Règlement 10 du DIFC : ce que l'application pleine implique pour vos systèmes d'IA
Ce n'est pas une loi nouvelle. Introduit en septembre 2023, appliqué depuis janvier 2026. Les quatre obligations, sur qui elles pèsent, et pourquoi aucun prestataire ne peut vous vendre le certificat.

À retenir
- DIFC Regulation 10 governs personal data processed through autonomous and semi-autonomous systems. It was introduced in September 2023, and 1 January 2026 is the compliance date from which it is treated as a live enforcement priority rather than a forward-looking standard.
- Four obligations carry the weight: certification of high-risk commercial AI systems, an appointed Autonomous Systems Officer, a maintained register of AI systems you can explain in non-technical terms, and a documented risk assessment completed before high-risk processing starts.
- Certification is system-specific, not entity-specific, and only a DIFC-accredited certification body can issue it. Certifying your organization does not certify your next model.
- Data subjects can dispute an outcome an AI system produced, which means you must be able to reconstruct how one specific decision was reached.
- Whether a given system is high-risk is a legal determination. Take it with counsel, and build to the position your advisors reach rather than to a vendor's summary, including this one.
Regulation 10 supplements DIFC Data Protection Law No. 5 of 2020 and sets specific obligations for organizations that process personal data through autonomous and semi-autonomous systems. It was introduced on 1 September 2023, with 1 January 2026 as the compliance date.
The Dubai International Financial Centre regulates data protection under its own law, separate from the federal PDPL. Regulation 10 is the piece of that regime aimed specifically at automated systems, and it arrived well before the current wave of AI regulation elsewhere.
That history matters, because the most common misreading is that this is new law. It is not. The obligations have been on the books since September 2023. What changed at the start of 2026 is that the Commissioner of Data Protection now treats Regulation 10 as something to enforce rather than something to prepare for.
If you are a DIFC-licensed entity running anything that makes or materially informs decisions about people, the question is no longer whether this applies on some future date.

- 1 Sep 2023
- Regulation 10 introduced, supplementing DIFC Law No. 5 of 2020 Dubai International Financial Centre
- 1 Jan 2026
- Compliance date from which full enforcement is treated as live Clyde & Co
Who does it apply to?
Obligations fall on Deployers and Operators of autonomous and semi-autonomous systems that process personal data in or from the DIFC. The heaviest requirements, including certification and the appointed officer, attach specifically to high-risk processing.
Two things decide your exposure: your role in relation to the system, and whether the processing counts as high-risk.
The role distinction matters because organizations frequently assume that buying a system off the shelf transfers the obligation to the vendor. It does not work that way. If you deploy it against personal data, you hold deployer obligations regardless of who built the model.
The high-risk question is the harder one, and it is where I would resist the temptation to self-assess from an article. It is a legal determination about your specific processing, not a category you can read off a product page.
- A system that scores, ranks or screens people, where the output drives a decision about them
- Automated or substantially automated decisions reached without meaningful human review
- Systems operating at a scale or sensitivity where an error has material consequences for an individual
- Any of the above where the human in the loop exists in the process description but not in the software
The last line is the one worth checking honestly. A human approval step that nobody can evidence is, for assessment purposes, closer to no approval step at all.
What does Regulation 10 actually require?
Four obligations do most of the work: certification for high-risk commercial AI systems, appointment of an Autonomous Systems Officer, a maintained register of AI systems with the ability to explain processing in non-technical terms, and a documented risk assessment completed and acted on before high-risk processing begins.
Taken together these are less about the model and more about whether your organization can account for what it runs.
- Certification: high-risk commercial AI systems require it, and it is issued per system rather than per organization
- Autonomous Systems Officer: Deployers and Operators engaged in high-risk processing appoint one to provide independent oversight
- Register and explanation: maintain a register of your AI systems, and be able to explain the processing to affected individuals in non-technical terms, backed by supporting evidence
- Risk assessment: assess and document privacy risks before high-risk processing starts, then mitigate them rather than simply record them
- Evidence of compliance: keep the records that show you met the audit and certification requirements, not just that you knew about them
- Right to challenge: data subjects can dispute an AI system's outcome by complaint under the Data Protection Law
Can a vendor certify my AI system?
No. Only a DIFC-accredited certification body can issue Regulation 10 certification, and it applies to a specific system rather than to your organization. Any engineering vendor promising guaranteed certification is promising an outcome a third party decides.
This is the point where the market gets murky, so it is worth stating plainly. Certification is system-specific and comes from an accredited body. A consultancy or software vendor can prepare you for it and build the evidence it runs on. It cannot grant it.
The system-specific part has a practical consequence that catches teams out. Getting one model through certification does not cover the next one, nor a materially changed version of the same one. If your roadmap involves shipping model updates, the certification boundary needs to be part of how you plan releases, not something you discover afterwards.
So when you are evaluating help: ask which accredited body issues the certificate, and what exactly the vendor is contracting to deliver. Readiness and evidence are honest deliverables. A guaranteed certificate is not one.
This cuts both ways for us. We build the register, the logging and the evidence pack. We do not issue certification, and we would not take an engagement premised on our being able to.
Where should you start?
Start with the register of AI systems. Every other obligation depends on it, because certification, risk assessment, officer oversight and the right to challenge all presuppose that you know which systems exist and what they do.
In the deployments we have reviewed, the register is almost never the thing that exists already. What exists is three partial lists that disagree with each other: one from procurement, one from engineering, and one someone assembled for a previous audit.
Build it properly once and the rest becomes tractable. Here is what it has to carry.
- Every system that makes or materially informs a decision, including tools bought on a card and never reviewed
- The model and version behind each one, so an output can be traced to what produced it
- What personal data goes in, where it came from, and the lawful basis for using it that way
- Whether a human approves the outcome, who that is by role, and where that approval is recorded
- The risk assessment, its date, and what was done about what it found
- The infrastructure nobody registers: vector stores, prompt and response logs, review queues, evaluation sets and reporting extracts
How does this fit with the PDPL and sector standards?
Regulation 10 sits on top of, not instead of, the rest. A single system can fall under the federal PDPL, a sector standard such as ADHICS, and Regulation 10 at the same time, so the controls have to be built once and mapped to each.
The UAE regime is layered, and 2026 added a layer rather than replacing any. Federal Decree-Law No. 45 of 2021 still governs personal data processing nationally. The UAE Charter for the Development and Use of Artificial Intelligence, published in June 2024, is guidance rather than binding law. Sector standards continue to bind the sectors they cover.
On top of that, in June 2026 the UAE created a Cabinet-level Federal Authority for Artificial Intelligence and Data, consolidating oversight that previously sat across several bodies.
The practical takeaway is not that you need a separate compliance programme per regime. It is that the underlying artefacts, the register, the risk assessments, the decision logs and the human approval records, are substantially the same ones each regime asks to see. Build them once, map them several times.
Read what the Federal Authority changes, and what it does not
Questions fréquentes
- When did DIFC Regulation 10 come into force?
- It was introduced on 1 September 2023 as a supplement to DIFC Data Protection Law No. 5 of 2020, with 1 January 2026 as the compliance date. From that date the Commissioner of Data Protection treats it as a live enforcement priority rather than a future standard.
- Who needs an Autonomous Systems Officer?
- Deployers and Operators engaged in high-risk processing through autonomous or semi-autonomous systems must appoint one to provide independent oversight. Whether your processing is high-risk is a legal determination to take with counsel, and the independence expectations around the appointment are worth confirming with your advisors before deciding how to resource it.
- Is Regulation 10 certification issued per company or per system?
- Per system. Certification is system-specific rather than entity-specific, and only a DIFC-accredited certification body can issue it. Certifying one system does not cover another, or a materially changed version of the same one.
- Does Regulation 10 apply outside the DIFC?
- Regulation 10 is part of the DIFC's own data protection regime. Organizations outside the DIFC are governed by the federal PDPL and any sector standards that apply to them. Many groups have entities on both sides of that line, which is why the register and the evidence pack are worth building once in a way that serves either.
- What is the first thing to do?
- Build a complete register of the AI and automated decision systems you actually run, including shadow deployments, then risk-tier them with the reasoning written down. Certification, officer oversight and risk assessment all depend on that inventory existing and being accurate.
Sources
- 1.Regulation 10 FAQs: personal data processed through autonomous and semi-autonomous systemsDubai International Financial Centre
- 2.Regulation 10 of the DIFC Data Protection Law: why it matters for processing conducted using Autonomous SystemsClyde & Co
- 3.DIFC Regulation 10: AI system certification requirements organizations need to knowVanta
- 4.UAE establishes Federal Authority for Artificial Intelligence and DataMorgan Lewis
Lire la suite
L'Autorité fédérale émirienne de l'IA et des données : ce qui change vraiment
Un régulateur au niveau du Cabinet regroupant trois organismes. Ce qu'il couvre, ce qu'il ne change pas aujourd'hui, et les éléments à construire avant que les règles ne se figent.
25 sept. 2026
PDPL des Émirats et IA : ce que l'échéance 2027 exige réellement
Tout le monde cite le 1er janvier 2027. Peu savent sur quoi cette date repose. Comment la PDPL s'applique aux systèmes d'IA, quels articles comptent, et par où commencer.
4 sept. 2026
ADHICS v2 et IA : ce que les établissements de santé d'Abou Dabi doivent maîtriser
ADHICS n'a pas besoin d'un article dédié à l'IA pour la régir. Où les déploiements échouent réellement à l'évaluation, et pourquoi le délai de notification de 24 heures est le vrai test.
4 sept. 2026
Faites entrer l'IA dans vos murs.
Parlons d'un déploiement privé et prêt pour la conformité au sein de votre organisation.