-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
Egypt has no statutory definition of artificial intelligence. The Egyptian Charter for Responsible Artificial Intelligence (First Edition, 2023), issued by the National Council for Artificial Intelligence (NCAI), describes AI systems through their operational lifecycle rather than through a closed technical definition. The IDSC’s 2024 legislative framework study recommends classifying systems by learning method, technical model and capability tier; that taxonomy is expected to inform the draft AI law currently before Parliament.
Sectoral regulators describe AI by reference to its function within their perimeters. The FRA addresses outcomes such as robo-advisory and automated credit scoring through its fintech frameworks. No Egyptian court has defined artificial intelligence. The Second National AI Strategy (2025–2030) identifies the establishment of a Centre for Responsible AI and the enactment of an AI law as the primary mechanisms for introducing formal AI definitions into Egyptian law.
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
Prime Ministerial Decree No. 2889 of 2019 (Official Gazette, Issue 47 bis, 24 November 2019) established the National Council for Artificial Intelligence (NCAI) under the Prime Minister, chaired by the Minister of Communications and Information Technology, with a mandate to formulate, govern and update the national AI strategy (Art. 2). The first National AI Strategy (launched May 2021) targeted AI for Government, AI for Development, AI for Human Capacity Building and AI for External Relations.
In January 2025 the NCAI launched the Second National AI Strategy (2025–2030). Its mission is to create a sustainable and competitive AI industry, supported by governance, technology, data, infrastructure, ecosystem and talents, to promote Egypt’s development. The Strategy is structured around six pillars: Governance, ICT and AI Infrastructure, Technology, Data, Talents and Ecosystem. The strategic goals include the ICT sector contributing 7.7% of Egypt’s GDP by 2030, 30,000 AI professionals and 250 or more successful AI companies. Key initiatives include developing a national Arabic large language model (the national foundation model), building a domestic data centre with GPU resources, establishing a Centre for Responsible AI, and issuing a Second Edition of the Charter and the AI law.
Prime Ministerial Decree No. 207 of 2026 (Official Gazette, Issue 3 bis “b”, 18 January 2026) restructured and renamed the Council as the National Council for Artificial Intelligence, Quantum Computing and Emerging Technologies. Under the supervision of the Prime Minister and chaired by the Minister of Telecommunications and Information Technology, its membership comprises representatives of the Ministries of Defence; Planning, Economic Development and International Cooperation; Interior; Higher Education and Scientific Research; and Foreign Affairs, Emigration and Egyptian Expatriates, together with the General Intelligence Service, the Administrative Control Authority and three appointed experts. The Council meets monthly and reports every six months to the Prime Minister for submission to the President (Prime Ministerial Decree No. 2889 of 2019, Art. 5). Both the Strategy and the Charter contemplate periodic review.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
No binding AI-specific statute is in force. The principal soft-law instrument is the Egyptian Charter for Responsible Artificial Intelligence (First Edition, 2023), issued by the NCAI. The Charter contains 13 general guidelines for all AI participants and 16 executive guidelines for entities developing, deploying or managing AI systems, covering human-centricity, transparency, fairness, accountability and security. It is not legally binding but is the government’s reference point.
In the absence of an AI act, the following existing instruments apply, though none was enacted specifically with AI in mind:
(i) the Personal Data Protection Law No. 151 of 2020 (PDPL) and its Executive Regulations issued by MCIT Decree No. 816 of 2025;
(ii) the Telecommunications Regulation Law No. 10 of 2003;
(iii) the Anti-Cyber and Information Technology Crimes Law No. 175 of 2018;
(iv) the Intellectual Property Protection Law No. 82 of 2002;
(v) the Consumer Protection Law No. 181 of 2018;
(vi) the Egyptian Civil Code;
(vii) the Labour Law No. 14 of 2025 (in force from 1 September 2025); and
(viii) sectoral frameworks, principally the Central Bank and Banking System Law No. 194 of 2020, the Non-Banking Financial Technology Law No. 5 of 2022 with FRA Board Decrees Nos. 139, 140 and 141 of 2023 – the last of which the Second National AI Strategy specifically identifies as addressing AI in the processing of consumer data in the financial sector – and the Unified Insurance Law No. 155 of 2024.
The main interpretive challenges are: (i) attributing fault when harm arises from an opaque model; (ii) authorship and inventorship concepts confined to natural persons; (iii) a consent-based data protection regime applied to large-scale training data; (iv) reconciling opaque models with evidentiary and explainability requirements; and (v) the absence of legal personality for AI systems, which the Charter confirms must not be granted.
The Government is preparing a draft AI law with the House of Representatives’ Communications and Information Technology Committee. The Second National AI Strategy confirms the draft will prioritise maximising the economic benefits of AI while protecting citizens against high-risk or prohibited AI and will establish a designated regulatory body on enactment. The Strategy also provides for an AI Regulatory Sandbox as a separate governance initiative.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
No general statutory transparency obligation applies to AI. Three sources create practical requirements.
Data protection. Where an AI system processes personal data, the PDPL’s requirements of lawful, purpose-limited processing on the basis of express consent, supported by documentation and record-keeping under the Executive Regulations, effectively require disclosure of that processing to data subjects (Art. 2).
The Charter. End users have the right to know when interacting with an AI system rather than a human (general guideline 2). Persons adversely affected by an AI decision must be able to challenge it on the basis of clear information about the underlying logic (general guideline 4). Developers are directed to prefer interpretable models where minimum accuracy permits (executive guideline 8).
Sectoral supervision. The FRA’s fintech framework under Decrees Nos. 139, 140 and 141 of 2023 imposes governance, auditability and disclosure duties on supervised entities in respect of fintech. The CBE’s electronic banking rules impose audit requirements over outsourced technology generally; those rules are not AI-specific but apply where an AI system forms part of the outsourced service. The Second National AI Strategy’s Governance Pillar identifies developing a comprehensive framework for ethical and responsible AI – including transparency obligations – as a strategic objective; more detailed Charter guidelines and AI law provisions are expected to follow, such as every end user has the fundamental right to know when they are interacting with an artificial intelligence system rather than a human, including, for example, in the case of automated call centres. (general guideline 2)
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
No statute mandates human oversight across all AI. The Charter is the operative framework.
The Charter requires that the final decision is always human; that system owners retain the ability to modify, suspend or withdraw any AI system; and that the specific individuals holding that authority must be designated (general guidelines 10 and 11). Future regulatory frameworks must maintain human oversight throughout the system lifecycle. Deployed systems must be monitored for data drift and models retrained or replaced where drift occurs (executive guideline 12).
For government projects, a prior impact assessment is required, and the Ministry of Communications and Information Technology holds supervisory responsibility, reporting periodically to the Council (executive guidelines 14 and 16). FRA Board Decree No. 57 of 2024, which for the first time regulates robo-advisors for investment in Egypt, is AI-specific: it requires client suitability assessments and gives clients the right to discontinue automated transactions. The Second National AI Strategy confirms that the forthcoming AI law will introduce mandatory human oversight requirements for high-risk AI applications, and the AI Regulatory Sandbox will test oversight models before they are embedded in permanent regulation.
Egyptian law has no equivalent to GDPR Art. 22. The draft AI law is expected to introduce mandatory human oversight for high-risk applications including employment, healthcare and justice.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
No AI-specific anti-bias statute exists. The framework rests on constitutional protections, the Charter and general law.
The Constitution prohibits discrimination and guarantees equality before the law (Art. 53), equal opportunity (Art. 9) and equality between women and men (Art. 11). These apply to algorithmic decisions as much as human ones.
The Charter’s fairness principle requires that no individual be harmed by an AI system; that special protection be given to vulnerable groups including children, persons with disabilities and those of modest economic or educational means; that datasets be checked periodically for bias; that system parameters be recalibrated regularly; and that development teams be diverse. Data must correct for under-representation of minorities; persons adversely affected must be able to challenge outcomes on intelligible grounds (general guidelines 3–5; executive guidelines 11–12). Foreign companies must train models on locally relevant data and respect local customs and social norms before entering the Egyptian market (executive guideline 13).
The Labour Law No. 14 of 2025 applies non-discrimination and equal-treatment protections, as a matter of general employment law and not AI-specific regulation, to employment decisions including those assisted by AI. The Second National AI Strategy’s Data Pillar includes a High-Quality Sectoral Arabic Datasets initiative that directly addresses the root cause of algorithmic bias: it requires diverse, representative and regularly updated datasets to underpin AI development across priority sectors.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
No dedicated AI liability regime exists. The Civil Code, the Consumer Protection Law and contract law apply, with criminal law overlaying deliberate misuse.
Civil liability. Civil Code Art. 163 requires the victim to prove fault, damage and causation, which is difficult where harm emerges from an opaque model. Art. 174 (vicarious liability) may support claims against principals who deploy AI as an instrument of their business. Art. 178 is most directly applicable: it imposes liability on the guardian of things – the person with effective control over a thing whose nature requires special care – who is presumed liable for the harm it causes and escapes liability only by proving force majeure, the victim’s own fault or a third party’s act. The IDSC’s 2024 study identifies this guardianship doctrine as applicable to AI operators. Contractual liability, including warranties against latent defects, governs as between the parties.
Product liability. The Consumer Protection Law No. 181 of 2018 imposes liability on suppliers across the supply chain for defective products; consumer rights cannot be waived. AI-enabled products placed on the Egyptian market fall within this framework.
Allocation. Developer-deployer allocation is primarily contractual. The CBE and FRA outsourcing frameworks are general technology-outsourcing regimes, not AI-specific, but prevent regulated financial entities from contracting away regulatory responsibility to their technology vendors. The IDSC’s 2024 study maps three accountability tracks: developers (direct liability for unlawful use and failure to exercise due care); owners (presumed liability for intentional or negligent harm); and guardians (failure to take required care). The Second National AI Strategy confirms that the forthcoming AI law will establish a formal liability and regulatory structure for AI.
Burden of proof. Under Art. 163 the victim must establish fault, damage and causation.
-
What cybersecurity obligations apply to AI systems?
Article 31 of the Constitution declares the security of cyberspace an integral part of the economic system and national security. No AI-specific cybersecurity instrument exists; obligations arise under the general framework and by sector.
General criminal law. The Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 imposes three core duties on service providers: retaining and storing system logs for 180 consecutive days covering service provider data, content data, communication traffic data and terminal equipment data (Art. 2(1)); maintaining confidentiality of stored data and prohibiting disclosure without a reasoned judicial order (Art. 2(2)); and securing data against hacking or damage (Art. 2(3)). Service providers must also provide national security entities with the technical capabilities to exercise their legal competences (Art. 2, Third). Failure to comply with the retention obligation carries fines of EGP 5 million to EGP 10 million (Art. 33). Unauthorised access (Art. 14), illegal interception (Art. 16), damaging data or programs (Art. 17) and network obstruction (Art. 21) are separately criminalised. Any administrator whose negligence exposes a system to these offences by failing to apply the security arrangements prescribed in the law’s executive regulations faces criminal liability (Art. 29), creating a positive and enforceable security obligation on AI system operators.
Financial services. Banks and payment participants are subject to the CBE’s electronic banking security rules; those rules are not AI-specific but apply to AI-enabled banking services as a matter of general electronic banking regulation. Telecommunications operators are regulated by the NTRA, which is also the competent technical authority for cybersecurity cooperation (Art. 4).
The Charter and the Strategy. AI developers must adopt a documented risk-management methodology covering digital security, privacy, safety and bias throughout the system lifecycle (Charter, executive guidelines 1 and 7). The Second National AI Strategy’s ICT and AI Infrastructure Pillar prioritises building secure, resilient AI infrastructure, including a national data centre with GPU resources and hyperscaler partnerships; the security requirements attached to those infrastructure commitments will set baseline standards for AI systems hosted on that infrastructure.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
AI risk may be insurable in Egypt under the general frameworks. No AI-specific mandatory lines, prohibitions or standard exclusions exist. The Unified Insurance Law No. 155 of 2024 consolidated the sector under FRA supervision and Art. 199 provides the framework for digital insurance and e-policies.
Cyber insurance is the most directly relevant line for AI risk. The FRA has activated its regulatory sandbox for InsurTech, consistent with the Second National AI Strategy’s AI Regulatory Sandbox initiative, allowing digital insurance models to be tested under supervision before full deployment.
The main structural limitation is that no AI-specific policy form exists in the Egyptian market. No Egyptian court has addressed how losses driven by autonomous AI decisions or model error respond under conventional policy wordings. Where legacy wordings are silent on AI-generated loss, coverage turns on the underlying cause and the applicable policy trigger, with no domestic precedent to guide the outcome.
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No. The Intellectual Property Protection Law No. 82 of 2002 assumes a natural-person inventor. Applications before the Egyptian Patent Office must name human inventors. No DABUS-type case has been filed or decided in Egypt.
AI-assisted inventions remain patentable provided a human inventive contribution is identified and named, subject to the standard requirements of novelty, inventive step and industrial applicability. Ownership follows the statute’s employment and commissioning provisions and the parties’ contracts. Purely machine-generated inventions with no identifiable human inventor fall outside the current system.
Businesses conducting AI-assisted research and development in Egypt should document human inventive contribution contemporaneously. The Second National AI Strategy includes an AI Patent Granting System as a specific Technology Pillar initiative, with the stated aims of developing AI-specific patent categories, raising awareness of intellectual property protection in the AI context, and making the patent application process more efficient for AI innovations, and attract investment by providing legal protection and commercialization opportunities for AI inventions.
Legislative change would be required to alter the current position on AI inventorship.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
Egyptian copyright under the Intellectual Property Protection Law No. 82 of 2002 (Book Three) protects original works bearing the author’s personal creative imprint; moral rights are perpetual and inalienable. Machine authorship is not recognised under current law.
Purely AI-generated output without meaningful human creative input is not protected and enters the public domain. Where a human’s creative choices satisfy the originality threshold through substantial selection, arrangement, editing and direction of the output, rather than simply entering a prompt, the work is protectable and authorship belongs to that human. Economic rights are allocated by the statute’s employment and commissioning provisions and by contract.
No Egyptian court has drawn the line between assisted and generated works; the Copyright Office has issued no guidance. The IDSC’s 2024 study identifies this as a legislative gap. The Second National AI Strategy’s Technology Pillar – through the AI Patent Granting System initiative – signals a broader intention to modernise the intellectual property framework for AI, of which copyright reform is a natural part. Output rights should be allocated expressly in commissioning agreements (moral rights are inalienable and cannot be contracted away); document the human creative process and rely on database protection, trade secrets and unfair competition as complementary protections, and it also provides that Egypt is aiming to attract investment by providing legal protection and commercialization opportunities for AI inventions.
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
No AI-specific employment regulation has been issued. Three layers of existing law govern.
Labour law. The Labour Law No. 14 of 2025 applies its non-discrimination and equal-treatment protections, as a matter of general employment law and not AI-specific regulation, to employment decisions including AI-assisted hiring, performance assessment and termination. Any decision must satisfy the law’s procedural and substantive requirements regardless of whether it was generated by a human or a model.
Data protection. Employee monitoring, CV screening and performance analytics constitute personal data processing under the PDPL, requiring a lawful basis, purpose limitation, proportionality and transparency. Biometric and health data attract the heightened sensitive-data regime (Art. 12). Employee monitoring specifically – including facial recognition attendance and productivity tracking – requires specific authorisation where it involves sensitive personal data. Full PDPL enforcement from 1 November 2026 applies to all employers.
Charter principles. AI systems should not be designed primarily to replace human labour. Where job losses are an inevitable consequence of a beneficial system, the owner must ensure a just transition, including retraining and access to new employment opportunities (general guideline 6). The Second National AI Strategy’s Talents Pillar targets 30,000 AI professionals by 2030 through structured upskilling and reskilling programmes across all sectors, which directly informs the just-transition obligations contemplated by the Charter. No rules on algorithmic management or collective consultation currently exist.
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
Egypt’s data protection regime became fully operational on 1 November 2025 when the PDPL Executive Regulations (MCIT Decree No. 816 of 2025) came into force. A one-year grace period runs to 1 November 2026. The Personal Data Protection Center (PDPC) is the supervisory authority;
The following features directly affect AI development and use, including the use of training data.
Pre-authorisation. Processing personal data generally requires a PDPC licence or permit with volume-based fees, differing materially from GDPR self-assessment and directly relevant to AI training pipelines that ingest personal data at scale.
Consent-centric. The regime requires consent for most processing (Art. 6), creating tension with bulk AI training data practices; publicly available data is not exempt.
Cross-border transfers. A PDPC licence or permit is required for any cross-border transfer, issued for transfers to countries with equivalent protection; licences are country-specific, constraining cloud-based model training and inference.
Sensitive data. The PDPL imposes enhanced requirements for processing sensitive personal data, including health and biometric data, and provides additional protections for children’s personal data (Art. 12). AI systems trained on or outputting such data face specific authorisation requirements.
Breach notification. The PDPC must be notified within 72 hours of a breach, or immediately where the breach concerns national security (Art. 7). Affected individuals must be informed within three working days.
Financial services carve-out. Data held by the CBE and its supervised entities is governed by banking confidentiality rules, not the PDPL. Bank-deployed AI is regulated by the CBE framework; non-bank fintech AI falls under the PDPL.
The PDPC has not yet issued AI-specific guidance. The Second National AI Strategy’s Data Pillar includes a specific initiative to optimise the PDPL in line with global leading practices in the field of AI, indicating that the PDPL itself is expected to be updated to better accommodate AI development and training workflows.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
No dedicated scraping regime exists. Exposure arises across four bodies of law, making unlicensed scraping for AI training a high-risk activity.
Intellectual property. Reproducing protected content to build training data engages the reproduction right under Law No. 82 of 2002. Copyright exceptions are a closed list with no text-and-data mining carve-out; databases are protected works. Unlicensed scraping of protected content is infringement.
Privacy. The PDPL does not exempt publicly available personal data: scraping personal data from public websites is processing, requiring a lawful basis and the relevant licences and permits under the Executive Regulations.
Criminal law. The Anti-Cyber and Information Technology Crimes Law No. 175 of 2018 criminalises unauthorised access. Scraping that bypasses authentication walls, rate limits or access controls risks prosecution for unlawful access (Art. 14).
No Egyptian court has ruled on AI-training scraping. The Second National AI Strategy’s Data Pillar includes a High-Quality Sectoral Arabic Datasets initiative that aims to create openly available, government-curated datasets for AI development, which over time may reduce the pressure to scrape protected or restricted sources. Disputes are currently managed contractually and through technical blocking.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
Under Egyptian law, a prohibition on data scraping contained in a website’s Terms of Use is generally enforceable against users who are bound by those terms. Pursuant to Article 147 of the Egyptian Civil Code, a valid contract has the force of law between the parties, meaning that users who have accepted the Terms of Use are required to comply with its provisions, including any restrictions on automated data scraping.
In addition, Article 148 requires contracts to be performed in accordance with their terms and in good faith. Accordingly, a user who deliberately engages in data scraping in violation of the agreed Terms of Use may be considered to have breached their contractual obligations.
Where such a breach causes harm to the website operator, the operator may seek compensation under Article 221 of the Egyptian Civil Code. Under this provision, the court assesses the amount of compensation where it has not been predetermined by the contract or by law. Compensation may include both the actual loss suffered and any loss of profit, provided these are the natural consequence of the breach. In the absence of fraud or gross negligence, compensation is generally limited to damages that were reasonably foreseeable when the contract was concluded. Operators should pair express prohibitions with affirmative acceptance flows and technical access controls.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
Egypt has no single AI-specific regulator with direct enforcement powers. A national coordination body works alongside sector-specific enforcers.
The Council. The National Council for Artificial Intelligence, Quantum Computing and Emerging Technologies was established by Prime Ministerial Decree No. 2889 of 2019 and restructured by Prime Ministerial Decree No. 207 of 2026. Chaired by the Minister of Communications and Information Technology, under the Prime Minister, its mandate includes formulating and updating the national strategy, recommending legislative changes and reviewing protocols and agreements concluded by State entities in the AI field, with an opinion due within one month, security and oversight bodies excepted (Prime Ministerial Decree No. 2889 of 2019, Art. 2, as amended). The Council meets monthly and reports every six months to the Prime Minister for submission to the President (Prime Ministerial Decree No. 2889 of 2019, Art. 5). It has no enforcement powers.
Sectoral enforcement. The Ministry of Communications and Information Technology supervises government AI projects for Charter compliance. Enforcement sits with the sectoral authorities, none of which holds an AI-specific mandate: the PDPC (warnings, licence suspension or revocation, and inspectors with judicial-officer status under PDPL Art. 34); the NTRA for telecommunications; the CBE and the FRA applying their general supervisory powers to AI-enabled financial activity; and the Consumer Protection Agency, the Egyptian Competition Authority and ITIDA within their respective sectors. These are not exhaustive.
The Second National AI Strategy’s Governance Pillar specifically calls for establishing a Centre for Responsible AI as a dedicated body with authority to ensure AI compliance, assess AI capabilities and manage the interconnections between AI actors. This is the anticipated dedicated enforcement mechanism, and the draft AI law is expected to settle its powers and mandate in full.
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
AI adoption has moved from pilots to production. Financial services leads: fraud detection, anti-money-laundering, credit decisioning and customer service automation are embedded across banks and licensed fintechs. Among other sectors adopting AI: Telecommunications operators run AI at network and customer scale., Manufacturing and Logistics sectors are embedding AI systems in their workflows to improve efficiency, and in E-commerce, AI customer support chatbots are being adopted at a very high pace. Egypt’s outsourcing and business-process sector increasingly delivers AI-enabled services internationally.
The Second National AI Strategy (2025–2030) targets the ICT sector contributing 7.7% of Egypt’s GDP by 2030, 30,000 AI professionals and 250 or more successful AI companies across priority sectors including healthcare, government, energy, culture and tourism, judiciary, BPO (commercial/Emergency), agriculture, manufacturing, education, transport and smart cities. The Strategy’s Technology Pillar is anchored on developing a national Arabic large language model as a foundation for sector-wide AI deployment.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
AI use in the Egyptian legal sector is growing. Legal research and summarisation, first-draft generation, Arabic-English translation, document review and knowledge management are the most common applications. Leading firms have moved from experimentation to structured AI programmes with usage policies and mandatory human verification of all outputs. In-house teams in banking, telecommunications and large corporates are among the most active users.
Three regulatory concerns stand out. Confidentiality: feeding client information into uncontrolled public AI tools breaches professional secrecy obligations under the Advocates Law (Law No. 17 of 1983, as amended) and client confidentiality undertakings. Data protection: personal data in prompts, training sets and outputs is regulated under the PDPL, with the November 2026 enforcement deadline applying to law firms as to any other controller. Accuracy: AI output must be independently verified; responsibility for the advice remains with the lawyer and cannot be delegated. The Second National AI Strategy’s Ecosystem Pillar and Talents Pillar both identify the legal and professional services sector as part of the broader AI ecosystem to be developed, and the forthcoming AI law will create a wave of new advisory work on AI governance, procurement and compliance.
The Egyptian Bar Association has not issued guidance on AI-assisted practice. No court has ruled on the question.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
Five key challenges
- Regulatory uncertainty: the AI bill, PDPC practice and sectoral expectations are all still developing, requiring advice from first principles rather than settled rules.
- Confidentiality and data protection: everyday tool use creates professional secrecy and PDPL exposure, with a hard enforcement deadline of 1 November 2026.
- Accuracy: hallucination risk – compounded by the difficulty of Arabic-language legal research in a civil-law system – places the entire verification burden on the lawyer.
- Fee model pressure: as research, drafting and document review compress in time, billing must shift toward judgement, strategy and client relationships.
- Access to primary sources: Egypt currently lacks comprehensive digital repositories of statutes, regulations and official publications in machine-readable form, limiting AI accuracy on Egyptian law and creating a market-specific hallucination risk the Second National AI Strategy’s Data Pillar is intended to address over time.
Five key opportunities
- Productivity gains across research, due diligence and bilingual drafting.
- A new advisory market: AI governance frameworks, PDPL compliance, AI procurement and development contracts, and AI aspects of mergers, acquisitions and financing transactions.
- Turnaround and consistency: routine tasks such as first-pass document review, translation and summarisation are completed faster, meeting client deadlines that were previously unworkable, while standardising drafting and review approaches across matters reduces the risk of inconsistent positions or overlooked precedent.
- Institutional knowledge: AI converts deep precedent archives into a queryable and usable asset.
- National foundation model: the Second National AI Strategy’s national Arabic large language model initiative, once operational, is expected to materially improve the quality and accuracy of Arabic legal AI tools, directly addressing the accuracy and hallucination challenges that currently limit adoption.
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
AI legislation. The draft AI law prepared with the House of Representatives’ Communications and Information Technology Committee is on Parliament’s agenda. The Second National AI Strategy confirms the expected deliverables: the AI law, implementing bylaws and a designated regulatory body. Enactment would introduce statutory AI definitions, a structured enforcement authority and mandatory human oversight for high-risk applications.
Data protection enforcement. The PDPC licensing portal, data protection officer registration and first enforcement decisions arrive with the expiry of the grace period on 1 November 2026. The PDPC’s early positions on training data, cross-border model workflows and breach notification standards will set practical compliance benchmarks more rapidly than any other instrument. The Second National AI Strategy’s Data Pillar includes optimising the PDPL for AI, so further regulatory evolution is expected.
Institutional deepening. The Second National AI Strategy calls for establishing a Centre for Responsible AI, issuing a Second Edition of the Charter and activating an AI Regulatory Sandbox – all within the Governance Pillar. The Council’s expanded mandate over quantum computing and emerging technologies will produce further legislative recommendations. The FRA and CBE, applying their general supervisory mandates, will raise governance expectations for AI-enabled activity within their perimeters. Intellectual property reform addressing AI-generated works remains an expected development; the Strategy’s AI Patent Granting System initiative is the most concrete signal.
Strategy delivery. The national Arabic large language model and the domestic data centre programme are the most capital-intensive near-term commitments.
Egypt: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in Egypt.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?