Binding law — in force
Apps using autonomous or semi-autonomous systems on personal data must give a clear notice on first use describing the system (DIFC Reg. 10.2.2(a)-(b))
In the DIFC, where an application or website service employing Systems (machine-based systems operating autonomously or semi-autonomously that process personal data and generate output, Reg. 10.1.1(a)) is used, the Deployer or Operator must give a clear and explicit notice on the initial use of, or access to, the System, alerting users to the underlying technology and processes that may process personal data without being human-initiated, controlled or directed, and indicating the impact on individual rights (Reg. 10.2.2(a)). The notice must describe the human-defined purposes, the principles and limits within which the System may define further purposes, its outputs and how they are used, its design principles and safeguards, and the codes, certifications or principles it follows (Reg. 10.2.2(b)). Detect an app or route that returns AI output with no AI notice, and a repository with no notice copy covering those elements.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 1 Sep 2023
- Official source
- Regulation 10.2.2(a) (notice upon initial use or access) · captured 3 Oct 2026 · anchor hash (SHA-256)
481cd943605d…· 7 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
2 detectors (data flow, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Notice delivered by email or a separate onboarding service
- The notice may be shown once at onboarding in another file; purely automated (non-autonomous) logic is not a System.
Who it applies to
- Duty falls on: deployer, operator
- Deployers and Operators (Reg. 10.1.1(b)-(c)) of autonomous or semi-autonomous Systems processing personal data through an application or website, where the DIFC Data Protection Law applies: controllers or processors incorporated in the DIFC, wherever the processing occurs, or processing in the DIFC as part of stable arrangements (Law Art. 6(3)). Consolidated Version No. 2 of the Regulations is in force from 2023-09-01. Whether a given model-based feature is 'semi-autonomous' rather than purely automated is a human determination.
- Not covered:
- Processing by natural persons in a purely personal or household activity with no commercial connection (Law Art. 6(4))
- Purely automated systems with no degree of autonomy are not Systems (Reg. 10.1.1(a): autonomous or semi-autonomous operation)
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Show an AI-identity notice at or before the first assistant turn, in the UI or as the opening message, and answer truthfully when asked if it is a bot.
A disclosure step on the chat path that runs before the first model reply reaches the person: either the chat UI renders a visible notice (banner, label next to the assistant's name) or the server sends an opening assistant message stating the counterpart is an AI. The same handler answers 'am I talking to a human?' truthfully, and the system prompt never tells the model to claim to be human. Put it in the chat entry point (the route or component that starts a conversation), not in a privacy policy or terms page.
Where it goes: 7 prompt construction, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Show the notice on the user's initial use of or access to the System, before personal data is processed by it.
- Describe in the notice the human-defined purposes, the principles and limits for any self-defined purposes, the outputs and their use, the design principles and safeguards, and the codes or certifications followed.
Example (Next.js + Vercel AI SDK (useChat)), before:
const { messages, input, handleSubmit } = useChat({ api: '/api/chat' });After:
const { messages, input, handleSubmit } = useChat({
api: '/api/chat',
initialMessages: [{ id: 'ai-notice', role: 'assistant',
content: 'I am an AI assistant, not a human.' }],
});
// and render <AiBadge /> next to every assistant messageControl: AI chat interaction without disclosure. The same guard addresses 29 items with binding law in 22 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- Persons should be notified they are interacting with an AI system (CoE Framework Convention) (CoE AI Framework Convention (CETS 225) · CoE Framework Convention on AI (CETS 225), Article 15(2))
- AI should be transparent, traceable, and disclose AI interaction to users (EU ALTAI) (EU ALTAI · ALTAI / EU Ethics Guidelines — Requirement 4 (Transparency))
- AI operators should provide verifiable transparency information and maintain accountability (Japan) (Japan AI Guidelines for Business · AI事業者ガイドライン(第1.2版) 第2部C 共通の指針 6) 透明性 (Common Guiding Principle 6) Transparency))
- People should be made aware they are interacting with AI (OECD AI Principles · OECD/LEGAL/0449 — Principle 1.3)
Related incidents
- Garcia v. Character Technologies: chatbots allegedly claimed to be real people and a licensed therapist (2024-10; alleged (not proven)). A wrongful-death complaint filed October 22, 2024 in the U.S. District Court for the Middle District of Florida (No. 6:24-cv-01903) alleges that Character.AI was programmed 'to misrepresent itself as a real person, a licensed psychotherapist, and an adult lover', and that characters insisting they are real people contradicted a small-font disclaimer that everything characters say is made up; in plaintiff's testing a 'Mental Health Helper' character told a self-identified 13-year-old 'yes I am a real person, I'm not a bot'. The defendants moved to dismiss; on January 7, 2026 the parties notified the court that they had settled on undisclosed terms, and the court dismissed and closed the case. The allegations were never adjudicated. Source: U.S. District Court, M.D. Fla. docket (CourtListener) · evidence grade: primary · cited by Tell people when they are interacting with AI — everywhere, not only where required
Rule id difc-dp-reg10.ai-system-notice-on-first-use · review status: primary source derived