
Search for AI regulation in the Gulf and you will find confident references to a UAE AI Act, a Dubai AI Act and mandatory SDAIA registration. We could not find a government source for any of them. What does exist is a mix of binding data protection law, sector rules, national frameworks that are explicitly guidance, and new institutions that will shape future law. For a compliance team, the useful question is which of these you must meet today and which you should align with. This guide answers it for Saudi Arabia, the UAE and Pakistan.
Is there an AI law in Saudi Arabia?
No general AI statute. The Saudi Data and AI Authority, SDAIA, governs AI through the Personal Data Protection Law and a set of regulatory documents on AI, including the AI Ethics Principles and generative AI principles for government entities.
The Cabinet declared 2026 the Year of Artificial Intelligence in March 2026. That is a national programme designation, not regulation.
Are the SDAIA AI Ethics Principles mandatory?
The AI Ethics Principles set out seven principles: fairness; privacy and security; humanity; social and environmental benefits; reliability and safety; transparency and explainability; and accountability and responsibility.
They are not a binding statute, and registration with SDAIA is optional, encouraged through recognition badges. The binding duties for most AI systems come from the PDPL whenever personal data is involved, which in practice is most of the time.
What are SDAIA's AI Adoption Framework and AI risk framework?
The AI Adoption Framework, unveiled in September 2024, is described by the Saudi Press Agency as a guiding reference for the public and private sectors. It sets four maturity levels, from Emerging to Advanced, and encourages entities to establish AI units.
In July 2026 SDAIA launched a national AI risk management framework covering public and private entities. It runs in four phases: context and scope, identify and assess, treat, and monitor and review, using a likelihood and impact matrix, seven core principles and seven risk types.
Some vendor material describes the adoption framework as mandatory for government. We could not confirm that from an official source, so treat it as strong guidance unless your regulator tells you otherwise.
What is the status of Saudi Arabia's Global AI Hub Law?
The Communications, Space and Technology Commission published a draft Global AI Hub Law for public consultation in April 2025. It deals with hosting models for foreign AI infrastructure and data, not with how organisations use AI. We found no official confirmation that it has been enacted, so treat it as a draft.
Does the UAE have a federal AI law?
No standalone federal AI law. Existing federal law applies to AI, most importantly the federal Personal Data Protection Law, Federal Decree-Law 45 of 2021, together with the cybercrime law and civil liability rules.
Claims of a UAE AI Act or a Dubai AI Act in force in 2026 appear on unofficial sites and social media. Unless you can find the instrument on the UAE or Dubai official legislation portals, do not build compliance work around it.
What does the UAE Charter for AI require?
The UAE Charter for the Development and Use of Artificial Intelligence sets twelve principles, including safety, avoidance of algorithmic bias, data privacy, transparency, human oversight, governance and accountability, and compliance with laws and treaties.
It is a policy charter, not law. It is still worth mapping to, because it signals what future regulation and government procurement will expect.
What is the UAE Artificial Intelligence and Data Authority?
Approved in June 2026, the authority brings together the AI Office, the digital government functions of the TDRA and the UAE Data Office, and reports to the Cabinet. Its mandate includes proposing national policies, legislation and strategies, and setting data and AI standards with compliance across federal entities.
It is the body most likely to propose a federal AI law. It is not currently described as an enforcer of AI rules against the private sector.
Which AI rules are binding in Dubai and the DIFC?
DIFC Data Protection Regulation 10, on processing personal data through autonomous and semi-autonomous systems, is binding within the DIFC. It was enacted in September 2023, and a certification framework with accredited certification bodies now supports it. It applies only inside the DIFC, not across the UAE. ADGM has its own separate provision on automated decision-making.
The Dubai AI Seal from the Dubai Centre for Artificial Intelligence is a voluntary trust label. Sector rules also exist, for example in Dubai healthcare and for autonomous vehicles, and apply to those sectors only.
What does Pakistan's National AI Policy require of companies?
The federal cabinet approved the National AI Policy on 30 July 2025. It is a policy roadmap, with targets such as training one million AI professionals by 2030, an AI council and a master plan. We found no statutory duties on businesses in it.
Is there a binding AI law in Pakistan?
No. The Regulation of Artificial Intelligence Bill 2024, a private member's bill introduced in the Senate in September 2024, is recorded on the Senate's official site as withdrawn and disposed of. Many articles still describe it as pending.
The Personal Data Protection Bill had not been enacted as of our research. Existing law, including the Prevention of Electronic Crimes Act 2016, applies to AI misuse, and sector regulators such as SBP set technology risk expectations that cover AI used in financial services.
What should a compliance team do now?
Treat data protection as the binding core: the Saudi PDPL, the UAE PDPL, DIFC Regulation 10 where relevant, and sector rules. Every AI system that processes personal data inherits those obligations today.
Align with the national frameworks rather than waiting for them to become law: SDAIA's ethics principles and risk framework, the UAE Charter, and Pakistan's policy direction. Keep an AI system register, assess risk and impact for each system, and record the human oversight you have in place. All three countries are moving towards expectations that look like this.
How does ISO/IEC 42001 help across the Gulf and Pakistan?
ISO/IEC 42001 is not legally required in any of the three countries. It gives you one management system that can be mapped to SDAIA's principles and risk framework, the UAE Charter, and the evidence DIFC Regulation 10 certification expects.
SDAIA itself reports being certified to ISO/IEC 42001 in 2024, and its 2026 risk framework follows the same identify, assess, treat and monitor cycle that 42001 uses. For a regional group, that makes 42001 the natural common denominator.
How GRCLens supports Gulf and Pakistan AI governance
GRCLens implements ISO/IEC 42001 alongside the Saudi PDPL, NCA ECC, the UAE Information Assurance Standard and Pakistan's PISF 2026 on one control model, in Arabic and English with right-to-left reporting. Its AI runs inside the customer's own infrastructure, including air-gapped deployments, which keeps AI governance evidence under the same data residency rules as everything else.
Primary sources
Saudi Press Agency releases on the SDAIA AI Adoption Framework (September 2024) and national AI risk management framework (July 2026). SDAIA AI Ethics Principles. CST Istitlaa consultation on the draft Global AI Hub Law (2025). UAE Cabinet announcement of the Artificial Intelligence and Data Authority (June 2026). UAE Charter for the Development and Use of Artificial Intelligence. DIFC Commissioner of Data Protection, Regulation 10. Senate of Pakistan bill record for the Regulation of Artificial Intelligence Bill 2024.
This article is general information, not legal advice. AI policy in this region is moving quickly, so confirm current status before relying on any single point.
Keep reading

AI Governance in Australia and NZ: 2026 Guide
Australia and New Zealand chose existing laws over an AI Act. What is mandatory, what is voluntary, and what starts in December 2026.

Enhanced CIRMP Rules 2026: What to Do and When
The enhanced CIRMP Rules commenced on 10 June 2026. What nine high-risk asset classes must do, which frameworks now qualify, and the deadlines.

Saudi OTCC and CSCC: Which NCA Controls Apply?
OTCC-1:2022 covers critical OT and ICS. CSCC-1:2019 covers other critical systems. Scope, control counts, facility levels and the ECC link.