Governed AI for the UAE, written the way a tender reads.
Enterprise and government buyers in the UAE do not ask whether a vendor "does AI." They ask which law the system answers to, who can stop it, whether a person signed off, and what happens to the money if it never goes live. This page answers those questions in the order a procurement team asks them — and shows where each answer is evidenced in the system itself rather than in a policy document.
Four instruments, by number and date.
A governance claim that does not name its instrument is a marketing claim. These are the ones a UAE AI deployment is judged against, with the dates that matter.
What a tender asks for, and where it is evidenced.
Each control below is a property of how the system is built or of the contract it is delivered under. None of them is a policy. That is the difference between a control an assessor can inspect and one an assessor has to take on trust.
| Requirement | How it is evidenced in a Xamun system | Instrument |
|---|---|---|
| Data residency | Deployed on the client's own infrastructure, in the region the client chooses. No Xamun-hosted copy of production data. Source code owned by the client. | PDPL Art. 22–23 cross-border transfer; DIFC DP Law |
| Human oversight | Customer- and regulator-facing actions require a named human approval every time; the server refuses an autonomous configuration. Internal autonomy is earned per decision on recorded evidence. | DIFC Regulation 10; PDPL Art. 9 automated decisions |
| Kill-switch | A deterministic rules-pack runs first and blocks a run outright on breach — the model is never called. Any agent can be stopped per role, with the stop recorded. | DIFC Regulation 10 safeguards |
| Model inventory | Every run records the model that drafted prose, the rules-pack and version applied, and whether the knowledge base answered live or from an offline copy. | Dubai agentic-AI mandate expectations; ISO/IEC 42001 controls |
| Audit trail | An append-only run ledger: the calculation, the rules applied with instrument, article and effective date, what was decided, who approved. Judged by the law in force on the date of the event. | PDPL accountability; DIFC Regulation 10 transparency |
| Determinism on regulated decisions | A deterministic engine has the final say over anything touching money, entitlement or compliance. The model is shown the names of figures, never their values; a figure it invents fails the run. | Two Minds architecture — see /two-minds |
| Data minimisation in the generative path | No free-text prompt from a person reaches the model; a guard test fails the build if one does. Personal data stays in the deterministic layer. | PDPL Art. 5 minimisation; DIFC Regulation 10 notice |
| Delivery commitment | Thirty days from approved specification to a live operation. Not met: nothing owed under usage; final licence tranche never paid. Three years of changes until it fits, unbilled. | Contract — see /outcomes-as-a-service |
Why the model cannot alter the ledger — the Two Minds architecture →
A policy says what should happen. A control is what cannot happen.
Most AI governance submissions are policies: a responsible-AI statement, an ethics board, a review cadence. An assessor cannot inspect a policy; they can only take it on trust. A control is different in kind. If the language model is architecturally unable to see a figure’s value, it cannot alter the ledger — not because a policy forbids it, but because the path does not exist. If a customer-facing action cannot be configured as autonomous because the server refuses it, human oversight is not a commitment; it is a property. The assurance table above is written entirely in that second register, and every row in it produces a record an assessor can read.
Loads the data. Computes every figure. Resolves the rules in force on the date being judged. Decides whether the run may proceed at all. If a rule blocks, the model is never called.
Shown the names of the figures, never their values. Every number it writes is substituted from the calculation; a figure it invents fails the run. No free-text prompt from a person ever reaches it.
What a procurement team actually asks.
What does DIFC Regulation 10 require of an AI system?
Regulation 10 of the DIFC Data Protection Regulations, enacted 1 September 2023 with full compliance expected from 1 January 2026, governs the processing of personal data by autonomous and semi-autonomous systems. Deployers and operators must adhere to the data-processing principles, notify users clearly about the technology and the purposes of processing, describe the system's capabilities and safeguards, and — for high-risk use — obtain certification demonstrating governance, transparency and accountability. In a Xamun system those properties are structural: every run records which rules applied, the model never has the final say over a regulated decision, and customer- or regulator-facing actions require a named human approval.
Does the UAE Personal Data Protection Law apply to an AI system?
Yes. Federal Decree-Law No. 45 of 2021, in force since 2 January 2022, applies to any controller or processor in the UAE processing personal data, and to the data of subjects inside or outside the UAE. It sets purpose limitation, minimisation, security and subject-rights obligations that an AI system inherits. Xamun systems are deployed on the client's own infrastructure in the region the client chooses, the language model is shown the names of figures rather than their values, and no free-text prompt from a person reaches the model — which keeps personal data out of the generative path by design.
How is human oversight evidenced rather than promised?
Anything customer-facing or regulator-facing is approved by a named person every time and cannot be made autonomous — the server refuses the configuration. Autonomy on internal steps is earned per decision on recorded evidence, not granted by default. Each approval and each refusal is a row in the run ledger with the person, the rule and the timestamp, so oversight is a record an auditor can read rather than a policy an auditor has to trust.
What is a kill-switch in practice?
Two mechanisms. A deterministic rules-pack runs first on every job and blocks the run outright when a rule is breached — the model is never called. And any agent can be stopped per role, with the stop recorded. Because every figure is computed by code and every rule resolves from a versioned, effective-dated pack, halting a run leaves a complete record of what was and was not done, which is the property a regulator asks for after the fact.
Can the language model change the ledger, an entitlement or the audit trail?
No, by architecture. In Xamun's Two Minds design a deterministic mind holds the rules, entitlements, calculations, compliance logic and audit trail; it runs first and has the final say. The model handles language, extraction, drafting and explanation and is shown the names of figures, never their values; a number it invents fails the run. Generation is placed where it helps and structurally excluded from where it cannot be allowed.
What are the contractual terms a procurement team can rely on?
A go-live gate of thirty days from approved specification to an operation running end to end; if it is not met, nothing is owed under usage pricing and the final licence tranche is never paid. Source code and deployment on the client's own infrastructure. No rate card and no billable change requests. And a three-year commitment to keep changing the system until it fits the operation, without distinguishing a bug from a change. These are the terms of the engagement, not a service-level aspiration.
Does Xamun hold ISO 42001 or a similar certification?
Where a tender requires a named certification, ask us directly and we will answer specifically for that tender. What this page describes is what is evidenced regardless of certificate: the controls are properties of the system's architecture and of the contract, recorded in the run ledger, and available for an assessor to inspect.
Bring the tender. We will answer it row by row.
Send us the assurance schedule from a live procurement and we will return it with each requirement mapped to the control that evidences it — and the rows where the honest answer is “not yet.”
