DIFC Regulation 10: The Complete Guide to the World's First AI and Autonomous Systems Data Protection Law
DIFC Regulation 10 is the world's first data protection regulation written for AI and autonomous systems. Here is what it covers, who it applies to, and how to comply.
DIFC Regulation 10: The Complete Guide to the World's First AI and Autonomous Systems Data Protection Law
DIFC Regulation 10 is the world's first data protection regulation written specifically for autonomous and semi-autonomous systems, introduced by the Dubai International Financial Centre in 2023 as an addition to the DIFC Data Protection Regulations that support DIFC Data Protection Law No. 5 of 2020. It governs how personal data is processed by AI, generative, and machine learning systems inside the DIFC, imposes obligations on Deployers, Operators, and Providers of such systems, establishes a permissive certification-based regime rather than a licensing model, and creates the Autonomous Systems Officer (ASO) role, the DIFC Regulation 10 Accelerator sandbox, and an Accreditation and Certification Framework for high-risk processing activities. For any organisation building toward DIFC's ambition of becoming the world's first AI-native financial centre, Regulation 10 is the legal foundation that makes responsible AI operationally possible.
Key Takeaways
World-first scope. Regulation 10 is the first data protection regulation globally to name autonomous and semi-autonomous systems as a distinct category, giving DIFC a legal head start on jurisdictions still writing horizontal AI acts.
Three actor roles. The regulation defines Providers, Deployers, and Operators. Deployers and Operators carry the same accountability as traditional controllers and processors for lawful processing under Article 9 of the Law.
Certification, not licensing. The regime is permissive: no license or registration is required to deploy a System, but certification is mandatory before any System may be used for High Risk Processing Activities.
The ASO role. Deployers and Operators of high-risk Systems must appoint an Autonomous Systems Officer with competencies, status, and tasks substantially similar to a Data Protection Officer under Articles 17 and 18.
Accelerator sandbox. The DIFC Regulation 10 Accelerator lets developers test privacy-by-design in a controlled environment, and can bolt on to sandboxes such as the UAE Reg Lab, the UK ICO sandbox, or the EU AI Act Article 57 sandbox.
ISO 42001 as the route. The regulation is designed for interoperability with recognised frameworks. ISO 42001 gives DIFC firms a clean, auditable operating model for meeting Regulation 10 in practice.
On This Page
- What Is DIFC Regulation 10?
- Why Regulation 10 Matters for the AI-Native Financial Centre
- Scope: Who and What Regulation 10 Applies To
- Regulation 10.2: Obligations of Deployers and Operators
- Regulation 10.3: General Requirements and High-Risk Processing
- The Autonomous Systems Officer (ASO)
- The DIFC Regulation 10 Accelerator
- The Regulation 10 Advisory Committee
- How ISO 42001 Operationalises Regulation 10
- Conclusion: DIFC as the Blueprint for AI-Native Finance
What Is DIFC Regulation 10?
DIFC Regulation 10 is the section of the DIFC Data Protection Regulations that governs personal data processed through digital, generative technology systems, including but not limited to artificial intelligence, generative AI, and machine learning technology. Introduced as part of the 2023 update to the Data Protection Regulations, it sits alongside the DIFC Data Protection Law No. 5 of 2020 (the "DP Law 2020") and gives the Commissioner of Data Protection a purpose-built framework for AI-driven processing that no other data protection regulator had at the time of its release.
The Regulation is structured in three parts. Regulation 10.1 defines autonomous and semi-autonomous Systems. Regulation 10.2 sets the obligations of the Deployers and Operators of those Systems. Regulation 10.3 establishes the general principles every System must be designed to respect and creates a certification pathway for Systems used in High Risk Processing Activities. Wrapping around all three parts sit the operational instruments the Commissioner has already published: the Accreditation and Certification Framework, the Regulation 10 Accelerator sandbox, the Regulation 10 Advisory Committee charter, and the emerging role definition for the Autonomous Systems Officer.
What makes Regulation 10 distinctive is its design philosophy. The Commissioner chose a permissive, certification-based regime rather than a licensing model, so innovation is not gated by a registration queue, and the regulation is explicitly written to plug into whatever responsible-AI framework an organisation is already using. Recognised codes and certifications from the Dubai Digital Authority, the OECD, UNESCO, and equivalent bodies are named in the regulation itself as acceptable design references, making Regulation 10 one of the most interoperable AI-adjacent regulations in the world.
Key Context:
Regulation 10 does not replace the DIFC Data Protection Law. It adds to it. All the base obligations of the Law, lawful basis under Article 9, data subject rights under Article 29, transfers under Articles 26 and 27, still apply in full to any personal data processed by an autonomous System.
Why Regulation 10 Matters for the AI-Native Financial Centre
On 21 April 2026, DIFC announced its Native AI programme, committing to become the world's first AI-Native financial centre. The vision is expansive: AI embedded at the foundational level across DIFC's legal and regulatory frameworks, business operations, talent development systems, ecosystem infrastructure, and the district's physical environment, with a projected USD 3.5 billion (AED 12.9 billion) in economic value and 25,000 new jobs. As Arif Amiri, Chief Executive Officer of DIFC Authority, put it, this is not about experimenting with AI at the edges. It is about embedding AI across every layer of the Centre and setting a global benchmark for AI governance and responsible innovation.
That ambition is credible because the legal scaffolding was put in place before the announcement, not after. The foundation was laid in 2023 with DIFC's five-year AI strategy, alongside the updated Data Protection Regulations that introduced Regulation 10. In other words, Regulation 10 gave DIFC a regulatory answer to the AI question three years before the AI-Native announcement, and well ahead of most other jurisdictions that were still drafting their first horizontal AI regulation.
The value of that head start is not just legal certainty for firms already operating in DIFC. It is the compounding effect of having a coherent, principles-based, interoperable regulation in the market when global capital and global AI talent are choosing where to concentrate. A firm considering a regional headquarters, a fund considering where to book its AI-driven strategies, or a startup considering where to incorporate its AI product all benefit from a jurisdiction where the rules for autonomous systems and personal data are already written, already published, already staffed by a Commissioner's Office, and already operationalised through a sandbox and a certification framework.
For society, the benefit runs in two directions. Individuals whose personal data is processed by AI in DIFC get the strongest set of purpose-built rights and transparency requirements in the region: explicit notice when a System is not human-controlled, plain-language descriptions of the System's principles and outputs, and the ability to challenge decisions that restrict their rights to erasure or rectification. Organisations get a regulator that behaves as a design partner rather than a gatekeeper, using guidance notes, an Accelerator sandbox, and an Advisory Committee to shape rules with the market rather than around it. That combination is what an AI-native financial centre actually looks like when it works, and Regulation 10 is what makes it work.
Scope: Who and What Regulation 10 Applies To
Regulation 10 applies whenever personal data is processed by, or used to train, an autonomous or semi-autonomous System within the DIFC. The three sub-sections below unpack what those terms mean and who carries which obligations.
Regulation 10 defines these as systems that process personal data for human-defined purposes, meaning functions pre-defined by the Provider and hard-coded into the System, and/or purposes that the System itself defines. The System then generates an output on the basis of that processing.
The definition is deliberately technology-neutral. It captures classical machine learning, generative AI, large language models, agentic AI, and any future architecture that fits the "processes personal data and produces an output" pattern. It applies whether the System is operated inside the DIFC, offered to Deployers inside the DIFC, or trained on personal data collected in the DIFC.
A Provider is the natural or legal person who develops the System, or who procures its development, with a view to making it available to Deployers or Operators. A Deployer is the entity that puts the System into use for its own purposes. An Operator runs the System on behalf of a Deployer.
The guidance notes to Regulation 10.2.1 are explicit: the Deployer and the Operator each carry the same substantive obligations as a controller and processor under the general DIFC Data Protection Law, applied to any personal data the System processes.
This is the accountability spine of the regulation. Even though the developer, Deployer, and Operator may be three different organisations in three different jurisdictions, Regulation 10 pins responsibility to the entities visible to the data subject, and expects them to procure Systems only from Providers that can give them contractual comfort of compliance-by-design.
Regulation 10 is triggered when personal data is processed for use in a System, or to enable a System's learning processes. Both matter. Training data is inside the scope, not just inference-time data. A firm that fine-tunes a foundation model on customer transaction records has performed processing under Regulation 10 from the moment those records enter the training pipeline.
This matters for the practical design of AI products. Data minimisation, synthetic data, pseudonymisation at the training stage, and provenance logging are not optional design choices under Regulation 10. They are the mechanisms by which a Deployer or Operator can demonstrate that the Article 9 principles have been respected across the full model lifecycle.
Regulation 10.2: Obligations of Deployers and Operators
Regulation 10.2 is the operational core of the framework. It sets out what a Deployer or Operator must do when personal data is processed by a System, and it is where most compliance work concentrates in practice. The obligations map cleanly to concrete design and documentation tasks, which is one reason ISO 42001 sits so naturally alongside the regulation.
Regulation 10.2.1 anchors the whole framework to Article 9 of the DP Law 2020. Every general principle of lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability, applies to a System's processing exactly as it would to a traditional workflow.
The novelty is that these principles now have to be traced through model training, model updates, and inference in ways that a traditional data-flow diagram cannot capture. This is where model cards, dataset cards, and lineage tracking become part of the compliance record, not just engineering hygiene.
Where a website or application uses a System to process personal data, the Deployer or Operator must provide clear and explicit notice on first use. That notice has to alert users to any underlying technology or processes that may undertake processing which is not human-initiated, controlled, or directed, and it has to spell out the impact of the System on the individual rights protected under Article 29(1)(h)(ix).
The notice must go further than a generic AI disclosure. It has to describe, in plain language, the human-defined purposes the System processes personal data for, the human-defined principles and limits within which the System may itself define further purposes, the output the System produces and how it is used, the safeguards built into the System by design, and the codes or certifications the System has been designed against.
Regulation 10.2.2(b)(v) is one of the most consequential provisions in the regulation. It requires the Deployer or Operator to state the codes, certifications, or principle-policy frameworks against which the System was designed, and it names the Dubai Digital Authority, the OECD, and UNESCO as accepted reference bodies.
The regulator's intent is interoperability. Rather than mandate a single DIFC-specific standard, the Commissioner recognises the responsible-AI frameworks the market is already converging on and asks Deployers to be explicit about which ones they have chosen.
ISO 42001 fits directly into this design surface. Naming ISO 42001 as the framework a System is designed against gives an auditable, third-party-verifiable answer to Regulation 10.2.2(b)(v), and it produces the evidence needed for the transparency obligations in the same clause.
The regulation acknowledges commercial reality. Information provided under Regulation 10.2.2(c) to (f) may be redacted or summarised to the minimum extent necessary to protect intellectual property or comply with restrictions under applicable laws. That flexibility applies to public-facing notices, not to the Commissioner.
If the Commissioner asks, the Deployer or Operator must provide the full, unredacted underlying information and implement any revisions the Commissioner requires. Building the documentation once, in a form that supports both public transparency and confidential regulator disclosure, is the practical response to this provision.
How reconn would approach it
For Regulation 10.2 obligations we start with discovery: inventory every System processing DIFC personal data, classify each by role (Provider, Deployer, Operator), and map the current notice, documentation, and design evidence against each sub-clause of Regulation 10.2.2. The output is a gap register that ties every finding to a specific ISO 42001 clause, so remediation and certification preparation run on the same evidence base.
The design-framework declaration under Regulation 10.2.2(b)(v) is where firms most often need help. We help the Deployer make a defensible choice, ISO 42001 for management-system rigour, OECD principles for public reference, and a Dubai Digital Authority alignment where relevant, and we draft the plain-language notice that flows from that choice.
Turning Regulation 10 obligations into an auditable AI management system.
reconn helps DIFC-registered firms design, implement, and prepare for certification against ISO 42001, mapped directly to Regulation 10 obligations. From gap assessment to Stage 2 audit readiness, our team runs the full programme. Reach us on WhatsApp, email, or by phone, +971 58 572 6270.
Regulation 10.3: General Requirements and High-Risk Processing
Regulation 10.3 establishes the overarching design principles every System must respect, and creates a stricter certification-gated regime for Systems used in High Risk Processing Activities. It is where the regulation's ambition to be a global responsible-AI reference is clearest.
Regulation 10.3.1(a) to (e) states five principles every System processing personal data must be designed to respect: fairness, ethical compliance, transparency, security of operation, and accountability. The Commissioner's guidance calls these the fundamental principles the framework is built on.
Crucially, the provision does not limit its application to developers. Deployers and Operators, as the entities with direct exposure to affected individuals, carry ultimate accountability. In practice, that means the procurement stage becomes a compliance stage: Deployers must select Providers who can give contractual comfort of compliance-by-design against all five principles.
Regulation 10.3.3 introduces a hard rule: no person may use, operate, provide, offer, or otherwise make available for commercial use a System to engage in High Risk Processing Activities set out in Schedule 1, Article 3 of the DP Law 2020, unless the Commissioner has established audit and certification requirements for such Systems and the System complies with them.
This is not a soft expectation. It is a use-restriction. Systems performing high-risk processing must be certified through the Accreditation and Certification Framework the Commissioner has published, awarded and monitored by an Accredited Certification Body, before they can be commercially deployed for those activities in DIFC.
Certification is valid for three years from the date of initial issuance. The Commissioner retains the authority to conduct periodic risk-based reviews, and can trigger a reassessment when certification criteria change, when a certified System changes significantly, or when verified complaints indicate the System is no longer meeting the criteria.
Certification is granted by an Accredited Certification Body, an entity that has applied to the Commissioner for accreditation under the published Framework. Applications for accreditation follow a defined submission and review process, and once accredited, a Certification Body awards and monitors certification of Systems submitted by Certification Applicants.
In exceptional circumstances, where an Accredited Certification Body is not available at the time of application, the Commissioner may perform the certification directly. Applications must be in English and submitted with documentation pertinent to the certification criteria.
The Autonomous Systems Officer (ASO)
Regulation 10.3.3(d) requires that any Deployer or Operator using a System for High Risk Processing Activities must appoint an Autonomous Systems Officer. The role is defined by reference to the Data Protection Officer function under Articles 17 and 18 of the DP Law 2020, meaning the ASO must have the same or substantially similar competencies, status, role, and tasks as a DPO, with additional AI-specific competencies to be defined by the Regulation 10 Advisory Committee.
The DIFC Commissioner's 2025 ASO survey found strong consensus that the ASO's core responsibilities cluster around data quality, model updates, monitoring and evaluation of outcomes for bias and security, and ensuring compliance with legal and ethical guidelines. The survey positions the ASO as a governance role first and a technical role second, with a strong steer that ASOs should think cross-functionally across the whole organisation rather than operating inside a single function.
In a DIFC firm, that means the ASO owns the AI governance operating model: the risk framework, the model inventory, the incident and complaint procedures, the design-framework choices under Regulation 10.2.2(b)(v), and the evidence base the firm would use to defend its System in a Commissioner review or a certification audit.
The recommended competency set spans three areas: AI and ML literacy, understanding of relevant legal and regulatory frameworks, and AI governance and ethics. The survey report is explicit that the role should not be overloaded on any one axis, and recommends that ASOs be supported by dedicated leads across AI engineering, compliance, and governance.
Certification pathways matter here. PECB's Certified AI Professional (CAIP), Certified AI Manager (CAIM), and Lead AI Risk Manager provide credentialed anchors for the technical, managerial, and risk pillars of the ASO role. An ISO 42001 Lead Implementer credential gives the ASO the operating-system view needed to run the AI management system that Regulation 10 will ultimately be audited against.
The Commissioner's recommendations, informed by the ASO survey, are that the ASO should report independently and directly to a senior leadership position such as the Board or the CEO, and should participate in or lead the organisation's AI ethics or steering committee. This is a strong signal that responsible AI is treated as a priority at the top of the house, not a middle-office concern.
Wearing multiple hats is expressly permitted. An existing Chief Information Officer, Chief Data Officer, Chief Technology Officer, or DPO with significant AI expertise may hold the ASO title, provided independence and competency are preserved. In many mid-sized DIFC firms, the DPO and ASO functions will be held by the same person supported by dedicated technical and engineering leads.
How reconn would approach it
We help firms stand up the ASO function in three moves: define the role and reporting line inside the AI governance charter, place the right credentials against it (PECB CAIP or CAIM for AI competency, ISO 42001 Lead Implementer for the management system, PECB Lead AI Risk Manager for the risk function), and connect the ASO to the Data Protection Officer through a shared operating model so accountability under Regulation 10 and the DP Law 2020 flows through one governance structure, not two.
The DIFC Regulation 10 Accelerator
The Regulation 10 Accelerator is the Commissioner's sandbox environment for developers, Deployers, and Operators to test autonomous or semi-autonomous Systems for privacy-by-design and the technical requirements set out in Regulation 10, using either recognised or bespoke frameworks. It is one of the clearest expressions of the regulation's design intent: interoperability, convergence, flexibility, and innovation inside safe boundaries.
The Accelerator has two components: governance procedures for acceptance, review, and reporting (how the programme is run), and substantive evaluation criteria (what is actually tested against the Regulation 10 requirements). The result is a structured environment where a System's design can be assessed against privacy-by-design principles before it is committed to production.
The Accelerator supports regulatory, operational, and hybrid sandbox models as described in the Datasphere Initiative's Report on Sandboxes for AI. That flexibility is deliberate: no single sandbox format fits every kind of System, and the Accelerator is designed to accommodate whichever format the participant is already using.
If an organisation is already participating in another sandbox, the Regulation 10 Accelerator can bolt onto that programme to assess privacy-by-design specifically. The regulation names the UAE Reg Lab, the UK Information Commissioner's Office sandbox, and the EU AI Act Article 57 sandbox as examples, and the Datasphere Report lists many more.
This is a rare feature. Rather than force firms to choose between DIFC's sandbox and another jurisdiction's, the Commissioner explicitly supports concurrent participation. For a firm running an AI product across multiple jurisdictions, that removes a real operational friction point.
The Accelerator is well suited to early-stage AI products, Systems undergoing significant redesign, Systems approaching a High Risk Processing Activity threshold, and any Deployer preparing for certification under Regulation 10.3.3. Using the Accelerator during the design phase compresses the eventual certification audit, because the evidence generated in the sandbox feeds directly into the certification package.
The regulation is clear that participation is not mandatory. It is an opt-in tool for organisations that want structured feedback and a lower-risk path to production.
The Regulation 10 Advisory Committee
Under Article 47 of the DP Law 2020, the Commissioner established the Regulation 10 Advisory Committee to oversee the implementation of Regulation 10 and to shape the accreditation, certification, and ASO frameworks that make it work. The Committee is one of the practical instruments through which the Commissioner keeps the regulation calibrated to how AI is actually developing.
The Committee advises the Commissioner on the requirements and updates needed to Regulation 10, including the accountability, audit, and certification requirements for High Risk Processing Activities. It assists with the drafting of guidelines and best practices, supports work on accreditation schemes and codes of conduct, prepares Committee reports for the Commissioner, and liaises with other data protection committees and authorities as directed.
In practice, the Committee is where the certification scheme itself is developed, where the Accreditation Body's criteria are shaped, and where the ASO's role definition continues to evolve.
The Committee operates through sub-committees for specific work streams, including a Regulation 10.3.3 Sub-committee focused on audit, certification, and ASO competencies. Participation is voluntary and expected to require a modest time commitment initially, with the option to scale involvement as the work progresses.
For AI, data protection, and legal professionals in Dubai and the wider region, Committee participation is one of the most direct ways to shape how the world's first AI-specific data protection regulation is implemented.
How ISO 42001 Operationalises Regulation 10
Regulation 10 is deliberately framework-agnostic, but its structure maps closely to ISO 42001, the international standard for AI management systems. Using ISO 42001 as the operating layer for a DIFC firm's Regulation 10 compliance is the fastest route to auditable, third-party-verifiable evidence, and it gives the firm a management system that also serves ISO 27001 and ISO 27701 audiences without duplicating work.
The five overarching principles in Regulation 10.3.1 (fairness, ethical compliance, transparency, security of operation, accountability) map directly to the leadership, policy, and organisational role requirements in ISO 42001 Clause 5. Establishing an AI policy that states each of these principles, assigning ownership of them to the ASO and the AI governance committee, and evidencing top-management commitment satisfies both the Regulation 10 principle expectation and the ISO 42001 Clause 5 requirements from a single set of documents.
The obligations of Deployers and Operators in Regulation 10.2, notice, purpose descriptions, safeguard documentation, and the design-framework declaration, map onto the planning, support, and operation clauses of ISO 42001. Clause 6 covers AI risk assessment and impact assessment, Clause 7 covers competence, awareness, and documented information, and Clause 8 covers the operational planning and control of the AI lifecycle.
The AI Impact Assessment (AIIA) required by ISO 42001 becomes the working document that supplies the plain-language descriptions Regulation 10.2.2(b) requires, and the design-framework declaration is a natural output of the AI management system scope statement.
The Regulation 10.3.3 certification regime for High Risk Processing Activities is an evidence-driven audit. Firms that already run an ISO 42001-conformant management system enter that certification audit with the internal control evidence, the AI risk register, the incident and change records, and the internal audit outputs already prepared.
In practice, an ISO 42001-certified DIFC firm shortens its Regulation 10.3.3 preparation from months to weeks, because the artefacts an Accredited Certification Body will ask for already exist. Our ISO 42001 Implementation Guide walks through the full methodology.
Regulation 10 is a data protection regulation, so information security and privacy management systems are directly relevant. ISO 27001 gives the firm the ISMS that answers the security-of-operation principle in Regulation 10.3.1(d). ISO 27701 extends the ISMS into a privacy information management system that aligns with the general DP Law 2020 requirements Regulation 10 layers onto.
The three standards run as integrated management systems inside most DIFC firms. Running them together, rather than in parallel silos, is what turns Regulation 10 compliance from a project into an operating model.
How reconn would approach it
For a DIFC firm targeting Regulation 10.3.3 certification, our recommended sequence runs in phases: scope and gap assessment against ISO 42001 and Regulation 10 in parallel, then AI management system design, AI Impact Assessment, and the policy set, then control implementation, internal audit, and management review, and finally Stage 1 and Stage 2 audits. Firms that already hold ISO 27001 typically compress this significantly because the security and documentation base is already in place.
Conclusion: DIFC as the Blueprint for AI-Native Finance
Regulation 10 is not a compliance burden layered onto DIFC's Native AI programme. It is the reason the AI-Native financial centre ambition is credible. By writing a regulation that is principles-based, framework-agnostic, interoperable with global sandboxes, and paired with a certification-not-licensing model, the Commissioner has created a jurisdiction where responsible AI is a design surface rather than a defensive posture, and where the USD 3.5 billion Native AI economic case has an actual legal operating layer beneath it.
The firms that will benefit most are the ones that treat Regulation 10 as an operating opportunity, not a regulatory obligation. Standing up an AI management system under ISO 42001, placing a credentialed Autonomous Systems Officer at the top of the AI governance structure, using the Regulation 10 Accelerator to shape products before certification, and participating in the Advisory Committee where possible: these are the actions that convert regulatory clarity into commercial advantage. DIFC has built the framework. What comes next is what firms build on top of it.
Ready to build the AI governance capability your Regulation 10 programme needs?
reconn runs corporate training on ISO 42001 Lead Implementer, GenAI Fluency, PECB CAIP, PECB CAIM, and PECB Lead AI Risk Manager, tailored for DIFC firms preparing for Regulation 10 certification and ASO appointment. Reach us on WhatsApp, email, or call +971 58 572 6270 for a training scoping call.
Further Reading
- ISO 42001: The Complete Global Guide to AI Management Systems The definitive reference for how the international AI management system standard works end-to-end.
- ISO 42001 Implementation Guide: Step-by-Step Methodology The full phased methodology reconn uses to take firms from gap assessment to certification-ready.
- AI Certifications for the UAE Government AI Mandate: A Practitioner's Guide How UAE-wide AI adoption ambitions connect to individual credentialing paths.
- How to Become an AI Governance Expert in 2026: Roles, Salaries, and Certification Roadmap A practical career map for the ASO, AI risk, and AI governance roles Regulation 10 is creating.
- UAE Personal Data Protection Law: Complete Compliance Guide How the federal PDPL sits alongside DIFC Data Protection Law No. 5 of 2020 and Regulation 10.
Frequently Asked Questions
DIFC Regulation 10 is the section of the DIFC Data Protection Regulations that governs personal data processed through autonomous and semi-autonomous systems, including artificial intelligence, generative AI, and machine learning technology. It was introduced as part of the 2023 update to the Data Protection Regulations and supports DIFC Data Protection Law No. 5 of 2020. Regulation 10 is the first data protection regulation globally to name autonomous systems as a distinct category.
Regulation 10 applies to any Provider, Deployer, or Operator of an autonomous or semi-autonomous System that processes personal data in the DIFC, or uses personal data collected in the DIFC to train such a System. Deployers and Operators carry the same substantive obligations as controllers and processors under the general DIFC Data Protection Law.
A Provider develops the System, or procures its development, with a view to making it available to Deployers or Operators. A Deployer puts the System into use for its own purposes. An Operator runs the System on behalf of a Deployer. Deployers and Operators are the entities directly accountable to data subjects and to the Commissioner, and Regulation 10 pins compliance responsibility to them.
Yes. Regulation 10 is part of the DIFC Data Protection Regulations that support DIFC Data Protection Law No. 5 of 2020, and it applies to any DIFC-registered entity that processes personal data through an autonomous or semi-autonomous System. The regulation uses a permissive certification-based regime, so no licence is required to deploy a System, but certification through the Accreditation and Certification Framework is mandatory before any System may be used for High Risk Processing Activities.
The Autonomous Systems Officer is the role required under Regulation 10.3.3(d) for any Deployer or Operator using a System for High Risk Processing Activities. The ASO must have the same or substantially similar competencies, status, role, and tasks as a Data Protection Officer under Articles 17 and 18 of the DP Law 2020, with additional AI-specific competencies. In practice, the ASO owns the AI governance operating model, including the risk framework, model inventory, incident procedures, and design-framework choices.
Certification is not required to deploy every System. Regulation 10 uses a permissive regime for general Systems. Certification is mandatory before any System may be used for High Risk Processing Activities as defined in Schedule 1, Article 3 of the DP Law 2020. That certification is issued by an Accredited Certification Body under the DIFC Regulation 10 Accreditation and Certification Framework and is valid for three years, subject to periodic risk-based reviews by the Commissioner.
The Regulation 10 Accelerator is the Commissioner's sandbox environment for developers, Deployers, and Operators to test autonomous or semi-autonomous Systems for privacy-by-design and the technical requirements set out in Regulation 10. It supports regulatory, operational, and hybrid sandbox models, and can be used alongside other sandboxes such as the UAE Reg Lab, the UK ICO sandbox, and the EU AI Act Article 57 sandbox.
ISO 42001 is the international standard for AI management systems and maps closely to the structure of Regulation 10. The five overarching principles in Regulation 10.3.1 align with ISO 42001 Clause 5 (leadership and policy), the Deployer and Operator obligations in Regulation 10.2 align with Clauses 6, 7, and 8 (planning, support, and operation), and the certification regime under Regulation 10.3.3 becomes an evidence-driven audit that an ISO 42001-conformant firm is already prepared for. Regulation 10 is explicitly designed to be interoperable with recognised frameworks, and ISO 42001 is one of the strongest choices.
Yes. The Commissioner has indicated that ASOs can wear multiple hats, provided the individual holds the required competencies and independence. In mid-sized DIFC firms, it is common for the DPO to also hold the ASO title, supported by dedicated AI engineering and governance leads. The reporting line should be independent and direct to a senior leadership position such as the Board or the CEO.
The full text of Regulation 10 is included in the DIFC Data Protection Regulations, which are published on the DIFC Commissioner of Data Protection website. The Commissioner has also published Guidance on Regulation 10, an FAQ document, the Accreditation and Certification Framework, the Regulation 10 Accelerator framework, and the Regulation 10 Committee charter, all available from the DIFC Regulation 10 page.
Ready to certify yourself against the standards Regulation 10 is built to interoperate with?
reconn offers online self-study PECB certifications for AI professionals and AI management system practitioners: CAIP, CAIM, Lead AI Risk Manager, ISO 42001 Lead Implementer, ISO 42001 Lead Auditor, and the ISO 42001 Bundle. Prefer to speak to us? WhatsApp, email, or call +971 58 572 6270.
About the Author
Shenoy Sandeep
Shenoy Sandeep is the Founder of reconn, an AI-first cybersecurity firm based in Dubai, UAE. With 20+ years across cybersecurity focussing on offensive security and threat intelligence portfolio, and over 10 years in Enterprise AI, AI governance and data protection, he has assisted over 25+ startups in scaling their business in the Middle East and African region.
Training is Shenoy's passion project and reconn has associated themselves with PECB, the global leaders in personal certifications for AI, cybersecurity, data protection, privacy and business continuity professionals. He is a PECB-certified trainer and one of the world's early PECB-certified AI professionals, also specialising in ISO/IEC 27001, ISO/IEC 27701, ISO 42001, ISO 22301, and GDPR.
Via Reconn, Shenoy runs an advisory service assisting organisations in the EMEA with compliance and certification on ISO 42001, ISO 27001, ISO 27701, ISO 22301 and local data protection and privacy laws. His current interests include EU AI Act, NIS2, DORA, EU/UK GDPR, UAE PDPL and SDAIA PRPL.