Quick Answer
DIFC Regulation 10 applies to any organisation that is licensed or registered in the Dubai International Financial Centre and uses AI systems that process personal data. This includes banks, fintechs, insurance companies, asset managers, family offices, and professional services firms operating inside the DIFC. If your organisation uses AI to make or influence decisions about customers, employees, or counterparties, and you hold a DIFC licence, Regulation 10 applies to you.
The Two Conditions That Trigger Regulation 10
You are subject to Regulation 10 if both of the following are true:
Condition 1: You are a DIFC-licensed or registered entity. Your organisation has a licence or registration issued by the DIFC Authority or the Dubai Financial Services Authority (DFSA).
Condition 2: You use AI systems that process personal data. You deploy, operate, or procure AI systems that take personal data as input, generate outputs about individuals, or make decisions that affect people.
Both conditions must be met. A company registered in mainland UAE that has no DIFC licence is not subject to Regulation 10, even if it uses AI extensively. Equally, a DIFC entity that uses AI only on fully anonymised data with no individual-level identifiers is unlikely to be in scope.
If you satisfy both conditions, Regulation 10 applies regardless of the size of your organisation, the sophistication of your AI systems, or where those systems are hosted.
Which Types of Organisations Are In Scope?
Financial Services Firms
Banks, investment managers, broker-dealers, and securities firms licensed by the DFSA are squarely within scope. These organisations routinely use AI for credit underwriting, fraud detection, market surveillance, client risk profiling, and algorithmic trading. Each of these use cases involves personal data and consequential decisions about individuals.
Fintech Companies
Payment processors, lending platforms, buy-now-pay-later providers, remittance services, and digital banking startups are among the most exposed organisations under Regulation 10. Fintechs tend to be AI-intensive by design. Automated credit decisions, KYC verification, transaction monitoring, and customer segmentation are all activities that bring fintech AI systems directly into scope.
Insurance Firms
Insurers and reinsurers licensed in the DIFC use AI for underwriting, claims processing, fraud scoring, and premium pricing. All of these involve processing personal data to make or influence decisions with significant financial consequences for individuals. Regulation 10 applies.
Asset Managers and Family Offices
Even where the primary business is portfolio management, AI systems used for client onboarding, suitability assessments, or client communications that process personal data bring these entities into scope.
Professional Services Firms
Law firms, accounting firms, and consultancies registered in the DIFC that use AI tools processing client data, employee data, or counterparty data are also in scope. This includes the use of AI-assisted document review, contract analysis, or due diligence tools if they process identifiable personal information.
Technology Companies and Platform Operators
Technology companies with a DIFC presence that build or operate AI platforms used by other DIFC entities may have obligations both as controllers and as processors. If you are a technology provider whose platform processes personal data on behalf of DIFC clients, you should assess your obligations carefully.
What About Third-Party AI Tools?
This is one of the most common sources of confusion, and it matters a great deal in practice.
If you are a DIFC-licensed entity and you purchase or subscribe to a third-party AI tool that processes personal data, Regulation 10 obligations fall on you as the data controller. The vendor is the data processor. You are responsible for:
- Conducting a DPIA before deploying the tool
- Ensuring the vendor has adequate data protection terms in place
- Including the tool in your AI System Registry
- Maintaining audit trail records for decisions made using the tool
The fact that a tool is built and hosted by a company outside the DIFC does not remove your obligations. If personal data flows through that tool as part of your business operations, you are accountable.
This applies to off-the-shelf AI tools, API-based AI services, and embedded AI features within software platforms your organisation uses.
What About Employees Who Use AI Tools Informally?
If employees use AI tools in the course of their work at a DIFC-licensed entity, and those tools process personal data, your organisation is still the controller. Informal or unsanctioned use does not transfer accountability to the individual employee or to the tool vendor.
This is a practical governance challenge. Many organisations have staff using general-purpose AI assistants, document tools with AI features, or AI-powered communications platforms without a formal procurement or risk assessment process. Under Regulation 10, those uses are the organisation's responsibility.
Who Is Explicitly Out of Scope?
Regulation 10 does not apply to:
- Organisations with no DIFC licence or registration
- AI systems that process only fully anonymised data with no capacity to re-identify individuals
- AI systems used purely for internal infrastructure purposes with no personal data involvement (for example, AI used to optimise server performance)
It is worth noting that the threshold for what constitutes "personal data" under DIFC law is broad. Pseudonymised data, device identifiers, behavioural data, and financial transaction data can all constitute personal data depending on context. If you are unsure whether your data qualifies, the default assumption should be that it does.
Does Regulation 10 Apply to Small Organisations?
Regulation 10 does not set a minimum size threshold for most obligations. The requirement to register AI systems, conduct DPIAs, provide transparency to individuals, and maintain audit trails applies to DIFC-licensed entities of all sizes.
The appointment of an AI Systems Officer (ASO) may be subject to proportionality. Smaller organisations may be able to assign ASO responsibilities to an existing role such as a Data Protection Officer or a compliance lead rather than hiring a dedicated individual. However, the role must exist and must be formally documented.
Small fintechs with a DIFC licence that use AI for any customer-facing function, including onboarding, credit assessment, or customer support automation, are in scope and should be treating compliance as a current obligation, not a future consideration.
Does Regulation 10 Apply to AI Systems Hosted Outside the DIFC?
Yes. Regulation 10 follows the entity, not the infrastructure. If you are a DIFC-licensed organisation and your AI systems are hosted on cloud infrastructure in another country, or operate through an API provided by a vendor based elsewhere, you remain subject to Regulation 10 for the personal data those systems process as part of your business activities.
This has practical implications for organisations that rely on US-based or EU-based AI infrastructure. Your vendor contracts, data processing agreements, and audit arrangements need to be structured with Regulation 10 compliance in mind.
Common Questions
We are registered in the DIFC but our AI systems are operated by a parent company in another jurisdiction. Does Regulation 10 still apply to us?
It depends on who controls the personal data being processed. If your DIFC entity is the controller of that data, Regulation 10 applies to you regardless of where the processing happens or who operates the systems on your behalf. If your parent company is the controller and your DIFC entity has no control over the data, the analysis is more nuanced and you should take legal advice specific to your structure.
We are a DIFC entity but we only use AI internally, for HR or operational purposes. Are we in scope?
If your HR AI systems process personal data about employees, yes. Employee data is personal data. AI systems used for performance monitoring, recruitment screening, scheduling, or workforce analytics all process personal data and bring you into scope.
We are a startup that recently received a DIFC licence. Do we need to be compliant immediately?
Full enforcement began in January 2026. If you hold a DIFC licence and use AI systems that process personal data, you are expected to be compliant now. If you are a newly licensed entity, you should treat Regulation 10 compliance as part of your operational setup, not something to address later.
Does Regulation 10 apply if we only process data about corporate entities, not individuals?
Regulation 10 is concerned with personal data, which is data relating to identified or identifiable natural persons. If you genuinely process only data about corporate entities with no natural person identifiers, you may fall outside scope. In practice, corporate data often includes personal data about directors, beneficial owners, and employees, so this analysis requires care.
Summary
DIFC Regulation 10 applies to you if:
- Your organisation is licensed or registered in the DIFC, and
- You use AI systems that process personal data
The type of organisation does not matter. Banks, fintechs, insurers, asset managers, professional services firms, and technology companies are all in scope if they meet both conditions.
The location of your AI infrastructure does not matter. Third-party tools you procure and deploy are your responsibility as the controller.
The size of your organisation does not exempt you from most obligations. Small and large DIFC entities face the same core requirements.
If you are unsure whether your organisation is in scope, the practical starting point is to map every AI system your organisation uses and identify which ones touch personal data. That exercise alone will tell you most of what you need to know.
How Magpie Supports Regulation 10 Scoping and Compliance
Magpie is a self-hosted AI governance platform designed for regulated industries. For organisations assessing their Regulation 10 obligations, Magpie provides:
AI System Registry: A structured inventory of every AI system in your organisation, including third-party tools, with fields mapped to Regulation 10 requirements. Building this registry is the first step in any scoping exercise.
DPIA Workflows: Guided assessments for each AI system that help you determine risk level and document your compliance position.
Third-Party AI Governance: Structured templates for assessing vendor AI tools against your Regulation 10 obligations before deployment.
Audit Trails: Immutable logs of AI system activity that satisfy the tamper-evident record-keeping requirements under Regulation 10.
Self-Hosted Architecture: All compliance data and AI evaluation stays inside your infrastructure. Nothing leaves your environment.
This guide is for informational purposes only and does not constitute legal advice. For advice specific to your organisation, consult a qualified legal practitioner familiar with DIFC law.
Related guides from Magpie:
- What Is DIFC Regulation 10? A Plain-Language Guide for Fintechs and AI Teams
- What Is an AI Systems Officer (ASO) and Do You Need One?
- How to Conduct a DPIA for AI Systems Under DIFC Regulation 10
- DIFC Regulation 10 Compliance Checklist for Fintechs
- Third-Party AI Tools and DIFC Regulation 10: What You Are Responsible For