Most conversations about AI ethics in UAE infrastructure start with the wrong question. Teams ask what the regulator will require of them, wait for the answer, and put the harder decisions on hold until it arrives. As of early 2026, that answer still has not come. The CMS AI regulation scanner, updated in February 2026, states the position plainly: "there is currently no dedicated AI law in force in the United Arab Emirates". Latham and Watkins reached the same conclusion in its October 2025 review of the UAE regulatory landscape, describing a sector by sector approach rather than a single comprehensive statute.
That is not a gap the country has failed to notice. It is a deliberate choice to lead with principles and sector rules while the technology settles. But it has a consequence that infrastructure operators need to sit with. If you run AI across a water network, a signalling system, a tower crane fleet, or a workforce of ten thousand people, nobody is going to hand you a list of things your AI may not do. You have to write that list yourself.
The gap between enthusiasm and governance is measurable. PwC's 29th Global CEO Survey, covering more than 300 Middle East chief executives and reported in January 2026, found that 85 percent of UAE respondents say their company culture enables AI adoption, while only around 59 percent of Middle East CEOs report having formalised responsible AI and risk processes, according to Middle East AI News. Roughly four in ten are moving fast with nothing written down. This article is about what to write down.
An Oversight Boundary Is Not a Red Line
The most common mistake in AI governance documents is treating every limit as a question of how much human review to apply. That framing quietly assumes every use case is permitted, and the only variable is supervision. It is not. There are two distinct kinds of limit, and confusing them is how firms end up with policies that look thorough and constrain nothing.
An oversight boundary says a human must approve, review, or be able to intervene in a decision. It is a control on how the system operates. Deciding which decisions need that control is the subject of our guide to when to trust human judgment over AI in UAE infrastructure decisions, and it is where most governance effort goes.
A red line says the system may not be deployed for this purpose at all, at any level of accuracy, with any amount of supervision. It is a control on what you build in the first place. Red lines are rarer, shorter, and far more useful, because they are the only part of a policy that survives commercial pressure. An oversight requirement can be diluted quietly when a project runs late. A red line either holds or is visibly broken.
A workable boundary policy needs both. Roughly speaking, expect a long list of oversight boundaries and a short list of red lines, perhaps five to ten items, that everyone from the board to the site engineer can recite.
What the UAE Actually Requires, and What It Leaves to You
Before drawing your own lines, it helps to know exactly which ones already exist. There are four instruments that matter for infrastructure firms, and each one is more specific than the general debate suggests.
The UAE Charter for the Development and Use of Artificial Intelligence, published in 2024, sets out twelve principles. Three speak directly to boundaries: Safety, which commits the country to the highest safety standards and encourages modifying or removing systems that pose risks; Algorithmic Bias, which requires that technological benefits reach people without exclusion or discrimination; and Human Oversight, which affirms the irreplaceable value of human judgment as the mechanism that corrects errors and bias. The Charter is a statement of national principle rather than an enforceable rulebook, which means it tells you what your boundaries must protect without telling you where to put them.
The National Cyber Security Policy for Artificial Intelligence, issued by the UAE Cyber Security Council, is the sharpest instrument available to a critical infrastructure operator. It sets minimum security requirements across six domains: Governance, Infrastructure and Application Security, Algorithm Security, Operational Safety, Adversarial AI Attacks, and AI Monitoring and Response. The Operational Safety domain requires organisations to tailor security measures to the distinct applications of AI and machine learning systems, ensure human oversight in critical decision making, establish protocols for system resilience, and ensure continuity and reliability through comprehensive testing and validation. If you operate national infrastructure, this is the document to map your boundary register against first.
Federal Decree-Law 45 of 2021, the Personal Data Protection Law, contains a right that most infrastructure firms overlook. Article 18 gives individuals the right to object to decisions based solely on automated processing where those decisions carry legal consequences or a serious effect on them, subject to exceptions where the processing is contractual, legally required, or consented to, as summarised by DLA Piper. The law came into force on 2 January 2022, though its Executive Regulations remain unpublished, and organisations will have a further six month window to comply once they are issued. For a fuller treatment of what this means operationally, see our guide to UAE data privacy rules for AI.
Finally, Dubai's AI System Ethics Self-Assessment Tool offers a classification scheme that is genuinely useful and unusually honest about its own limits. It sorts AI systems by decision impact into non-significant, significant, and critical decisions, then scores them on fairness, accountability, transparency, and explainability. The tool states directly that "the guidelines in this self-assessment tool are recommended instead of compulsory" and that it "is used for self-assessment purposes only and will not be audited, checked or regulated during this time." It also carries a line worth quoting to any executive who thinks a passing score is the goal: it is not suggested to proceed with AI system implementation unless a certain level of ethics performance is reached.
There is one further detail in the underlying Smart Dubai AI Ethics Principles and Guidelines, first launched in January 2019 and recorded by OECD.AI as a non-binding initiative. Guideline 1.2.3 requires that AI systems informing critical decisions be subject to appropriate external audit, and it is marked SUSPENDED in the published document. Dubai wrote the external audit requirement for critical-decision AI, then paused it. That single word tells you everything about where the responsibility currently sits.
Red Line One: Safety Critical Control
The clearest boundary in infrastructure is also the least negotiable. A machine learning model should not be the final actuating authority in a protective function whose failure kills people or takes a network down. That covers emergency shutdown logic, protective relay tripping, pressure relief, gas detection interlocks, rail signalling authority, crane load limiters, and confined space entry permits.
The reason is not that AI is unreliable. It is that protective functions are engineered to a demonstrable, testable failure rate, and a model whose behaviour changes with its training data cannot carry that kind of proof. This is why the European Union, in Annex III of the EU AI Act, specifically classifies as high risk those systems "intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity." That definition names exactly the sectors UAE infrastructure firms operate in, and it is a useful external reference point even though it does not bind you.
The practical version of this red line is a separation rule. AI may advise, predict, prioritise, and alert on the safety layer. It may not sit inside it. A model that predicts a transformer failure three weeks out is enormously valuable and entirely appropriate. The same model wired to trip the breaker directly is a different system with a different risk profile, and it should require a different decision to approve.
- AI may generate an alert, a ranking, or a recommendation on any safety related asset.
- AI may not be the sole trigger for a shutdown, isolation, or protective trip.
- Any AI output feeding a safety layer must be logged with its inputs and model version.
- Overriding a safety interlock on the basis of an AI recommendation requires named human authorisation.
- Safety instrumented functions remain certified, deterministic, and independent of the AI stack.
Red Line Two: Decisions About People
The second boundary is where bias stops being an abstract concern. Infrastructure firms in the UAE make consequential decisions about very large, very diverse workforces, and about subcontractors whose businesses depend on being selected. Any model that scores a person carries the historical patterns of whoever was hired, promoted, or awarded work before.
This matters more now that automated screening is becoming normal in the wider system. The Ministry of Human Resources and Emiratisation began using AI and robotics to screen work permit applications from May 2026, as reported by Khaleej Times. When automated assessment is running upstream of your hiring, the last thing your own process should do is stack a second unexamined model on top of it.
The red line here is narrower than "do not use AI in HR." It is that no person should receive a materially adverse outcome from a model alone. Sifting a thousand CVs into a shortlist is a legitimate use. Rejecting a candidate, terminating a contract, denying a safety clearance, or removing a subcontractor from a panel on a model score with no human decision maker is not, and Article 18 of the PDPL gives the affected person a legal handle on it. The related exposure is covered in more depth in our guide to the legal risks of AI in UAE infrastructure.
Bias testing should be routine rather than heroic. Take the model's outputs, group them by nationality, age band, and job grade, and look for outcome rates that differ without an operational explanation. If a subcontractor scoring model consistently downgrades firms from one emirate, that is a finding, not a coincidence. The point is not to reach a perfect distribution. It is to have looked, written down what you found, and be able to show it.
Red Line Three: Worker Data and Monitoring
UAE construction and utilities sites already run biometric attendance, camp to site transport logging, GPS on plant, and increasingly wearables and camera analytics. Each of these is defensible individually. Combined into a single model that scores an individual worker's productivity or behaviour continuously, they become something the workforce did not agree to and would not recognise.
The useful distinction is between monitoring a process and monitoring a person. Camera analytics that count how many people on a deck are missing a harness is a safety control. The same camera producing a per worker compliance league table is a performance management system built without anyone deciding to build one. Draw the line at aggregation: state which datasets may be joined to an individual identity, and require an explicit approval to add a new one.
- Name every worker data source feeding an AI system, and who owns each one.
- Define which sources may be linked to a named individual and which must stay aggregated.
- Set a retention period for each source and enforce deletion, not just policy.
- Require written notice to workers in a language they read before any new source is added.
- Prohibit inferred sensitive attributes such as health status, religion, or family circumstance.
Writing the Boundary Register
A boundary policy that lives in a slide deck does not change behaviour. What works is a single register, owned by a named person, that lists every AI system in the business alongside its limits. Six columns are enough: the system and its owner, the decision impact tier borrowed from Dubai's non-significant, significant, and critical classification, the oversight boundary, any red lines that apply, the evidence that the boundary is actually enforced in the system rather than merely written down, and the review date.
That fifth column is the one that separates real governance from documentation. "Human approves" is a claim. "Approval is enforced by a workflow gate in the maintenance system, screenshot attached, tested on 14 August" is evidence. If you cannot produce evidence for a boundary, you do not have that boundary, you have an intention.
Two international frameworks are worth borrowing structure from without adopting wholesale. The NIST AI Risk Management Framework, released in January 2023, organises the work into four functions, Govern, Map, Measure, and Manage, which map neatly onto a register of this kind. ISO/IEC 42001:2023, published in December 2023, specifies requirements for an AI management system and gives you a certifiable structure if a client or lender eventually asks for one. Both are voluntary. Both are more useful as a skeleton than as a compliance target.
Boundaries Belong in Contracts, Not Just Policies
Most AI in UAE infrastructure arrives through a vendor, which means most of your boundaries are things a supplier has to honour. If they only exist in your internal policy, they are unenforceable at the moment they matter.
Four clauses carry most of the weight. Require disclosure of what the model was trained on and whether your operational data will be used to train anything else. Require that model versions be pinned and that material updates be notified in advance, because a silent upgrade can move a system across your own risk tier overnight. Require access to enough logging to reconstruct a decision after an incident. And require the vendor to state, in writing, which decisions their system is not designed to make, which is a question surprisingly few vendors are asked and a revealing one to ask. Our guide to choosing the right AI provider covers the wider evaluation process.
There is also a commercial reason to formalise this. The Dubai AI Seal, launched in January 2025 by the Dubai Centre for Artificial Intelligence, had drawn applications from 325 companies representing 77 international offices by May 2025, and certification is described as a prerequisite for participation in upcoming government led AI initiatives and projects, according to the Dubai Media Office. In a market where much infrastructure work is government linked, demonstrable AI governance is drifting from a virtue toward a qualification requirement.
Boundaries Have to Move
A red line drawn against 2024 capability may be either obsolete or dangerously permissive in 2027. Set a fixed review, twice a year is reasonable, and treat three events as automatic triggers regardless of the calendar: a model or vendor upgrade that changes what the system can do, a near miss or incident involving an AI output, and the publication of the PDPL Executive Regulations or any new sector rule.
Review does not only mean tightening. Some boundaries were set out of unfamiliarity and can safely be relaxed once a system has a track record. Being able to move a line in both directions, with a written reason, is what distinguishes a governance process from a moratorium.
Bringing It Together
The UAE has been deliberate about principles and patient about legislation. The Charter tells you what to protect. The National Cyber Security Policy for AI tells critical infrastructure operators that human oversight of critical decisions is a security requirement, not an optional ethic. The PDPL gives individuals a right to object to purely automated decisions that seriously affect them. Beyond that, the lines are yours to draw, and Dubai's own tool says as much in plain language.
The firms that handle this well are not the ones with the longest policy. They are the ones that can answer three questions on the spot: what will our AI never be allowed to do, how do we know that boundary is actually enforced, and when do we look at it again. If your organisation is still working out its overall position, our practical guide to AI ethics and risk boundaries in UAE infrastructure is the place to start. Then write the short list. Five red lines that hold are worth more than fifty pages that do not.
Research sources used
- UAE Government, The UAE Charter for the Development and Use of Artificial Intelligence, published 2024
- UAE Cyber Security Council, The National Cyber Security Policy for Artificial Intelligence
- CMS, AI Regulation Scanner: United Arab Emirates, updated 17 February 2026
- Latham and Watkins, AI in the UAE: Understanding the Regulatory Landscape and Key Authorities, 30 October 2025
- Digital Dubai, AI System Ethics Self-Assessment Tool
- Smart Dubai, AI Ethics Principles and Guidelines (PDF), January 2019
- OECD.AI, AI Principles and Ethics for the Emirate of Dubai
- DLA Piper, Data Protection Laws of the World: United Arab Emirates (Federal Decree-Law 45/2021), last modified 27 January 2025
- Dubai Media Office, Dubai AI Seal Sets Industry Standard for Trusted AI, 15 May 2025
- EU Artificial Intelligence Act, Annex III: High-Risk AI Systems, Regulation (EU) 2024/1689
- NIST, AI Risk Management Framework (AI 100-1), released 26 January 2023
- IEC Webstore, ISO/IEC 42001:2023 Artificial Intelligence Management System, published 18 December 2023
- Middle East AI News, Middle East CEOs Lead Globally in AI Adoption (PwC 29th Global CEO Survey), January 2026
- Khaleej Times, UAE to Use AI, Robotics to Screen Work Permit Applicants from May