AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Beyond the EU: UK, US, Gulf and Pakistan · Lesson 11 of 17

The UAE, Saudi Arabia and Pakistan

Article · 14 min · 8 min lecture

Video lecture

The UAE, Saudi Arabia and Pakistan

13 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 13

UAE, KSA, Pakistan

  • Strategy-led, guidance-heavy
  • Binding data, cyber and media laws
  • One program, local layers

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

A different model: strategy-led, guidance-heavy

The UAE, Saudi Arabia and Pakistan share a pattern: ambitious national AI strategies, ethics principles and guidelines that are mostly non-binding, and binding data protection, cybercrime and media laws that already apply to AI use. For businesses, the practical compliance load comes mainly from the binding laws, while the guidelines signal what regulators and government clients expect.

Always verify current status on official government sources. This region moves fast, and free-zone rules (for example DIFC and ADGM in the UAE) can differ from onshore federal law.

United Arab Emirates

  • Strategy and institutions: the UAE appointed a Minister of State for Artificial Intelligence in 2017 and runs the UAE National Strategy for Artificial Intelligence 2031.
  • UAE Charter for the Development and Use of Artificial Intelligence (2024): a non-binding charter setting out 12 principles, including human-machine relations, safety, algorithmic bias, data privacy, transparency, human oversight, governance and accountability, technological excellence, human commitment, peaceful coexistence with AI, promoting AI awareness and inclusive access, and commitment to treaties and applicable laws.
  • Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021): consent and other lawful bases, data subject rights, rights related to automated processing, cross-border transfer rules. Check the status of implementing regulations.
  • Free zones: the DIFC Data Protection Law includes specific requirements for processing personal data through autonomous and semi-autonomous systems (Regulation 10), such as notices and, for certain systems, additional safeguards. The ADGM has its own data protection regime.
  • Media and content: UAE media law and content standards, plus cybercrime law (Federal Decree-Law No. 34 of 2021 on combating rumors and cybercrimes), apply to AI-generated content, including rules on misinformation and on using people's images without consent.

Saudi Arabia

  • SDAIA (Saudi Data and Artificial Intelligence Authority) leads AI and data policy under Vision 2030 and the National Strategy for Data and AI.
  • AI Ethics Principles (2023): fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, accountability and responsibility, with a risk-based approach to AI systems.
  • Generative AI Guidelines (2024), for government entities and for the public, covering responsible use, transparency, accountability, privacy and risks such as hallucination and deepfakes.
  • Deepfakes Guidelines: SDAIA has issued guidance on mitigating deepfake risks, emphasizing consent, personal data protection and safeguards such as watermarking and source verification.
  • Personal Data Protection Law (PDPL): in force since September 2023 with enforcement from September 2024, with implementing regulations including on cross-border transfers. It applies to processing of personal data in the Kingdom and of residents' data by entities abroad.

Pakistan

  • National Artificial Intelligence Policy 2025, approved by the federal cabinet in 2025, sets goals for skills, public-sector adoption, an AI fund, centers of excellence, regulatory sandboxes and ethical data governance, with institutional structures under the Ministry of IT and Telecommunication. It is a policy, not a binding AI statute.
  • Data protection: as of 2026, Pakistan has no enacted comprehensive personal data protection law. A Personal Data Protection Bill has been through multiple drafts and cabinet approval but not passed by Parliament. Businesses should still follow good practice, not least because clients in the EU, UK and Gulf will require it contractually.
  • Prevention of Electronic Crimes Act 2016 (PECA), as amended, covers offences relevant to AI misuse, such as unauthorized use of identity information, and harmful online content. Sectoral regulators (for example the State Bank of Pakistan for financial institutions) may issue their own requirements.

Running one program across many jurisdictions

A practical approach for a regional business: adopt the strictest common baseline that is cheap to follow everywhere, then add local layers.

Baseline control (everywhere)Local additions
AI inventory and risk classificationEU: AI Act tiers and dates
AI disclosure for chatbots and voice agentsKSA/UAE: Arabic-language disclosure; US: state-specific rules
Consent before cloning any voice or likenessTennessee ELVIS, KSA deepfake guidance, UAE image rights
Personal data only in approved tools with DPAsUAE PDPL/DIFC, KSA PDPL, GDPR transfer rules
Human review of public-interest contentEU Art. 50(4) exception evidence

Worked example: a Dubai-based e-commerce brand selling across the GCC and to Pakistan

The brand launches an Arabic-English AI shopping assistant and AI-generated product videos.

  • Chatbot: bilingual disclosure in the first message; human handoff; no processing of payment data in prompts.
  • Data: customer chats contain personal data; processing under UAE PDPL; KSA customers' data triggers KSA PDPL, including transfer rules if servers sit outside the Kingdom; contractual DPAs with the AI vendor.
  • Videos: synthetic presenters are fictional; the brand labels them and avoids resembling real public figures, consistent with SDAIA deepfake guidance and UAE content rules.
  • Pakistan customers: no specific data law in force, but the same baseline applies.

Hands-on: a jurisdiction register row

use_case,jurisdiction,instrument,binding,duty_summary,official_source,verified_on,owner
AI shopping assistant,UAE (onshore),Federal PDPL (Decree-Law 45/2021),yes,Lawful basis; notice; rights; transfer rules,uaelegislation.gov.ae,2026-09-20,DPO
AI shopping assistant,KSA,PDPL + implementing regulations,yes,Lawful basis; transfers outside KSA,sdaia.gov.sa,2026-09-20,DPO
AI product videos,KSA,SDAIA Deepfakes Guidelines,no (guidance),Consent; labeling; safeguards,sdaia.gov.sa,2026-09-20,Head of content
AI shopping assistant,UAE,UAE AI Charter,no (principles),Transparency; human oversight,uaelegislation.gov.ae,2026-09-20,AI lead
All,Pakistan,National AI Policy 2025,no (policy),Monitor for sandbox/regulation,moitt.gov.pk,2026-09-20,AI lead

Pitfalls

  • Treating non-binding charters as irrelevant; government clients and regulators use them as expectations.
  • Forgetting free-zone regimes differ from onshore law.
  • Assuming "no data protection law" in Pakistan means no obligations; contracts and foreign laws still apply.

Key takeaways

  • UAE, KSA and Pakistan are strategy-led with mostly non-binding AI guidelines, while data, cybercrime and media laws bind.
  • The UAE AI Charter (2024) sets 12 principles; the DIFC has specific rules for autonomous systems processing personal data.
  • SDAIA's AI Ethics Principles, GenAI Guidelines and deepfake guidance set expectations; the KSA PDPL is binding, including transfer rules.
  • Pakistan's National AI Policy 2025 is policy, not law, and no comprehensive data protection law has been enacted; contracts still require good practice.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Which Saudi instrument is legally binding for processing customers' personal data?
  2. A Karachi agency processes EU customers' data for a German client. Pakistan has no enacted data protection law. What follows?
  3. Why might an agency in Dubai's DIFC face different AI-related data rules from one onshore in Dubai?

Put it into practice

Create a jurisdiction register for one AI use case covering every country where your users are. Record instrument, binding or guidance, duty summary, official source and verification date.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.