UAE · Governance · Procurement

Governed AI for the UAE, written the way a tender reads.

Enterprise and government buyers in the UAE do not ask whether a vendor "does AI." They ask which law the system answers to, who can stop it, whether a person signed off, and what happens to the money if it never goes live. This page answers those questions in the order a procurement team asks them — and shows where each answer is evidenced in the system itself rather than in a policy document.

The instruments that apply

Four instruments, by number and date.

A governance claim that does not name its instrument is a marketing claim. These are the ones a UAE AI deployment is judged against, with the dates that matter.

Decree-Law 45/2021UAE Personal Data Protection Law (PDPL). Federal Decree-Law No. (45) of 2021, in force since 2 January 2022. Applies to any controller or processor in the UAE, and to data subjects inside or outside it. Purpose limitation, minimisation, security, subject rights, and conditions on automated decision-making and cross-border transfer — all of which an AI system inherits.
DIFC Reg. 10DIFC Data Protection Regulation 10 — autonomous and semi-autonomous systems. Enacted 1 September 2023; full compliance expected from 1 January 2026. Deployers and operators must adhere to the processing principles, notify users of the technology and purpose, describe capabilities and safeguards, and obtain certification for high-risk use. The first data-protection instrument anywhere written specifically for AI systems.
4 May 2026Dubai’s agentic-AI programme. A two-year move of the private sector to agentic AI through the Dubai Chamber’s business councils, alongside the federal framework requiring agentic AI across 50% of government sectors, services and operations within two years. Expectations named in that context: model inventories, audit trails, kill-switches and data residency. What fills the two years →
21 Aug 2026Assistant AI Government Experience Design Guide. The National Committee for the Agentic AI Project’s unified guide for federal services: understand intent before the procedure, never ask for information already held, act through real systems with approval, follow through to completion, hand off to a human without re-explaining. Success measured by the service completed, not messages exchanged. Translated for the private sector →
The assurance table

What a tender asks for, and where it is evidenced.

Each control below is a property of how the system is built or of the contract it is delivered under. None of them is a policy. That is the difference between a control an assessor can inspect and one an assessor has to take on trust.

Requirement How it is evidenced in a Xamun system Instrument
Data residencyDeployed on the client's own infrastructure, in the region the client chooses. No Xamun-hosted copy of production data. Source code owned by the client.PDPL Art. 22–23 cross-border transfer; DIFC DP Law
Human oversightCustomer- and regulator-facing actions require a named human approval every time; the server refuses an autonomous configuration. Internal autonomy is earned per decision on recorded evidence.DIFC Regulation 10; PDPL Art. 9 automated decisions
Kill-switchA deterministic rules-pack runs first and blocks a run outright on breach — the model is never called. Any agent can be stopped per role, with the stop recorded.DIFC Regulation 10 safeguards
Model inventoryEvery run records the model that drafted prose, the rules-pack and version applied, and whether the knowledge base answered live or from an offline copy.Dubai agentic-AI mandate expectations; ISO/IEC 42001 controls
Audit trailAn append-only run ledger: the calculation, the rules applied with instrument, article and effective date, what was decided, who approved. Judged by the law in force on the date of the event.PDPL accountability; DIFC Regulation 10 transparency
Determinism on regulated decisionsA deterministic engine has the final say over anything touching money, entitlement or compliance. The model is shown the names of figures, never their values; a figure it invents fails the run.Two Minds architecture — see /two-minds
Data minimisation in the generative pathNo free-text prompt from a person reaches the model; a guard test fails the build if one does. Personal data stays in the deterministic layer.PDPL Art. 5 minimisation; DIFC Regulation 10 notice
Delivery commitmentThirty days from approved specification to a live operation. Not met: nothing owed under usage; final licence tranche never paid. Three years of changes until it fits, unbilled.Contract — see /outcomes-as-a-service

Why the model cannot alter the ledger — the Two Minds architecture →

The distinction that decides a tender

A policy says what should happen. A control is what cannot happen.

Most AI governance submissions are policies: a responsible-AI statement, an ethics board, a review cadence. An assessor cannot inspect a policy; they can only take it on trust. A control is different in kind. If the language model is architecturally unable to see a figure’s value, it cannot alter the ledger — not because a policy forbids it, but because the path does not exist. If a customer-facing action cannot be configured as autonomous because the server refuses it, human oversight is not a commitment; it is a property. The assurance table above is written entirely in that second register, and every row in it produces a record an assessor can read.

The deterministic mind — code

Loads the data. Computes every figure. Resolves the rules in force on the date being judged. Decides whether the run may proceed at all. If a rule blocks, the model is never called.

The model — prose only

Shown the names of the figures, never their values. Every number it writes is substituted from the calculation; a figure it invents fails the run. No free-text prompt from a person ever reaches it.

Questions

What a procurement team actually asks.

What does DIFC Regulation 10 require of an AI system?

Regulation 10 of the DIFC Data Protection Regulations, enacted 1 September 2023 with full compliance expected from 1 January 2026, governs the processing of personal data by autonomous and semi-autonomous systems. Deployers and operators must adhere to the data-processing principles, notify users clearly about the technology and the purposes of processing, describe the system's capabilities and safeguards, and — for high-risk use — obtain certification demonstrating governance, transparency and accountability. In a Xamun system those properties are structural: every run records which rules applied, the model never has the final say over a regulated decision, and customer- or regulator-facing actions require a named human approval.

Does the UAE Personal Data Protection Law apply to an AI system?

Yes. Federal Decree-Law No. 45 of 2021, in force since 2 January 2022, applies to any controller or processor in the UAE processing personal data, and to the data of subjects inside or outside the UAE. It sets purpose limitation, minimisation, security and subject-rights obligations that an AI system inherits. Xamun systems are deployed on the client's own infrastructure in the region the client chooses, the language model is shown the names of figures rather than their values, and no free-text prompt from a person reaches the model — which keeps personal data out of the generative path by design.

How is human oversight evidenced rather than promised?

Anything customer-facing or regulator-facing is approved by a named person every time and cannot be made autonomous — the server refuses the configuration. Autonomy on internal steps is earned per decision on recorded evidence, not granted by default. Each approval and each refusal is a row in the run ledger with the person, the rule and the timestamp, so oversight is a record an auditor can read rather than a policy an auditor has to trust.

What is a kill-switch in practice?

Two mechanisms. A deterministic rules-pack runs first on every job and blocks the run outright when a rule is breached — the model is never called. And any agent can be stopped per role, with the stop recorded. Because every figure is computed by code and every rule resolves from a versioned, effective-dated pack, halting a run leaves a complete record of what was and was not done, which is the property a regulator asks for after the fact.

Can the language model change the ledger, an entitlement or the audit trail?

No, by architecture. In Xamun's Two Minds design a deterministic mind holds the rules, entitlements, calculations, compliance logic and audit trail; it runs first and has the final say. The model handles language, extraction, drafting and explanation and is shown the names of figures, never their values; a number it invents fails the run. Generation is placed where it helps and structurally excluded from where it cannot be allowed.

What are the contractual terms a procurement team can rely on?

A go-live gate of thirty days from approved specification to an operation running end to end; if it is not met, nothing is owed under usage pricing and the final licence tranche is never paid. Source code and deployment on the client's own infrastructure. No rate card and no billable change requests. And a three-year commitment to keep changing the system until it fits the operation, without distinguishing a bug from a change. These are the terms of the engagement, not a service-level aspiration.

Does Xamun hold ISO 42001 or a similar certification?

Where a tender requires a named certification, ask us directly and we will answer specifically for that tender. What this page describes is what is evidenced regardless of certificate: the controls are properties of the system's architecture and of the contract, recorded in the run ledger, and available for an assessor to inspect.

Dubai · DIFC

Bring the tender. We will answer it row by row.

Send us the assurance schedule from a live procurement and we will return it with each requirement mapped to the control that evidences it — and the rows where the honest answer is “not yet.”