← Back to Perspectives

On 14 June 2026, Sheikh Mohammed bin Rashid Al Maktoum announced the creation of the Federal Authority for Artificial Intelligence and Data, a single body reporting directly to the Cabinet, that absorbs three previously separate functions: the UAE Artificial Intelligence Office, the Information and Digital Government Sector within the Telecommunications and Digital Government Regulatory Authority, and the recently announced Emirates Data Office. It will be led by Omar Sultan Al Olama, the UAE's Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications.

The mandate is broad by design: setting unified national AI and data policy, proposing legislation, ensuring coherence between federal and local digital initiatives, establishing standards for data and AI management, driving compliance across federal entities, building national R&D capacity, and expanding international AI partnerships. The authority is also tasked with supporting the UAE's target of delivering half of all government services through agentic AI within two years, with around 400 officials assigned to the effort.

For anyone who has tried to get an AI or data programme approved inside UAE federal government over the past two years, the significance of this is less about any single new rule than about who you now call.


What actually changes

Before this consolidation, a federal AI programme touching citizen data could plausibly need sign-off, or at least alignment, across three bodies with three different institutional histories and three different sets of priorities: the AI Office focused on strategy and adoption, TDRA's digital government arm focused on service delivery and interoperability standards, and the Emirates Data Office (itself only recently stood up) focused on data governance. Getting three bodies to agree on a data-sharing model or an AI ethics exception was, in practice, a coordination exercise as much as a compliance one.

A single authority collapses that coordination overhead internally. It does not necessarily make the substance of what's required simpler: the standards, the compliance obligations, the R&D expectations are all still there. But it removes the risk of getting three different answers to the same question, and it gives external parties one relationship to manage instead of three.


What hasn't changed

It is worth being precise about the boundary of this authority, because the temptation is to read "unified AI and data policy" as "the only body that now matters", and that would be a mistake with real consequences for a compliance plan.

This is a federal, mainland-government consolidation. It does not fold in sector regulators that already issue their own binding AI guidance, most notably the Central Bank of the UAE, whose AI/ML guidance for licensed financial institutions we've covered here remains a separate instrument for a separate regulatory perimeter. Financial services firms building AI programmes still answer to CBUAE on top of whatever the new federal authority sets as baseline policy: the count of bodies in scope for a bank did not go from three to one, it went from four to two.

Nor does it reach into the free zones. DIFC's own AI-specific data protection regime, in force since the start of this year, sits under the DIFC's independent regulatory structure and is unaffected by a change to federal mainland government. A firm operating across DIFC and the mainland is still managing two distinct regulatory postures, not one.


What it means for market entrants and delivery partners

We've written previously about what GCC market entrants need in place before they deploy, and that groundwork doesn't change. What does change is the practical shape of engagement for anyone bidding into UAE federal government AI or digital transformation work:


The bottom line

This is a real structural change, and a sensible one: institutional fragmentation was a genuine source of delay and inconsistency in UAE federal AI programmes. But it consolidates one layer of a multi-layer system, not the whole system. Firms that treat this as "the UAE now has one AI regulator" will misjudge their compliance planning the moment a financial services client or a DIFC-based entity is in scope. Firms that read it correctly, as a faster, more coherent federal mainland counterparty sitting alongside sector and free zone regimes that haven't moved, will have an easier time of the next two years than everyone assuming the map just got shorter.