Three regimes, one system
The DIFC and wider UAE frameworks, the UK's regulator-led approach and the EU AI Act differ in scope, enforcement and documentation. They agree almost entirely on what the underlying system must be able to do: explain a decision, limit an action, and prove both.
That agreement is what makes a single technical model viable across markets, even when the filings are separate.
Where the real divergence is
Data residency, notification timelines and the definition of a sensitive use case are the genuine forks. These are configuration and hosting decisions, and they are cheaper to make once, deliberately, than to retrofit per market.
Everything downstream of them, the logging, the receipts, the oversight path, can be shared.
Practical footing
We are registered in the DIFC, Dubai, and deliver into the UK and EU with the same team and the same method. For groups operating across all three, that removes a layer of translation between advisor, engineer and regulator.
“Write the control once at the strictest bar you face, then vary the paperwork by jurisdiction rather than the system.”
Continue
- The gap between intelligence and action6 min
- What 'autonomy with evidence' looks like in practice7 min
- How to evaluate an AI system you intend to let act5 min
- AI governance in London: what boards are actually asking for5 min
- How to choose an ethical tech consultancy without buying theatre6 min
- The EU AI Act, translated into changes in your codebase7 min
- How we work inside a transformation programme5 min