DIFC Regulation 10: AI Rules for Companies Operating in the DIFC

The DIFC has purpose-built rules for AI systems that process personal data. If you deploy or operate autonomous or semi-autonomous systems in the DIFC, Regulation 10 sets requirements for transparency, accountability and, for high-risk uses, an Autonomous Systems Officer and certification.

9+ Years of Compliance Expertise
Saudi Arabia
Oman
Bahrain
End-to-End Execution
Europe
Regulation 10 of the DIFC Data Protection Regulations governs the processing of personal data through autonomous and semi-autonomous systems, including AI, generative models and machine-learning tools. It was introduced in September 2023 and supplements the DIFC Data Protection Law, with enforcement from January 2026. It places obligations on deployers and operators of such systems, built around principles of fairness, transparency, security and accountability. For high-risk processing, commercial use is conditional on audit and certification requirements set by the DIFC Commissioner of Data Protection, use for human-defined or human-approved purposes, and the appointment of an Autonomous Systems Officer (ASO).
Why This Matters

Regulation 10 applies to any organisation in the DIFC that deploys or operates AI systems processing personal data, not only financial firms.

Everyday tools can qualify. Automated candidate screening and processing of special category data are commonly cited examples of high-risk processing.
For high-risk systems, certification and an Autonomous Systems Officer are conditions of commercial use, and building the documentation takes time.
The Commissioner's certification guidance has been evolving, so organisations that prepare early are better placed whichever way the detailed requirements land.
What's Included

Inventory of AI systems used in the DIFC, with an AI register

High-risk processing assessment for each system
Gap analysis against Regulation 10's principles and notice requirements
Autonomous Systems Officer advisory: role design, competencies, reporting
Certification readiness: documentation, testing evidence, audit trail
Alignment with existing governance frameworks such as ISO/IEC 42001

Frequently Asked Questions

Related

Not sure whether your AI systems count as high-risk under Regulation 10?
By submitting this form, I acknowledge that I have read and agree to the Privacy Policy, and I consent to the processing of my personal data.


Please note: We do not provide any personalized investment advice, token selection guidance, or transaction recommendations. AMLzone is a compliance consultancy and project management services provider, not a Virtual Asset Advisor.