United Arab Emirates - AI Adoption Guidelines

AI Adoption Guideline in Government Services (UAE AI Office)

United Arab Emirates

RAI-AE-NA-AAGSUXX-2023
Effective: 1 Mar 2023
In Force(In Force)As published at ai.gov.ae

United Arab Emirates - AI Adoption Guidelines is In Force in United Arab Emirates, according to u.ae. We have not yet been able to confirm the status.

GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The AI Adoption Guideline in Government Services (2023) published by the UAE Artificial Intelligence Office provides non‑binding, practical guidance for federal and local government entities on safe, ethical, and effective AI adoption. It sets out governance structures, maturity assessment, risk management, documentation, and implementation steps to accelerate AI deployment while protecting privacy, rights and security.

Summary

The AI Adoption Guideline in Government Services (2023), produced by the UAE Artificial Intelligence Office (the AI Office) and published as part of the UAE government’s suite of AI publications, is a practical framework intended to guide federal and local government entities in adopting AI technologies in public services. The Guideline is non‑binding in nature but is positioned as an authoritative repository of best practices, maturity models, use cases and operational advice to achieve the UAE’s ambition to become an AI-native government.

The Guideline frames AI adoption as a strategic, multi-dimensional transformation that requires: a clear vision and executive sponsorship; governance and institutional coordination; robust data management; risk and impact assessment; human oversight and ethical safeguards; model testing, validation and monitoring; cybersecurity and model security; procurement practices; and capacity building. The document encourages entities to adopt a staged maturity model (from Explorer to Transformer) across dimensions such as strategy, data, technology infrastructure, people and governance. It emphasizes early risk identification (including privacy, fairness, explainability, safety and cybersecurity), and mandates proportionate mitigations particularly for applications with high potential impact on individuals or communities (for example, systems used in law enforcement, immigration, healthcare, benefits allocation or critical infrastructure).

Operationally the Guideline recommends concrete steps: conduct AI maturity assessments and inventory of use cases; perform Data Protection Impact Assessments (DPIAs) and algorithmic risk assessments; document data provenance, features and training/validation procedures; retain human oversight and decision review where appropriate; adopt testing and evaluation plans (including bias and safety testing); implement incident response and model monitoring processes; follow secure procurement and vendor due-diligence for third-party models; and deliver training and change management for staff and users. It also encourages alignment with the AI Ethics Guide and sectoral laws (e.g., data protection), and suggests tools such as maturity self-assessments and templates for model cards and algorithmic impact assessments.

Although the Guideline is advisory rather than prescriptive, it is intended to be used by government program leads, IT and data teams, procurement officers and legal/compliance staff to reduce implementation risk and accelerate trusted AI adoption. The AI Office acts as a central coordinator — providing publications, templates and a knowledge repository — and works alongside other federal regulators (such as the Telecommunications and Digital Government Regulatory Authority) and sector ministries to ensure interoperability with existing laws and policies. The Guideline is part of a suite of UAE AI resources (including the AI Ethics Guide, the Generative AI Guide, the Deepfake Guide and sector-specific guidance) and is explicitly designed to align UAE practice with international best practice while reflecting local priorities and cultural values.

Full article

Read full text ↗

Overview

The "AI Adoption Guideline in Government Services" is a practical framework published by the UAE Artificial Intelligence Office to support federal and local government entities in responsibly adopting artificial intelligence across public services. The Guideline consolidates a maturity model, governance recommendations, risk and impact assessment templates, and operational controls to accelerate AI deployment while safeguarding privacy, safety and public trust. It forms part of the AI Office's publication series together with the AI Office Publications and the UAE government AI resources portal (AI resources — u.ae), and is intended for policy‑makers, program managers, procurement teams and technical implementers seeking a unified approach to AI in government.

Definitions

The Guideline defines key terms in plain language to support cross-disciplinary adoption. Core definitions include: "AI system" — a software or machine-based system that uses data-driven models to perform tasks and that may iteratively improve; "human oversight" — governance, review and decision-making mechanisms ensuring final authority rests with designated humans; "model card" — standardized documentation summarizing model purpose, training data characteristics, limitations and performance; and "algorithmic impact assessment" (AIA) — a structured assessment of potential harms, distributional effects and mitigation measures. The definitions are designed to be technology‑neutral and to map to relevant terms used in the AI Ethics Guide and other UAE guidance.

Governance and Institutional Framework

The Guideline recommends a layered governance approach combining entity-level bodies and central coordination. At the organizational level, recommended bodies include an Executive Sponsor, an AI Steering Committee, a Data Governance Board, and a Technical Review Panel to oversee design, procurement and operation. The AI Office is designated as the national coordinating entity that publishes tools, templates and maturity assessments and which facilitates cross-entity knowledge sharing via the AI Office publications page. The guidance emphasizes clear roles and responsibilities (policy owners, data stewards, model owners, system operators) and suggests integration with existing procurement, security, legal and privacy functions. It further recommends establishing escalation pathways for high-risk deployments and appointing a single accountable official for each AI project to ensure traceability and rapid remedial action where needed.

Key Focus Areas

The Guideline structures practical adoption around a small set of focus areas. First, Strategy & Maturity: entities should set a measurable AI strategy, assess current capabilities using the AI maturity self-assessment and prioritize high-value use cases. Second, Data Governance: secure, accessible and high-quality data pipelines are required along with metadata, provenance records and retention policies. Third, Risk Management: perform algorithmic impact assessments and privacy risk assessments proportional to potential harm, with particular scrutiny for systems affecting fundamental rights or safety. Fourth, Human Oversight & Explainability: ensure human-in-the-loop or human-on-the-loop controls, provide explanations suitable for affected stakeholders and maintain clear operational boundaries for automated actions. Fifth, Testing & Validation: require pre-deployment testing for accuracy, robustness, bias, adversarial resilience and safety, and establish continuous monitoring. Sixth, Procurement & Vendor Management: include contractual clauses for transparency, audit rights, model updates, security obligations and incident reporting when engaging third-party or commercial-off-the-shelf AI. Seventh, Security & Resilience: secure model weights, training data and inference endpoints; assess supply chain risks and adopt secure development lifecycle practices. Eighth, Accountability & Documentation: document data sets, model training and validation artifacts, change history and decision logs — enabling audits and audits by oversight authorities. Ninth, Capacity & Change Management: invest in staff training, citizen awareness and user support. Finally, Legal & Ethical Alignment: ensure alignment with the AI Ethics Guide, national data protection laws and sectoral rules to protect privacy and fundamental rights.

Implementation Framework

The Guideline provides a step-by-step implementation path. It begins with scoping and use case prioritization, then requires a baseline maturity assessment and an initial risk screening. For prioritized projects, entities are instructed to perform a detailed algorithmic impact assessment and Data Protection Impact Assessment where personal data is involved. Design and procurement phases should include model cards, testing plans and contractual safeguards. Prior to deployment, entities must complete an acceptance test, certify model performance and secure approval from a governance body. Live operation requires telemetry and continuous monitoring, periodic revalidation, and clear rollback procedures. The AI Office provides templates and self-assessment tools to standardize these steps and recommends phased rollouts and pilot programs to ensure learnings are captured and scaled across the government estate.

Monitoring and Evaluation

Monitoring is framed as continuous, proportionate and evidence-driven. The Guideline recommends instrumentation at inference time (logging inputs, outputs and key metrics), ongoing evaluations for performance drift, fairness audits, and scheduled re-training or decommissioning triggers. Entities are advised to maintain dashboards for operational KPIs (accuracy, latency, complaint volumes, bias indicators) and to report aggregated adoption metrics to central coordinating bodies. The AI Office encourages periodic independent audits, randomized testing, and participation in inter‑governmental exercises to evaluate resilience to adversarial inputs and emergent safety concerns.

Penalties, Liability, and Appeals

The Guideline itself is advisory and does not prescribe criminal sanctions; however it situates liability and redress within existing UAE legal frameworks and sectoral laws. It recommends contractual and administrative remedies for non-compliance (suspension of deployments, mandatory remediation plans, withholding of approvals) and suggests entities define clear user complaint and appeals procedures for individuals affected by automated decisions. The document notes that where harm arises from negligent or unlawful use of AI, existing civil and administrative remedies may apply and that entities must cooperate with investigations by relevant regulators including the AI Office and sectoral authorities.

Relationship to Other Instruments

The Guideline is designed to be used alongside the UAE AI Ethics Guide, the Deepfake Guide and sectoral policies and aligns with the UAE National Strategy for Artificial Intelligence. It references data protection and cybersecurity instruments, and urges entities to reconcile the Guideline’s operational recommendations with sector-specific legal obligations. Where conflicts arise, entities are instructed to seek legal advice and coordinate with the AI Office and relevant regulators to ensure coherent application across systems and sectors.

International Alignment

The Guideline references international best practices and encourages alignment with global standards (including model documentation, testing frameworks and algorithmic impact assessments) to facilitate interoperability and cross-border cooperation. It positions the UAE approach as pragmatic and pro-innovation, aiming to harmonize local policies with norms from multilateral and leading national initiatives while maintaining cultural and legal particularities of the UAE context.

Implementation Timeline

PhaseMilestoneTarget
Phase 0Baseline maturity assessment & use case inventory0–3 months
Phase 1Pilot projects & risk assessments completed3–9 months
Phase 2Controlled deployments & monitoring infrastructure9–18 months
Phase 3Scale-up, audits & cross-entity learning18–36 months

Sources and References

SourceType
AI Office Publications — AI Adoption Guideline in Government Services (AI Office)Primary Source
AI resources — Official Portal of the UAE GovernmentPrimary Source

Requirements for a company

What an organisation has to do under United Arab Emirates - AI Adoption Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Establish executive sponsorship and a layered governance framework for AI adoption.Federal and local government entities adopting AI.
  • Assess current AI capabilities using the AI maturity self-assessment tool.Federal and local government entities adopting AI.
  • Perform algorithmic impact assessments and Data Protection Impact Assessments where personal data is involved.Federal and local government entities deploying AI systems.
  • Ensure human-in-the-loop or human-on-the-loop controls and provide suitable explanations for affected stakeholders.Federal and local government entities deploying AI systems.
  • Require pre-deployment testing for accuracy, bias, and safety, and establish continuous monitoring.Federal and local government entities deploying AI systems.
  • Document data sets, model training, validation artifacts, change history, and decision logs, including model cards.Federal and local government entities deploying AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Invest in staff training, citizen awareness, and user support for AI systems.Federal and local government entities adopting AI.

Should not do

0

Nothing in this category.

Who must do what

The obligations under United Arab Emirates - AI Adoption Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Federal and local government entities adopting AI.Establish executive sponsorship and a layered governance framework for AI adoption.
“The Guideline recommends a layered governance approach combining entity-level bodies and central coordination.”
—Governance and Institutional FrameworkImportant
2Federal and local government entities adopting AI.Assess current AI capabilities using the AI maturity self-assessment tool.
“entities should... assess current capabilities using the AI maturity self-assessment.”
Within 3 months of guideline adoptionKey Focus Areas: Strategy & MaturityImportant
3Federal and local government entities deploying AI systems.Perform algorithmic impact assessments and Data Protection Impact Assessments where personal data is involved.
“perform algorithmic impact assessments and privacy risk assessments proportional to potential harm”
Before deployment for prioritized projectsKey Focus Areas: Risk ManagementImportant
4Federal and local government entities deploying AI systems.Ensure human-in-the-loop or human-on-the-loop controls and provide suitable explanations for affected stakeholders.
“ensure human-in-the-loop or human-on-the-loop controls, provide explanations suitable for affected stakeholders”
Before deploymentKey Focus Areas: Human Oversight & ExplainabilityImportant
5Federal and local government entities deploying AI systems.Require pre-deployment testing for accuracy, bias, and safety, and establish continuous monitoring.
“require pre-deployment testing for accuracy, robustness, bias, adversarial resilience and safety, and establish continuous monitoring.”
Before deploymentKey Focus Areas: Testing & ValidationImportant
6Federal and local government entities deploying AI systems.Document data sets, model training, validation artifacts, change history, and decision logs, including model cards.
“document data sets, model training and validation artifacts, change history and decision logs”
Before deploymentKey Focus Areas: Accountability & DocumentationImportant
7Federal and local government entities deploying AI systems.Secure model weights, training data, and inference endpoints, and assess AI supply chain risks.
“secure model weights, training data and inference endpoints; assess supply chain risks”
Before deploymentKey Focus Areas: Security & ResilienceImportant
8Federal and local government entities deploying AI systems.Define clear user complaint and appeals procedures for individuals affected by automated decisions.
“suggests entities define clear user complaint and appeals procedures for individuals affected by automated decisions.”
Before deploymentPenalties, Liability, and AppealsImportant
9Federal and local government entities procuring AI systems.Include contractual clauses for transparency, audit rights, and security when procuring third-party AI.
“include contractual clauses for transparency, audit rights, model updates, security obligations and incident reporting”
During procurement phaseKey Focus Areas: Procurement & Vendor ManagementImportant
10Federal and local government entities deploying AI systems.Certify model performance and secure approval from a governance body prior to deployment.
“Prior to deployment, entities must complete an acceptance test, certify model performance and secure approval from a governance body.”
Prior to deploymentImplementation FrameworkImportant
11Federal and local government entities operating AI systems.Perform periodic revalidation of AI systems and establish clear rollback procedures for live operations.
“Live operation requires telemetry and continuous monitoring, periodic revalidation, and clear rollback procedures.”
During live operationImplementation FrameworkImportant
12Federal and local government entities deploying AI systems.Ensure alignment with the UAE AI Ethics Guide, national data protection laws, and sectoral rules.
“ensure alignment with the AI Ethics Guide, national data protection laws and sectoral rules to protect privacy and fundamental rights.”
Before deployment and continuouslyKey Focus Areas: Legal & Ethical AlignmentImportant
13Federal and local government entities adopting AI.Invest in staff training, citizen awareness, and user support for AI systems.
“invest in staff training, citizen awareness and user support.”
—Key Focus Areas: Capacity & Change ManagementRecommended

© Regulations.AI · updated on 20 Sep 2026