| In force | CBUAE |
Fraud-liability transfer for entities retaining OTP-based authentication (since July 2025) | Migration off OTP; 24/7/365 fraud monitoring with device, location and behaviour analysis |
| 27 Nov 2025 | UAE Cyber Security Council |
National Encryption Policy approved | Formally approved post-quantum transition plans; automated cryptographic inventory; crypto-agility |
| During 2026 | UAE |
Mandatory submission of PQC migration plans | A migration plan resting on an inventory you can defend |
| 1 Jan 2026 | DIFC Commissioner of Data Protection |
Regulation 10 in full enforcement | Documented pre-processing risk assessments, transparency notices, human-oversight design, and either certification or a named Autonomous Systems Officer |
| 11 Feb 2026 | CBUAE |
Guidance Note on Consumer Protection and Responsible AI Adoption | Board and senior-management accountability for every AI system deployed; human oversight of high-impact decisions |
| Sep 2025 | UAE Central Bank |
Decree-Law No. 6 (2025) extends oversight to fintech and crypto firms | Statutory fraud-prevention capability, prompt breach reporting; criminal liability attaches to management negligence |
| Jul 2025 | DIFC |
Data Protection Amendment No. 1 | Private right of action including for distress; processors carry direct liability |
| From 2026 | KSA — NCA |
NCNICC-1:2025 brings private-sector entities into mandatory scope | Governance, audit, third-party and cloud-provider controls |
| 2024 | KSA — SAMA |
Cyber Security Framework and e-KYC framework | Biometric identity proofing for licensed digital banks and payment service providers |
| 2027 | SWIFT |
SwiftNet 8.0 expected to be PQC-enabled | Participant migration inside a 15-month window |
| 2028 | CBUAE |
PQC readiness expectation for banks | Migration executed on critical systems |