Quick Answer
Regulation 10 does not use the term "high-risk AI system." The relevant classification is "High Risk Processing Activity," defined in Schedule 1, Article 3 of the DIFC Data Protection Law. An AI system triggers this classification if it meets any one of four criteria: it uses new technology in a way that materially increases risk to data subject rights; it processes a considerable amount of sensitive personal data; it makes automated decisions with legal or similarly significant effects on individuals; or it processes special categories of personal data such as health, biometric, or financial data. Meeting any single criterion is sufficient. Commercial operation of a system that qualifies is prohibited without certification from a DIFC-accredited body.
The Four Criteria That Define High Risk Processing
The definition comes from Schedule 1, Article 3 of the DIFC Data Protection Law. One criterion is enough. A system does not need to meet all four.
New technology that increases risk to data subjects. The system uses new or different technology or methods in a way that creates a materially higher risk to data subjects' security or rights, or makes it harder for them to exercise those rights. The Commissioner's guidance explicitly names "using AI to automate a decision-making process" as an example. Importantly, the technology must actually increase the risk or difficulty, not just be new.
Large volume of sensitive personal data. The system processes a considerable amount of personal data where the risk to data subjects is high, due to the sensitivity of the data or risks to its security, integrity, or privacy. Financial institutions with several hundred staff or several thousand customer records typically meet the volume threshold. Data such as bank account details, salary information, identity documents, and location data is treated as high-risk by default.
Automated decisions with significant effects. The system systematically evaluates personal characteristics using automated processing, including profiling, and the decisions produced have legal effects or similarly significant effects on the individual. This is the criterion most AI systems in financial services will meet. Any output that materially affects a customer's access to products, pricing, or services qualifies.
Special categories of personal data. The system processes a material amount of data from the DIFC's protected categories: health and medical data, biometric data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sexual orientation, or criminal records.
Which AI Systems at DIFC Financial Institutions Are Likely to Qualify?
The Commissioner's guidance states that regulated financial businesses should assume they are conducting High Risk Processing Activities. In practice, these systems almost always qualify:
Credit scoring and lending decisioning. Automated evaluation of financial data that produces decisions on credit access or terms. Meets criteria 2 and 3.
AML and transaction monitoring. Systematic processing of transaction histories to detect suspicious activity, resulting in account restrictions, escalations, or regulatory reporting. Meets criteria 1 and 3.
Customer risk classification and KYC. Automated processing of identity and behavioural data to assign risk ratings that determine service levels or products available to a customer. Meets criteria 2 and 3.
Fraud detection. Processing of transaction patterns to flag or block activity with material effects on customer accounts. Meets criteria 1 and 3.
Insurance underwriting models. Automated processing of personal data to determine coverage eligibility or premium pricing. Meets criteria 2 and 3.
Employee monitoring. Systematic evaluation of staff behaviour or communications using automated processing. Meets criteria 2 and 3, and potentially criterion 4 if health data is involved.
AI tools that process personal data. Tools used to draft client communications, summarise customer records, or generate compliance documents meet criterion 1, provided the associated risk to data subject rights is material.
For borderline cases, the Commissioner's position is clear: where there is doubt, conduct a DPIA before proceeding.
What Are Special Categories of Personal Data Under DIFC Law?
Criterion 4 applies where a system processes a material amount of any of the following:
- Health or medical data
- Biometric data used for identification
- Racial or ethnic origin
- Religious or philosophical beliefs
- Political opinions
- Trade union membership
- Data about sex life or sexual orientation
- Criminal convictions or offences
Financial institutions using biometric authentication, processing health-related insurance data, or handling identity document scans are almost certainly processing special category data at material volume. The Commissioner's guidance notes that simply storing highly sensitive data creates a high risk to data subjects due to the risk of a data breach alone.
Can You Operate a High-Risk AI System Without Certification?
No. Under Regulation 10.3.3, commercial operation of an AI system for High Risk Processing is prohibited unless three conditions are met:
- The Commissioner has established audit and certification requirements for that type of system.
- The system has been certified by an accredited certification body as meeting those requirements.
- The system processes personal data solely for human-defined or human-approved purposes.
The Commissioner published an Accreditation and Certification Framework and approved White Label Consultancy as the first accredited certification body under Regulation 10. System certification is valid for up to three years, subject to ongoing monitoring.
Further guidance on certification requirements for specific high-risk system types is expected following Consultation Paper No. 3 of 2026, which closes 18 July 2026. Until that guidance is finalised and certification is obtained, operating uncertified systems for High Risk Processing is a live compliance risk.
What Else Is Required for High Risk Processing?
Certification is not the only obligation. Firms must also:
Appoint an Autonomous Systems Officer (ASO). Required for both Deployers and Operators engaging in High Risk Processing. The role covers compliance monitoring and cooperation with the Commissioner. One person can hold both the DPO and ASO roles if their competencies cover both functions.
Complete a DPIA before starting. The DPIA must be specific to the AI system. It must cover the system's processing operations and technologies, categories of data subjects, risks to data subject rights, and the technical and organisational measures in place to address those risks. Skipping the DPIA carries a fine of USD 50,000.
Notify the Commissioner before commencing High Risk Processing Activities.
Consult the Commissioner if the DPIA identifies risks that cannot be reduced to an acceptable level. Early engagement costs far less than redesigning a system after it has been deployed and reviewed.
How Does This Compare to the EU AI Act?
The EU AI Act defines high-risk AI through a named list of sectors and application types. Regulation 10 uses a criteria-based approach tied to data protection risk. The practical effect is that DIFC's definition is broader: a system does not need to be in a named sector to qualify. An AI system processing large volumes of sensitive financial data is in scope under Regulation 10 even if it does not appear in the EU AI Act's annexes.
The overlap is significant. Credit scoring, biometric identification, and employment monitoring appear in both frameworks. Firms that are already mapping systems against the EU AI Act should treat that exercise as a starting point, not a complete answer, for Regulation 10 compliance.
The Question to Ask About Each AI System
For every AI system that processes personal data, ask:
- Does it use new or different technology in a way that makes data rights harder for customers to exercise?
- Does it process a considerable volume of sensitive or financial personal data?
- Does it make automated decisions, or inform decisions, that materially affect a customer's access to products, pricing, or services?
- Does it process health, biometric, financial, or other special category data at material volume?
A yes to any one of these means the system is likely in High Risk Processing territory. That requires a DPIA, an ASO, notification to the Commissioner, and certification before commercial operation.
Magpie provides the audit trails, DPIA documentation, and observability records that Regulation 10 requires for AI systems in High Risk Processing. Request a demo.