AI POLICY FOR UAE TEAMS

AI Usage Policy for Employees in the UAE: A One-Page Guide

An AI usage policy tells your people which AI tools they may use, what information must never go into them, and who checks the output. In the UAE, keep it to one page, tie it to the PDPL and the national AI Charter, and back it with a short practice session. A policy nobody reads protects nobody.
By Hitesh Motwani  |  Updated 29 September 2026  |  7 min read
Three data levels for AI use: fine, approved tools only, neverPublic information: fine to useInternal documents: approved tools onlyPersonal or client data: never

Why a policy, and why now

Your staff are already using ChatGPT, Copilot or Gemini. Some do it on company accounts. Plenty do it on personal ones, because it is quicker and nobody told them not to. That gap has a name, shadow AI, and the problem with it is simple: you cannot manage what you cannot see.

The risk is rarely dramatic. Picture an account manager pasting a client contract into a free chatbot to get a quick summary. Or an HR executive uploading a salary sheet to tidy the formatting. Nobody meant any harm. The data left the building anyway.

Which UAE rules actually touch AI use

You do not need to become a lawyer. You do need to know that these four things exist.

Rule or frameworkWhat it means for AI useBinding?
UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021)Personal data of customers, employees and others must be handled lawfully and kept secure. Putting it into an AI tool is a form of processing it.Yes, for mainland UAE. In force since January 2022.
DIFC and ADGM data protection lawsCompanies licensed in these two financial free zones follow their own data protection regimes.Yes, inside those zones.
UAE Charter for the Development and Use of AI (2024)Twelve principles, including human oversight, transparency and data privacy. Good backbone for your own policy.Guiding framework, described as non-binding.
Sector rules (banking, health, government)Regulated firms often carry stricter internal rules on data and outsourcing.Depends on your regulator.

For a local example of the tone to aim for, Dubai’s Department of Finance publishes an AI policy built on transparency, accountability, fairness and data protection. A private company needs the same basics, just shorter.

One caution. Legal commentary is not uniform on where the PDPL’s implementing regulations stand, which is a good reason to have your counsel read the final version before you roll it out.

The traffic-light rule for data

The most useful thing in any policy is a data rule people can remember at the end of a long day. Three colours do the job.

GREEN: fine to use
Public information. Your own published marketing. Generic questions. Brainstorming with no company details.
AMBER: approved tools only
Internal documents. Meeting notes. Draft proposals. Data that has been properly anonymised.
RED: never in any AI tool
Customer or employee personal data. Passwords and keys. Unreleased financials. Contracts under NDA. Health records.

Your own list will look different. Which documents sit in amber for a logistics firm is not the same as for a clinic, and getting that split right is where most teams need a second pair of eyes.

What goes in a one-page policy

Six parts. Each one gets three or four sentences, not a page.

Purpose and scope
Who the policy covers, including contractors and interns.
Approved tools
Which tools and which accounts. Personal accounts stay out.
The data rule
Your traffic-light list, with three examples for each colour.
Human review
A named person checks anything customer-facing before it goes out.
Disclosure
When you tell a client or colleague that AI helped.
Owner and reporting
Who to ask, and how to report a slip without fear of blame.

My view: the moment a policy runs to six pages, people stop reading it. The clause wording and the UAE-specific version are what I build with teams in a live session, because that is where the real questions come out.

Want this worked out with your team, not just read?

Hitesh runs practical sessions for UAE teams: a leadership briefing on AI rules, and a hands-on session where staff practise the data rule on their own work. Bring your questions.

Five mistakes to avoid

  • Copying a US or UK template. The legal references and data terms do not carry over.
  • Banning everything. People keep using AI, just quietly and on personal phones.
  • Writing it once and filing it. Tools change every few months. Review twice a year.
  • Having no named owner. Somebody senior has to answer the questions and own the slips.
  • Policy without practice. Nobody learns a data rule from a PDF. They learn it by using it on a real task.

Your next seven days

1
Day 1
Ask every team which AI tools they really use. Keep the survey anonymous so people answer honestly.
2
Days 2 to 3
Choose the tools you approve. Set up company accounts so nobody needs a personal one.
3
Days 4 to 5
Draft your traffic-light data list with IT and legal. Keep it to one page.
4
Day 7
Brief the whole team for 30 minutes, let them practise on one real task, and diary a review in six months.

Once the policy exists, the next question is what your people can safely do with AI. Our guide to writing Arabic and English business emails with AI shows a safe everyday use. If you would rather have someone lead the room, see how Hitesh runs Generative AI training in Dubai.

Questions people ask

I am not aware of a rule that forces every private company to hold a standalone AI policy. Data protection law does require you to protect personal data, and an AI policy is the practical way to show you do. Confirm your own position with legal counsel.
Usually not. A ban tends to push usage onto personal phones where you see nothing. Approving specific tools and setting clear data rules works better in most teams.
One page, two at the most. If it needs more, put the detail in a separate guide and keep the policy itself short enough to remember.
One named senior person with reach across IT, HR and legal. In many firms that is the COO, CIO or head of risk. Shared ownership usually means nobody answers the phone.
Those zones have their own data protection laws, but the working principles are the same: protect personal data, keep a human in charge and know which tools your people use.

This article is general information, not legal advice. Have your legal counsel review any policy before you roll it out.

Get your team using AI safely, and well

Individual coaching, corporate training, function-specific sessions or a general AI briefing for your leadership team. Tell Hitesh your team size and the problem you want to fix, and he will suggest a format.
Prefer email? Write to hitesh@skillopediagroup.com

About the author

Hitesh Motwani is a Generative AI trainer and the founder of Skillopedia FZC LLC, a registered UAE company, running hands-on workshops for teams in the UAE and India. He founded Skillopedia, is visiting faculty at K J Somaiya Institute of Management, and wrote Generative AI 360° (ZebraLearn, 2025).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top
WhatsApp WhatsApp me