The Signal & The Noise · Vol. 03
Dubai's financial centre has required a named human being to answer for high-risk AI since late 2023. Almost nobody has filled the seat, and most architectures could not give that person anything to work with.
There is a question I have started asking in executive conversations across the region, and I ask it gently, because it is not a trick. If one of your AI systems makes a decision about a person, and that person objects, whose name is on it?
What usually follows is not defensiveness. It is a pause, and then an honest admission that it has not come up yet. The system is new, the results look good, the pilot went well, and nobody has been forced to answer for it in front of someone it affected. That is not carelessness. It is simply the order in which these things tend to happen: capability first, accountability later, usually under pressure.
In the Dubai International Financial Centre, that order has been reversed since late 2023. Most of the leaders I speak to are unaware of it.
Regulation 10 of the DIFC Data Protection Regulations does something most AI regulation carefully avoids. It does not only describe what a system may and may not do. It requires that a human being be placed in a specific seat.
Where personal data is processed through autonomous or semi-autonomous systems at high risk, the organisation deploying the system is treated as the controller, the party operating it is treated as the processor, and one of two things must be true. Either the Commissioner has established certification requirements that apply, or an Autonomous Systems Officer must be appointed, with, in the language of the regulation itself, substantially similar status, competencies and tasks to a Data Protection Officer.
Not a committee. Not a policy document. An officer, with standing, competence and named responsibility.
On 18 June this year the DIFC opened a thirty-day consultation on amendments to those regulations, and it closed on 18 July. Consultation Paper No. 3 of 2026 proposes greater clarity on certification requirements and on the role of that officer, and introduces a new Regulation 11 empowering the Commissioner to recognise accreditation and certification frameworks. Jacques Visser, Chief Legal Officer at DIFC Authority, put it plainly when it opened:
As the use of AI and data-driven systems continues to develop, it is important that the regulatory framework remains practical, clear and able to respond to the way these technologies are being used.
Four days before that consultation opened, the UAE announced a Federal Authority for Artificial Intelligence and Data, consolidating AI oversight, digital government and data regulation under a single body reporting directly to the Cabinet.
Read those two developments next to each other and the direction is not subtle. The period in which AI governance could remain a document is ending here, and it is ending earlier than in most of the world.
Meanwhile, almost every conversation about AI in the region is about agents. What they can do, how autonomous they will become, which vendor has the better orchestration layer, how many processes can be handed over and how soon.
Those are real questions, and I enjoy them. They are simply not the hard ones. The hard one is older and far less exciting: when this thing acts, who answers for it, and with what evidence?
Here is where it becomes uncomfortable, and it is uncomfortable in two directions at once.
The first is that the seat is largely empty. In the conversations I have across this region I almost never meet an Autonomous Systems Officer, and I rarely meet an organisation that has decided who theirs would be. The rule has been on the books for well over two years. That is not resistance. The role sits awkwardly between legal, data, technology and risk, and belongs comfortably to none of them, so it quietly belongs to nobody.
The second is harder. Suppose you appoint someone tomorrow. Suppose you find a capable person, give them real standing and a mandate, and put their name on the register.
Can your architecture give them anything to work with?
Because Regulation 10 does not only ask for a person. It asks the organisation to maintain registers of processing activities, to produce evidence of audit and certification compliance, and to implement mechanisms that trigger human intervention where there is unfair impact, discriminatory bias or unlawful processing.
That last requirement is not a policy commitment. It is an architectural one, written into regulation. A system cannot trigger human intervention on unfair impact unless something in its design is capable of recognising unfair impact, and unless the knowledge needed to make that judgement is structured, connected and traceable rather than scattered across systems and buried in code somebody wrote three years ago and has since left.
You can appoint an officer by decision. You cannot make the role executable by decision. That part has to be built, and it takes longer than anyone would like.
The pace makes this sharper rather than gentler. Public commitments point to more than thirty billion dollars going into AI data centre capacity across the GCC between now and 2030, and Saudi Arabia has declared 2026 its Year of Artificial Intelligence. The compute is arriving, at scale and at speed.
None of that is a bad thing. It is genuinely impressive, and it is moving faster than most observers outside the region realise. But capacity and accountability are being built on very different timelines, and the space between them is where the next round of expensive surprises is going to come from.
Europe is arriving at accountability by classifying systems. The Gulf is arriving at it by naming people and institutions. Different instruments, different philosophies, and in the end the same requirement: somebody has to be able to explain what happened, and stand behind the explanation.
I find the Gulf route the more demanding of the two, because it is harder to satisfy on paper.
A system can be classified in a spreadsheet by someone who has never seen it run. A person cannot sign for something they do not understand.
If a supervisor asked you today to name your Autonomous Systems Officer, you could probably produce a name by the end of the week.
The more useful question is the one after that. Hand that person the system you put into production last quarter, and ask them to explain, end to end and in plain language, where the answer came from and why it was reasonable. How far would they get?
That distance, between the name and the evidence, is the honest state of your AI foundation. Everything on top of it is ambition.
There is one more thing worth saying, and it is the part I keep turning over.
Even if every organisation in the DIFC decided this week to fill the seat, I am not sure where they would find the people. This is a genuinely new discipline. It asks for someone who understands data protection, model behaviour, knowledge structure and institutional risk well enough to hold them together, and who is willing to put their name on the result. That person is not produced by a two-day certification course, and there is no meaningful pipeline for them in this region yet.
I think that gap matters more than the regulation does, and it is one of the reasons I have been working quietly on how such people might be trained here rather than imported. I have nothing to announce and no date to give you. I would simply rather say out loud that the shortage is coming than act surprised when it arrives.
Where would your own foundation stand? The more modest starting point is an honest look at whether your organisation could support that role at all, across the eight domains where a foundation either holds or quietly gives way.
Take the Capability IndexRegulation 10 applies to DIFC entities, not to the UAE as a whole. The wider direction of travel does.
The Signal & The Noise
A fortnightly read on what is actually changing in AI across the UAE and the Gulf, written personally. No content calendar, no generated filler.