DIFC
DIFC Regulation 10: What You Must Be Able to Show for AI
While much of the world was still drafting AI rules, the Dubai International Financial Centre quietly enacted its own. In 2023, the DIFC introduced Regulation 10 on Personal Data Processed through Autonomous and Semi-Autonomous Systems, the region's first regulation written specifically for AI that handles personal data.
What makes it worth reading is not that it exists. It is what it asks for. Regulation 10 does not ask whether you have an AI policy. It asks whether you can produce evidence.
Who it applies toRegulation 10 splits responsibility in two. Deployers, the entities under whose authority or for whose benefit the system operates, are treated as controllers. Operators, providers that run or supervise a system on a deployer's direction, are treated as processors. If your organization uses, or supplies, an autonomous or semi-autonomous system that touches personal data in the DIFC, one of those labels is yours.
What it actually requiresThe obligations read like a definition of a defensible system:
Systems must be designed to be "ethical, fair, transparent, secure, and accountable."
Human oversight is not optional. Systems must include algorithms that trigger human intervention for processing that may produce unfair, discriminatory, or unjust outcomes, and human-defined purposes must prevail over purposes the system defines for itself.
Deployers and Operators must maintain and provide a register of system use cases, including necessity, proportionality, and any data sharing.
Organizations must be able to explain the processing in non-technical terms, with appropriate supporting evidence, and data subjects can challenge the outcome.
For high-risk processing, you need either a Commissioner-recognized certification or an appointed Autonomous Systems Officer, with status and competencies similar to a Data Protection Officer.
Read that list againHuman-intervention triggers. A register of what the system did. The ability to explain a decision with supporting evidence. That is not a policy on a shelf. That is a per-decision record, demanded by a regulator, before anyone has complained.
Regulation 10 is what "defensible" looks like when a supervisor writes it into law. A framework does not satisfy it. Only the evidence does, of what the system decided, why, and who could intervene. (We unpack that distinction in What Defensible AI Means in a Regulated Environment.)
The standard we build toNextvise is the infrastructure for Defensible AI. It validates every AI output against the rule that governs it, returns it signed, and keeps the register-grade, explainable record Regulation 10 expects, escalating anything that does not hold to a named human, on the record. It deploys in-region, so the evidence stays where the DIFC can see it.
Regulation 10 asks you to explain the decision with supporting evidence. That is precisely what a Nextvise record is.
― basis: DIFC Data Protection Regulations, Regulation 10, Personal Data Processed through Autonomous and Semi-Autonomous Systems (enacted 2023)
Get Audit-Ready