Deploying AI in the UAE means answering to more than one rulebook. Federal laws set the floor, but the compliance obligations that actually bite come from the sector regulator that holds your licence. Understanding UAE AI regulation by sector is what separates a clean deployment from a fine or a licence review.
A clinic in Dubai reports to a different authority than one in Abu Dhabi. A bank's AI credit model faces expectations no proptech has ever seen. An outbound calling agent breaches TDRA rules the moment it dials the wrong number.
This piece walks through each regulator with the specific obligations your team needs on the desk before deployment day.
Key Takeaways
- The UAE's ethical AI frameworks aren't the enforcement layer — The AI Charter (June 2024) and National Strategy 2031 set ethical direction; enforceable obligations come from the sector regulator holding your licence — DHA, DoH, CBUAE, RERA, KHDA or TDRA.
- TDRA's outbound-calling fines are the toughest in force today — Cabinet Resolutions 56 and 57 of 2024, effective 27 August 2024, fine AI-powered dialling AED 50,000 for a first Do Not Call Registry breach, AED 75,000 for a second and AED 150,000 for a third — per breach, not per campaign.
- Federal data law applies even before a regulator writes AI rules — Federal Decree-Law No. 45 of 2021 on personal data protection underlies every sector, giving customers rights of access and correction regardless of what a regulator has published on AI specifically.
- A Dubai AI clearance doesn't work in Abu Dhabi — DHA and DoH are separate licensing bodies with their own inspection frameworks and clinical validation standards, so a dual-emirate healthcare group needs two parallel approval tracks for the same tool.
- The soft-law window on AI is closing — The UAE has adopted ISO/IEC 42001:2023 as a certifiable AI management standard and announced in April 2025 it will be the first nation to use AI to draft legislation, both signalling that formal rules are coming faster than most compliance calendars assume.
The National Framework: What the UAE AI Charter Actually Requires of Businesses
Two federal laws bind every AI deployment before any regulator-specific rule engages: Federal Decree-Law No. 45 of 2021 on Personal Data Protection and Federal Decree-Law No. 25 of 2018 on Projects of Future Nature. The first governs how customer data may be processed.
The second creates interim licensing pathways for genuinely novel AI use cases.
Sitting above those laws is the UAE National Strategy for Artificial Intelligence 2031, launched in October 2017 and updated in 2023. Six core values anchor the national policy: progress, collaboration, community, ethics, sustainability and safety. These are direction-setting principles, not statutes.
In June 2024 the government issued the UAE Charter for the Development and Use of Artificial Intelligence. The Charter is non-binding and sets out 12 ethical principles covering safety, algorithmic bias, human oversight and privacy. "Non-binding" has a specific meaning here.
When a sector regulator like CBUAE or DHA writes the Charter's language into its own supervisory guidance, that language becomes enforceable through the licence, not through the Charter itself. Sector regulators borrow vocabulary from it, so treating the uae ai charter business obligations as optional is a bad bet.
Two more signals matter. The UAE has adopted ISO/IEC 42001:2023, the first global AI management system standard, giving regulated firms a certifiable framework to show inspectors. In April 2025 the country announced it will be the first nation to use AI to draft new legislation.
Both point the same way: the soft-law period is closing. Operationalising obligations before a regulator asks is now the pragmatic move.
Each sector regulator focuses on a different part of an AI deployment, so it helps to see them side by side before working through the detail.
| Regulator | Sector | Core AI Focus |
|---|---|---|
| DHA | Dubai healthcare | Clinical validation, algorithmic transparency, incident response |
| DoH | Abu Dhabi healthcare | Separate licensing track, own inspection framework |
| CBUAE | Banks and fintechs | Model risk management, explainability, bias testing on credit and fraud AI |
| RERA | Real estate advertising | AI-generated images must not misrepresent the property |
| TDRA | Outbound AI calls | Prior approval, Do Not Call Registry checks, 09:00-18:00 window |
| KHDA | Dubai private schools | AI tools assessed inside the inspection and quality framework |
DHA and DoH: AI Compliance in UAE Healthcare

Photo: Vitaly Gariev on Pexels
Healthcare in the UAE has two clinical AI regulators, not one. DHA (Dubai Health Authority) licenses clinical activity in Dubai. DoH (Department of Health, Abu Dhabi) licenses it in Abu Dhabi, and approval from one does not extend to the other.
A dual-emirate hospital group running the same AI triage tool in both cities runs two parallel compliance tracks. Each authority has its own inspection framework, its own health data standards and its own expectations around clinical validation. This is the single biggest reason ai healthcare regulation uae operators budget too little time before rollout.
Underneath both authorities sits the PDPL. Any AI diagnostic, triage or patient-management tool processes personal health data, a special category. Lawful basis, patient consent and data minimisation are the floor.
Three documents should be ready before deployment:
- Clinical validation records showing the model performs on a population representative of UAE patients, not only the dataset it was trained on.
- Algorithmic transparency evidence a clinician can actually read: what the model considers, what it excludes and where its confidence drops.
- An incident-response procedure aligned with each authority's inspection framework, so an adverse event has a defined reporting path from day one.
CBUAE: What Licensed Financial Institutions Must Do Before Deploying AI
Banks, finance companies and licensed fintechs answer to the Central Bank of the UAE. CBUAE's supervisory expectations for AI cover model risk management, explainability and bias testing across the highest-impact use cases: credit scoring, fraud detection, anti-money laundering triage and customer onboarding. Following current CBUAE AI guidance means being able to show, on request, how a model was validated, how it is monitored in production and what happens when it drifts.
The PDPL applies in parallel. Any AI touching customer personal data must have a lawful basis, and customers keep rights of access and correction regardless of what the Central Bank has said about the model behind the decision. An automated credit denial without a documented, contestable rationale is a defect on two axes at once.
Firms licensed in DIFC or ADGM face a further layer. The DIFC Data Protection Law (Law No. 5 of 2020, as amended in 2023) applies to autonomous and semi-autonomous systems inside the free zone and adds obligations on top of federal requirements.
Where financial AI data may legally be hosted is a linked question with its own trade-offs.
One trap worth naming: the perimeter includes finance-function AI, not only customer-facing AI. An AI copilot used inside the finance team to categorise transactions or draft management accounts sits inside scope the moment it touches personal or regulated data.
If you are already running an AI model in a regulated function and are not sure which of these layers you have covered, book a 30-minute session and we will map your obligations against your licence.
RERA and TDRA: AI Rules for Property Advertising and Outbound Outreach
Real estate teams using AI now sit between two regulators at once. RERA sets advertising standards, while TDRA governs how a call or message can be sent. Both apply simultaneously to a proptech running AI voice agents against a property database, and non-compliance with one does not reduce liability under the other.
Start with RERA. AI-generated property images and descriptions must not misrepresent the property. A generative render of a view that does not exist, or a floor plan the AI cleaned up beyond reality, creates the same liability as any misleading listing.
Published rera ai marketing rules do not yet mandate an "AI-generated" label, but explicit disclosure is a defensible risk-management position.
Now TDRA. Cabinet Resolutions 56 and 57 of 2024, effective 27 August 2024, set the rules any outbound AI call must respect:
- Prior TDRA approval before any campaign runs.
- A locally registered UAE originating number.
- The Do Not Call Registry checked and honoured on every dial.
- Calling window capped at 09:00 to 18:00.
Fines for DNCR breaches are AED 50,000 for a first offence, AED 75,000 for a second and AED 150,000 for a third. These TDRA telemarketing rules apply per breach, not per campaign, so a single misconfigured dialler accumulates quickly.
The intersection is where most proptech operators get exposed. An AI voice agent doing outbound property outreach falls under RERA for what it says and under TDRA for how it says it, and both regulators can act on the same call.
KHDA: AI in Dubai's Private Schools and Education Platforms

Photo: Yusuf Çelik on Pexels
KHDA (Knowledge and Human Development Authority) regulates private schools in Dubai. Any AI tool going into a KHDA-inspected classroom sits inside the authority's quality framework, which evaluates technology use as part of school ratings. A poor governance finding on an AI tool does not stay contained, and it can affect the whole school's rating.
Student data adds a second layer. Under the PDPL, data relating to minors carries heightened obligations, and khda ai schools deployments have to reflect that from day one. Before a tutoring, attendance or assessment tool enters a classroom, the school needs a data processing agreement with the vendor covering purpose, security controls and sub-processors.
A workable pre-deployment checklist has four items:
- Purpose limitation, stated in writing and matched to a single use case.
- A lawful basis for processing, usually parental consent or a demonstrable legitimate interest tied to educational outcomes.
- Data retention limits, expressed in months and enforced by the vendor rather than left aspirational.
- A procedure for parental access and deletion requests that a school administrator can actually operate.
Where to Start
Sector rules are moving faster than most compliance calendars. If you are unsure which regulator holds your deployment, or whether an existing tool already breaches a rule you did not know applied, book a free 30-minute call with Lenoo AI. You will get an honest assessment mapping your obligations to your licence, and a straight answer if a proposed AI build does not need to happen at all.
FAQ
Does the UAE have a single AI law, or does each sector regulator set its own compliance rules?
There is no single omnibus AI law. Federal laws like the PDPL (Federal Decree-Law No. 45 of 2021) and Federal Decree-Law No. 25 of 2018 apply across the board, but the enforceable AI-specific expectations sit with each sector regulator: DHA, DoH, CBUAE, RERA, KHDA and TDRA.
The UAE Charter of June 2024 provides ethical direction, not statute.
Do DHA and DoH require separate approvals for the same AI clinical tool if a healthcare provider operates in both Dubai and Abu Dhabi?
Yes. DHA and DoH are separate licensing bodies with different processes and standards, so a clinical AI tool cleared in one emirate is not automatically cleared in the other. Dual-emirate operators should plan two parallel compliance tracks from the start.
What fines apply if an AI-powered outbound calling system contacts a number on the TDRA Do Not Call Registry?
Under Cabinet Resolutions 56 and 57 of 2024, effective 27 August 2024, DNCR breaches carry fines of AED 50,000 for the first offence, AED 75,000 for the second and AED 150,000 for the third. The same rules require prior TDRA approval, a UAE-registered originating number and a 09:00 to 18:00 calling window.
Can a Dubai real estate agency use AI-generated images in property listings, and must it disclose they are AI-generated under RERA rules?
AI-generated images are allowed provided they do not misrepresent the property. Published RERA guidance does not currently mandate an "AI-generated" disclosure label, but explicit disclosure is a strong risk-management position and consistent with the direction sector regulators are moving.
Does a private school in Dubai need KHDA approval before introducing an AI tutoring or grading platform?
KHDA does not yet publish a formal AI-tool approval process, but AI tools sit inside its inspection and quality framework. Schools should have a data processing agreement with the vendor, a lawful basis for processing student data, retention limits and a parental access procedure in place before deployment.
What does the UAE AI Charter issued in June 2024 actually require businesses to do today, and is it legally binding?
The Charter is not legally binding. It sets 12 ethical principles covering safety, human oversight, algorithmic fairness and privacy that sector regulators are already borrowing from when they draft their own supervisory guidance. Treating it as preparation for the enforceable rules coming next is the pragmatic read.