The numbers behind the model
On 8 September 2026, Abu Dhabi Global Market published its H1 2026 results. According to the Abu Dhabi Media Office's account of the release, assets under management in ADGM rose 54 per cent against H1 2025. Active licences reached 13,974, and the workforce on Al Maryah and Al Reem Islands reached 49,027 professionals. ADGM also said entities established in the financial centre now hold more than US$100 billion in AI-focused investment. It named MGX, which deploys capital into AI infrastructure, and RIQ, which signed an MoU with Swiss Re to develop AI-enabled reinsurance.
None of this happened under an AI-specific statute. ADGM does not have one. AI systems operating there are governed by the general Data Protection Regulations 2021 and regulator guidance, alongside sectoral financial supervision by the Financial Services Regulatory Authority (FSRA).
The strongest case for a dedicated AI law
The case for a dedicated AI law deserves a fair hearing. Capital is concentrating fast, and a fund or insurer that automates underwriting, credit or trading creates risks that data-protection law was not drafted to capture: model failure, correlated errors across institutions, and opaque vendor dependencies. A dedicated law would give firms certainty about what counts as high-risk. It would also give individuals a clearer path to redress than a rule written for personal data. Regulators in other jurisdictions have moved this way, and a financial centre courting institutional money may worry that a missing statute reads as a missing guardrail.
What the existing rules already do
That argument is weaker in ADGM than it first appears, because the data-protection regime already reaches the places where AI harms individuals. ADGM's explainer on automated decision-making and profiling describes a right not to be subject to decisions based exclusively on automated processing. Where such processing is used, firms must tell people about it. They must also offer human intervention, appeal or objection, and keep data and systems accurate through regular checks. Automated decisions are allowed only where they are tied to a contract, authorised by applicable UAE law, or based on explicit consent. The explainer's worked examples come from financial services, including automated loan-eligibility decisions.
This is a proportionate, technology-neutral design. It regulates the decision and its effect on a person, not the model architecture, so it does not need rewriting each time the technology changes. It also sits on top of the FSRA's existing supervisory relationship with licensed firms. In the same results, the FSRA finalised frameworks for virtual-asset staking and climate-related financial risk. That is the pattern of a regulator extending existing supervision to new activity, not waiting for new primary legislation.
The record so far is consistent with this approach attracting capital rather than repelling it. The 54% growth in AUM, and a reported 190 fund and asset managers (up from 154 a year earlier), came with no AI statute. Correlation is not proof, and the press release is ADGM's own account, so these figures should be read as self-reported. But no one has shown that the absence of an AI law has cost the centre business.
The risk: a federal authority that overreaches
The live question is what the UAE's new national body does next. On 14 June 2026 the UAE announced a federal Artificial Intelligence and Data Authority. Morgan Lewis's summary says it will set unified national AI and data policy direction, propose legislation and strategies, set standards and guidelines for data and AI management, and drive compliance across federal entities. It consolidates the AI Office, the UAE Data Office and the digital-government portfolio of TDRA.
A single body is a sensible response to fragmentation, and its mandate to propose legislation is not in itself a problem. The risk is in how the proposals are written. The mainland already has a federal data-protection law, Federal Decree-Law 45 of 2021 (the PDPL), in force since 2 January 2022. The summary notes that ADGM and DIFC operate independently within their jurisdictions and without reference to the PDPL. If the new authority writes prescriptive AI rules without regard to that separate framework, it could create overlapping obligations for firms that sit under both regimes.
The better course is to treat ADGM's approach as a tested model. That means keeping obligations tied to outcomes for individuals, using guidance and supervisory dialogue before binding rules, and carving out clear coordination with free-zone regulators. The Morgan Lewis piece itself argues that a regulator "structured to engage with the market and not simply control it" is the right design. The authority's early choices will show whether it meets that standard.
The sovereignty trap
There is a wider caution. Governments often justify tighter control of data and AI under the banner of digital sovereignty. The EFF's September 2026 essay argues the idea can mean real resilience and user autonomy, but warns that it can also become a justification for censorship and surveillance. A national AI authority that also oversees national data platforms and cybersecurity coordination holds a lot of power. Transparency about what it can compel, and how rulings can be challenged, matters as much as what AI rules it eventually proposes.
What to watch
Three tests will show whether the UAE keeps the flexibility that ADGM's numbers suggest is working. First, whether any federal AI proposal is published as a draft for comment before it is enacted. Second, whether it distinguishes high-impact automated decisions from routine tooling. Third, whether it respects the separate legal frameworks inside ADGM and DIFC. Growth of 54% in a year is not a mandate to stand still, but it is good evidence for regulating the decision rather than the technology, and for testing any new federal rule against what already works.