Back to Blog
Governance & Compliance

DIFC Regulation 10: The AI Rules Every DIFC Company Using Personal Data Should Know

Bill Anderson, FCCA· Corporate Structuring2 October 20267 min readLast reviewed 2 October 2026
A data centre with rows of servers and cabling, the infrastructure behind the AI systems DIFC Regulation 10 governs

If your DIFC business uses AI on personal data, Regulation 10 applies. Here is what it requires, from notices and a register of use cases to high risk rules, and how the DIFC's new certification process works.

The short answer

  • It applies to AI using personal data. Regulation 10 of the DIFC Data Protection Regulations covers autonomous and semi-autonomous systems that process personal data.
  • Deployers carry the responsibility. A DIFC business using a third-party AI tool is usually the deployer and is treated as the controller.
  • Five core duties. Clear notices, human-defined purposes, plain-language explanation, a register of use cases, and ethical, fair, transparent, secure and accountable design.
  • High risk uses need more. High risk processing carries stricter conditions, including appointing an Autonomous Systems Officer.
  • Certification is live. The DIFC publishes a certification framework, an application portal and an assessment tool, with accredited certification bodies approved.

Last reviewed 2 October 2026

Almost every DIFC business now uses some form of artificial intelligence: a screening tool in recruitment, an onboarding system that checks identity documents, a chatbot on the website, or a model that helps analyse client portfolios. Where those systems process personal data, the DIFC has a specific rule for them. Regulation 10 of the DIFC Data Protection Regulations governs personal data processed through autonomous and semi-autonomous systems, and in 2026 its certification regime has moved from plan to practice.

This guide explains what Regulation 10 requires, who it applies to, what certification involves, and the practical steps a DIFC company can take now. It is written for founders, compliance officers and boards of DIFC businesses that use AI in any part of their operations.

The short answer

Regulation 10 applies to DIFC businesses that deploy or operate AI systems processing personal data. They must tell people when a system processes their data without human direction, keep processing within human-defined purposes, be able to explain what the system does in plain language, keep a register of AI use cases, and design systems to be ethical, fair, transparent, secure and accountable. High risk processing carries stricter conditions, including appointing an Autonomous Systems Officer. The DIFC Commissioner of Data Protection now operates a certification process through accredited certification bodies.

Where Regulation 10 sits

The DIFC has its own data protection regime, the DIFC Data Protection Law No. 5 of 2020, supported by the Data Protection Regulations. The updated Regulations, enacted on 1 September 2023, added Regulation 10 on processing personal data through autonomous and semi-autonomous systems. It was one of the first rules of its kind in the region, and the DIFC's Regulation 10 page now hosts the certification framework, an application portal and an assessment tool.

For DIFC businesses this is a genuine advantage. A clear, published framework tells clients, investors and partners exactly what standard a DIFC company works to, which matters more each year as AI becomes part of financial services.

A smartphone payments app, the kind of DIFC product where AI may process customer data and Regulation 10 applies
A smartphone payments app, the kind of DIFC product where AI may process customer data and Regulation 10 applies

Who it applies to: deployers and operators

Regulation 10 uses two roles, explained in Mayer Brown's January 2026 analysis:

RoleWho it isData protection status
DeployerThe business under whose authority, or for whose benefit, the system operatesTreated as the controller
OperatorThe provider that runs or supervises the system on the deployer's instructionsTreated as the processor

Most DIFC companies using a third-party AI tool are deployers. The responsibility stays with the deployer even when the software comes from an outside vendor, which is why contracts with AI providers deserve the same care as any other data processing agreement.

What Regulation 10 requires

Clear notice

People must be told when technology processes their personal data without being initiated or directed by a human. The notice should describe the human-defined purposes, the principles and limits that govern any purposes the system sets for itself, the system's outputs and how they are used, the safeguards built into its design, and any codes or certifications it relies on.

Human-defined purposes

A system may be used only for purposes defined or approved by people, or for purposes it sets itself strictly within human-defined principles and constraints. Human-defined purposes always take precedence.

Explanation in plain language

Deployers and operators must be able to explain what a system does in non-technical terms, with evidence, and make sure people can still exercise their data protection rights.

A register of use cases

Businesses must keep a register of their AI use cases and processing activities. It records why each use is necessary and proportionate, how people can exercise their rights, whether the system makes automated decisions, who personal data is shared with and on what lawful basis, where those parties are located, and the safeguards for any transfers.

Design principles

Systems must be designed to be ethical, fair, transparent, secure and accountable.

High risk processing

Stricter conditions apply to high risk processing, such as uses that could produce unfair or discriminatory outcomes. A business may engage in high risk processing only where the conditions are met, which include appointing an Autonomous Systems Officer. That role has a status and responsibilities similar to a Data Protection Officer, focused on governance, impact assessments and reporting risk to senior management.

Certification

The Commissioner has chosen a certification-based approach rather than a licensing regime. The DIFC now publishes a Regulation 10 Accreditation and Certification Framework, a certification application on its portal, a step-by-step portal guide and a Regulation 10 Certification Assessment Tool (2026), and a small number of accredited certification bodies have been approved to carry out certifications.

For a DIFC business, certification is a way to show clients and counterparties that its AI use meets a recognised standard. It is worth starting with the assessment tool to see where your systems stand.

A startup team collaborating over laptops and notes, the kind of DIFC business that benefits from building Regulation 10 into its AI tools from the start
A startup team collaborating over laptops and notes, the kind of DIFC business that benefits from building Regulation 10 into its AI tools from the start

Practical steps for a DIFC company

  1. List every AI tool. Include recruitment screening, identity checks, chatbots, analytics and any model used on client data.
  2. Identify your role. For each tool, record whether you are the deployer, and who the operator is.
  3. Start the register. Capture the purpose, lawful basis, automated decisions, data sharing and transfers for each use case.
  4. Update your notices. Make sure privacy notices tell people where AI processes their data and why.
  5. Check for high risk uses. Where a use could produce unfair or discriminatory outcomes, consider whether an Autonomous Systems Officer is needed.
  6. Review vendor contracts. Confirm that AI providers support explanation, data subject rights and your register.
  7. Run the assessment tool. Use the DIFC's Regulation 10 Certification Assessment Tool to plan any certification.

For technology businesses still choosing how to set up in the DIFC, our guide to the Innovation Licence, FinTech routes and VARA covers the licensing side, and our guide to setting up an AI business in Dubai covers the wider picture.

How Atlas helps

Atlas Corporate Services is a DFSA-registered Corporate Service Provider in the DIFC. We help DIFC companies keep their governance and compliance in order, including data protection notifications, registers and board records, through our compliance and company secretarial and governance services. For Regulation 10 certification itself, we work alongside the accredited certification bodies and specialist privacy advisers your systems require.

This article is general information and does not constitute legal or regulatory advice. Regulation 10 and its guidance continue to develop; confirm the current requirements with the DIFC Commissioner of Data Protection or a qualified adviser before acting.

Frequently Asked Questions

What is DIFC Regulation 10?

Regulation 10 of the DIFC Data Protection Regulations governs the processing of personal data through autonomous and semi-autonomous systems, meaning artificial intelligence. It was added to the Regulations enacted on 1 September 2023 and sits within the DIFC Data Protection Law No. 5 of 2020.

Does Regulation 10 apply if we use a third-party AI tool?

Usually yes. The business under whose authority or for whose benefit the system operates is the deployer and is treated as the controller, even where the software comes from an outside provider, which is treated as the operator.

What must a DIFC company tell people about its AI systems?

It must alert people where technology processes their personal data without human direction, and describe the human-defined purposes, any limits on purposes the system sets for itself, the system's outputs and how they are used, the safeguards built into its design, and any codes or certifications it relies on.

What is an Autonomous Systems Officer?

A role similar to a Data Protection Officer, required to engage in high risk processing under Regulation 10. The Autonomous Systems Officer focuses on governance, impact assessments, and reviewing risk with senior management.

Is Regulation 10 certification available now?

Yes. The DIFC publishes a Regulation 10 Accreditation and Certification Framework, a certification application on its portal, a step-by-step guide and a Regulation 10 Certification Assessment Tool, and has approved accredited certification bodies.

What should a DIFC company do first?

List every AI tool that touches personal data, record whether you are the deployer, start a register of use cases, update privacy notices, check for high risk uses, review contracts with AI providers, and run the DIFC's Regulation 10 assessment tool.

Speak to an Expert

Enquire About This Topic

Have questions about governance & compliance matters in the DIFC? Our specialists are available for a free initial consultation.

By submitting this form you agree to be contacted by Atlas Corporate Services. We respect your privacy.