
Six-Rule Gatekeeper: Ensuring Outbound AI Calling Compliance in the UAE
A Compliance Warning in Dubai: Where the Real Risk Lies
Consider a scenario where a CX leader in Dubai receives a formal warning from Dubai Economy. The reason: an outbound AI-driven telemarketing call triggered a hefty fine, despite the customer’s written consent. The culprit was a missed Do Not Call Registry (DNCR) check—a technical, not human, gap. This is not an isolated case. In 2025 alone, 159 companies were fined AED 50,000 each for telemarketing violations, according to industry analysts. The costs for individual missteps are high, but the reputational fallout can be even steeper.
The Six-Rule Gatekeeper: Why Real Compliance Needs a Workflow
The regulatory framework for outbound telemarketing in the UAE is technology-neutral. Whether a call is placed by a human or an AI, compliance failures are treated the same. What sets apart companies that avoid fines from those that don’t? The answer is the 'Six-Rule Gatekeeper': unless all six rules are enforced automatically and auditable at workflow level, risk remains. Cabinet Resolutions 56/2024 and 57/2024 define the obligations; the enforcement is strict, as recent disconnections and fines confirm.
Rule 1: Opt-In and DNCR—Written Consent Alone is Not Enough
Every outbound call, regardless of prior consent or existing customer relationship, must be screened against the UAE’s National Do Not Call Registry (DNCR) before dialling. The DNCR takes precedence over written opt-ins—even if a customer has consented, if their number is listed, the call is prohibited. According to industry analysts, calling a DNCR-listed number triggers fines starting at AED 50,000 for a first offence. The only secure technical approach is an automated, up-to-date DNCR check integrated into the outbound workflow. Manual or ad hoc checks are not defensible if challenged.
Common error: Companies rely on static consent records or fail to re-check the DNCR before each call. Regulatory practice is clear: the DNCR always overrides written permission.
Rule 2: Time Windows—09:00 to 18:00, UAE Time Only
Outbound marketing calls are permitted strictly between 09:00 and 18:00 (UAE time). Calls placed outside this window are direct violations, regardless of customer preferences or campaign urgency. To enforce this, the technical system must block any outbound call attempts outside these hours. Relying on agent discipline or manual scheduling is not sufficient; only workflow-level automation can guarantee compliance.
Common error: Overlooking time zone differences in multinational operations, or allowing campaign tools to execute calls during maintenance or off-hours.
Rule 3: Only Licensed UAE Numbers—The VoIP Trap
Every outbound telemarketing call must originate from a local UAE number that is registered to the company’s own commercial licence, with e& or du. Private SIM cards, unregistered VoIP numbers, or overseas lines are explicitly forbidden. Using any unauthorised number is a fineable breach.
Technical enforcement requires integration with licensed SIP trunks assigned to the company, not generic VoIP accounts. Systems should automatically validate the origin number before placing calls.
Common error: Attempting to use cloud-based or international VoIP providers without proper local registration, or failing to update number ownership records after organisational changes.
Rule 4: Identification, Purpose, and Recording—Script Blocks Matter
At the start of every marketing call, the caller must clearly state the company’s identity, the purpose of the call, and inform the customer that the call is being recorded. This applies to both human and AI-led calls. The script must include these elements verbatim, and technical controls should prevent the call from continuing if the introduction is incomplete or deviates from the approved text.
Common error: Allowing agents or bots to improvise or skip the compliance block, or failing to update scripts after regulatory changes. Recording notices must be clear and documented in the call log.
Rule 5: Explicit Permission to Proceed—No Assumptions
Before presenting any offer or pitch, the caller must ask the recipient for explicit permission to continue. This step must be documented in the call record. While the precise legal language may vary, best practice is an unambiguous prompt and a logged response before moving forward. Without this, even a technically perfect workflow can be found non-compliant if audited.
Common error: Embedding the consent request too late in the call or relying on implied consent. Systems should enforce a mandatory stop until permission is received and logged.
Rule 6: Human Review—Respecting the Right to Refuse AI
Under the UAE’s Personal Data Protection Law (PDPL, Federal Law 45/2021, Articles 17/18), recipients have the right to refuse interaction with an AI caller or to request immediate handover to a human. Companies must provide a documented process for escalation and ensure that refusals are acted upon without delay. No public documentation as of August 2026 provides further technical detail, but the legal requirement is clear.
Common error: Failing to log or act on requests for human review, or treating them as optional. The workflow must enable and record immediate escalation.
Enforcement in Practice: Fines, Disconnections, and Escalation
The regulator’s approach is visible in public enforcement data. Since August 2024, over 9,400 numbers have been disconnected for violations, with AED 19 million in fines issued. Fines range from AED 10,000 to AED 150,000 per violation, escalating with repeat offences. Most commonly, breaches involve missed DNCR checks, calls outside the permitted window, or unauthorised use of phone numbers. The enforcement is systematic and, in many cases, automated.
WhatsApp Messaging: A Legal Alternative—With Limits
WhatsApp Messaging is permitted for customer outreach in the UAE, provided specific compliance steps are met (such as double opt-in, approved message templates, and clear unsubscribe options). However, current regulatory guidance indicates that WhatsApp Calls are not authorised for telemarketing purposes in the UAE, even if technically feasible (see also industry analysts). Misunderstandings here are common and can trigger regulatory action. For outreach, messaging—when done correctly—is a compliant route; voice calls in this channel are not.
Where Amira Stands on This
With Amira, companies reduce regulatory risk and ensure auditability by automating every compliance step at the workflow level. Features such as licensed SIP trunk integration, automated DNCR checks, and instant human handover are built to meet UAE requirements as standard. Regular test calls and process logs provide the evidence regulators expect. If you want to see how this works with your own processes, book a 60-minute demo.
Get Amira Weekly
AI in customer service, from the Gulf – one email every Friday. No spam, unsubscribe anytime.
By subscribing you agree to our privacy policy.



