All insights

Compliance

Voice AI in UAE, Dubai - TDRA | DNCR | PDPL Regulations

Yes, voice AI is legal in the UAE. How xAIa runs AI employees under TDRA licensing, the Do Not Call Register and the PDPL: in region, on-premise, PII redacted.

Team xAIa
Dubai skyline across the water at dusk
Compliance / xAIa
Author
Team xAIa
Published
18 September 2026
Reading time
8 min read

Is voice AI legal in the UAE? It is the first question in most of our meetings in Dubai and Abu Dhabi, usually from a compliance officer or a procurement lead. Behind it sit three more: which rules apply to an AI employee on a phone line, who is accountable when it calls someone, and where the recording goes afterwards.

Yes, voice AI is legal in the UAE. The rules that govern it are the rules that already govern every business phone call in the country: TDRA licensing of operators and numbers, the telemarketing regulations with the Do Not Call Register, and the Personal Data Protection Law. Neither text mentions AI. The obligations attach to the call and to the data, whichever system produced them.

Below are the main rules, how the infrastructure satisfies each one, and what government and enterprise buyers asked us to prove before they signed.

Yes. Cabinet Resolution No. 56 of 2024 on the Telemarketing Regulations states in Article 5(6) that "Automated communication systems may be used for marketing, advertising and promoting the products or services provided by the Company in accordance with the provisions of this resolution". Cabinet Resolution No. 57 of 2024 sets the penalties. The TDRA licenses the operators that carry the calls and runs the Do Not Call Register. Federal Decree-Law No. 45 of 2021, the PDPL, governs the personal data in the conversation, and a call recording is personal data.

TDRA rules: licensed operators and numbers in your name

The rule. Carrying calls on the public phone network in the UAE is a licensed activity. The TDRA licenses the operators, and a phone number is issued by a licensed operator to a business under a contract against its trade licence. Automated calling from personal numbers is a violation: as of June 2026 the regulator had issued AED 19.19 million in fines and disconnected 9,433 personal numbers used for telemarketing.

How we run it. xAIa connects to the telephony you already hold. Voice AI employees join your existing SIP trunk, contact centre platform or cloud PBX, and UAE numbers come through licensed UAE operators, contracted in your name. Where a mandate requires it, the trunk terminates inside your own perimeter. The four routes are in connecting voice AI to UAE phone numbers.

The Do Not Call Register and the outbound calling rules

The rule. Resolution 56 requires prior approval to practise telemarketing (Article 4(1)), no calls to numbers on the Do Not Call Register (4(5)), the recording disclosed at the start of the call (4(7)), the company and purpose identified (4(11)), a calling window of 09:00 to 18:00 (5(3)), no further calls once the consumer has declined (5(4)), and unanswered calls capped at once a day and twice a week (5(5)). Resolution 57 prices the failures: automated calling in violation carries AED 10,000, rising to 25,000 and 50,000 on repeat, and operating without prior approval starts at AED 75,000.

How we run it. Each clause is a setting with a record behind it. The 4(1) approval belongs to your company, and a campaign stays disabled until the reference is on file. Registry suppression runs before a list is loaded, and the check is timestamped. The calling window is set in Gulf Standard Time at campaign level, and the scheduler refuses an out-of-window dial. The retry counter is keyed to the number, so two campaigns with overlapping lists cannot add up to four calls in a week. A decline writes to a suppression list shared by every dialler. The opening turn is scripted per language, in the register the consumer speaks, with the recording notice and the identification in the first seconds. Inbound service agents open the same way. The clause-by-clause table is in the UAE AI call center guide.

The rule. The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, prohibits processing personal data without consent except in listed cases, lets the data subject restrict or stop processing, and sets separate requirements for cross-border transfer. A call recording, its transcript and the CRM record the agent writes are all personal data. The law's implementing regulations had yet to be issued as of March 2026, so organisations comply against the decree-law itself.

How we run it. Every deployment starts with the lawful basis and the purpose written down. The agent reads only the fields the task needs. Retention is set by your policy. Access is role-based, and every read and write is logged against the conversation that caused it. Transcripts are searchable, so a subject access or erasure request is a query. Your data is never used to train shared models.

On cross-border transfer, residency is about where the understanding happens, and a recording stored in the UAE and transcribed abroad has left the country. xAIa keeps the speech, the model and the edge in region, in one of three models: a UAE-region cloud, including Azure's UAE North and UAE Central regions; on-premise, on infrastructure you control; or air-gapped. The architecture is in on-premise voice AI for Gulf government and enterprise.

PII redaction and no-retention mode

The rule. Purpose limitation and data minimisation under the PDPL mean a company holds the personal data it needs for its stated purpose, and no more. A verbatim call transcript holds far more than that: ID numbers, card numbers, addresses and dates of birth, read out to complete the task and then sitting in a log.

How we run it. Personal identifiers spoken during the call are masked before the transcript is written, so the stored record carries the outcome of the call without the identifiers. The same redaction applies to the operational logs. For stricter mandates, a no-retention mode discards audio and transcript when the call ends and keeps only the audit trail of who accessed what and which action fired. Both settings are per deployment and written into the scope document.

What government and enterprise procurement asked for

The procurement questionnaires we have answered for government entities and regulated enterprises in the UAE asked the same questions in the same order. Where is the audio understood? Who are your sub-processors, and where are they? Who can open a recording, and is that access logged? How long is it kept, and who sets that? Can the models run inside our estate? How do you prove a call complied after the fact?

Each question became a design decision: in-region processing by default, a named sub-processor list, role-based access with an audit trail, retention set by the client, on-premise and air-gapped deployment, and a compliance layer that reviews every call.

Every obligation in these rules has a place in the stack where it is either satisfied or breached, and the platform is built so that place is a setting with a record behind it. The registry check runs before the list loads. The calling window lives in the scheduler. The audio is understood in the country it was spoken in, and the identifiers are masked before the transcript is written. When a regulator asks why a number was called on a given day, the answer already exists.

Team xAIa

Reviewing 100% of calls with ComplAI

ComplAI, xAIa's compliance platform, reviews every recorded call against the rules that govern it. It tests each obligation in the phase of the call where it was supposed to occur, so a recording notice read at minute nine fails a check that a transcript search would pass. Verdicts are cross-checked across several agents, reviewers get a queue ranked by risk with the evidence attached, and when a rule changes the archive is re-scored against it. The reasoning is in why we built ComplAI.

AI disclosure rules in the UAE

Neither the telemarketing resolution nor the PDPL requires a company to tell a caller that the voice is an AI. Whatever disclosure your regulator or your brand requires is scripted into the opening turn and verified on every recorded call. Decide it in writing before the first call.

FAQ

Yes. Cabinet Resolution No. 56 of 2024 permits automated communication systems for marketing under Article 5(6), subject to the rest of the resolution, and inbound service lines run under the same operator licensing and the PDPL.

Do AI calls have to respect the Do Not Call Register?

Yes. Article 4(5) prohibits calls to numbers on the TDRA's Do Not Call Register. xAIa runs the suppression before a list is loaded and timestamps the check.

Does the PDPL apply to AI call recordings?

Yes. A call recording, its transcript and the record the agent writes are all personal data under Federal Decree-Law No. 45 of 2021. xAIa processes them in region, masks identifiers before the transcript is stored, sets retention to your policy and logs every access.

Can voice AI run on-premise or in Azure in the UAE?

Yes. xAIa deploys in a UAE-region cloud, including Azure's UAE North and UAE Central regions, on-premise in your own data centre, or air-gapped. In every model the speech is understood inside the country, which is the test data residency sets.

Who holds the telemarketing approval, the vendor or the company?

The company. Article 4(1) of Resolution 56 places prior approval with the company marketing the products. In an xAIa deployment the campaign stays disabled until your approval reference is recorded against it.

What does PII redaction do in a voice AI deployment?

It masks personal identifiers, such as ID numbers, card numbers and addresses, before the transcript and logs are written. A no-retention mode goes further and discards audio and transcript when the call ends, keeping only the access and action audit trail.

Speak to us and we will map your regulator's questionnaire to the settings that answer it.

AI for every department. Starting with yours.

A quick chat to answer questions and see if we can help.

Book a consultation