schedule of fines drops, not after. Below is a baseline checklist drawn from AGBI reporting and Morgan Lewis recommendations:
- Audit your data flows. Map what personal data you collect, where it lives, and where it moves — including third-party vendors, cloud services and AI providers.
- Document the lawful basis for processing. Consent, contract, legitimate interest — for every category of customer and employee data.
- Assign a data protection lead. A Data Protection Officer or equivalent role, where the scale and nature of processing require it.
- Refresh privacy notices. On your website, in customer contracts, in HR documentation — aligned with Federal Decree-Law No. 45 of 2021.
- Deploy safeguards. Technical (encryption, access control, logging) and organisational (staff training, incident procedures, periodic review).
- Build AI accountability. Document what data feeds your models, which decisions are automated, and how they can be explained or contested.
What is still open
The schedule of fines is not published yet — confirmed by both Morgan Lewis and AGBI. Fixed amounts for specific PDPL breaches do not exist in official form. Secondary regulation from the new Authority is expected in the coming months.
A second open item is the jurisdictional boundary between the new Authority and TDRA on IoT regulation. Morgan Lewis notes that lines of responsibility have not been finalised. For companies running IoT stacks — retail, logistics, real estate with smart meters, healthcare devices — that means tracking both regulators until coordination documents appear.
The wider 2026 AI strategy
The Federal Authority for AI and Data is not a standalone move. It sits inside a sequenced 2026 AI agenda. Timeline according to the UAE Cabinet and Dubai Media Office:
- 23 April 2026: Sheikh Mohammed unveiled a framework plan to deploy agentic AI across 50% of the government sector within two years.
- 28 April 2026: The Ministerial Development Council was renamed Ministerial Council for Artificial Intelligence and Development, chaired by Sheikh Mansour bin Zayed.
- 18 May 2026: The UAE Cabinet approved a federal framework for the Agentic AI Project.
- 14 June 2026: Establishment of the Federal Authority for AI and Data was approved.
The frame is clear. The UAE is positioning itself as an AI hub with a unified rulebook — not a jurisdiction of prohibitions and barriers. For business, that means predictability: rules are shaped in one place, not across three parallel agencies with mismatched positions.
What this means for our clients
Practical implications — broken down for the three groups of companies we work with at Garant Business Consultancy.
Mainland companies. If you deal with UAE residents directly, you are on the hook for full PDPL compliance. Priority actions: audit data flows, appoint a DPO where applicable, refresh privacy policies and internal procedures. Getting there before the Authority's first investigations means engaging the regulator as a prepared party — not one playing catch-up.
Free zone residents. Free zones have long maintained their own data protection frameworks — DIFC DPL, ADGM DPR and others. Federal PDPL layers on top for operations touching mainland customers and specific cross-border scenarios. Draw a clear line on which regime applies where, and align policies so neither clients nor regulators end up looking at "two versions of the truth".
International entrepreneurs. If you process personal data of UAE residents from abroad, PDPL jurisdiction still reaches you. Review cross-border transfer mechanisms, contracts with local partners, and whether you need a data protection representative in the UAE. This matters most for SaaS platforms, e-commerce and marketing agencies holding databases of Emirati contacts.
At Garant Business Consultancy, we are already preparing clients for the new regulator: from process audits and policy drafting to staff training and structured engagement with the Authority. The rules are being written in real time — using this quiet window for preparation beats scrambling after the first inbound query. Initial consultation is complimentary.
Attribution and sources
- UAE Cabinet (primary source) — Mohammed bin Rashid approves establishing Artificial Intelligence and Data Authority
- Al Etihad News Center — Mohammed bin Rashid approves establishing AI and Data Authority (14.06.2026)
- Gulf News — UAE creates Federal Authority for Artificial Intelligence and Data
- Khaleej Times — UAE Authority: AI, data and digital government
- Morgan Lewis — UAE Establishes Federal Authority for Artificial Intelligence and Data
- Ashurst Perkins Coie — Data Bytes 67: EMEA data privacy update for July 2026
- AGBI (22.07.2026) — Closer AI and data scrutiny in UAE under new authority



