Confidentiality

Can a Gulf law firm put client files into ChatGPT? (2026)

Not into a free or personal ChatGPT account. In a practice direction signed on 6 January 2026, the court of the Qatar Financial Centre (QFC) gave the lawyers who appear before it a written rule: "Confidential, privileged, or protected information must not be entered into AI tools, except where private, secure AI platforms are used" (Practice Direction No. 1 of 2026, paragraph 12). The DIFC Courts' guidance points the same way, and the secrecy rules elsewhere in the Gulf do not say whether a paid AI provider counts as a disclosure, so the safest design keeps client files inside the firm, with written consent where the rules ask for it.

I build private AI systems for firms, and I read each text below to know what a system has to do. The sources were checked on 8 October 2026, and where I could not settle a point, I say so.

UAE onshore: written consent is the only consent route the Code of Ethics names

The federal Decree-Law No. 34 of 2022 on the legal profession forbids a lawyer from "Disclosing any secret entrusted to him / her, whether orally, in writing or via e-mail, means of modern technology or any other means of communication, or which comes to his / her knowledge ex officio" (Article 45(1)(a)). The disciplinary penalties in Article 86 range from a warning to removal from the Roll, with fines of AED 5,000 to 30,000 and suspension of up to two years in between.

Two Cabinet resolutions of February 2025 add detail. The Executive Regulations put the duty on the firm itself: "The Firm must ensure the confidentiality of clients' information" (Article 51(1)). The Code of Ethics bars disclosure of information obtained "from a Client or a third party" "except with the express written consent of the owner of the confidential information or as required by applicable laws in the State" (Article 8(2)), and makes the lawyer jointly liable for breaches by partners and employees (Article 8(6)).

Disclosure is also a crime. Under Article 432 of the Crimes and Penalties Law, a person entrusted with a secret by reason of their profession who discloses it faces incarceration of at least one year and/or a fine of at least AED 20,000, unless the person concerned allowed it.

None of these texts says whether giving a file to a technology vendor is a disclosure. Article 45 names "means of modern technology" as a channel and says nothing about cloud services or AI providers. On my reading, the safe course under the Code is written consent from the owner of the information, who is not always the client, or a tool that keeps client data inside the firm.

I found no AI practice direction for lawyers from the federal courts, the Ministry of Justice or the Dubai Courts. The AI Justice Atlas, a mapping tool of the Oxford Institute of Technology and Justice (Blavatnik School of Government and Clooney Foundation for Justice), says in its UAE entry, marked "Information uploaded as at March 2026": "As at March 2026, only the Dubai International Financial Centre (DIFC) Courts have issued specific guidelines for legal practitioners on the use of AI" (AI Justice Atlas, UAE).

On 29 September 2026, the Minister of Justice launched "Guiding Principles for the Use of Artificial Intelligence Systems by Law Firms", which set out "ten core principles" (press release). The release quotes him: "professional responsibility cannot be delegated. The outputs generated by artificial intelligence systems must always be subject to careful human review, verification and oversight." I could not find the text of the ten principles on the Ministry's site or elsewhere. Their Arabic title calls them guiding (استرشادية), which I read as non-binding (Emarat Al Youm).

Dubai has its own regulator for lawyers, the Government of Dubai Legal Affairs Department, whose functions include licensing firms and monitoring their practice (Administrative Resolution No. 51 of 2022). I found no Dubai text with its own confidentiality article. Whether the federal decree-law and its Code of Ethics bind Dubai-licensed lawyers is unclear to me: Article 3(1) applies the decree-law to everyone practising "in the State", while Article 3(2) lets emirates with their own judicial authorities regulate the profession. The criminal article above and the federal data protection law apply in Dubai either way.

Client personal data raises a second question. The federal PDPL, Federal Decree-Law No. 45 of 2021, lets personal data leave the UAE for countries the regulator approves (Article 22), and I found no published list. Article 23 adds other routes, among them "an explicit consent granted by the Data Subject" (Article 23(1)(b)) and a contract route for companies in "countries where there are no laws for Data Protection" (Article 23(1)(a)). The executive regulations meant to set the controls had not been issued as of 6 October 2026 (UAE PDPL and AI). The PDPL leaves out companies in free zones that have their own data protection law, such as the DIFC and ADGM (Article 2(2)).

For a US-hosted AI service, the explicit consent of each person whose data is sent is the clearest of those routes on my reading. A client can consent only for its own personal data: on that route, the other side, the witnesses and the employees named in a file each have to consent for theirs. I found no federal rule that requires a law firm's client data to stay in the UAE.

For an onshore firm, then, a public chatbot raises two questions at once: a possible disclosure, where written consent is the only consent route the Code names, and a transfer abroad under the PDPL. A system that stores and processes the data in the UAE removes the transfer question. Whether an outside provider's access counts as a disclosure stays open until a text or a court settles it.

DIFC: in court proceedings, the Courts' guidance asks for client consent before confidential data goes into AI

The Mandatory Code of Conduct for practitioners in the DIFC Courts, DIFC Courts' Order No. 2 of 2025, says: "Practitioners shall keep information communicated to them by their client confidential unless such disclosure is authorised by the client, ordered by the Courts or required by law" (Part C(10)). The right to practise in the Courts depends on observing the Code.

The Courts' Practical Guidance Note No. 2 of 2023 on generative AI, in effect since 21 December 2023, applies "to parties in proceedings before the DIFC Courts" and is "to be treated as guidance only" (section 1). It names "breaching client confidentiality" among the risks and tells parties to "avoid using free conversational GCGs (i.e. tools that provide you with answers to questions)" (section 4.3), GCG meaning generative content generator. Practitioners should "seek their consent for the use of GCG material in making submissions" (section 4.4). On confidential data, section 4.5 says: "if confidential information needs to be provided to a GCG, practitioners should ensure they first have their client's consent. Further, practitioners should speak with any potential GCG and read their terms of use to understand exactly how they will use any personal data and for what purposes and whether they comply with the Data Protection Law (DIFC No. 5 of 2020)."

It is the only court text in the Gulf I found that ties the use of AI to client consent.

The DIFC Data Protection Law allows transfers to jurisdictions on the Commissioner's adequacy list, which includes the EU, the UK, California and ADGM, also lists "Global CBPR / PRP" (the Global Cross-Border Privacy Rules and Privacy Recognition for Processors certifications), and does not name the United States as a whole or onshore UAE (Article 26). Other transfers need a safeguard such as the DIFC standard contractual clauses, or a narrow derogation such as explicit consent after being told the risks (Article 27). The law regulates transfers and has no rule that data must stay in the DIFC.

Under Regulation 10 of the DIFC Data Protection Regulations, the firm that benefits from an AI system's output is the "Deployer" and is treated as the controller, even when someone else hosts the system (Regulation 10.3.4). Since 15 July 2025, Article 64A of the law has also let a person who suffers damage, distress included, claim compensation in the DIFC Courts (DIFC Data Protection Law and AI).

For work in DIFC Courts proceedings, a free chatbot is the tool the guidance says to avoid, and a paid tool hosted in the US needs the client's consent and a read of the vendor's terms. Under the data protection law, the same tool also needs an Article 27 safeguard unless the California entry or a Global CBPR or PRP certification covers the vendor. Onshore UAE is not on the list either, so on my reading a cloud region in Dubai outside the DIFC still needs a transfer route.

ADGM: the same confidentiality duty, and an AI rule for document searches

Rule 7(6) of the ADGM Courts Rules of Conduct, which apply to "lawyers appearing before the ADGM Courts", sets the same confidentiality duty in the same words as the DIFC Code.

The ADGM Courts' Practice Direction 2, re-issued on 17 October 2025, has two paragraphs on AI, both about searching for documents. A search is not unreasonable "solely because that party has used artificial intelligence" (paragraph 2.84), and a party that intends to use AI for the search "must inform all other parties of that intention and provide sufficient details of the parameters of the search" (paragraph 2.85). I found no general ADGM Courts guidance on generative AI. An ADGM judge has also ordered costs over AI citations, which I cover in AI-invented citations in Gulf courts.

Under the ADGM Data Protection Regulations 2021, the United States is on the adequacy list only for "commercial organisations participating in the EU-US Data Privacy Framework" (section 41). Otherwise a firm needs a safeguard such as ADGM's standard contractual clauses (section 42), or a derogation such as explicit consent (section 44), which the Office of Data Protection expects to be limited to "certain one off situations" (Guidance Part 6). The same guidance says onshore UAE counts as outside ADGM, and the list does not include it.

On my reading, an ADGM firm needs a transfer route even for a cloud region in Abu Dhabi, and should check a US vendor's Data Privacy Framework entry before relying on it. A model on hardware inside ADGM sends nothing out of ADGM (ADGM Data Protection Regulations and AI).

Qatar: a court rule in the QFC, and no consent exception onshore

The Practice Direction quoted at the top was signed by Lord Thomas of Cwmgiedd and Sir William Blair for the QFC Civil and Commercial Court and Regulatory Tribunal (court announcement). It "applies to litigants, their legal representatives, and any legal practitioners who appear in the QFC Court and the RT" (paragraph 2), and it does not bind Qatar's onshore courts. Besides paragraph 12, it encourages court users to "disable chat history or use privacy-protective settings when using AI tools" (paragraph 13), and it warns that "Misuse of AI in breach of confidentiality may result in sanctions or other appropriate measures" (paragraph 14).

The Practice Guidance issued the same day says: "Never input confidential client data or Court evidence into public-facing AI tools" (paragraph 10(iii)). Neither text defines "private, secure". The guidance sets it against "AI tools that store or transmit data externally" and says: "The Practice Direction allows limited use of private, secure AI platforms within authorised systems, where confidential information remains protected" (paragraph 9). As an engineer, I read that as a test the firm must be able to pass on paper: for each tool, where the data goes and who outside the firm can read it.

Onshore, Article 57 of the Law of Advocacy, Law No. 23 of 2006, says: "A lawyer shall not be permitted to disclose any facts or information which comes to his knowledge through his profession, even after expiry of his power-of-attorney, unless such disclosure is intended to prevent the commitment of any crime or misdemeanor or report the occurrence thereof." It has no exception for client consent. The Penal Code punishes a professional who divulges a secret "without the consent of the person concerned with the secret" with up to two years in prison and/or a fine of up to QR 10,000 (Article 332). I found no AI guidance from Qatar's onshore courts, the Supreme Judiciary Council or the Ministry of Justice.

Qatar's data protection law, Law No. 13 of 2016, does not gate transfers abroad: Article 15 forbids a controller from limiting cross-border data flows unless the processing breaks the law or may cause serious damage to the data or to the person's privacy. Article 16 matters more for law firms. Data on "ethnic origin, children, health, physical or psychological condition, religious creeds, marital relations, and criminal offenses" is "Personal Data with special nature", and it "may only be processed after obtaining the permission from the Competent Department". Family and criminal files hold plenty of it. How that permission works for law firms in practice is unclear; I did not find the ministerial decisions.

Firms in the QFC follow the QFC Data Protection Regulations 2021. A transfer outside the QFC, onshore Qatar included, needs an adequacy decision by the Data Protection Office (Article 23(1)), standard data protection clauses (Article 24(2)(B)), or a derogation such as explicit consent after being told the risks, or a transfer "necessary for the establishment, exercise or defence of a legal claim" (Article 24(3)). Whether the United States is on the QFC adequacy list today is unclear; the QFC's data protection page returned a 404 when I checked.

Before the QFC Court, paragraph 12 settles the question for public tools. Onshore, the Law of Advocacy gives no consent route while the Penal Code does, and whether client consent answers the professional rule is unclear. A system that keeps client files inside the firm avoids the question.

Saudi Arabia: written client consent, and a duty to check the platform

Article 23 of the Law of Legal Practice says: "A lawyer shall not disclose any confidential information which has been communicated to him or of which he has become aware in the course of practicing his profession even after the expiration of his power of attorney, unless such non-disclosure constitutes a violation of a Sharia requirement." The English text is the Ministry of Justice's unofficial translation, and the Arabic text governs.

The Rules of Professional Conduct for Lawyers (gazette notice) allow disclosure in five cases, one of which is "the client's written consent to the disclosure" (Rule 21, my translation from the Arabic). As in the UAE Code of Ethics, written consent is the consent route.

The Implementing Regulations of the law (gazette notice) hold the only professional rule I found in the Gulf that tells a lawyer to check a technology provider. Under Article 19, a lawyer who works "through an intermediary electronic platform" must "verify that the platform through which he provides his work complies with the related laws and preserves the confidentiality of his clients' data and does not misuse it" (my translation). The duty falls away for a platform approved by the Saudi Bar Association (Article 19(2)). Whether an AI tool is such a platform is unclear; the words point to platforms that connect lawyers and clients. I read both sets of rules in a compilation by the Saudi Judicial Scientific Society (Qadha), which is not an official government source.

I found no AI guidance from the Ministry of Justice courts, the Board of Grievances or the Saudi Bar Association. SDAIA's Generative AI Guidelines For Public, which are non-binding, say: "Organizations should implement policies for GenAI use that prohibits users from entering classified information into third-party tools" (section 5.4).

The Personal Data Protection Law allows transfers abroad only for listed purposes, with protection "at least equivalent" to the Saudi level on the competent authority's assessment, and limited "to the minimum amount of Personal Data needed" (Article 29). Under the transfer regulation of August 2024, SDAIA is to publish a list of countries with adequate protection (Article 3(1)), and I did not find it. Without that list, a transfer has to fit one of the cases in Article 4(2), with the matching safeguard such as standard contractual clauses, and a risk assessment under Article 7, which also covers sensitive data sent abroad on a continuous or widespread basis. The text does not settle which case fits a firm's routine use of a US AI service. Neither text requires data to stay in the Kingdom; sector rules may, and I did not read them.

None of the six large AI vendors I compared documents storage or model processing in Saudi Arabia (the tools comparison). For a Saudi firm that wants client files to stay in the Kingdom, that leaves a system on infrastructure the firm controls there.

Bahrain, Oman and Kuwait: secrecy rules, no AI guidance

I found no court or bar guidance on AI in Bahrain, Oman or Kuwait. Bahrain's Advocacy Law (Article 29) and Oman's Advocacy and Legal Consultancy Law (Article 47, unofficial translation) forbid disclosure with no consent exception, and Kuwait's law on the profession lists "disclosing the client's secrets" first among breaches of the profession's principles and honour (Article 35, my translation of a lawyer's compilation that I could not check against the Official Gazette). On data, Bahrain's Resolution No. 42 of 2022 lists the United States among the countries personal data may go to without a permit, though the secrecy rule still applies. Oman's executive regulation requires the explicit consent of each person concerned before personal data leaves the country, unless it is anonymised (Article 37, my translation of the Arabic text on a private legal portal), which is the strictest transfer rule I found. The law itself does not apply to processing for the "Execution of a contract to which the data subject is a party" (Article 3(g), unofficial translation). On my reading, that may cover a firm's own client, and it would not cover the other side or witnesses. I found no general data protection law in Kuwait.

What the rules mean for a public chatbot and for a private system

The DIFC guidance says to avoid free conversational tools, and the QFC Practice Guidance says never to put confidential client data into public-facing ones. I found no Gulf text that points the other way, so personal and free accounts are the first thing to close.

A business plan under contract gives the firm a processor that follows its instructions. The file still leaves the firm, though, so the consent and transfer questions above remain. The tools comparison shows which vendors keep data and model processing in the Gulf.

A system the firm runs itself changes what the firm has to show. When the model runs on the firm's own hardware, no outside company processes the file, so there is no transfer and no vendor to check. When it runs in the firm's own cloud account, the firm picks the region and the cloud provider acts as its processor. On my reading, both fit the QFC's "private, secure AI platforms" better than a shared public tool, though the direction does not define the words. On its own hardware, the firm decides who can open a client's file and can show a court or a client where that file has been.

The duty to check what the AI writes does not change with the setup. The ADGM and QFC courts have already acted on unchecked AI citations.

What to put in your firm's AI policy

Keep the points for the places where your firm practises and the courts where it appears.

  1. A written list of approved AI tools, and no client material in personal or free chatbot accounts (QFC Practice Direction paragraph 12, QFC Practice Guidance paragraph 10(iii), DIFC guidance section 4.3).
  2. A data classification with three levels: material allowed in a public tool, material allowed only in a tool the firm controls, and material kept out of AI (UAE Executive Regulations Article 51(1) and the secrecy rules above).
  3. Consent in writing before confidential material goes to an outside AI service: the client's, ideally in the engagement letter, and under the UAE Code that of any other owner of the information (UAE Code of Ethics Article 8(2), Saudi Conduct Rule 21, DIFC guidance sections 4.4 and 4.5). Personal data sent abroad on consent needs the consent of each person it is about (UAE PDPL Article 23(1)(b), Oman executive regulation Article 37).
  4. A file on each AI vendor: where it stores and processes data, whether it trains on firm data, its sub-processors, deletion and breach notice, checked against its terms (Saudi Implementing Regulations Article 19, Qatar data protection law Article 11(8), DIFC guidance section 4.5).
  5. A transfer map: for each tool and each jurisdiction, the route that lets the data leave, or a note that it stays.
  6. An extra gate for health, criminal and family data (Qatar data protection law Article 16, Saudi transfer regulation Article 7).
  7. A check of every citation before it reaches a court or a client, with a record of how it was checked (QFC Practice Direction paragraph 16, QFC Practice Guidance paragraph 5(iv), Arabyads costs judgment paragraph 41).
  8. Disclosure of AI use as each forum requires it: early in the DIFC Courts (guidance section 4.2), on request in the QFC Court (Practice Direction paragraphs 24 to 26), and before an AI document search in ADGM (Practice Direction 2 paragraph 2.85).
  9. A named partner who answers for staff use, with training (UAE Code of Ethics Article 8(6), and the ADGM judge's call in Arabyads for "practical and effective measures" by those "with individual leadership responsibilities").

The AI policy generator on this site turns these points into a first draft. Have a lawyer review it before the firm adopts it.

Questions

Can lawyers in Qatar put client documents into ChatGPT?

Not lawyers who appear before the QFC Court, unless the tool is a private, secure platform. Paragraph 12 of the court's Practice Direction No. 1 of 2026 bars confidential, privileged or protected information from AI tools except on private, secure AI platforms, and its Practice Guidance says never to put confidential client data into public-facing AI tools. I found no AI guidance from Qatar's onshore courts, and the secrecy article of Qatar's Law of Advocacy has no exception for client consent.

Does a DIFC lawyer need client consent before using AI?

For work in DIFC Courts proceedings, the Courts' guidance asks for it. Practical Guidance Note No. 2 of 2023, which applies to parties in proceedings before the DIFC Courts, asks practitioners to get the client's consent before giving confidential information to an AI tool and before using AI material in submissions, to read the tool's terms on personal data, and to avoid free conversational AI tools. The note is guidance only, but the Code of Conduct that requires client confidentiality is mandatory for practitioners in the DIFC Courts.

Has the UAE issued rules for law firms that use AI?

On 29 September 2026 the Minister of Justice launched ten Guiding Principles for the Use of Artificial Intelligence Systems by Law Firms. The press release quotes him saying that professional responsibility cannot be delegated and that people must review and verify AI output. I could not find the text of the ten principles as of 8 October 2026, and the Arabic title calls them guiding, which I read as non-binding.

Can a UAE law firm send client personal data to a US-hosted AI tool?

Under the federal PDPL, personal data may go abroad to a country approved by the regulator, for which I found no published list, or through one of the exceptions in Article 23. For a US-hosted service, the explicit consent of each person whose data is sent is the clearest of those on my reading. A client can consent only for its own personal data: on that route, the other people named in its file, such as the other side, witnesses and employees, each have to consent for theirs. The executive regulations that set the details had not been issued as of 6 October 2026. Firms in the DIFC and ADGM follow their own data protection laws.

Which Gulf country has the strictest rule on sending personal data abroad?

Oman, among the texts I read. Article 37 of the executive regulation of its Personal Data Protection Law requires the explicit consent of the person concerned before personal data leaves the country, unless the data is anonymised so that it cannot be linked to them. The law itself does not apply to processing for the execution of a contract to which the person is a party (Article 3(g)); on my reading, that may cover a firm's own client, and it would not cover the other side or witnesses. I read the regulation in Arabic on a private legal portal and translated it myself.