AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Beyond the EU: UK, US, Gulf and Pakistan · Lesson 11 of 17
The UAE, Saudi Arabia and Pakistan
Video lecture
The UAE, Saudi Arabia and Pakistan
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 UAE, KSA, Pakistan
If you work across the Gulf and South Asia, AI governance looks different from Europe. Instead of one big AI law, you'll find ambitious national strategies, ethics charters and guidelines that are mostly voluntary, and binding data protection, cybercrime and media laws that already apply to AI. In this lesson you'll learn the landscape in the UAE, Saudi Arabia and Pakistan as of September twenty twenty-six, and how to run one governance program across all of them.
0:33 Why a regional lesson
Why does this region need its own lesson? Because it's where many of you work, and the style of regulation is different. Instead of a single AI statute, you'll face national strategies with big goals, ethics principles that government clients expect you to follow, and binding data protection, cybercrime and media laws. Rules also differ between onshore and free zones. If you only know the EU model, you'll either over-engineer compliance or miss the laws that actually bite here.
1:07 UAE
Start with the UAE. It appointed the world's first Minister of State for Artificial Intelligence in twenty seventeen and runs the National Strategy for AI twenty thirty-one. In twenty twenty-four it published the UAE Charter for the Development and Use of AI, with twelve principles covering safety, bias, privacy, transparency, human oversight and accountability. The charter isn't binding, but government clients treat it as an expectation. What is binding: the federal Personal Data Protection Law, cybercrime and media laws that cover AI-generated content, and free-zone regimes like the DIFC, whose data rules specifically address autonomous and semi-autonomous systems.
1:50 Analogy: a national sports strategy
An analogy for this region: think of a national sports strategy. The government sets ambitious goals, publishes a code of conduct for fair play, and funds academies. The code of conduct isn't a criminal law, but clubs that ignore it won't get government contracts or sponsorship. Meanwhile, the actual laws, like fraud, safety and privacy, apply to everyone. In the UAE, Saudi Arabia and Pakistan, AI strategies and ethics charters set the direction and expectations, while data protection, cybercrime and media laws are the binding rules.
2:27 Saudi Arabia
Now Saudi Arabia. SDAIA, the Saudi Data and AI Authority, leads policy under Vision twenty thirty. It published AI Ethics Principles in twenty twenty-three: fairness, privacy and security, humanity, social and environmental benefit, reliability and safety, transparency and explainability, and accountability. It followed with Generative AI Guidelines in twenty twenty-four, and guidance on deepfakes emphasizing consent, data protection and safeguards like watermarking. The binding piece is the Personal Data Protection Law, in force since twenty twenty-three with enforcement from September twenty twenty-four, including rules on transferring data outside the Kingdom.
3:06 Pakistan
And Pakistan. The federal cabinet approved a National AI Policy in twenty twenty-five, focused on skills, public-sector adoption, an AI fund, centers of excellence, regulatory sandboxes and ethical data governance, under the IT ministry. It's a policy, not a binding AI law. Pakistan also has no enacted comprehensive data protection law yet. A bill has been drafted and approved by cabinet, but not passed by Parliament. The Prevention of Electronic Crimes Act covers offences like misusing someone's identity information. The practical point: Pakistani agencies serving EU, UK or Gulf clients still need strong data practices, because contracts and foreign laws demand them.
3:50 One program, local layers
How do you run one program across all of this? Use a strictest common baseline that's cheap to follow everywhere, then add local layers. The baseline: an AI inventory with risk classification, AI disclosure for chatbots and voice agents, consent before cloning any voice or likeness, personal data only in approved tools with data processing agreements, and human review of public-interest content. Then layer local rules: EU AI Act tiers, Arabic-language disclosures in the Gulf, US state rules, and each country's data transfer requirements.
4:27 Worked example: Dubai e-commerce
A worked example. A Dubai e-commerce brand launches an Arabic-English AI shopping assistant and AI-generated product videos across the Gulf and Pakistan. The assistant discloses it's AI in both languages in its first message, offers a human, and never takes payment details. Chats are personal data, so the UAE data law applies, Saudi customers trigger the Saudi law and its transfer rules, and the vendor signs a data processing agreement. The videos use fictional presenters, are labeled, and avoid resembling real public figures. Pakistani customers get the same baseline.
5:06 Example 2: Lahore agency, Saudi client
A simpler example. A Lahore agency builds a chatbot for a Saudi client's website. Pakistan has no comprehensive data protection law in force yet, but that doesn't matter much here. The chatbot processes Saudi residents' personal data, so the Saudi law applies, including its rules on transferring data outside the Kingdom. The client's contract will require a data processing agreement and security measures. And SDAIA's guidelines set expectations on transparency. So the agency discloses the AI in Arabic and English, minimizes data, and confirms where the chatbot vendor processes conversations.
5:45 Common mistakes
Three mistakes to watch for. Treating non-binding charters and guidelines as irrelevant, when government clients and regulators use them as the yardstick. Forgetting that free zones like the DIFC and ADGM have their own data regimes that differ from onshore law. And assuming that because Pakistan has no data protection law in force, there are no obligations, when foreign laws and client contracts still apply to the data you handle.
6:15 Language matters
One more practical tip for this region: language. Disclosures, privacy notices and consent requests should be available in the languages your users actually read, often Arabic and English in the Gulf, and Urdu and English in Pakistan. Machine translation is a starting point, but have legal wording reviewed by a fluent speaker. A disclosure nobody understands doesn't really disclose anything, and regulators and government clients notice when Arabic versions are clearly an afterthought.
6:47 Watch me do it: regional rows
Watch me do it. In the jurisdiction register I add rows for our Arabic and English shopping assistant serving the UAE, Saudi Arabia and Pakistan. UAE onshore: the federal Personal Data Protection Law, binding, duties on lawful basis, notice and transfers, source is the official UAE legislation portal, verified today. Saudi Arabia: the PDPL and its implementing regulations, binding, including transfer conditions for data leaving the Kingdom. I add an action: confirm with the chatbot vendor where conversations are stored. Saudi Arabia again: SDAIA's generative AI guidelines, guidance, transparency and human oversight expectations. UAE: the AI Charter, principles, not binding, but our government-sector clients reference it. Pakistan: the National AI Policy, policy, no direct duty, monitor for sandbox and regulation. Pakistan data protection: bill not enacted, so I write no comprehensive law in force, contractual and foreign-law duties apply. Then I add a baseline column: yes for bilingual disclosure, approved tools and consent for any likeness. Local layers go in the notes. One table now shows the whole region.
8:00 Recap and next step
Recap. In the UAE, Saudi Arabia and Pakistan, strategies and ethics guidelines set expectations, while data protection, cybercrime and media laws create binding duties. Free zones can have their own rules. Pakistan has an AI policy but no data protection law yet, and client contracts still demand good practice. Your next step: add a jurisdiction register to your governance pack, using the CSV row format in the lesson text, and record the official source and the date you verified each item.
A different model: strategy-led, guidance-heavy
The UAE, Saudi Arabia and Pakistan share a pattern: ambitious national AI strategies, ethics principles and guidelines that are mostly non-binding, and binding data protection, cybercrime and media laws that already apply to AI use. For businesses, the practical compliance load comes mainly from the binding laws, while the guidelines signal what regulators and government clients expect.
Always verify current status on official government sources. This region moves fast, and free-zone rules (for example DIFC and ADGM in the UAE) can differ from onshore federal law.
United Arab Emirates
- Strategy and institutions: the UAE appointed a Minister of State for Artificial Intelligence in 2017 and runs the UAE National Strategy for Artificial Intelligence 2031.
- UAE Charter for the Development and Use of Artificial Intelligence (2024): a non-binding charter setting out 12 principles, including human-machine relations, safety, algorithmic bias, data privacy, transparency, human oversight, governance and accountability, technological excellence, human commitment, peaceful coexistence with AI, promoting AI awareness and inclusive access, and commitment to treaties and applicable laws.
- Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021): consent and other lawful bases, data subject rights, rights related to automated processing, cross-border transfer rules. Check the status of implementing regulations.
- Free zones: the DIFC Data Protection Law includes specific requirements for processing personal data through autonomous and semi-autonomous systems (Regulation 10), such as notices and, for certain systems, additional safeguards. The ADGM has its own data protection regime.
- Media and content: UAE media law and content standards, plus cybercrime law (Federal Decree-Law No. 34 of 2021 on combating rumors and cybercrimes), apply to AI-generated content, including rules on misinformation and on using people's images without consent.
Saudi Arabia
- SDAIA (Saudi Data and Artificial Intelligence Authority) leads AI and data policy under Vision 2030 and the National Strategy for Data and AI.
- AI Ethics Principles (2023): fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, accountability and responsibility, with a risk-based approach to AI systems.
- Generative AI Guidelines (2024), for government entities and for the public, covering responsible use, transparency, accountability, privacy and risks such as hallucination and deepfakes.
- Deepfakes Guidelines: SDAIA has issued guidance on mitigating deepfake risks, emphasizing consent, personal data protection and safeguards such as watermarking and source verification.
- Personal Data Protection Law (PDPL): in force since September 2023 with enforcement from September 2024, with implementing regulations including on cross-border transfers. It applies to processing of personal data in the Kingdom and of residents' data by entities abroad.
Pakistan
- National Artificial Intelligence Policy 2025, approved by the federal cabinet in 2025, sets goals for skills, public-sector adoption, an AI fund, centers of excellence, regulatory sandboxes and ethical data governance, with institutional structures under the Ministry of IT and Telecommunication. It is a policy, not a binding AI statute.
- Data protection: as of 2026, Pakistan has no enacted comprehensive personal data protection law. A Personal Data Protection Bill has been through multiple drafts and cabinet approval but not passed by Parliament. Businesses should still follow good practice, not least because clients in the EU, UK and Gulf will require it contractually.
- Prevention of Electronic Crimes Act 2016 (PECA), as amended, covers offences relevant to AI misuse, such as unauthorized use of identity information, and harmful online content. Sectoral regulators (for example the State Bank of Pakistan for financial institutions) may issue their own requirements.
Running one program across many jurisdictions
A practical approach for a regional business: adopt the strictest common baseline that is cheap to follow everywhere, then add local layers.
| Baseline control (everywhere) | Local additions |
|---|---|
| AI inventory and risk classification | EU: AI Act tiers and dates |
| AI disclosure for chatbots and voice agents | KSA/UAE: Arabic-language disclosure; US: state-specific rules |
| Consent before cloning any voice or likeness | Tennessee ELVIS, KSA deepfake guidance, UAE image rights |
| Personal data only in approved tools with DPAs | UAE PDPL/DIFC, KSA PDPL, GDPR transfer rules |
| Human review of public-interest content | EU Art. 50(4) exception evidence |
Worked example: a Dubai-based e-commerce brand selling across the GCC and to Pakistan
The brand launches an Arabic-English AI shopping assistant and AI-generated product videos.
- Chatbot: bilingual disclosure in the first message; human handoff; no processing of payment data in prompts.
- Data: customer chats contain personal data; processing under UAE PDPL; KSA customers' data triggers KSA PDPL, including transfer rules if servers sit outside the Kingdom; contractual DPAs with the AI vendor.
- Videos: synthetic presenters are fictional; the brand labels them and avoids resembling real public figures, consistent with SDAIA deepfake guidance and UAE content rules.
- Pakistan customers: no specific data law in force, but the same baseline applies.
Hands-on: a jurisdiction register row
use_case,jurisdiction,instrument,binding,duty_summary,official_source,verified_on,owner
AI shopping assistant,UAE (onshore),Federal PDPL (Decree-Law 45/2021),yes,Lawful basis; notice; rights; transfer rules,uaelegislation.gov.ae,2026-09-20,DPO
AI shopping assistant,KSA,PDPL + implementing regulations,yes,Lawful basis; transfers outside KSA,sdaia.gov.sa,2026-09-20,DPO
AI product videos,KSA,SDAIA Deepfakes Guidelines,no (guidance),Consent; labeling; safeguards,sdaia.gov.sa,2026-09-20,Head of content
AI shopping assistant,UAE,UAE AI Charter,no (principles),Transparency; human oversight,uaelegislation.gov.ae,2026-09-20,AI lead
All,Pakistan,National AI Policy 2025,no (policy),Monitor for sandbox/regulation,moitt.gov.pk,2026-09-20,AI leadPitfalls
- Treating non-binding charters as irrelevant; government clients and regulators use them as expectations.
- Forgetting free-zone regimes differ from onshore law.
- Assuming "no data protection law" in Pakistan means no obligations; contracts and foreign laws still apply.
Key takeaways
- UAE, KSA and Pakistan are strategy-led with mostly non-binding AI guidelines, while data, cybercrime and media laws bind.
- The UAE AI Charter (2024) sets 12 principles; the DIFC has specific rules for autonomous systems processing personal data.
- SDAIA's AI Ethics Principles, GenAI Guidelines and deepfake guidance set expectations; the KSA PDPL is binding, including transfer rules.
- Pakistan's National AI Policy 2025 is policy, not law, and no comprehensive data protection law has been enacted; contracts still require good practice.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Create a jurisdiction register for one AI use case covering every country where your users are. Record instrument, binding or guidance, duty summary, official source and verification date.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.