rotascale

Blog

A Regulator Wrote Down What an Agent Is

TL;DR: Most AI regulation is written for systems in general and has agents fitted to it afterwards. The DIFC’s Regulation 10 was written for autonomous systems specifically, and it says something the others do not: a system acting under its deployer’s authority is like an employee, and the deployer is responsible for keeping it inside limits a human established. That sentence is a specification, and almost nothing in production today can satisfy it.

The sentence

Regulation 10 has been in force in the Dubai International Financial Centre since January 2026. It governs personal data processed through autonomous and semi-autonomous systems, and clause 10.3.4 says this:

Its position is substantially similar to that of an employee within the Deployer organisation, and the Deployer should therefore be liable for its actions in the same way it may be liable for an employee’s actions. As a corollary to that, the Deployer will be responsible for ensuring that, when processing Personal Data, the System always operates within the appropriate human-established limits and on the basis of human-established principles, much in the same way the Deployer would train and require its employees to process Personal Data on its behalf only in accordance with its privacy policies.

Read that as an engineer rather than a lawyer. It contains a claim about liability, which is familiar, and a requirement about runtime, which is not.

Always operates within human-established limits. Not “has a policy describing its limits”. Not “was evaluated against its limits before deployment”. Always operates within them, as a property of every action, on a Tuesday afternoon when nobody is watching.

Why that is harder than it sounds

The employee analogy is doing more work than it appears to.

An employee who exceeds their authority can be asked afterwards what they did and why. There is a person to ask, a record they left, and an approval chain that either existed or did not. When a bank cannot answer those questions about an employee, that is a control failure with a name and a remedy.

An agent that exceeds its authority usually leaves none of that. The logs record what succeeded. The prompt that shaped the decision is gone. The scope it operated under was a configuration value that has since changed. And the question a supervisor actually asks, which is under whose authority did this run, has no field to read it from.

That is not a gap in anyone’s diligence. It is a gap in what the systems were built to record.

The second clause, which is the one nobody expects

Regulation 10.2.2(b) divides purposes into two kinds. Human-defined purposes are externally pre-defined and, in the regulation’s own phrase, “hard coded” into the system, which the system cannot change. Self-defined purposes are ones the system can generate itself, and where a system can do that, the regulation requires the generation to happen only within an exhaustive set of principles that humans defined, hard coded, and the system cannot alter.

An agent may not decide what it is for.

This is a striking thing for a data protection regulator to write, and it lands directly on the way most agent frameworks are built. A tool-using agent with an open-ended objective is, in Regulation 10’s vocabulary, generating its own purposes. The regulation does not forbid that. It requires the generation to sit inside a boundary the system cannot widen.

A grant is that boundary. It enumerates what an agent may do, it is issued by a named human, and an action outside it is refused before it runs rather than reported after. Delegation attenuates: a sub-agent receives some subset of its parent’s authority and can never acquire more, so a purpose the parent never held is not reachable from below.

What the regulation asks you to produce

Four things, none of which is a document you write once:

A register of AI processing activities. An inventory of what is running, what it does, and what it touches. Most estates cannot produce this on demand because nothing has been keeping it.

Notice that gives the subject something to act on. Regulation 10.2.2(a) is unusually specific: individuals must be given enough detail to assess the risk and decide whether to object or to withdraw the basis for the processing. It gives force to a provision of the DIFC’s data protection law about advanced technology that does not permit rights such as erasure to be exercised, which is a problem worth taking seriously rather than a formality.

Allocation between the parties. A Deployer carries controller responsibilities. An Operator, the service provider running the system on the deployer’s behalf, carries processor responsibilities. Both must be identifiable per action, not per contract.

Certification, when it exists. Regulation 10.3.3 states the intent that no system may be used for High Risk Processing Activities until the Commissioner has promulgated the certification requirements. That framework was still to come when the guidance was published, which means this is a gate on operating rather than a control you can implement.

The honest part

We have mapped Regulation 10 clause by clause, and two of the nine clauses are not ours to answer. The certification requirements under 10.2.2(c) and 10.3.3 are between a deployer and the Commissioner. No platform can evidence a certification it does not hold on your behalf, and any vendor telling you otherwise is selling you a gap.

That makes it the first instrument we have mapped where the “yours” column is not zero, and we think that is the honest shape of a regulation which gates your ability to operate rather than describing a control you can install.

The fairness principle under 10.3.1 is also yours. The DIFC enumerates no protected characteristics for outcome testing, so the objective and its justification belong to the firm, exactly as MAS FEAT does in Singapore and for the same reason.

Why this matters outside the DIFC

Two reasons.

The first is timing. The UAE’s federal data protection law carries a compliance deadline of 1 January 2027, and Regulation 10 is already live in the free zone. Firms operating there are inside the window now.

The second is that Regulation 10 is the clearest published statement we have seen of what agent governance has to mean operationally. Other regimes will arrive at similar requirements by other routes, and several are already circling the same idea: the EU AI Act’s human oversight obligations, the UK’s senior manager accountability, MAS’s expectation that a named individual carries responsibility personally. Regulation 10 is further along in saying what that implies for a system that acts on its own initiative.

If you want to know whether your estate could satisfy it, the test is short. Pick an agent that took an action last week. Name the human whose authority it acted under, produce the scope that authority carried at the moment it ran, and show the refusal it would have received had it exceeded that scope.

Most estates cannot do the first part.

The clause map is published. Nine clauses, seven we can evidence, two that are yours.

Newsletter

If this was useful, the next one is too.

Notes on agent governance, what the regulations actually say, and what we are building. Roughly monthly. Double opt-in, no tracking, and unsubscribing takes one click and asks you nothing.

RSS works too and needs nothing from you · What happens to your address