Egypt is not a member of the European Union and has not enacted a horizontal AI statute comparable to Regulation (EU) 2024/1689. AI governance in Egypt in 2026 rests on three pillars instead: a national policy strategy coordinated by a dedicated council, a general data protection law that reaches AI systems processing personal data, and sector guidance from regulators such as the Central Bank of Egypt. This guide sets out what each pillar requires, how they interact, and what an operator deploying AI in Egypt, or exporting AI products to Egyptian or EU customers from an Egyptian base, needs to address.

Key takeaways

  • Egypt has no comprehensive AI statute as of 2026. Governance flows from the National AI Strategy, first launched in 2021, coordinated by the National Council for Artificial Intelligence (NCAI) under the Ministry of Communications and Information Technology (MCIT).
  • Personal Data Protection Law No. 151 of 2020 is the binding legal instrument that reaches AI systems processing personal data. It requires a lawful basis for processing, consent in most commercial contexts, data subject rights, and cross-border transfer restrictions, supervised by the Personal Data Protection Center (PDPC).
  • The NCAI is a policy and coordination body, not an enforcement authority. It does not currently issue penalties against private operators for AI-related conduct, which distinguishes Egypt's structure from jurisdictions with a designated AI market surveillance authority.
  • Sector regulators, particularly the Central Bank of Egypt for AI used in financial services and credit decisions, layer additional supervisory expectations onto AI systems operating in regulated industries.
  • Egyptian companies placing AI systems on the EU market or whose AI outputs affect persons in the EU must independently assess EU AI Act applicability. Egypt's own regulatory posture does not affect that separate analysis.

The Egyptian regulatory architecture for AI

Egypt's approach to AI governance as of 2026 is strategy-led rather than statute-led. Rather than legislating a horizontal AI framework, the government's primary instrument has been the National AI Strategy, first launched in 2021 under the coordination of the National Council for Artificial Intelligence, itself established under the Ministry of Communications and Information Technology. The strategy sets policy direction across government adoption, workforce development, and sector-level AI applications, and functions as the reference point for how Egyptian public institutions think about AI risk and opportunity, rather than as a source of binding obligations for private operators.

This means that, unlike jurisdictions with a single designated AI regulator, an operator assessing legal exposure in Egypt must look to three separate sources: the National AI Strategy and NCAI coordination as policy context, Personal Data Protection Law 151/2020 as the binding legal floor wherever personal data is involved, and sector-specific supervisory guidance, most developed in financial services, for AI systems operating in regulated industries. General contract and tort law fills the remaining gaps, as it does in most jurisdictions without AI-specific liability statutes.

The practical effect for operators is that compliance analysis proceeds instrument by instrument, similar in structure to jurisdictions such as Switzerland that have also chosen a sector-based approach over a horizontal statute, covered in the Switzerland AI regulation guide on this site. The absence of a single AI law does not mean the absence of legal exposure. It means the exposure is distributed across existing instruments rather than consolidated into one.

The National AI Strategy and the National Council for Artificial Intelligence

The National Council for Artificial Intelligence was established under the Ministry of Communications and Information Technology to coordinate Egypt's AI policy across government. Its central output is the National AI Strategy, first published in 2021, which set out priorities for AI adoption in government services, human capital development, and support for the domestic AI ecosystem. The NCAI has continued to develop and update this strategic direction in the years since, and has represented Egypt in international AI governance conversations, including engagement with UNESCO's Recommendation on the Ethics of Artificial Intelligence, which sets non-binding global principles for responsible AI development that member states are encouraged to translate into national policy.

It is important for operators to understand what the NCAI is not. It is not a market surveillance authority with powers to investigate, fine, or order remediation from private companies deploying AI systems, in the way that Article 70 authorities function under the EU AI Act or that FINMA functions for Swiss financial institutions. It is a coordination and policy body. This means an Egyptian operator cannot look to NCAI guidance as a source of binding compliance obligations in the way it would look to a sectoral regulator or a data protection authority. It should instead be read as an indicator of policy direction: where the National AI Strategy signals priority areas, such as government service automation or specific economic sectors, operators active in those areas should expect closer policy attention and, over time, a higher likelihood of more specific sector rules following.

Personal Data Protection Law 151/2020

Law No. 151 of 2020 is Egypt's general data protection statute and the clearest binding legal constraint currently reaching AI systems in Egypt, wherever those systems process personal data. The law establishes core data protection principles broadly comparable in structure, though not identical in detail, to other national data protection regimes: a lawful basis is required for processing personal data, consent is required in most commercial contexts and must be specific and informed, data subjects have rights including access to and correction of their data, controllers must implement appropriate security safeguards, and transfers of personal data outside Egypt are restricted unless the receiving jurisdiction is assessed as providing an adequate level of protection or another lawful transfer mechanism applies.

The Personal Data Protection Center (PDPC) is the supervisory authority responsible for the law. Any AI system that scores, profiles, ranks, or makes automated decisions about individuals using their personal data, credit assessment tools, recruitment screening systems, or customer risk-scoring agents among them, falls within the law's general scope as a processing activity. Operators should note that Law 151/2020 does not contain a dedicated automated-decision-making provision comparable to Article 21 of the equivalent Swiss regime or Article 22 of the GDPR, meaning the specific rights of notification, explanation, and human review that attach explicitly to automated decisions in those frameworks do not have a direct statutory equivalent in Egyptian law as of 2026. The general consent, fairness, and security obligations of Law 151/2020 still apply to any AI system processing personal data, but an operator should not assume an Egyptian data subject has an explicit statutory right to demand human review of a specific automated decision in the way an EU or Swiss data subject does.

Sector regulation: financial services as the most developed example

Financial services is the sector where AI-adjacent supervisory expectations are most developed in Egypt. The Central Bank of Egypt (CBE) oversees banks and, through Egypt's broader fintech and digital transformation initiatives, has taken an active interest in the governance of algorithmic and AI-driven systems used in credit decisioning, fraud detection, and customer-facing financial services. Banks and other CBE-regulated entities deploying AI in consequential financial decisions should expect their existing prudential and operational risk obligations to extend to AI systems, in a manner structurally similar to how FINMA in Switzerland or national competent authorities elsewhere apply existing supervisory frameworks to AI rather than creating a separate AI-specific regime.

The Financial Regulatory Authority (FRA), which oversees non-bank financial services including insurance, leasing, and capital markets activity, occupies a parallel role for AI systems used outside traditional banking. Operators in either category should treat existing sector compliance obligations, model risk governance, operational resilience, and consumer protection rules among them, as the practical channel through which AI-specific expectations will most likely be enforced in Egypt in the near term, pending any future horizontal AI statute.

Egypt and the EU AI Act

Egypt is not a member of the European Union and is not bound by Regulation (EU) 2024/1689 as a matter of Egyptian law. The Regulation nonetheless has extraterritorial reach that is directly relevant to Egyptian companies with European customers or users. It applies to providers placing AI systems on the EU market, and to deployers whose AI system outputs are used within the EU or affect persons in the EU, regardless of where the provider or deployer is established. An Egyptian software company exporting an AI-enabled product to EU-based businesses, or an Egyptian business process outsourcing operator whose AI tools handle interactions with EU consumers on behalf of a client, is, in respect of that EU-facing activity, potentially a provider or deployer subject to the Regulation's obligations for the relevant risk category, independent of its Egyptian regulatory position.

This matters more, not less, given the Digital Omnibus on AI's entry into force on 27 July 2026, which deferred the Annex III high-risk obligations to 2 December 2027. An Egyptian operator assessing EU exposure should not assume the deferral removes the need for analysis. It changes the compliance timeline for in-scope systems, not whether a given Egyptian company's EU-facing AI activity falls into scope in the first place. For the comprehensive treatment of EU AI Act obligations that would apply to any Egyptian company's EU-facing activity, see the EU AI Act operator obligations guide on agentliability.eu, and for what the Omnibus specifically changed, see the Digital Omnibus explainer on the same site.

What operators should do now

A practical compliance posture for 2026 addresses three areas in sequence. First, map every AI system against Law 151/2020: identify which systems process personal data, confirm a lawful basis exists, and document the consent or other legal basis relied upon, since this is the instrument most likely to generate an actual enforcement inquiry from the PDPC in the near term. Second, if operating in financial services or another regulated sector, review AI systems against existing CBE or FRA supervisory expectations, treating AI governance as an extension of existing prudential and operational risk obligations rather than a separate compliance track. Third, if any AI system's outputs reach EU-based customers or users, conduct a separate EU AI Act scoping exercise on its own terms, since Egyptian compliance status has no bearing on that analysis. Operators building toward eventual EU market access should also track NCAI strategy updates, since Egypt's stated direction of travel, coordination with international frameworks including UNESCO's AI ethics recommendation, suggests continued movement toward more structured AI governance over time, even without a confirmed date for horizontal legislation.

The penalty landscape

Egypt does not have an AI-specific penalty regime as of 2026. The operative enforcement channel is Law 151/2020, which provides for administrative and criminal sanctions, including fines, for data protection violations, with the most serious violations attracting the law's higher penalty tiers. The Personal Data Protection Center can investigate complaints and issue enforcement action against processing activities, including AI systems, that breach the law's core obligations. Sector regulators including the CBE and FRA hold separate supervisory powers, including remediation orders and licensing consequences, for regulated entities whose AI governance falls short of existing prudential expectations. No AI-specific fine structure comparable to the EU AI Act's Article 99 penalty regime, reaching EUR 35 million or 7 per cent of global turnover for the most serious violations, exists in Egypt as of this article's publication.

For AI liability questions that reach beyond Egypt into European markets, including the insurance and underwriting dimensions relevant to any Egyptian company building an EU-facing AI product, the agentinsured.eu coverage desk provides analysis of how European carriers price AI liability risk for cross-border operators.

Frequently asked questions

Does Egypt have a dedicated AI law?

No. As of 2026, Egypt has no single horizontal AI statute comparable to the EU AI Act. AI governance flows from the National AI Strategy, coordinated by the National Council for Artificial Intelligence under the Ministry of Communications and Information Technology, from Personal Data Protection Law No. 151 of 2020 for AI systems processing personal data, and from sector guidance such as Central Bank of Egypt expectations for financial services.

What is the National Council for Artificial Intelligence and what does it do?

The NCAI is Egypt's coordinating body for AI policy, responsible for developing the National AI Strategy and coordinating AI initiatives across government, including engagement with UNESCO's Recommendation on the Ethics of Artificial Intelligence. It is a strategy and coordination body, not a market surveillance or enforcement authority with direct powers over private operators.

What does Personal Data Protection Law 151/2020 require of AI systems in Egypt?

The law requires a lawful basis for processing personal data, consent in most commercial contexts, data subject rights including access and correction, security safeguards, and restrictions on cross-border data transfer. The Personal Data Protection Center supervises compliance. An AI system that scores, profiles, or makes automated decisions using personal data falls within scope, though the law does not contain an automated-decision provision comparable to Article 21 of the EU's equivalent regime.

Does the EU AI Act apply to Egyptian companies?

Egypt is not bound by Regulation (EU) 2024/1689 as a matter of Egyptian law. However, the Regulation applies to providers placing AI systems on the EU market and to deployers whose outputs affect persons in the EU, regardless of establishment. An Egyptian company exporting AI-enabled products or services to EU customers must assess EU AI Act applicability to that activity independently of its Egyptian regulatory position.

References

  1. National Council for Artificial Intelligence (NCAI), Arab Republic of Egypt, under the Ministry of Communications and Information Technology (MCIT). National AI Strategy, first launched 2021.
  2. Personal Data Protection Law No. 151 of 2020, Arab Republic of Egypt. Personal Data Protection Center (PDPC) as supervisory authority.
  3. UNESCO. Recommendation on the Ethics of Artificial Intelligence, adopted November 2021.
  4. Central Bank of Egypt (CBE). Supervisory framework for banks, extending to algorithmic and AI-driven financial services systems.
  5. Financial Regulatory Authority (FRA), Arab Republic of Egypt. Supervisory authority for non-bank financial services.
  6. Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), OJ L, 12 July 2024. Extraterritorial scope under Article 2.
  7. Digital Omnibus on AI, amending Regulation (EU) 2024/1689. Entered into force 27 July 2026.