
For a brief period in June 2026, access to two advanced artificial intelligence models was restricted under United States export rules, and then restored within weeks following constructive discussion between the developer and the authorities. The episode was short and resolved cooperatively. Its significance is likely to endure, because it marked something genuinely new: a large language model treated as a strategic asset in its own right, governed by the law of export rather than the law of software. Few developments illustrate more clearly how quickly legal thinking has adapted to this technology.
That is not the story usually told about artificial intelligence and the law. The familiar version holds that the technology has outpaced its regulators, leaving legislatures drafting rules for a world that has already moved on. The past eighteen months suggest something more encouraging. Courts, agencies and legislatures around the world have produced a remarkable number of workable answers, and they have done so largely by asking established questions more precisely rather than by inventing new ones. For businesses, that means there is now enough clarity to act with confidence.
Provenance is becoming the answer
Intellectual property remains the largest category of AI litigation, and a coherent principle is emerging from it. Courts have proved receptive to fair use where training material was lawfully acquired, and considerably less so where its origins were doubtful. Early decisions such as Thomson Reuters v. ROSS Intelligence turned on whether the training use competed directly with the original product, and subsequent author litigation has focused closely on how material was obtained. Several significant settlements have followed. Europe has reached a similar destination by another route, obliging providers of general-purpose models under the AI Act to summarise their training content and to respect copyright opt-outs.
The effect in both places is the same, and it is constructive. Provenance has become the organising question, and a licensing market is forming around instruments the profession already understands well: permitted datasets, territory, duration, model restrictions, royalties, audit and deletion rights. The ownership question on the other side of the model has settled more quietly. Protection follows meaningful human contribution, and the United States Patent and Trademark Office confirmed in November 2025 that an AI system cannot be named as an inventor, though AI-assisted inventions remain patentable where human conception meets the ordinary standard. Due diligence now asks not only who owns the intellectual property, but how it was created and whether generated code carries open-source obligations worth documenting.
The question courts now ask
For a century, when technology caused harm, courts asked who built it or who programmed it. That question serves less well for systems that behave differently each time they run, so courts have begun asking a more useful one: who had the legal duty to control this system at the moment the harm occurred. The reframing does more work than any AI statute yet drafted. It reaches developers, deployers and users according to their actual influence over the system, and it rests on duty, foreseeability and reasonable care, three ideas the law has long understood. Europe considered a dedicated AI Liability Directive and ultimately chose to rely on existing doctrine and the revised Product Liability Directive, and several member states have added helpful refinements concerning access to technical documentation and evidential presumptions.
Agentic systems sharpen the point without altering it. An agent authorised to conclude contracts up to five million that commits to eight raises questions of actual authority, apparent authority, ratification and reasonable reliance, each with centuries of case law behind it. The novelty lies in the failure modes rather than the doctrine, since an agent may exceed its mandate through a prompt-injection attack as easily as through simple error. The practical response is reassuringly familiar: define the mandate, cap the authority, log the actions and insure the gap. Courts are adapting in parallel, giving renewed attention to chain of custody, metadata and provenance now that audio, images and documents can be convincingly generated.
What the machine keeps
Data protection rests on purpose limitation, minimisation and erasure. Models improve with scale and retain the statistical trace of information after the original record has gone, and regulators including the European Data Protection Board are working through what lawful basis, anonymisation and erasure sensibly mean in that setting. They are doing so pragmatically, which is welcome. Established interception and confidentiality statutes are also being tested against AI assistants and chatbots, and are proving more adaptable than expected. One further point deserves attention: prompts, chat logs and agent traces are records, and they may be disclosable in later proceedings. Confidential material entered into a public system may lose its protected character. Nearly all of this is addressed by an acceptable use policy and a retention rule, which together remain the most cost-effective governance step available to any organisation today.
One technology, several rulebooks
Different jurisdictions have chosen different instruments, and each choice has its logic. The EU AI Act is phasing in, with prohibited practices and AI-literacy duties already live, general-purpose model obligations in force, and the high-risk requirements covering employment, biometrics and critical infrastructure sequenced under the Digital Omnibus into 2027 and 2028. That additional preparation time is a practical benefit to anyone using it well. The United States has favoured targeted measures over a single comprehensive statute, with Colorado, New York, California, Texas, Illinois and Connecticut legislating on automated decisions, frontier models, synthetic media, companion systems and child safety, an approach that allows rules to be tested before they are generalised. A model may be trained in one country, hosted in a second, tuned in a third and used in a fourth, and questions of applicable law, competition and market structure are being examined thoughtfully in several forums. Artificial intelligence has become a subject of private international law and trade law at the same moment, which plays to the strengths of cross-border practitioners.
Accountability follows the decision
Artificial intelligence now assists in screening applicants, pricing insurance, assessing credit and prioritising patients. There is an understandable temptation to treat such decisions as objective because they are mathematical, and regulators have gently declined to do so. Existing equality law is proving well suited to reaching automated decisions, and where technology changes roles, ordinary consultation, redundancy and retraining obligations apply as they always have. The principle is a constructive one: the system may generate the decision, and the organisation retains responsibility for how it is used. Explainability has resolved more gracefully than many expected. Regulators have accepted that complete technical transparency may be unattainable and have asked instead for something procedural: what data was used, what testing was done, who approved deployment, what oversight existed and whether the decision can be reviewed.
Legislatures have moved quickest, and with broad consensus, on child safety and non-consensual imagery, in Europe and across many American states. Digital replicas of performers and of the deceased are receiving careful attention, drawing on publicity rights, contract and estate law. The professions have responded in the same spirit. Courts have made clear that verification remains the professional's responsibility, and bar associations and regulators are issuing thoughtful guidance on competence and supervision. Boards are following. Directors are increasingly able to state what systems the organisation uses, what decisions those systems inform, what data feeds them and what happens if something fails. Standards such as ISO/IEC 42001 provide a ready structure, and a documented governance framework is valuable evidence of reasonable care.
The Gulf's quiet advantage
The United Arab Emirates is sometimes described as a jurisdiction still awaiting its AI law. That reading overlooks both what has been built and the order in which it was built. The UAE appointed the world's first Minister of State for Artificial Intelligence in 2017, at a point when the subject was still emerging elsewhere. The National AI Strategy followed, framing artificial intelligence as economic infrastructure and national capability. The UAE Charter for the Development and Use of Artificial Intelligence set out responsible development, privacy, data security, human oversight and compliance with existing law as national commitments, and the country's international AI policy, updated in June 2026, places ethics, safety, sustainability and international cooperation at its centre.
The advantage of that sequencing is considerable. The UAE has clear principles in place, sectoral regulators able to move quickly and proportionately, and the entire existing body of contract, tort, intellectual property, employment, confidentiality, cybersecurity and evidence law applying to artificial intelligence from the first day of deployment. Businesses therefore enjoy legal coverage without a sudden compliance burden, and the country retains the flexibility to legislate precisely where experience shows it is needed. Regulatory patience, in this instance, looks a great deal like strategy.
The financial free zones have advanced the position further. The DIFC's data protection regime was among the earliest anywhere to address the processing of personal data through autonomous and semi-autonomous systems as a distinct question, and ADGM has developed governance guidance along a comparable path. Both offer a common law environment, an English-language judiciary and regulators who engage with artificial intelligence in commercial terms. Add the country's position between Europe, Asia and Africa, its arbitration infrastructure and its substantial investment in data centres, and the picture is of a jurisdiction unusually well configured for the cross-border questions this technology raises. Those questions are already live: a European company deploying a system into the UAE, a UAE company training a model on European data, a DIFC entity procuring a service from an international provider. The work is advisory rather than contentious, and it is available now, well before anyone reaches a courtroom.
The question underneath
It would be tidy to conclude that the central legal question of the AI era is copyright, or privacy, or regulation. It is probably none of them. It is agency, in the old-fashioned sense: when one party's actions may properly be attributed to another. The law has spent centuries deciding when an employee's conduct binds an employer and when an agent's promise binds a principal. Artificial intelligence poses the same question about an actor that is not a person at all. When a machine acts on our behalf, at what point does its action become, in law, our own. That question is being answered steadily and sensibly, by judges, by regulators, by standard-setters and by governments, each within their proper sphere. The printing press prompted copyright to mature; the motor car did the same for tort; the internet reshaped privacy and jurisdiction. Artificial intelligence differs in one respect only, though it is a significant one. It is the first technology to give the tool itself something resembling the capacity to act, and the law is proving equal to it. That should be a considerable source of confidence for anyone building, financing or advising in this field.
For more information and legal consultation reach out to Al Safar and Partners Law Firm at +971 52 758 3267 - reception@alsafarpartners.com or visit https://www.alsafarpartners.com.
Written by: Mr. Niaz Brohi - Partner and & Senior Legal Counsel at Al Safar and Partners Law Firm.