A Plain-Language Guide for Fintechs and AI Teams
Quick Answer
DIFC Regulation 10 is the Dubai International Financial Centre's AI-specific data protection regulation. It governs how organisations licensed in the DIFC can use artificial intelligence systems that process personal data. It came into full enforcement in January 2026 and is the first regulation of its kind in the MEASA region.
If your organisation operates inside the DIFC and uses any AI system that touches personal data, Regulation 10 applies to you.
What Is the DIFC?
The Dubai International Financial Centre is a financial free zone in Dubai, United Arab Emirates. It has its own independent legal and regulatory framework, separate from mainland UAE law. Over 5,000 companies are registered there, spanning financial services, fintech, professional services, and technology.
The DIFC is regulated by two bodies:
- DFSA (Dubai Financial Services Authority): supervises financial services firms
- DIFC Authority: governs the broader free zone, including data protection
Data protection inside the DIFC is governed by the DIFC Data Protection Law (Law No. 5 of 2020) and the regulations made under it. Regulation 10 is one of those regulations.
What Does Regulation 10 Actually Cover?
Regulation 10 sets out specific rules for the use of AI systems that process personal data. It does not regulate all AI. It focuses on AI that interacts with, analyses, or makes decisions about individuals.
The regulation applies to you if you are a DIFC-licensed entity and you:
- Use an AI system that processes personal data about customers, employees, or counterparties
- Use automated decision-making that produces legal or significant effects on individuals
- Deploy AI models trained on personal data
It does not apply to AI systems that process only anonymised data with no link back to individuals.
The Six Core Obligations Under Regulation 10
1. Register Your AI Systems
You must maintain a register of every AI system in your organisation that processes personal data. This is sometimes called an AI System Inventory or AI Registry.
For each system, the register must include:
- What the AI system does
- What personal data it processes
- The legal basis for processing that data
- The risks the system poses to individuals
- Who is responsible for it
Why this matters: Regulators can ask to see this register at any time. If you cannot produce it, you are in breach.
2. Conduct a Data Protection Impact Assessment (DPIA)
Before deploying any high-risk AI system, you must conduct a DPIA. This is a structured risk assessment that asks: what harm could this AI system cause to individuals, and what have we done to reduce that harm?
A DPIA under Regulation 10 must specifically address:
- The AI-specific risks of the system (bias, opacity, drift)
- How the system makes decisions
- What safeguards are in place
- Whether the risks are acceptable before deployment
DPIAs are not a one-time exercise. If you significantly change an AI system, you must reassess.
3. Appoint an AI Systems Officer (ASO)
Regulation 10 requires organisations above a certain threshold to appoint an AI Systems Officer. The ASO is responsible for overseeing compliance with Regulation 10 across the organisation.
The ASO role is similar in concept to a Data Protection Officer (DPO) but focused specifically on AI governance. In many organisations, the same person holds both roles.
The ASO's responsibilities include:
- Maintaining the AI system register
- Overseeing DPIAs
- Acting as the internal point of contact on AI compliance
- Liaising with the DIFC Commissioner of Data Protection
4. Provide Transparency Notices
When an AI system makes or meaningfully influences a decision about an individual, that individual must be told. Transparency notices must explain:
- That an AI system is involved in the decision
- What data the AI used
- The logic behind the decision (in general terms)
- Their right to request human review
This applies in areas like credit decisions, fraud scoring, customer segmentation, and employee monitoring. If your AI system touches a customer and affects their outcome, they have a right to know.
5. Ensure Human Oversight
Regulation 10 prohibits fully automated decisions that have a legal or significant effect on an individual, unless that individual has explicitly consented or the decision is permitted by law.
In practice, this means:
- A human must be able to review and override AI decisions in high-stakes scenarios
- You must have documented processes for human review
- You cannot simply point to a model's confidence score as a substitute for human judgment
Human oversight is not optional. It is a hard requirement for high-risk AI use cases.
6. Maintain Tamper-Evident Audit Trails
You must keep detailed records of how your AI systems are operating and how decisions are being made. These audit logs must be tamper-evident, meaning it must be impossible to alter them without detection.
Audit trails under Regulation 10 must capture:
- Model versions and configurations
- Input data and outputs for significant decisions
- Human interventions and overrides
- Changes to the AI system over time
These logs are your primary evidence of compliance. In the event of a regulatory investigation or a customer complaint, the audit trail is what you will rely on.
What Is the Role of the DIFC Commissioner of Data Protection?
The Commissioner of Data Protection is the regulatory authority responsible for enforcing Regulation 10. The Commissioner can:
- Investigate complaints from individuals
- Conduct audits of DIFC-licensed organisations
- Issue fines and enforcement notices
- Require organisations to stop processing personal data
Fines under the DIFC Data Protection Law can reach USD 100,000 for serious breaches.
Who Does Regulation 10 Apply To?
Regulation 10 applies to any organisation that:
- Is licensed or registered in the DIFC
- Uses AI systems that process personal data
This includes banks, payment processors, insurance companies, fintech startups, family offices, professional services firms, and technology companies operating in the DIFC.
It applies regardless of where your AI systems are hosted. If you are a DIFC entity and you use a third-party AI tool that processes personal data, Regulation 10 obligations fall on you as the controller.
When Did Regulation 10 Come Into Force?
Regulation 10 came into full enforcement in January 2026. Organisations that have not yet begun compliance work are already operating outside the regulation.
The DIFC published transitional guidance ahead of enforcement, but that window has closed. The expectation now is full compliance.
Common Questions About DIFC Regulation 10
Does Regulation 10 apply to AI tools we buy from third parties?
Yes. If you are a DIFC entity and you deploy a third-party AI tool that processes personal data, you remain the data controller. You are responsible for ensuring that tool meets Regulation 10 requirements, including DPIAs, transparency, and audit trails.
What counts as a "high-risk" AI system under Regulation 10?
High-risk systems are those that process sensitive personal data, make consequential decisions about individuals, or have a significant potential for harm. Credit scoring, fraud detection, employee monitoring, and customer profiling are all likely to be classified as high-risk.
Does Regulation 10 require AI systems to be explainable?
Not in a technical sense. You do not need to use explainable AI methods by default. But you do need to be able to describe the logic of your AI decisions to affected individuals in plain language. In practice, black-box models that cannot be explained at all create significant compliance risk.
Can we self-certify compliance?
Some elements of Regulation 10 compliance can be self-assessed. However, the DIFC also recognises approved certification bodies. Working with a recognised certification partner provides stronger evidence of compliance in the event of an audit.
What is the difference between Regulation 10 and the EU AI Act?
Both regulate AI use, but they are distinct frameworks. The EU AI Act applies to AI systems placed on the EU market and is risk-tiered by use case. Regulation 10 applies specifically to DIFC-licensed entities and is grounded in data protection law. DIFC entities with EU operations may need to comply with both.
How Magpie Helps With Regulation 10 Compliance
Magpie is a self-hosted AI governance and observability platform built specifically for regulated industries. It is designed to help DIFC-licensed organisations meet every core obligation under Regulation 10.
AI System Registry: Magpie gives you a centralised, structured registry of all AI systems in your organisation, with the fields required for Regulation 10 compliance built in.
DPIA Workflow: Magpie guides your team through structured DPIAs for each AI system, capturing risk assessments and sign-offs in a format regulators can review.
Audit Trails: Magpie generates tamper-evident, immutable audit logs of model behaviour, decisions, and human interventions, automatically.
Transparency Evidence: Magpie produces the documentation you need to demonstrate that affected individuals were informed about AI-driven decisions.
Human Oversight Tracking: Magpie records human review actions and overrides, giving you a clear evidence trail that automated decisions are not operating unchecked.
Self-Hosted: Unlike cloud-based observability tools, Magpie runs inside your own infrastructure. Your data never leaves your environment, which matters for DIFC data residency obligations.
Summary
DIFC Regulation 10 is the MEASA region's first AI-specific data protection regulation. It applies to all DIFC-licensed organisations that use AI systems processing personal data. Full enforcement began in January 2026.
The six core obligations are:
- Register all AI systems that process personal data
- Conduct DPIAs before deploying high-risk AI
- Appoint an AI Systems Officer
- Issue transparency notices to affected individuals
- Ensure human oversight of consequential AI decisions
- Maintain tamper-evident audit trails
Non-compliance carries fines of up to USD 100,000 and reputational risk in one of the world's most scrutinised financial centres.
If you are a DIFC-licensed fintech or financial services firm and you want to understand where you stand on Regulation 10 compliance, Magpie offers a structured readiness review to help you identify gaps and build your evidence pack.
This guide is for informational purposes only and does not constitute legal advice. For advice specific to your organisation, consult a qualified legal practitioner familiar with DIFC law.
Related guides from Magpie:
- What Is an AI Systems Officer (ASO) and Do You Need One?
- How to Conduct a DPIA for AI Systems Under DIFC Regulation 10
- AI Audit Trails: What Regulators Actually Want to See
- DIFC Regulation 10 vs EU AI Act: Key Differences for Global Fintechs
- Self-Hosted vs Cloud AI Observability: A Compliance Comparison