All resources
Blog 6 min read

DIFC Regulation 10 explained: the region's first AI data-protection regime

C1The Compliance One team4 October 2026

Most data-protection laws handle AI with a single clause about decisions made solely by automated means. The Dubai International Financial Centre went further and wrote a dedicated instrument, Regulation 10, for autonomous and semi-autonomous systems that process personal data. If you run AI in the DIFC, this is a distinct set of duties layered on top of the DIFC Data Protection Law itself, and it is worth understanding on its own terms.

It defines who is responsible

Regulation 10 names roles rather than leaving responsibility vague. There is the Deployer, which behaves like a controller for the system, the Operator, which behaves like a processor, and an Autonomous Systems Officer (ASO) who holds oversight. The first practical step is simply mapping which of your people and vendors sit in which role for each system, because the duties attach to the roles.

Transparency, oversight and human intervention

Autonomous processing has to be lawful, transparent, fair, accountable, non-discriminatory and subject to human oversight. In practice that means telling people when a system is being used and what it does, keeping registers of use cases and automated decisions, and honouring the right to human intervention for decisions that carry legal or similarly significant effect. The spirit is that an autonomous system does not get to be a black box that no human is answerable for.

Certification is coming

Regulation 10 points toward certification for higher-risk systems, with standards that are still finalising. Treat this as a moving target: build the inventory, assign the ASO, keep the registers, and watch for the current certification requirements rather than assuming today's position is the final one. High-risk autonomous processing also triggers a DPIA under the Law, so the AI work and the privacy work connect.

Regulation 10 is the DIFC saying the quiet part out loud: if a machine is making decisions about people, someone with a name and a job title is accountable for it.

In Compliance One

The DIFC control library includes a dedicated Regulation 10 domain for autonomous and AI systems, so the roles, the transparency and oversight duties and the certification track sit alongside the rest of your DIFC programme rather than in a separate tool. Because high-risk autonomous processing also needs a DPIA, the AI controls connect to the impact-assessment workflow, and the whole thing can be crosswalked to your AI-management evidence under ISO 42001 and the NIST AI RMF.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.