Skip to content
← Insights

Governance

Two regimes, one programme: AI governance across the UK, EU and UAE

5 September 2026 · 5 min read

If your organisation operates in both Europe and the Gulf, you are now inside two AI regulatory regimes that were designed independently, arrived within roughly a year of each other, and do not share definitions.

Most organisations respond by opening two workstreams. That is usually a mistake, and an expensive one.

What the European regime asks of you

The EU AI Act is staged. Transparency obligations and oversight of general-purpose AI providers are in force. Obligations for high-risk systems follow later on a revised timetable, after amendments deferred several of the original dates.

The deferral is worth understanding correctly. It moves deadlines; it does not reduce the work. Classifying your systems, assembling technical documentation, and establishing post-market monitoring take months of elapsed time, much of it waiting on other people. Organisations that treat a deferral as a reason to stop tend to restart from zero later, with less time.

What the UAE regime asks of you

The UAE has moved to a dedicated national framework for AI, alongside the federal data protection law and sector-specific rules from Dubai authorities. The structure is tiered: obligations scale with the risk profile of the system, and higher tiers carry registration and assessment requirements.

Practically, an organisation operating in Dubai needs to be able to produce an inventory of the AI it uses, a defensible classification of each system, and evidence that someone is accountable for the risk.

Where the two regimes overlap

Here is the part that saves money. The artefacts underneath both regimes are substantially the same:

  • An inventory of AI systems in use, including the ones procured inside a SaaS product without anyone calling it AI.
  • A classification of each system by risk.
  • A named owner accountable for AI risk, with enough authority to stop something.
  • Documentation of purpose, data sources, limitations and human oversight.
  • A monitoring arrangement that survives the system going live.

Build those once, to the higher standard of the two, and you are most of the way to satisfying both. Build them twice and you have paid twice for one artefact set that will drift out of sync within a quarter.

Where ISO/IEC 42001 fits

ISO/IEC 42001 is the international standard for AI management systems, published at the end of 2023 and now the reference point for enterprises selling into regulated markets.

Two things are true about it at once, and both matter:

  • It is not a harmonised standard under the EU AI Act. Certification does not by itself create a presumption of conformity.
  • It nonetheless covers a large share of the documentation and governance an AI Act high-risk assessment will ask for, and is the most credible way to demonstrate to a customer or regulator that your governance is real rather than declared.

Treating 42001 as the backbone, then adding jurisdiction-specific requirements on top, is generally cheaper than the reverse.

Governance is a change problem too

The failure mode for AI governance is not that the policy is wrong. It is that the policy exists and nobody follows it, because it arrived as a PDF from a function nobody in delivery talks to.

Shadow AI use is the clearest symptom. If your inventory says four systems and your staff are using eleven, you do not have a documentation gap. You have an adoption gap, and it is fixed with the same tools as any other behaviour change: make the compliant path the easy path, explain why it exists, and give people somewhere to declare what they are already doing without being punished for it.

That is why we run governance inside the change programme rather than beside it.


Regulatory timetables in both jurisdictions have changed more than once and remain subject to amendment. Nothing here is legal advice. We confirm the current position for each client’s jurisdiction and sector, with local counsel where required, at the start of every engagement.

Where does your organisation stand?

Four minutes, twelve questions, no email required.

Take the scorecard