AI governance · Dubai

AI Governance Training in Dubai — rules your staff can actually follow

Most AI policies in Dubai are written once, filed and ignored at the desk. Meanwhile staff paste company data into whatever tool is open. AI governance training closes that gap: a policy grounded in the rules that apply to you, and people who know what it means for their own work.

I work with boards and with risk, compliance, legal and IT teams in Dubai — first to shape a workable AI policy and risk register, then to train staff on what is approved, what must never be pasted, and who reviews what.

  • ✓Skillopedia FZC LLC, a registered UAE company with a UAE office
  • ✓Author of Generative AI 360° (ZebraLearn, 2025)
  • ✓600+ organisations and 200,000+ professionals trained
  • ✓Recent Dubai work: Jeebly leadership AI Excellence Workshop, Sept 2026
AI governance trainer in Dubai Hitesh Motwani
Hands-on, and a number you can defend

What a hands-on AI governance workshop looks like

Governance is practised, not presented. Participants classify real use cases, write the rules for them, and test those rules against scenarios from their own departments.

You bring
  • Your current AI or acceptable-use policy, if you have one
  • The AI tools staff use today — approved or not
  • Three or four real use cases from different departments
We build in the room
  • A tool register: approved, restricted and not allowed
  • A data classification staff can apply in seconds
  • Use cases scored for value and risk, with owners
  • Review rules for AI output that leaves the building
You leave with
  • A draft AI policy, or a red-lined update of yours
  • A one-page do and don’t for every employee
  • An AI risk register to maintain
  • A 30-day check on adoption of the rules

Work out the return on your own numbers

I don’t publish other organisations’ savings, because I can’t verify what happened in their business after I left. This uses your inputs and updates live. Nothing is sent anywhere.

On your inputs

—

recovered capacity per year, at your own blended cost

Hours released per month—
Value per month—
Pays for itself—
First-year return on spend—
—

Read this honestly. Recovered hours are worth money only if they go somewhere — more cases closed, faster turnaround, hiring you no longer need. That is why each engagement ends with a 30-day review of which outputs actually changed.

Governance at the desk

Where AI governance shows up in daily work

Governance only works when it answers the questions people ask at their desks.

Shadow AI
Before

Staff use free tools on personal accounts because nobody said what is allowed.

After

A short approved-tool list, a way to request new tools, and enterprise accounts that keep data protected.

Customer and personal data
Before

People are unsure whether a customer email can go into an AI tool.

After

A three-level data classification with a one-line rule for each level, matched to DIFC or PDPL obligations.

AI output leaving the company
Before

AI-drafted text reaches clients and regulators without anyone checking.

After

Named reviewers for external output, and a simple record of what was AI-assisted.

Tool and vendor approval
Before

Every department buys its own AI tool.

After

A short assessment template covering data location, retention, training on your data and contract terms.

Automated decisions
Before

AI quietly starts influencing hiring, credit or pricing decisions.

After

Those use cases flagged as high-risk, with human decision-makers and documented reasons.

Board oversight
Before

The board hears about AI only when something goes wrong.

After

A quarterly one-page AI report: use cases live, incidents, risks and decisions needed.

UAE rules

Which AI and data rules apply to your Dubai organisation

There is no single AI law for every Dubai company; the rules depend on where you are licensed and what you do. DIFC firms are covered by the DIFC Data Protection Law No. 5 of 2020 and its Regulation 10, which addresses personal data processed through autonomous and semi-autonomous systems, including AI. Most mainland and free-zone companies start from the federal Personal Data Protection Law (Decree-Law No. 45 of 2021), with sector rules on top — health data, for example, has its own regime.

Government entities are excluded from the PDPL and follow their own policies alongside Dubai’s AI principles and ethics guidance. The UAE Charter for the Development and Use of Artificial Intelligence sets national principles, and companies selling into Europe may also fall under the EU AI Act.

For organisations that want a recognised management-system approach, ISO/IEC 42001 sets requirements for an AI management system. I don’t certify you against it, but the policy, register and review habits built in training map onto it.

Who should attend

  • Board members and the executive committee
  • Risk, compliance and internal audit
  • Legal and data protection officers
  • IT and information security
  • Department heads who own AI use cases
The programme

AI governance training modules

A half-day board briefing covers modules 1, 2 and 6. A full-day working session adds the policy and register work.

MODULE 01

The AI risk landscape

Accuracy, confidentiality, bias, IP and over-reliance, illustrated with realistic workplace incidents.

MODULE 02

Which rules apply to you

DIFC Regulation 10, PDPL, sector rules, government policy, the UAE AI Charter and the EU AI Act where relevant.

MODULE 03

Writing a workable AI policy

Approved tools, data classes, review rules and a request process — short enough to be followed.

MODULE 04

Use-case risk scoring

Scoring real use cases for value and risk, with controls proportionate to each.

MODULE 05

Vendor assessment

The questions to ask any AI vendor about data location, retention and training on your data.

MODULE 06

Board oversight

What a board should see each quarter, and which decisions should come back to it.

Four ways to run it, all private to your organisation

HALF DAY

Leadership briefing

What AI changes in your business, a live demonstration on your own material, and a ranked shortlist of use cases with owners.

FULL DAY, ON-SITE

Team working session

One function at your office, mostly hands-on work on redacted examples from participants’ own jobs.

2–3 SHORTER BLOCKS

Live online

Consecutive days on Gulf Standard Time (UTC+4), for teams split across offices or emirates.

ONE-TO-ONE OR SMALL GROUP

Coaching

Working sessions on a senior person’s own workload, ending with a reusable assistant on their licensed tool.

Named work

Engagements you can check yourself

I only name organisations with a public or published record of the work. Across a 17-year training career that adds up to 600+ organisations and 200,000+ professionals, with a 4.8/5 average post-session rating across 300+ surveyed participants.

Jeebly, Dubai

AI Excellence Workshop for the leadership team, September 2026 — confirmed in Jeebly’s own LinkedIn post.

Transworld Group

Hands-on leadership training, described publicly by a participant. Skillopedia’s case card records four batches of 25 and an in-house AI platform built afterwards.

Beroe

Research analysts working hands-on across several AI tools and data analysis.

“Hands-on practice across multiple LLM tools, with good explanations that were easy to follow.”
Indorama

Generative AI and NotebookLM workshops for teams in Nigeria, India and Indonesia.

Tata Teleservices

Sessions on where AI is not the answer, as well as where it is.

“It clarifies what should be expected from AI and where AI is not needed.” — Rahul Arora, Deputy General Manager
Questions

AI governance questions from Dubai organisations

Does the UAE have an AI law?

There is no single AI statute covering every company. Obligations come from data protection law (DIFC or the federal PDPL), sector regulators, government policy for public entities, and national principles such as the UAE AI Charter. Which apply depends on where you are licensed.

What does DIFC Regulation 10 cover?

It sets requirements for processing personal data through autonomous and semi-autonomous systems, including AI, under the DIFC Data Protection Law. DIFC firms using AI with personal data should check their notices, assessments and oversight against it with their DPO or counsel.

Do you write our AI policy?

I help you draft or red-line one in the workshop, grounded in your tools and use cases. Final sign-off should sit with your legal and compliance teams.

Is this the same as ISO/IEC 42001 certification?

No. Certification is carried out by accredited certification bodies. The training builds the policy, register and review habits that a 42001 programme needs.

Who should attend first?

Start with a half-day briefing for leadership and risk owners, then department heads, then a short session for all staff on the do’s and don’ts.

Can you train all staff on our AI policy?

Yes, in short sessions built around realistic scenarios from their own work, so the policy is understood rather than just acknowledged.

Is this legal advice?

No. The training explains the rules and turns them into practical habits. For legal interpretation of your obligations, involve your counsel or DPO — they are welcome in the session.

Tell me where your AI governance stands

Tell me where you are licensed (DIFC, mainland, free zone or government), which AI tools are in use, and whether you have a policy today. Prefer to talk first? Book a 20-minute call.

Your information is safe. We don’t spam or send emails unless necessary.

UAE

A registered UAE company. Delivered by Skillopedia FZC LLC, licence no. 2623220140888, with a UAE office and on-site delivery across Dubai. Company details & office address →

Scroll to Top
WhatsApp WhatsApp me