What Is Prompt Injection? Attack Patterns and Practical Mitigations
A clear definition of what is prompt injection, including scope, purpose, components, obligations, common misunderstandings and operational system implications.
What Is Prompt Injection? Attack Patterns and Practical Mitigations
What Is Prompt Injection? In practical terms, what is prompt injection is a concept, institution, standard or platform that organisations must translate into owned data, controlled workflows and retrievable evidence. Its exact scope can vary by jurisdiction, activity and effective date. Verify current requirements with the applicable authoritative sources, distinguish the formal definition from common shorthand, and record the operational consequences in the relevant business system.
Definition at a glance
| Question | Working answer |
|---|---|
| What is it? | What Is Prompt Injection? In practical terms, what is prompt injection is a concept, institution, standard or platform that organisations must translate into owned data, controlled workflows and retrievable evidence. Its exact scope can vary by jurisdiction, activity and effective date. Verify current requirements with the applicable authoritative sources, distinguish the formal definition from common shorthand, and record the operational consequences in the relevant business system. |
| Who owns it internally? | Assign the operational or compliance owner responsible for the underlying process and evidence. |
| What should the system hold? | Authoritative master data, dated requirements, workflow status, approvals, exceptions and retrievable evidence. |
| What is the main mistake? | Treating a general definition as a substitute for the current rule, standard, contract or operating context. |
Use this definition as orientation. Verify current primary sources before making a regulated, financial, safety or certification decision.
This is for CIOs and heads of automation who have been asked what Dubai's AI push requires of them. Most of what is published on the subject is announcements, and almost none of it creates an obligation on a private company. One instrument does, it has been in force since 2023, and it is the one nobody mentions.
Three different kinds of document, and why the difference matters
Almost every summary of "UAE AI regulation" lists a strategy, a charter and a regulation in the same bullet list. They are not the same class of thing, and a programme built on the mixture spends its quarter in the wrong place.
A strategy allocates government resources and sets targets. The Dubai Universal Blueprint for Artificial Intelligence, announced by the Crown Prince of Dubai in April 2024, is one. Its first phase names a Chief AI Officer in each Dubai government entity, an AI and Web3 incubator, an AI week in schools, a Dubai commercial licence for artificial intelligence and land allocated for data centres, against a target of AED 100 billion annually to Dubai's economy. Every item is something the government does. The UAE National Strategy for Artificial Intelligence 2031 works the same way.
A charter states principles with no supervisory authority, no compliance test and no penalty. The UAE Charter for the Development and Use of Artificial Intelligence, dated 10 June 2024, sets out twelve principles including safety, algorithmic bias, data privacy, transparency, human oversight, and governance and accountability. The UAE Legislation portal files it under policy, not legislation. It is a reasonable drafting reference for an internal standard, not something you can be found in breach of.
A regulation has an issuing authority, an enforcement power and a defined population. In Dubai exactly one speaks to agents, and it applies only inside a free zone.
What actually binds a private company on the Dubai mainland
Federal Decree-Law No. 45 of 2021 on the protection of personal data was issued on 20 September 2021, published in Official Gazette No. 712 of 26 September 2021, and came into force on 2 January 2022. It is active law and it does not mention artificial intelligence. It does not need to: an agent that reads a customer record, calls a tool and writes a decision is processing personal data, and every obligation attaches to the controller that deployed it.
The complication is that the executive regulations, expected to fix the operational detail, have not been issued. [NEEDS SOURCE: a primary UAE government confirmation of the status of the PDPL executive regulations as at August 2026.] A federal authority for artificial intelligence and data was announced in June 2026 and is expected to take them on. [NEEDS SOURCE: the decree-law or Cabinet resolution establishing the Federal Authority for Artificial Intelligence and Data, and its published mandate.]
Two mainland points get missed. Dubai Law No. 24 of 2023, which established the Dubai Data and Statistics Establishment, defines Data Providers to include private entities it designates, and Article 11(b) requires them to supply any data or statistics it requests to the standards it prescribes.
And sector regulators move faster than the general framework. The Central Bank of the UAE issued a Guidance Note on Consumer Protection and Responsible Adoption and Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions in February 2026. It is guidance, not rule, but it is specific: a documented governance framework proportionate to size and complexity, board accountability, a model inventory, bias testing at least annually and on every model upgrade, plain-language disclosures in Arabic and English for high-impact decisions, and an oversight taxonomy of human-in-the-loop, human-on-the-loop and human-out-of-the-loop, the last permitted only for low-risk, non-material processes. Design against that taxonomy if you are supervised.
The instrument map
| Instrument | Issuing body | Status | Who it applies to |
|---|---|---|---|
| Federal Decree-Law No. 45 of 2021 (UAE PDPL) | UAE federal government | Binding, in force 2 January 2022; executive regulations pending | Controllers and processors in the UAE, subject to the law's exclusions; free zones with their own regime sit outside |
| DIFC Law No. 5 of 2020 and Regulation 10 | DIFC Commissioner of Data Protection | Binding; Regulation 10 effective September 2023 | Deployers and Operators of autonomous systems processing personal data in or from the DIFC |
| ADGM Data Protection Regulations 2021 | ADGM Office of Data Protection | Binding; transition ended 14 Aug 2021 and 14 Feb 2022 | Controllers and processors in ADGM. No AI-specific layer |
| Dubai Law No. 24 of 2023 | Government of Dubai | Binding | Government entities, and private entities determined to be Data Providers |
| CBUAE Guidance Note on AI and ML | Central Bank of the UAE | Directional guidance, February 2026 | Licensed financial institutions, including insurers |
| Dubai Universal Blueprint for AI | Government of Dubai | Directional strategy, April 2024 | Dubai government entities. No private-sector duty |
| UAE Charter for Development and Use of AI | UAE federal government | Directional policy, 10 June 2024 | General guidance. No enforcement mechanism |
| UAE National Strategy for AI 2031 | UAE federal government | Directional strategy | National programme. No private-sector duty |
| Dubai AI Seal | Dubai Centre for Artificial Intelligence | Voluntary certification, January 2025 | Dubai-licensed AI suppliers. Precondition for selection on UAE and Dubai government projects |
| Chief AI Officer appointments | Government of Dubai | Administrative appointment, June 2024 | 22 Dubai government entities. Not a private-sector requirement |
Two qualifications. The u.ae portal entry for the Universal Blueprint records a different launch date from the Media Office release. [NEEDS SOURCE: reconcile the Blueprint launch date between the u.ae portal and the April 2024 Media Office announcement.] And the AI Seal is reported to carry tiers, including a supplier tier for government work, which the launch announcement does not describe. [NEEDS SOURCE: the Dubai AI Seal tier structure and assessment criteria.]
DIFC Regulation 10: the one rule written for autonomous systems
Regulation 10 of the DIFC Data Protection Regulations, made under DIFC Law No. 5 of 2020 and in force since September 2023, predates most of the agentic vocabulary and reads better for it.
A System is a machine-based system operating autonomously or semi-autonomously that processes personal data and generates output from it. A Deployer is the entity under whose authority, on whose direction or for whose benefit it operates. An Operator operates or supervises a System on behalf of and on the direction of a Deployer. Buy an agent platform, point it at your customer data, and you are the Deployer; the vendor running the orchestration does not move that.
The requirements to design against, as the Commissioner's FAQs describe them:
- Notice that names the technology. Clear and explicit notice on initial use or access, disclosing the underlying technology and that processing is not human-initiated, with purposes, capabilities and safeguards described. A footer link to a 2021 privacy policy is not this.
- Purpose control. Processing only for human-defined or human-approved purposes. This is the provision a general-purpose agent with an open tool set fails first, because nobody defined the purpose of the fourteenth tool.
- A register of processing activities specific to the System.
- Evidence on demand. Audit and certification evidence to the Commissioner on request, credible evidence of privacy by design, and material addressing bias, discrimination and legal compliance in the algorithms used.
- High Risk Processing Activities, as defined in Schedule 1, Article 3 of the DIFC Data Protection Law, trigger the harder set: an advance assessment by the Deployer, certification requirements set by the Commissioner, and an Autonomous Systems Officer or a DPO covering the role. Regulation 10.3.3 is prohibitory: no person may make a System available for commercial use to engage in High Risk Processing Activities unless it complies with the applicable requirements.
DIFC published Consultation Paper No. 3 of 2026 on 19 June 2026, closing 18 July 2026, proposing amendments to Regulation 10 and a new Regulation 11 on recognition of accreditation and certification schemes, certification obligations and the Autonomous Systems Officer role. [NEEDS SOURCE: whether those amendments have been enacted, and the effective date.]
ADGM, and why the free zone boundary is not a technicality
The ADGM Data Protection Regulations 2021 are a familiar shape: rights in relation to automated decision-making and profiling, a DPIA where processing is likely to result in high risk, a DPO where core activities involve high-risk or large-scale processing. What ADGM lacks is a Deployer and Operator split, a notice obligation naming the technology, and a certification gate. An architecture that satisfies Regulation 10 satisfies ADGM; the reverse is not true, and a group that standardises on its ADGM control set then opens a DIFC entity finds the gap at first notice. [NEEDS SOURCE: whether the ADGM Office of Data Protection has published AI-specific guidance since 2024.]
Regulation 10 follows the entity and the processing, not the rack. A DIFC-licensed entity whose engineering team, model endpoints and vector store sit on mainland infrastructure is still the Deployer.
The directional instruments reach you through procurement
The Dubai AI Seal, launched by the Dubai Centre for Artificial Intelligence in January 2025, is free to apply for and open to Dubai-licensed technology companies providing AI products or services. Applications are evaluated on six areas including the nature of the company's activities, the number of employees specialising in AI, current and future projects, and public and private sector partnerships. Application is voluntary, and the announcement is explicit that companies wishing to be selected as partners in UAE and Dubai government projects must be certified. That is a procurement gate, and it binds harder than most regulation because it decides whether you can bid. The twenty-two Chief AI Officers appointed in June 2024 matter for the same reason: the counterparty in a public-sector procurement now has an AI mandate.
A readiness procedure that survives whatever becomes binding
Every step produces an artefact you would need anyway.
- Fix jurisdiction per deployment, not per company. For each agent, record the licensing jurisdiction of the deploying entity, where the data subjects are, and where processing physically occurs. A group with DIFC and mainland entities has two regimes and one platform.
- Classify your role per system. Deployer or Operator under Regulation 10; controller or processor under the PDPL and ADGM regulations. Where a vendor runs orchestration and you set the purpose, you are the Deployer, whatever the contract says.
- Enumerate tools and declare a purpose for each. One human-defined purpose per tool or tool group, approved by a named person, with the data classes that tool sees.
- Run the High Risk Processing assessment before deployment. Test against Schedule 1, Article 3 of the DIFC Data Protection Law, and the high-risk threshold in the ADGM regulations where those apply. Record the outcome and date; a negative determination matters as much as a positive one.
- Name the accountable officer. An Autonomous Systems Officer, or a DPO covering the role, for DIFC High Risk Processing. Appointment in writing, escalation path documented.
- Rewrite the notice at the interface. On initial use, disclose that the counterparty is a machine-based system, that processing is not human-initiated, the purposes running, the capabilities and the safeguards. Version it, store the version identifier against each interaction, and treat a tool-set change as a notice change.
- Build the system-level register. One per System, listing tools, data classes, purposes, models and versions, retention per store, and the sub-processors behind each endpoint.
- Fix the oversight mode per decision type. Use the CBUAE taxonomy even if you are not supervised, and enforce it in the orchestration rather than in a policy document.
- Schedule bias and reliability testing at least annually and on every model upgrade, keeping the evaluation set, metric, threshold and result.
- Settle the vendor paperwork. For every model provider, vector store, observability and transcription vendor: retention of prompts and completions, training use, abuse-monitoring logs, sub-processors, processing location.
- Decide on the AI Seal if any revenue depends on UAE or Dubai government projects. The evaluation asks for staffing and project evidence that takes weeks to assemble.
- Diarise the two open items with an owner and a review date: the PDPL executive regulations, and the outcome of DIFC Consultation Paper No. 3 of 2026.
Where teams get this wrong
Assuming the corporate privacy notice does the work. Regulation 10 wants notice on initial use or access, naming the technology and the non-human-initiated processing. The most common gap in DIFC deployments, and the cheapest to close.
Buying against the Charter. Procurement teams have started sending twelve-question vendor assessments derived from the Charter principles. The answers are unfalsifiable. Ask instead for the purpose register, the notice version, the oversight mode per decision type and the last bias test result.
Letting the tool set drift. An agent whose tool list grew from six to nineteen over two quarters has no declared purpose for thirteen of them. Nobody notices until the register is requested, and by then the runs are in the logs.
Waiting for the executive regulations. The PDPL is in force; regulations would add detail, not obligation. Programmes that deferred have years of traces and evaluation sets to remediate at the point they are also trying to ship.
What to automate, and what not to
Automate the record. The purpose register, the notice version stamped on each interaction, the model and prompt version per run, retention clocks per store and the evidence pack for a Commissioner request are mechanical and impossible to reconstruct after the fact.
Do not automate the determinations. Whether a deployment is High Risk Processing, whether you are Deployer or Operator, whether a decision type can run human-out-of-the-loop, and whether a bias result is acceptable are judgements a named person signs. Tooling should get that person to a decision in ten minutes with the evidence in front of them.
Where a system helps
The usual gap is evidential rather than architectural. The controls exist somewhere, but nobody can produce, on a Tuesday afternoon, the tools an agent was permitted to call in March, the purpose each was approved for, the notice version the customer saw and who approved the run. CohortaOS records purpose, tool scope, oversight mode and notice version on every run and keeps an action ledger of every downstream write, so an evidence request is a query rather than a project.
Related reading: What Is Agentic AI? (KB-045); What Is Prompt Injection? (KB-046).
FAQ
Is there an AI law in the UAE that applies to my private company? There is no general AI statute binding private companies. The binding instruments are data protection ones: Federal Decree-Law No. 45 of 2021 on the mainland, the DIFC Data Protection Law and Regulation 10 in the DIFC, and the ADGM Data Protection Regulations 2021 in ADGM.
Does DIFC Regulation 10 apply if we are licensed on the mainland? Not on its own. It applies to Deployers and Operators of systems processing personal data in or from the DIFC. If you sell an agent platform to a DIFC customer you are likely an Operator to their Deployer, and the obligations arrive contractually.
What is an Autonomous Systems Officer and do we need one? Regulation 10 contemplates appointing one, or a DPO covering the role, where a System engages in High Risk Processing Activities as defined in the DIFC Data Protection Law. Determine High Risk status first; the officer requirement follows from it.
Does the UAE Charter create obligations we can be audited against? No. It is filed as policy, dated 10 June 2024, with no supervisory authority or penalty attached. It is the vocabulary your government counterparties will use, but nothing in it is enforceable against you.
Sources
- DIFC Data Protection Regulations, Regulation 10
- DIFC, FAQs on Regulation 10 (PDF)
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
- UAE Charter for the Development and Use of Artificial Intelligence
- Dubai Universal Blueprint for Artificial Intelligence (Dubai Government Media Office)
- Dubai appoints 22 Chief AI Officers (Dubai Government Media Office)
- Dubai Centre for Artificial Intelligence launches the AI Seal (Dubai Government Media Office)
- CBUAE Guidance Note on AI and ML for Licensed Financial Institutions
- Dubai Law No. 24 of 2023 Establishing the Dubai Data and Statistics Establishment
- ADGM Data Protection Regulations 2021 (PDF)
- UAE National Strategy for Artificial Intelligence 2031
