AI Approval Process: Who Approves New AI Use Cases at Your UAE Company?

Set up an AI approval process your company can actually run. Who approves, what they check, and when UAE rules require more than an internal sign-off.

Shadi Hossam
Shadi Hossam
Wooden rubber stamp resting on an official document

Someone started using ChatGPT for customer emails last month. Someone else pushed a hiring tool through a free trial. A third feeds financial data through an AI summariser.

Who approved any of that? In most UAE companies, the honest answer is nobody.

A working AI approval process needs no committee. It needs one named decision-maker, three questions at intake, and a written record.

Key Takeaways

  • No one owns AI approval at UAE firms — A tool trialled by one employee becomes critical infrastructure within two months and leaves no audit trail. That absence is a governance gap, not an acceptable shortcut.
  • Three questions decide most AI approvals — The filter asks whether the tool touches personal data, automates a judgment call, or is customer-facing. Most tools clear it in under a day without a panel meeting.
  • PDPL requires a documented trail for personal data — Federal Decree-Law No. 45 of 2021 requires a formal review for any AI use case touching personal data, with no exception for testing.
  • Telemarketing AI needs TDRA approval, not just sign-off — Cabinet Resolutions 56 and 57 of 2024, effective 27 August 2024, require TDRA prior approval for any system that places or sequences outbound calls. First-breach fines are AED 50,000, rising to AED 75,000 for a second breach and AED 150,000 for a third.
  • 88% use AI, but only 6% outperform — Adoption rose from 78% a year earlier to 88% today, but only 6% of organisations are high performers. Governance, not tool selection, separates the two groups.

Why informal AI adoption is a risk your UAE company is already carrying

Most UAE companies have no single person with formal authority to approve or reject a new AI use case. The tool gets trialled by a curious employee, becomes critical infrastructure inside two months, and leaves no audit trail.

That is a governance problem, not a technology one.

88% of organisations now use AI in at least one function, up from 78% a year earlier, but only 6% are high performers. The differentiator is governance, not tool selection.

Without a documented sign-off, no one can prove what data the AI touched or what decisions it automated. That silence is a live exposure under Federal Decree-Law No. 45 of 2021, the UAE's federal data protection law.

The regulator does not need a policy binder. It needs a decision trail.

Who should own AI approval decisions inside your company

Three executives in suits working together at a laptop
Photo: Kampus Production on Pexels

The approver is one named person, or a small panel of three. Size the choice to the company.

In companies of 1 to 20 employees, one person holds approval authority with a written remit, usually the owner or operations lead. The role does not require technical expertise. Pretending it does is how companies hire consultants to answer questions the operations lead could answer in twenty minutes.

Between 21 and 100 employees, a panel of three works better: operations lead, legal or compliance contact, and the department head who wants the tool.

The approver's job is not to understand the model. It is to answer four questions: what data does this touch, what decisions does it affect, who monitors outputs, and what is the rollback plan.

A lightweight intake filter that handles most use cases in a day

Three questions at intake. Answer them in writing. Most tools clear the filter in under a day.

Question one: does this use case touch personal data? Customer records, employee files, financial data, CVs.

A yes triggers a formal review under Federal Decree-Law No. 45 of 2021 (PDPL). No exceptions, no "just for testing".

Question two: does it automate a decision that currently requires human judgment? Hiring, credit, customer escalations, refund limits. A yes moves the use case straight to medium or high risk.

Question three: is it customer-facing or internal only? Internal productivity tools, drafting, summarising, scheduling, that clear questions one and two, can be logged by the designated owner without a panel meeting.

Most AI use cases in a UAE SME land in the low-risk internal tier, so the panel is not summoned for every new note-taker.

Risk tiers: how to categorise AI use cases so the process scales

Once tagged, drop the use case into one of three tiers. The tier depends on what the AI touches and whose decisions it replaces, not on the technology. The same model can sit in low risk in one deployment and high risk in another.

Risk tier Typical use cases What the approval requires
Low Internal drafting, email summarisation, scheduling, meeting notes. No personal data, no decisions automated. Log the tool, name the approver, no panel meeting.
Medium HR screening, customer sentiment analysis, document classification touching personal data. Panel review, written approval record, named monitor with a check-in schedule.
High Automated hiring decisions, credit scoring, customer-facing decisions with financial consequences. Legal review, data protection impact assessment, possible DIFC or ADGM consultation depending on jurisdiction.

The trap here is assuming a tool stays in its original tier forever. It does not.

A note-taker that was low risk for internal meetings becomes medium risk when it starts on recorded customer calls. Retag on change of use, not vendor.

What the approval review actually covers: a working checklist

Hand writing a checklist in a notebook
Photo: Jakub Zerdzicki on Pexels

The approver or panel works through four items before signing off.

Data source and handling. Where does the AI get its inputs, where do outputs go, and who outside the company can access any of it?

A tool that sends prompts to a third-party model provider is exporting data whether the vendor's marketing page uses that word or not.

Accuracy threshold and monitoring. What error rate is acceptable, who reviews outputs, and how often?

An approved tool with no named monitor is not a managed risk. It is an unmanaged one wearing the paperwork of a managed one.

Rollback plan. What does the company do if the AI produces a wrong or harmful output? Who pulls the plug, tells the affected customer, and documents the incident?

That last part hands off to your AI incident response plan; the two documents should reference each other.

Sign-off format. A short written record, a message in a shared log, is enough.

The format matters less than that it exists and can be retrieved. That is the audit trail PDPL asks for.

If your team is still figuring out where AI fits, the ground floor is covered in getting started with AI in Dubai.

When an internal sign-off is not enough: UAE rules that require external approval

Most internal AI tools do not need regulatory approval. A handful do, and the point of knowing where the line sits is to see it before deployment.

Free zone regimes layer on top of federal law. DIFC and ADGM operate their own data protection frameworks.

If your company is registered in either free zone, that regime takes precedence where more specific. Mainland licences default to federal PDPL.

AI in hiring, scoring or ranking candidates creates exposure under UAE labour law and PDPL at once. A screening tool that quietly deprioritises candidates by nationality is a labour issue, a data issue and a reputational issue in one incident.

Telemarketing AI is a hard yes on external approval. Any system that places or sequences outbound calls requires TDRA prior approval under Cabinet Resolutions 56 and 57 of 2024, effective 27 August 2024. Compliance also means using the Do Not Call Registry, calling only within the 09:00 to 18:00 window, and using local registered numbers.

First-breach fines are AED 50,000, rising to AED 75,000 for a second breach and AED 150,000 for a third.

If you are unsure whether your highest-risk use case sits inside internal governance or requires external engagement, book a free 30-minute consultation.

Keeping the approval process lightweight as your AI portfolio grows

The process only stays lightweight if maintained. Three habits keep it that way.

Build a pre-approved category list. Any tool meeting defined criteria, internal only, no personal data, no automated decisions, is approved by category, not individual review.

Schedule a brief quarterly log review instead of reconvening for every new tool. A single session catches tools that have drifted out of their original tier: the note-taker now summarising customer calls, or the drafting tool touching CVs.

Treat the intake filter and risk tiers as living documents. Update them when UAE regulation changes or when an approved use case produces an unexpected output.

The process stays lightweight only when it has a named owner. Without one, every new tool restarts the debate about who decides.

Related reading

FAQ

Does a UAE company need a written record before deploying an AI tool, or is an informal trial enough?

A written record is required whenever the tool touches personal data, under Federal Decree-Law No. 45 of 2021. For internal tools without personal data or automated decisions, a logged entry naming the approver is enough. "Informal trial" is not a defensible category once the tool is in use.

What happens if an employee starts using an AI tool without going through any approval process?

The company still carries the exposure, sanctioned or not. Retroactive approval works for low-risk tools once run through the intake filter. For anything touching personal data or automated decisions, stop, review, and resume only if it clears.

Which UAE regulation applies when an AI tool handles employee or customer personal data?

Federal Decree-Law No. 45 of 2021 (PDPL) is the baseline. If your company is registered in DIFC or ADGM, that free zone regime applies on top and takes precedence where more specific. Cross-border transfer rules apply when the AI vendor processes data outside the UAE.

Can a company in the 1 to 20 employee range run an informal AI approval process?

The process can be informal in structure. The record cannot. One named approver, a shared log with the tool name, intake answers, and a sign-off line is enough at that size.

How is approving an AI use case different from approving a regular software purchase?

A regular software purchase evaluates cost, security and fit. An AI approval adds three questions: what data does the model see, what decisions does it influence, and what happens when it is wrong.

Which AI use cases in the UAE require TDRA or government approval before going live?

Telemarketing AI is the clearest case. Any automated outbound calling system needs TDRA prior approval under Cabinet Resolutions 56 and 57 of 2024. Regulated financial services or healthcare may require sector-specific engagement with the Central Bank of the UAE or the relevant health authority.

Who is liable if an AI tool that was formally approved still produces a harmful outcome for a customer?

The company remains liable to the customer. A written approval record does not transfer liability, but shows the regulator the risk was considered, monitored and rolled back. That distinction is often the difference between a warning and a fine.

Found this useful? Share it with your team.

Ready to find your highest-ROI AI opportunity?

We map your workflows, identify quick wins, and build a custom AI roadmap in one free strategy call.

Book a Free Strategy Call →