DIFC Regulation 10: AI Rules for Companies Operating in the DIFC
The DIFC has purpose-built rules for AI systems that process personal data. If you deploy or operate autonomous or semi-autonomous systems in the DIFC, Regulation 10 sets requirements for transparency, accountability and, for high-risk uses, an Autonomous Systems Officer and certification.
Regulation 10 of the DIFC Data Protection Regulations governs the processing of personal data through autonomous and semi-autonomous systems, including AI, generative models and machine-learning tools. It was introduced in September 2023 and supplements the DIFC Data Protection Law, with enforcement from January 2026. It places obligations on deployers and operators of such systems, built around principles of fairness, transparency, security and accountability. For high-risk processing, commercial use is conditional on audit and certification requirements set by the DIFC Commissioner of Data Protection, use for human-defined or human-approved purposes, and the appointment of an Autonomous Systems Officer (ASO).
Why This Matters
Regulation 10 applies to any organisation in the DIFC that deploys or operates AI systems processing personal data, not only financial firms.
Everyday tools can qualify. Automated candidate screening and processing of special category data are commonly cited examples of high-risk processing.
For high-risk systems, certification and an Autonomous Systems Officer are conditions of commercial use, and building the documentation takes time.
The Commissioner's certification guidance has been evolving, so organisations that prepare early are better placed whichever way the detailed requirements land.
What's Included
Inventory of AI systems used in the DIFC, with an AI register
High-risk processing assessment for each system
Gap analysis against Regulation 10's principles and notice requirements
Autonomous Systems Officer advisory: role design, competencies, reporting
Regulation 10 of the DIFC Data Protection Regulations governs how personal data is processed through autonomous and semi-autonomous systems, such as AI. It supplements the DIFC Data Protection Law and was introduced in September 2023.
It applies to deployers and operators of autonomous and semi-autonomous systems that process personal data in the DIFC. Entities outside the DIFC are governed by their own regime, such as the federal PDPL.
High-risk processing is defined by criteria in the DIFC Data Protection Law. Automated candidate screening and processing of special category data are commonly cited examples. Each system should be assessed individually.
An ASO is a role for deployers and operators of high-risk systems. It must have status, competencies and tasks substantially similar to a Data Protection Officer under the DIFC Data Protection Law.
For high-risk processing, commercial use is conditional on audit and certification requirements set by the DIFC Commissioner. Detailed certification guidance was still expected in 2026, so organisations should prepare documentation now and follow the Commissioner's updates.
No, but it helps. AI governance aligned with ISO/IEC 42001 or the NIST AI Risk Management Framework gives a strong foundation. Certification under Regulation 10 follows the scheme set by the DIFC Commissioner.
Not sure whether your AI systems count as high-risk under Regulation 10?
By submitting this form, I acknowledge that I have read and agree to the Privacy Policy, and I consent to the processing of my personal data.
Please note: We do not provide any personalized investment advice, token selection guidance, or transaction recommendations. AMLzone is a compliance consultancy and project management services provider, not a Virtual Asset Advisor.