L'Autorité fédérale émirienne de l'IA et des données : ce qui change vraiment
Un régulateur au niveau du Cabinet regroupant trois organismes. Ce qu'il couvre, ce qu'il ne change pas aujourd'hui, et les éléments à construire avant que les règles ne se figent.

À retenir
- On 14 June 2026 the UAE announced the Federal Authority for Artificial Intelligence and Data, a Cabinet-level body reporting directly to the Cabinet and chaired by the Minister of State for Artificial Intelligence, Omar Sultan Al Olama.
- It consolidates three existing bodies: the UAE Artificial Intelligence Office, the Information and Digital Government Sector of the TDRA, and the previously announced Emirates Data Office, which had never become fully operational.
- Creating a regulator is not the same as creating new obligations. Nothing in the announcement changes what the PDPL requires of you today.
- What it does change is the direction of travel: a single body now leads national strategy for data, AI and digital government, and proposes the policy and legislation that follows.
- The sensible response is not to wait for new rules. It is to get the artefacts in order that every version of those rules will ask for: an inventory, a lawful basis per use, and a record of who decided what.
On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum announced the Federal Authority for Artificial Intelligence and Data, a unified national body consolidating AI oversight, data regulation and digital government under one structure reporting directly to the UAE Cabinet.
The Authority is chaired by Omar Sultan Al Olama, Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. Its remit covers national strategy for data, AI and digital government, and it proposes the policies, legislation, strategies and programmes that follow from that strategy.
The structural point is the significant one. Before this, AI policy, data regulation and digital government sat in different places. Now they report into one Cabinet-level body.

- 14 June 2026
- Date the Federal Authority for Artificial Intelligence and Data was announced Morgan Lewis
- 3 bodies
- Consolidated: the AI Office, TDRA's digital government sector, and the Emirates Data Office Eversheds Sutherland
What does it consolidate?
Three bodies: the UAE Artificial Intelligence Office, the Information and Digital Government Sector within the TDRA, and the Emirates Data Office, which had been formally announced but never became fully operational.
That third item is worth pausing on, because it explains part of why this happened. The Emirates Data Office was announced and then did not materialise into a functioning regulator. Data governance at the federal level has therefore had a gap where the operating body should have been.
Consolidation addresses that gap by putting data alongside AI and digital government in one place with Cabinet-level standing, rather than standing up a separate office again.
- The UAE Artificial Intelligence Office, which held national AI strategy
- The Information and Digital Government Sector of the Telecommunications and Digital Government Regulatory Authority
- The Emirates Data Office, announced previously and never fully operational
Does this change my obligations?
Not directly, and not yet. Creating a regulator does not itself impose new duties. Federal Decree-Law No. 45 of 2021 remains the operative data protection law, and the sector standards that already bind you continue to do so unchanged.
This is where most coverage of the announcement overreaches, so it is worth being careful. A new authority with a broad mandate is a signal about what is coming. It is not, on its own, a new compliance requirement.
What has not changed as a result of the announcement:
- The PDPL remains the governing federal law on personal data processing
- The UAE Charter for the Development and Use of Artificial Intelligence, published June 2024, remains guidance rather than binding law
- Sector regulators continue to bind their sectors, including ADHICS and the Department of Health's Responsible AI requirements in Abu Dhabi healthcare
- DIFC Regulation 10 continues to apply to DIFC entities under the Centre's own data protection regime, independent of federal arrangements
If a vendor tells you the Federal Authority has introduced an obligation you must now meet, ask them to cite the instrument. As of writing, the announcement establishes a body and a mandate.
What should you expect next?
Expect policy and legislative proposals to come from a single source rather than several, and expect the long-outstanding pieces of the federal data regime to be this Authority's to resolve. Treat timing as unknown rather than imminent.
The honest position is that nobody outside the Authority can tell you its sequencing. What can reasonably be said is which questions now have an obvious owner.
The PDPL's Executive Regulations have been the outstanding piece of the federal data protection regime for some time. Responsibility for that area of policy now sits with a body that has Cabinet-level standing and a mandate covering it. That is a meaningful change in who resolves it, without being a commitment to when.
I would plan on the basis that the direction is settled and the dates are not. That argues for building the things every plausible version of the rules will want, rather than waiting to see the final text.
What is worth doing now?
Build the artefacts that every version of these rules will ask for: a complete inventory of AI and automated decision systems, a lawful basis recorded per use, and a durable record of who approved what. None of that is speculative work.
The reason this is safe to do before the rules settle is that these are not regulation-specific deliverables. The PDPL wants them. ADHICS wants them. DIFC Regulation 10 wants them in a more prescriptive form. Any future federal AI instrument will want them too.
- A register of every system that makes or materially informs a decision, including tools bought on a card and never reviewed
- Model and version per system, so an output can be traced to what produced it
- The lawful basis for each processing purpose, written down rather than assumed
- Where data physically sits, and the transfer mechanism if it leaves the country
- Human approval captured in the system and not only in the process document
- Decision logs written where they cannot be edited after the fact
What if you are DIFC-licensed?
Then you have a dated obligation already, independent of federal developments. DIFC Regulation 10 reached its compliance date on 1 January 2026 and is being treated as a live enforcement priority, with certification, an appointed officer, a register and a pre-processing risk assessment.
Groups with entities inside and outside the Centre tend to discover this unevenly, because the DIFC regime is genuinely separate from the federal one. The practical approach is to build to the stricter requirement once and map it down, rather than running two programmes.
Regulation 10 is currently the most prescriptive AI-specific instrument applying in the UAE, which makes it a reasonable design target even for entities it does not bind.
Questions fréquentes
- What is the UAE Federal Authority for Artificial Intelligence and Data?
- A Cabinet-level body announced on 14 June 2026, reporting directly to the UAE Cabinet and chaired by Omar Sultan Al Olama, Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. It leads national strategy for data, AI and digital government and proposes the policy and legislation that follows.
- Which bodies does it replace?
- It consolidates the UAE Artificial Intelligence Office, the Information and Digital Government Sector within the TDRA, and the Emirates Data Office, which had been announced previously but never became fully operational.
- Does the new Authority create new compliance obligations?
- Not of itself. The announcement establishes a body and a mandate. Federal Decree-Law No. 45 of 2021 remains the operative data protection law, and existing sector standards continue to apply unchanged. Treat the Authority as a signal of direction rather than as a new requirement.
- Does it affect DIFC Regulation 10?
- No. The DIFC operates its own data protection regime, and Regulation 10 applies to DIFC entities independently of federal arrangements. Its compliance date was 1 January 2026 and it is being enforced.
- What should organizations do while the rules are still forming?
- Build the artefacts common to every version of the rules: a complete inventory of AI and automated decision systems, a lawful basis recorded per processing purpose, clarity on where data sits and how it transfers, and durable records of human approval. None of that depends on which instrument lands first.
Sources
- 1.UAE establishes Federal Authority for Artificial Intelligence and DataMorgan Lewis
- 2.UAE establishes the Federal Artificial Intelligence and Data Authority, centralising AI, data and digital government under a single national bodyEversheds Sutherland
- 3.Regulation 10 of the DIFC Data Protection Law: why it matters for processing conducted using Autonomous SystemsClyde & Co
Lire la suite
Règlement 10 du DIFC : ce que l'application pleine implique pour vos systèmes d'IA
Ce n'est pas une loi nouvelle. Introduit en septembre 2023, appliqué depuis janvier 2026. Les quatre obligations, sur qui elles pèsent, et pourquoi aucun prestataire ne peut vous vendre le certificat.
2 oct. 2026
PDPL des Émirats et IA : ce que l'échéance 2027 exige réellement
Tout le monde cite le 1er janvier 2027. Peu savent sur quoi cette date repose. Comment la PDPL s'applique aux systèmes d'IA, quels articles comptent, et par où commencer.
4 sept. 2026
ADHICS v2 et IA : ce que les établissements de santé d'Abou Dabi doivent maîtriser
ADHICS n'a pas besoin d'un article dédié à l'IA pour la régir. Où les déploiements échouent réellement à l'évaluation, et pourquoi le délai de notification de 24 heures est le vrai test.
4 sept. 2026
Faites entrer l'IA dans vos murs.
Parlons d'un déploiement privé et prêt pour la conformité au sein de votre organisation.