On 8 September 2026, Abu Dhabi Global Market published its H1 2026 results. Assets under management rose 54% year on year and active licences reached 13,974. ADGM also said it has deployed AI across 25 business functions, including licensing, supervision and customer service. It says this removed more than 5,000 staff hours of manual work a year and lets about 25% of customer enquiries be resolved instantly. It plans to invest more than AED 400 million through 2029 to expand AI capabilities. And it says entities in its jurisdiction, anchored by the FSRA-licensed investor MGX, hold over US$100 billion in AI-focused investment (Abu Dhabi Media Office).
The strongest case for the UAE's approach
The skeptic's argument is that a financial centre with no AI statute is a regulatory experiment run on other people's money. Its supporters counter that the opposite is true. A regulator that has put AI into 25 of its own functions understands the technology's failure modes first-hand, and ADGM's own release stresses "governed, verifiable AI deployment with clear accountability and human oversight." That is a real advantage over rule-writers who have never operated a model.
The numbers give this view weight. The reported 5,000 hours saved is modest, roughly two or three full-time staff. It is not a transformation. But quick, routine service is exactly what a licensing regime should deliver, and it is the kind of proportionate, use-case-level AI adoption that a horizontal statute would struggle to protect.
What the results do not tell us
The results are self-reported. They describe efficiency, not outcomes. We do not know how many of the 25% instantly resolved enquiries were resolved correctly, how many licensing or supervisory decisions had AI input, or what appeal route exists when they did. Those are the questions that determine whether the tools are trustworthy, and a press release cannot answer them.
The headline growth also should not be read as proof that light-touch AI rules cause capital inflows. ADGM's licence and AUM growth reflects many factors: tax treatment, common-law courts, geography and sovereign capital. The MGX-anchored AI investment is a capital-markets story. It tells us where money is being raised and managed, not how AI systems operate on the ground.
The federal gap
The UAE has no single AI law. Instead there is a layered patchwork. Federal Decree-Law No. 45 of 2021 on personal data protection came into force on 2 January 2022 (u.ae). Legal commentary notes that its Implementing Regulations, needed to operationalise key concepts, have still not been issued (Morgan Lewis). That is nearly four years after the law took effect.
In June 2026 the UAE announced a Federal Authority for Artificial Intelligence and Data. It consolidates the AI Office, TDRA's digital government sector and the Emirates Data Office, and is charged with setting unified policy direction and proposing legislation (same source). That is a sensible institutional step. But an authority that proposes legislation is not the same as rules a firm can read today.
For businesses this matters more than it might seem. A compliance team deploying a credit-scoring or hiring model in Abu Dhabi needs to know which regime applies: ADGM's, DIFC's, or the federal one. Uncertainty is a cost, and it falls hardest on start-ups without in-house counsel. Large, well-lawyered sovereign-backed players like MGX can live with ambiguity. Smaller firms cannot.
What proportionate looks like
The answer is not a sweeping EU-style AI Act. It is narrower and quicker:
- Issue the outstanding Executive Regulations. Data rules are the operative constraint on AI in practice, and firms cannot plan around regulations that do not exist.
- Publish how regulators use AI. If ADGM wants AI to be governed and verifiable, it should publish error rates, human-review rules and complaint routes for its 25 deployments. A regulator that asks firms for model governance should show its own.
- Map the free zone and federal boundaries. Say plainly which rule governs a model deployed across ADGM, DIFC and the mainland.
- Regulate by harm, not by technology. Target concrete risks such as automated decisions on credit and employment, and leave general-purpose research alone.
The wider debate over digital sovereignty is relevant here. EFF argues that sovereignty should mean users having a "clear understanding of who can lawfully access" their data, rather than states simply gaining control (EFF). A jurisdiction that invests AED 400 million in AI and cybersecurity should be equally clear about who can see what its AI systems process.
Bottom line
ADGM has shown that a regulator can adopt AI quickly and attract capital while doing so. That is worth celebrating, and it is a better model than blanket restrictions. But its results are a proof of operational competence, not of legal clarity. The UAE's next step should be to finish the rules it already promised, before writing new ones.