DIFC Regulation 10: What the Gulf’s First AI Data Rule Actually Requires (+ the June 2026 Consultation)
Published: 27 July 2026 · Last updated: 27 July 2026
The Dubai International Financial Centre wrote artificial intelligence into its data protection framework earlier than almost anyone in the region — and most of what is written about that rule gets its date wrong. This tracker explains what Regulation 10 of the DIFC Data Protection Regulations actually requires, what the July 2025 amendments changed, and what to watch in the public consultation opened on 18 June 2026. It is a living page: the dates at the top show when it was last reviewed, and the update log at the end records every substantive change. It is information, not legal advice.
What Regulation 10 is — and what it isn’t
The DIFC Data Protection Law — Law No. 5 of 2020 — has been in force since 1 June 2020. Regulation 10 is part of the Data Protection Regulations made under that law, and it entered into force on 7 September 2023 through amendments to those Regulations. That made the DIFC the first jurisdiction in the MEASA region with a regulation aimed squarely at the processing of personal data by autonomous and semi-autonomous systems — machine learning and AI, in plain terms.
It is worth being precise, because a wave of commentary dates the rule to “January 2026”. That is wrong. Regulation 10 has been binding since September 2023; deployers of AI systems in the DIFC have been inside its scope for almost three years. What is genuinely new in 2026 is not the rule’s birth but its revision — the consultation covered below.
Regulation 10 is also not a standalone AI law. It creates no parallel regime with its own regulator and licensing. It works by extending the existing Data Protection Law’s obligations onto the organisations that deploy autonomous systems — which is why the rest of this page keeps returning to controllers, processors, and impact assessments.
Who it applies to
Regulation 10 attaches to controllers and processors already subject to the DIFC Data Protection Law when they deploy autonomous or semi-autonomous systems that process personal data. “Deploy” is the operative word: the obligation sits with the organisation putting the system to work on personal data, not only with the vendor that built it. If you buy an AI product and point it at your customer records in the DIFC, the regulation is talking to you.
The systems covered are those that operate autonomously or semi-autonomously — technology that reaches or shapes outcomes with limited human involvement — when personal data is processed through them. A workable rule of thumb: if a machine learning system touches personal data in your DIFC operations, treat Regulation 10 as relevant until your DPO concludes otherwise.
What Regulation 10 actually requires
Rather than inventing new duties from scratch, the regulation applies the Data Protection Law’s existing obligations to AI deployments and makes three of them concrete.
First, risk assessment. Deploying these systems can constitute a “High Risk Processing Activity” under the framework, and High Risk Processing Activities trigger a Data Protection Impact Assessment under Article 21 of the Law. The DPIA is not optional paperwork: since July 2025, failing to conduct a required one carries fines of up to $50,000.
Second, transparency. Notice to affected individuals is a core requirement of Regulation 10 — people whose personal data is processed through these systems must be told. An AI feature that quietly profiles customers, employees or patients without notice is not a grey area; it is the specific failure mode the regulation was written against.
Third, accountability. Because the regulation routes existing obligations through the deployer, the controller remains answerable for what the system does with personal data — and for holding the documentation that proves it was done lawfully.
The July 2025 amendments raised the stakes
In July 2025, the DIFC Laws Amendment Law No. 1 of 2025 changed the environment Regulation 10 operates in, in three ways. It introduced a private right of action, so individuals can bring claims for compensation rather than relying solely on the regulator. It expanded the extraterritorial scope of the framework to capture sub-processors — directly relevant to any AI stack where your vendor’s vendor touches DIFC personal data. And it raised the fine for failing to conduct a required DPIA to $50,000, converting the impact assessment from governance hygiene into a priced liability.
Read together with Regulation 10, the message is that AI deployment in the DIFC is no longer judged only at the regulator’s discretion: individuals can sue, sub-processors are in scope, and skipping the assessment has a number attached.
The June 2026 consultation — the regime is being revised now
On 18 June 2026, the DIFC opened a 30-day public consultation on new AI-focused amendments to the data protection framework. Regulation 10 is being revised, and the consultation window is the moment when deployers can see — and shape — where the regime is heading.
What to watch as it develops: how the amended text recasts the obligations of deployers versus developers; whether the High Risk Processing Activity triggers and the Article 21 DPIA linkage are redrawn; and how the transparency requirements are framed for systems whose logic is hard to compress into a notice. Each of these lands differently depending on whether you build AI or buy it.
This page is maintained as a tracker. When the consultation closes and the amendments are issued, this section will be rewritten against the final text — and the change will appear in the update log below.
What this means if you run AI on personal data in the DIFC
Regulation 10 turns two questions into engineering requirements: can you show what your AI did with personal data, and can you show that you assessed it before it did so. That is the layer DEBO is built for. DEBO deploys inside your own environment, so personal data is processed where it already sits rather than streamed to an outside service, and every question and every answer is written to a native audit log — the evidence trail an Article 21 impact assessment asks you to produce, generated as a by-product of normal use instead of reconstructed after the fact. Role-based permissions decide what each user can ask, which keeps processing aligned with the purposes you documented.
Whatever you deploy, the regulation’s direction is consistent: assess before you process, tell the people whose data is involved, and keep records you can hand to a regulator — or, after July 2025, to a court.
Update log
27 July 2026 — First published. The public consultation opened on 18 June 2026 is within its 30-day window as of this date.
Frequently asked questions
When did DIFC Regulation 10 take effect?
On 7 September 2023, through amendments to the Data Protection Regulations made under DIFC Data Protection Law No. 5 of 2020 — not in January 2026, as some commentary claims. It was the first AI/ML personal-data processing regulation in the MEASA region.
Who does Regulation 10 apply to?
Controllers and processors subject to the DIFC Data Protection Law that deploy autonomous or semi-autonomous systems processing personal data. The obligation sits with the deployer, not only with the vendor that built the system.
Does Regulation 10 require an impact assessment?
Where deploying the system constitutes a High Risk Processing Activity, yes — a Data Protection Impact Assessment under Article 21 of the Law. Since the July 2025 amendments, failing to conduct a required DPIA carries fines of up to $50,000.
What changed in July 2025?
The DIFC Laws Amendment Law No. 1 of 2025 introduced a private right of action for individuals, expanded extraterritorial scope to sub-processors, and raised the fine for failing to conduct a required DPIA to $50,000.
What is the June 2026 consultation?
On 18 June 2026 the DIFC opened a 30-day public consultation on new AI-focused amendments to its data protection framework. Regulation 10 is being revised; this page is updated as the consultation develops and records each change in its update log.
Do we have to tell people when AI processes their data?
Yes. Transparency and notice to affected individuals are a core requirement of Regulation 10 — people whose personal data is processed through autonomous or semi-autonomous systems must be informed.
See audit-ready AI inside your own environment
A 30-minute demo on your own use case: watch DEBO answer questions straight from your data, inside your environment, with the audit log your next impact assessment will ask for.
Book a demo