Solutions — instrument
The regulator wrote down what an agent is. It reads like a grant.
Every other instrument here was written for models or for processing in general, and agents were fitted to it afterwards. This one was written for autonomous systems, and it reaches the exact question: when a system acts on its own initiative, under whose authority did it act, and inside what limits a human established.
The clause that reads like a product specification
Regulation 10.3.4 describes what a system operating under its deployer's authority actually is, and it is worth quoting rather than paraphrasing:
“Its position is substantially similar to that of an employee within the Deployer organisation, and the Deployer should therefore be liable for its actions… the Deployer will be responsible for ensuring that, when processing Personal Data, the System always operates within the appropriate human-established limits and on the basis of human-established principles, much in the same way the Deployer would train and require its employees to process Personal Data on its behalf only in accordance with its privacy policies.”
Always operates within human-established limits is a runtime property, not a policy document. It is the difference between writing down what an agent may do and being able to show, afterwards, that it never did anything else.
Purposes a system cannot change
Regulation 10.2.2(b) divides purposes into human-defined — externally pre-defined and hard-coded, which the system cannot alter — and self-defined. Where a system can generate a purpose for itself, it must do so only from an exhaustive set of principles that humans defined, hard coded, and the system cannot change.
A grant is that boundary, enforced rather than documented. It enumerates what an agent may do; an action outside it is refused before it runs, with the gate that produced the refusal recorded. Delegation attenuates and never widens, so a sub-agent cannot acquire a purpose its parent never held.
What is mapped, and what is yours
Nine clauses. Seven this platform can produce evidence for, and two that are yours — which makes this the first map on the platform where that column is not zero, and the honest shape of a regulation that gates your ability to operate rather than describing a control.
- 10.2.2(c) and 10.3.3 — certification
- The Commissioner is to establish certification requirements, and 10.3.3 states the intent that no system may be used for High Risk Processing Activities until they exist. No platform can evidence a certification it does not hold on your behalf. What it produces is the operating record such an assessment would ask for.
- Fairness, under 10.3.1
- Outcome-based, and the DIFC enumerates no protected characteristics. So the objective and its justification are yours to state — the same position MAS FEAT takes, and for the same reason.
- The Autonomous Systems Officer
- A role the Commissioner describes as performing a similar function to a DPO: impact assessments, reviewing risks with senior management, and recommendations for accountability. A person, not a system. What a deployment gives them is the record they would otherwise have to assemble by hand.
Cut from the Commissioner's published guidance DIFC-DP-GL-23 Rev. 03, which is expressly not legal advice and has no force of law. Clause numbering is the regulation's own. Whether the mapping fits your deployment is a determination for you and your counsel.