AI governance,before the audit.
Every board now deploys AI, few can explain how it is governed, and the regulators have started asking. RPLC UAE designs AI governance that works: frameworks, policies, risk assessments and contracts calibrated to the UAE's AI strategy and charter, the DIFC's Regulation 10, the EU AI Act's extraterritorial reach and India's emerging guidelines, so that innovation continues and accountability is provable.
The UAE has positioned itself as an AI-first economy, with a Minister of State for Artificial Intelligence, the National AI Strategy 2031, the UAE AI Charter and Dubai's AI ethics principles setting expectations of fairness, transparency, accountability and human oversight. Binding obligations arrive through existing law: the PDPL and free-zone data protection regimes govern personal data in models, the DIFC's Regulation 10 imposes specific duties on autonomous and semi-autonomous systems that process personal data, sector regulators expect model-risk management, and consumer, employment and IP law apply to AI outputs just as they do to human ones.
The EU AI Act, in force since August 2024 with obligations phasing in through 2027, reaches any provider or deployer whose AI system's output is used in the EU, regardless of where the company sits. Prohibited practices, general-purpose model duties and high-risk system requirements will touch UAE and Indian companies selling into Europe. India has taken a guidelines-led approach: MeitY advisories, the India AI Governance Guidelines and the DPDP Act together shape what responsible deployment means for Indian data and Indian users.
Our practice, led by Raunak Rane, sits at the intersection of law and product. We build AI governance frameworks that boards can own and engineers can implement: inventories and risk classification, responsible-AI and acceptable-use policies, AI impact assessments aligned to ISO/IEC 42001 and NIST AI RMF, EU AI Act readiness roadmaps, and the contracts that allocate AI risk between vendors, customers and partners. We also advise founders building AI products on the regulatory perimeter, IP and data-licensing strategy that investors and enterprise buyers now diligence.
Every mandate is staffed by a founding partner and a small, dedicated team. Where formal representation before UAE courts or authorities is required, we instruct and coordinate registered Emirati advocates so that clients receive one accountable file across legal consultancy and formal representation. Cross-border work between the UAE, India and the USA is run from the same file, with local counsel engaged where applicable law requires.
Board-level AI governance charters, roles and committees, AI system inventories, risk classification and lifecycle controls aligned to ISO/IEC 42001 and the NIST AI Risk Management Framework.
Enterprise policies for generative-AI use, model development, procurement, human oversight and incident reporting, with employee training and practical guardrails.
Algorithmic impact assessments, fundamental-rights and bias assessments, and combined AI/DPIA assessments for high-impact systems in HR, credit, health, insurance and public services.
Applicability analysis, prohibited-practice screening, high-risk classification, provider and deployer obligation mapping, conformity-assessment roadmaps and general-purpose model duties for UAE and Indian companies selling into the EU.
Assessments and notifications for autonomous and semi-autonomous systems under DIFC Regulation 10, alignment with the UAE AI Charter and Dubai AI principles, and sector-regulator model-risk expectations.
AI-specific terms in customer, vendor and cloud agreements: data and model IP, training-data rights, output ownership, indemnities, performance warranties, audit rights and regulatory-change clauses.
Training-data licensing and provenance, copyright and database rights in inputs and outputs, trade-secret protection for models and prompts, and open-source model licence compliance.
MeitY advisory compliance, India AI Governance Guidelines alignment, DPDP Act implications for model training and inference, and sector rules from RBI, SEBI and IRDAI for AI in regulated services.
The work, on record.
Client names withheld under counsel duties; details rendered indicative.
EU AI Act readiness for a MENA enterprise SaaS platform
Applicability analysis, high-risk classification of HR-analytics features, provider obligation mapping, conformity roadmap and customer-facing documentation for a Dubai SaaS company with EU enterprise clients.
Group AI governance framework for a listed BFSI group
AI governance charter, inventory and risk-tiering of 60+ models, model-risk policy aligned to regulator expectations, and quarterly board reporting for a regional financial group across five jurisdictions.
Regulation 10 assessment for an AI credit-decisioning engine
Autonomous-system assessment, explainability and contestability documentation, human-oversight controls and commissioner notification for a DIFC lender's credit engine.
AI vendor programme for a healthcare operator
AI-specific procurement standards, due-diligence questionnaire, contract clause bank and clinical-oversight requirements for a GCC healthcare group deploying diagnostic and administrative AI tools.
AI Governance & Emerging Technology
Reading, between the codes.
Speak to the practice.
A discreet, no-obligation first conversation, usually within one working day. Urgent matters are triaged the same day.
