AI Usage Policy for Employees in the UAE: A One-Page Guide
Why a policy, and why now
Your staff are already using ChatGPT, Copilot or Gemini. Some do it on company accounts. Plenty do it on personal ones, because it is quicker and nobody told them not to. That gap has a name, shadow AI, and the problem with it is simple: you cannot manage what you cannot see.
The risk is rarely dramatic. Picture an account manager pasting a client contract into a free chatbot to get a quick summary. Or an HR executive uploading a salary sheet to tidy the formatting. Nobody meant any harm. The data left the building anyway.
Which UAE rules actually touch AI use
You do not need to become a lawyer. You do need to know that these four things exist.
| Rule or framework | What it means for AI use | Binding? |
|---|---|---|
| UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) | Personal data of customers, employees and others must be handled lawfully and kept secure. Putting it into an AI tool is a form of processing it. | Yes, for mainland UAE. In force since January 2022. |
| DIFC and ADGM data protection laws | Companies licensed in these two financial free zones follow their own data protection regimes. | Yes, inside those zones. |
| UAE Charter for the Development and Use of AI (2024) | Twelve principles, including human oversight, transparency and data privacy. Good backbone for your own policy. | Guiding framework, described as non-binding. |
| Sector rules (banking, health, government) | Regulated firms often carry stricter internal rules on data and outsourcing. | Depends on your regulator. |
For a local example of the tone to aim for, Dubai’s Department of Finance publishes an AI policy built on transparency, accountability, fairness and data protection. A private company needs the same basics, just shorter.
One caution. Legal commentary is not uniform on where the PDPL’s implementing regulations stand, which is a good reason to have your counsel read the final version before you roll it out.
The traffic-light rule for data
The most useful thing in any policy is a data rule people can remember at the end of a long day. Three colours do the job.
Your own list will look different. Which documents sit in amber for a logistics firm is not the same as for a clinic, and getting that split right is where most teams need a second pair of eyes.
What goes in a one-page policy
Six parts. Each one gets three or four sentences, not a page.
My view: the moment a policy runs to six pages, people stop reading it. The clause wording and the UAE-specific version are what I build with teams in a live session, because that is where the real questions come out.
Want this worked out with your team, not just read?
Five mistakes to avoid
- Copying a US or UK template. The legal references and data terms do not carry over.
- Banning everything. People keep using AI, just quietly and on personal phones.
- Writing it once and filing it. Tools change every few months. Review twice a year.
- Having no named owner. Somebody senior has to answer the questions and own the slips.
- Policy without practice. Nobody learns a data rule from a PDF. They learn it by using it on a real task.
Your next seven days
Once the policy exists, the next question is what your people can safely do with AI. Our guide to writing Arabic and English business emails with AI shows a safe everyday use. If you would rather have someone lead the room, see how Hitesh runs Generative AI training in Dubai.
Questions people ask
This article is general information, not legal advice. Have your legal counsel review any policy before you roll it out.
Get your team using AI safely, and well
About the author
Hitesh Motwani is a Generative AI trainer and the founder of Skillopedia FZC LLC, a registered UAE company, running hands-on workshops for teams in the UAE and India. He founded Skillopedia, is visiting faculty at K J Somaiya Institute of Management, and wrote Generative AI 360° (ZebraLearn, 2025).
WhatsApp me