A Free Zone Iterates on Its Own AI Rule
On 18 June 2026, the Dubai International Financial Centre opened a 30-day public consultation — closing 18 July — on amendments to its Data Protection Regulations (DP Regulations), the operating rules issued under DIFC Law No. 5 of 2020. Consultation Paper No. 3 of 2026 proposes two changes: it refines Regulation 10, the MEASA region's first rule governing personal data processed by autonomous and semi-autonomous systems, and introduces an entirely new Regulation 11 that lets the Commissioner of Data Protection formally recognise accreditation and certification frameworks. DIFC Chief Legal Officer Jacques Visser framed the goal plainly: to keep the regime "practical, clear, and responsive to evolving AI technologies."
This is not DIFC's first pass at AI-specific data rules. Regulation 10 was proposed in April 2023 and took effect that September, building a structure in which a Deployer (treated as the data controller) and an Operator (treated as the processor) must keep registers of autonomous-system use cases, issue notices when processing is not directed by a human, and maintain intervention mechanisms for potentially discriminatory outcomes. High-risk processing requires an Autonomous Systems Officer (ASO), a role Mayer Brown's analysis of the rule describes as carrying "substantially similar status, competencies and tasks to a DPO." The 2026 amendments don't rip that structure up — they sharpen the ASO's mandate and, more consequentially, answer the question every regulated firm eventually asks an outcomes-based regime: how do we prove we're compliant, rather than just asserting it?
The Case for a Certification Layer
DIFC's original approach to Regulation 10 was deliberately principles-based rather than prescriptive — it told firms what outcomes to avoid (undisclosed autonomous decision-making, undetected discrimination) without dictating the technical means of avoiding them. That flexibility is defensible: AI systems evolve faster than most regulators can draft rules, and a rigid technical checklist risks becoming obsolete before it's enforced. But principles-based regulation has a well-known cost — uncertainty. Without a recognized way to demonstrate compliance, firms face open-ended exposure to a regulator's case-by-case judgment, which disproportionately burdens smaller companies that can't afford bespoke legal opinions for every deployment. Large financial institutions can absorb that ambiguity; a five-person fintech building on top of a foundation model cannot. Regulators who take AI accountability seriously — the EU AI Act's conformity-assessment regime is the obvious comparison — have converged on the same fix: give firms a certification pathway that substitutes for individualized scrutiny.
That's what Regulation 11 does. By empowering the Commissioner to recognise third-party accreditation and certification schemes — plausibly including standards like ISO/IEC 42001 for AI management systems — DIFC is converting an open-ended "prove it to the Commissioner" obligation into a bounded, predictable one: get certified against a recognised scheme, and you have a defensible compliance position. That is precisely the kind of proportionate move this publication has argued for elsewhere: regulation that reduces uncertainty for a broad base of firms rather than regulation that maximises discretionary regulatory power.
Where the Design Still Needs Scrutiny
The risk sits in what "recognised" means in practice. A certification market only serves smaller firms if certification is cheap, accessible, and genuinely portable — if the Commissioner recognises only a narrow set of costly, resource-intensive schemes, Regulation 11 could invert its own purpose and become a moat that favours incumbents with compliance budgets, rather than a low-friction pathway for the market DIFC's ~8,800 active registered firms represent. The consultation paper doesn't yet specify which frameworks will qualify or what the recognition process costs; that detail, not the headline concept, will determine whether this is genuinely proportionate or merely relabelled gatekeeping. DIFC's own record offers some reassurance — its outcomes-based approach to Regulation 10 in 2023 was explicitly built, in Visser's words at the time, on a "more collaborative, transparent way of creating" rules with industry input, and this consultation follows that same pattern of public comment before enactment.
Why a Free Zone's Rule Matters Beyond Dubai
DIFC is a common-law financial free zone, not the UAE's federal government — its Data Protection Law sits alongside, not inside, the UAE's Federal Decree-Law No. 45 of 2021. That separate, judicially-overseen track is exactly why DIFC can move faster than most national AI regulators: a specialist Commissioner amending sector regulations through consultation is a materially lighter process than a legislature amending statute. DIFC Law No. 5 of 2020 was built, per the law's own framing, to support an eventual EU and UK adequacy finding, so any credibility DIFC builds on AI accountability compounds into its case for treatment as a trusted data corridor. If Regulation 11 lands with accessible, well-specified certification criteria, it becomes a genuinely exportable model — proof that jurisdictions can regulate autonomous systems without either the EU's compliance-heavy conformity bureaucracy or a regulatory vacuum. If it lands vague, DIFC will have proven the opposite: that "accreditation" is regulatory language for discretion by another name.