Blog

AI Implementation

The Legal Risks of AI in UAE Infrastructure: A Practical Guide

A practical guide to the legal risks UAE infrastructure firms face when deploying AI, from PDPL and decennial liability to IP ownership and vendor contracts.

A person signing a legal contract document at a desk
Photo by Scott Graham on Unsplash Source

UAE infrastructure firms are moving AI from pilot to production faster than most legal teams can review the paperwork behind it. Predictive maintenance models are reading sensor data from live grids, generative tools are drafting engineering reports, and vendor contracts for AI platforms are getting signed on tight project timelines. The gap between how fast the technology moves and how well anyone has checked the legal exposure underneath it is where the real risk sits.

The UAE does not have one law called the AI Act that governs all of this, and firms hoping to find a single rulebook to check against will not find one, a point covered in more detail in our guide to AI compliance in the UAE. What exists instead is a patchwork of federal and free zone laws, each written before generative AI became a boardroom topic, that now has to be read and applied to it. Two of the biggest recent shifts landed within the same year: DIFC Regulation 10 moved to full enforcement on January 1, 2026, and a new federal Civil Code, Federal Decree-Law No. 25 of 2025, replaced the 1985 Civil Transactions Law on June 1, 2026, according to Bracewell's analysis of the new code. Any infrastructure firm running AI in the UAE right now is operating under both.

No Single AI Law, But Real Penalties Attached to Existing Ones

The clearest evidence that these rules have teeth comes from the penalty framework already attached to the UAE's ethical AI guidelines. According to Chambers and Partners' legal analysis of AI in the UAE, violations tied to AI discrimination, data protection breaches, or non-compliance with the national ethical guidelines can carry fines of 500,000 to 1,000,000 AED, with imprisonment possible for the most severe cases. Systems that make consequential decisions, such as flagging a structural inspection or prioritizing maintenance work, are also expected to undergo regular quality assessments, keep audit records, and offer an accessible way for a decision to be challenged and reviewed by a person.

The Artificial Intelligence and Advanced Technology Council, established in Abu Dhabi in January 2024, and the federal AI Office both sit above this framework, coordinating strategy rather than issuing one binding statute. For a firm running AI on live infrastructure, that means compliance work happens statute by statute: data protection law, sector regulation, free zone rules if the entity sits in DIFC or a similar zone, and now the new Civil Code for anything touching contracts or liability.

Data Protection Is Where Most AI Legal Risk Actually Lives

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, in force since January 2, 2022, is the single most consequential statute for any UAE infrastructure firm running AI, because nearly every AI system in production touches personal data somewhere: employee records feeding a workforce planning model, resident data behind a smart city dashboard, or contractor details in a procurement tool. According to Securiti's overview of the law, the PDPL requires clear, specific consent before that data is processed, restricts cross-border transfers to countries the UAE Data Office deems to have adequate protection, and requires a data protection impact assessment before deploying any system, AI included, that is likely to create high risk for the people whose data it touches. Firms hosting AI workloads on cloud infrastructure outside the UAE need to check that hosting arrangement against these rules before go-live, not after.

Firms operating in or through the DIFC face an additional layer. Regulation 10 of the DIFC's Data Protection Regulations, which moved to full enforcement on January 1, 2026, governs personal data processed by autonomous and semi-autonomous systems specifically, according to Mayer Brown's January 2026 analysis. It splits responsibility between the deployer, the entity that authorizes an AI system's use and is treated as the data controller, and the operator, the party that provides the system and is treated as a processor. High-risk processing under the regulation requires appointing an Autonomous Systems Officer, a role built around the same governance and risk review functions as a data protection officer. This is worth checking even for firms headquartered outside DIFC, because any infrastructure project that routes data through a DIFC-based vendor or partner can pull that data under Regulation 10's scope. The overlap with cyber risk is direct too, since a poorly governed AI system is also a poorly secured one, a connection covered in more depth in our guide to AI cybersecurity risks for UAE infrastructure firms.

Who Is Liable When an AI System Gets It Wrong

UAE liability law does not carve out a special, lighter standard for harm caused by an AI system. General negligence principles, now set out in the new Civil Code, Federal Decree-Law No. 25 of 2025, which took effect June 1, 2026 and replaced the 1985 Civil Transactions Law, still apply: a party that fails to exercise the care a competent professional would exercise in the same circumstances can be held liable for the resulting harm. Where multiple parties, an AI vendor, an integrator, and the infrastructure firm itself, contributed to a decision that went wrong, UAE law allows for joint and several liability, meaning each party can be pursued for the full loss regardless of how the fault is eventually apportioned between them internally.

This lands with particular force in construction and engineering, where UAE law imposes decennial liability, a strict ten-year liability on contractors and supervising engineers for any total or partial collapse, or any defect threatening a structure's stability or safety, running from the date of delivery. According to Alkabban's summary of engineering liability under UAE construction law, this liability cannot be excluded or limited by contract and does not require proof of fault, only that the defect exists and falls inside the ten-year window. If an AI tool assisted with the structural design, load calculations, or predictive maintenance schedule behind a failure, that does not shift decennial liability away from the contractor and engineer of record. The AI vendor's contract terms determine whether the firm can recover from the vendor afterward, but they do not change who the client can sue first.

This is exactly why the question of how much a firm lets an AI system decide versus flag for a human matters as a legal question, not just an operational one, a distinction covered in our guide to AI ethics and risk boundaries in UAE infrastructure. Keeping a licensed engineer as the accountable decision-maker on anything touching structural safety is not just good practice, it is what UAE decennial liability law already assumes is happening.

Intellectual Property: Who Owns What the AI Produces

The UAE's copyright framework, Federal Decree-Law No. 38 of 2021 on Copyright and Neighboring Rights, protects original creative and technical works, but like most copyright regimes it was written around human authorship. According to Al Suwaidi's analysis of IP rights and AI in the UAE, rights generally attach to the human creator or the party commissioning the work, not to the AI system itself, which creates real uncertainty for reports, drawings, or designs generated with minimal human input. A structural report drafted almost entirely by a generative AI tool, with an engineer only reviewing and signing off, sits in a gray area the law has not explicitly resolved.

Patents face a similar gap. Federal Decree-Law No. 11 of 2021 on Industrial Property Rights excludes pure software from patent protection and has no provision recognizing an AI system as an inventor, so any patentable innovation still needs a named human inventor and a genuine hardware or technical component. Trade secret protection is the more reliable fallback for the parts of an AI deployment a firm actually wants to keep proprietary, such as a custom-trained predictive maintenance model or a tuned dataset. Because trade secrets do not require registration, only demonstrated confidentiality through NDAs, access controls, and internal governance, they are usually the fastest and most defensible way to protect AI-specific work product while the copyright and patent frameworks catch up.

Getting the AI Vendor Contract Right

Most of the legal exposure covered above gets negotiated, or missed, at the contract stage, well before an AI system ever touches live infrastructure data. Procurement teams under pressure to move fast on an AI pilot often accept a vendor's standard terms without checking them against PDPL, decennial liability, or IP ownership questions, which is the exact moment risk gets built in for years. Our guide to choosing the right AI provider covers the evaluation criteria in more detail, but from a legal standpoint, four contract terms deserve specific attention: where the data is hosted and processed, and whether that location satisfies PDPL's cross-border transfer rules; how liability and indemnity are split between the vendor and the firm if the AI system's output causes harm; whether the firm retains audit and inspection rights over the vendor's model and data handling, mirroring what DIFC Regulation 10 already expects of high-risk systems; and who owns the output, the trained model, and any derivative work product once the contract ends.

None of these terms are standard in most off-the-shelf AI vendor agreements, which are typically written to protect the vendor rather than the client. Getting legal counsel to review and negotiate them before signing, not after a dispute, is the single highest-leverage step most firms skip.

A Practical Legal Checklist Before You Deploy

Before any new AI system goes live on an infrastructure project, a short internal legal review can catch most of what is covered above:

  • Map every AI system against what data it touches, including whether that data is personal data under the PDPL and where it is hosted
  • Confirm cross-border data transfers meet PDPL adequacy requirements before go-live, not after an audit flags them
  • Keep a named, accountable human decision-maker on anything touching structural safety, matching what decennial liability law already assumes
  • Negotiate liability, indemnity, audit rights, and IP ownership into every AI vendor contract rather than accepting standard terms
  • Document human review and sign-off on any AI-assisted engineering report or design before it is submitted or acted on
  • Re-check contracts signed before June 1, 2026 against the new Civil Code, particularly for any project still in dispute or under warranty

The Bottom Line

The UAE's legal framework for AI is not a single document a firm can check off once. It is data protection law, sector-specific rules, construction liability doctrine, IP statutes, and now a newly modernized Civil Code, all applying to the same AI system at once. None of it is designed to slow AI adoption down for its own sake, but it does mean the legal review has to happen at the same pace as the technical rollout, not after. Firms that treat contract terms, data residency, and human accountability as part of the AI implementation plan itself, rather than a compliance afterthought, are the ones least likely to discover the gap the hard way.

FAQ

Common questions.

Does the UAE have a dedicated law regulating artificial intelligence?

No. The UAE regulates AI through existing statutes rather than one dedicated AI law: the Federal Decree-Law No. 45 of 2021 Personal Data Protection Law, sector regulations, free zone rules such as DIFC Regulation 10, the new Civil Code (Federal Decree-Law No. 25 of 2025), and the National AI Ethics Guidelines, which carry fines of 500,000 to 1,000,000 AED for serious violations.

Who is legally liable if an AI-assisted design leads to a structural defect?

The contractor and supervising engineer of record remain liable under UAE's decennial liability rule, a strict ten-year liability for structural collapse or safety defects that cannot be limited or excluded by contract. Using an AI tool in the design or calculation process does not shift that liability away from the engineer and contractor, though the firm's contract with its AI vendor determines whether it can recover costs from the vendor separately.

Can a UAE infrastructure firm copyright a report or design generated primarily by AI?

It is legally uncertain. Federal Decree-Law No. 38 of 2021 on Copyright protects works with human authorship, and rights generally attach to the human creator or commissioning party rather than the AI system itself. A report or design with substantial, documented human review and revision has a stronger copyright claim than one produced almost entirely by an AI tool with minimal human input.

What is DIFC Regulation 10 and does it apply to firms outside the DIFC?

DIFC Regulation 10 governs personal data processed by autonomous and semi-autonomous systems within the Dubai International Financial Centre, and moved to full enforcement on January 1, 2026. It can still reach firms headquartered outside DIFC if their AI project routes data through a DIFC-based vendor, partner, or data processor, so it is worth checking even for mainland companies.

What should an infrastructure firm demand in an AI vendor contract?

At minimum: clear terms on where data is hosted and processed and whether that satisfies PDPL cross-border transfer rules, an explicit split of liability and indemnity if the AI system's output causes harm, audit or inspection rights over the vendor's model and data handling, and clear ownership terms for the trained model and any output once the contract ends.