Morocco / Cross-sector
What AI rules apply in Morocco?
No AI statute. Law 09-08 already governs AI processing of personal data, and the CNDP has said so in its own words.
No AI-specific law was identified in Morocco as of August 31, 2026. What it has is a data protection regime from 2009 that the regulator has publicly confirmed applies to AI, and a supervisor actively building the framework that comes next. The CNDP stated in March 2025 that AI processing of personal data is governed by Law 09-08, that automated decisions require citizens to retain access to remedies, and that work toward a formal deliberation on AI processing has begun. This entry is cross-sector because nothing sector-specific exists.
Secondary source
Some requirements on this page rest on Tier 2 reporting rather than the primary text. Treat those as indicative.
Scope
Who this applies to
- Any organization processing personal data of individuals in Morocco, in any sector
- AI systems making or supporting automated decisions affecting individuals
- Public administration and private sector alike; no carve-out exists
- Offshoring, BPO and development operations serving European clients, which may also fall inside the EU AI Act's extraterritorial reach
What pulls a system into scope
- Processing of personal data by an AI system, which brings Law 09-08 and CNDP supervision into scope
- Automated decision-making affecting individuals, where the CNDP emphasizes integrity, transparency, fairness and readability, and insists decisions remain contestable
- Producing AI system output that is used inside the EU, which can pull a Moroccan operator into the EU AI Act under Article 2 regardless of Moroccan law
Obligations
What is actually required
Compliance of AI processing with Law 09-08
CNDP communiqué, 18 March 2025The CNDP states that where they use personal data, AI processing operations are governed by Law 09-08 on the protection of individuals with regard to the processing of personal data. There is no AI exemption and no separate AI regime to comply with instead.
Contestability of automated decisions
CNDP communiqué, 18 March 2025So that citizens always retain access to remedies in the case of automated decisions, the CNDP states these processing operations require particular attention to integrity, transparency, fairness and readability. In practice this means an automated decision has to be explainable well enough to be challenged.
CNDP supervision and authorization
Law 09-08; CNDP mandateThe CNDP monitors compliance with Law 09-08, investigates complaints, and issues authorizations for complex processing. Its stated mission includes ensuring that AI processing of personal data conforms to the law.
Corridor delta
What the labels meanIf you already built for the EU AI Act
An institution that has built to the EU AI Act for Annex III high-risk systems, alongside its existing GDPR program, including Article 22 controls on automated decision-making.
| Dimension | EU AI Act | Morocco | Delta |
|---|---|---|---|
| Underlying data protection regime | GDPR, operating alongside the AI Act. | Law 09-08, drafted on EU data protection principles and in force since 2009. Different text, closely related logic. A GDPR program transfers here better than to any Gulf jurisdiction. | Already covered by EU work |
| Contestability and recourse | GDPR Article 22 rights over solely automated decisions with legal or similarly significant effects. | Law 09-08 carries automated decision provisions predating the GDPR, and the CNDP frames the requirement as citizens retaining access to remedies, with attention to integrity, transparency, fairness and readability. | Already covered by EU work |
| Risk tiers and who assigns them | A full risk-tiered regime with conformity assessment, technical documentation and post-market monitoring. | No risk tiering, conformity assessment or registration duty was identified as of August 31, 2026. | EU is stricter |
| Cross-border reach | Article 2 reaches providers outside the EU when the output of their AI systems is used within the EU. | No equivalent outward reach was identified as of August 31, 2026. For Moroccan operators serving European clients, the binding AI constraint is more likely to arrive from Brussels than from Rabat. | EU is stricter |
| When it bites | A regime and a deadline. High-risk obligations for standalone Annex III systems apply from 2 December 2027, and for Annex I embedded systems from 2 August 2028. | No AI-specific compliance date was identified as of August 31, 2026. The binding date is behind rather than ahead: Law 09-08 has been in force since 2009, and the CNDP stated on 18 March 2025 that it governs AI processing as written. The deliberation in preparation may add detail later, but it is not what makes the obligations apply: a system processing personal data in Morocco sits inside an examinable regime today. | |
| What is coming | High-risk obligations for standalone Annex III systems apply from 2 December 2027. | A CNDP deliberation under development with reference to the EU AI Act, and a National Agency for AI Governance reported as anticipated in late 2026. Neither is adopted, and neither carries a published compliance date. | Does not map |
Instruments
What the requirements rest on
Law 09-08 on the protection of individuals with regard to the processing of personal data
Kingdom of Morocco
Drafted on EU data protection principles and containing automated decision-making provisions that predate the GDPR. For an institution with European compliance experience the substantive requirements are familiar territory.
Promulgated by Dahir n° 1-09-15 of 22 safar 1430 (18 February 2009), published in Bulletin Officiel n° 5714 of 5 March 2009, as recorded by the CNDP. The statute text itself was not separately reviewed for this entry.
Communiqué de presse: IA et protection des données à caractère personnel
CNDP
The regulator saying plainly that Law 09-08 governs AI processing, and announcing that work toward a deliberation has been initiated following an international benchmark and consultation with foreign data protection authorities. It also opens hearings to experts, professional and scientific organizations and civil society, with an address for parties wanting to be heard.
Read in full in the original French on the CNDP website.
Deliberation on AI processing
CNDP
The instrument to watch. Moroccan reporting indicates it is being developed with reference to the EU AI Act and adapted to the Moroccan context, which would make EU-aligned work directly transferable when it lands.
The CNDP communiqué of 18 March 2025 states that work toward such a deliberation has been initiated. No adopted text was identified at the verification date.
Maroc IA 2030 roadmap
Kingdom of Morocco
Policy direction rather than obligation. Notable for its sequencing: Morocco intends to stand up a governance body before enacting an AI statute, which is the reverse of the usual order.
Launched January 2026, translating the July 2025 National AI Conference into an operational framework. Reported in Moroccan and regional press; the roadmap document was not reviewed in primary form.
Bill establishing the National Agency for AI Governance
Kingdom of Morocco
Would be an independent administrative authority working alongside the CNDP on privacy and compliance. Its arrival would move Morocco from indirect regulation toward an enforcement model with a dedicated supervisor.
Introduced April 2024. Formal launch of the Agency reported as anticipated in late 2026. Not adopted at the verification date.
EU-Morocco Digital Dialogue
European Commission and Kingdom of Morocco
Not a source of obligation, but the reason Moroccan requirements are likely to converge toward EU ones rather than diverge. Morocco is the first MENA country with a standing AI governance channel to Brussels.
Launched at GITEX Africa in Marrakech, 8 April 2026, with AI governance within the stated scope.
Enforcement
How this is actually supervised
- Supervisor
- CNDP, created by the same Dahir that promulgated Law 09-08
- Mechanism
- Supervision under Law 09-08: monitoring compliance, investigating complaints, and issuing authorizations for complex processing. AI shortfalls surface as data protection findings, because the CNDP's own deliberation on AI processing was still only initiated as of its communiqué of 18 March 2025.
- Observed to date
- No AI-specific enforcement action identified at the verification date. The CNDP's posture is visibly preparatory rather than punitive: it has run an international benchmark, consulted foreign authorities, and opened hearings.
Action
What to do Monday morning
- 1Treat AI systems as personal data processing under Law 09-08 and bring them into the existing CNDP compliance perimeter, rather than waiting for an AI framework to appear.
- 2Identify every automated decision affecting individuals and check it can actually be explained to the person affected. Contestability is the CNDP's stated concern, and it is testable today under law already in force.
- 3If you serve European clients or your AI output is used inside the EU, assess EU AI Act Article 2 exposure. For most Moroccan operators that is the binding constraint, and it arrives before anything domestic.
- 4Consider responding to the CNDP's call for hearings. It invited experts, professional and scientific organizations and civil society to be heard, which is a rare chance to shape a framework before it is drafted.
- 5Map the AI portfolio against EU AI Act risk tiers now. Moroccan reporting indicates the coming deliberation draws on the EU AI Act, so that mapping is likely to carry over rather than be wasted.
This page tells you what applies. It cannot tell you what you are running.
The Diagnostic maps your actual AI systems against these requirements and returns the gaps in priority order, with the evidence an examiner would ask for. Built once against the most demanding specification you face, it answers the questions in every other jurisdiction you operate in.
Request the DiagnosticWatch list
What would change this verdict
- When the CNDP deliberation on AI processing is adopted, and how closely it tracks the EU AI Act it is reported to draw on.
- Whether the National Agency for AI Governance is established on the reported late 2026 timeline, and how its remit divides from the CNDP's.
- Whether the Digital X.0 framework law, reported as under review by the General Secretariat of the Government, becomes the vehicle for statutory AI obligations.
Questions
Common questions
Does Morocco have an AI law?
No AI-specific law was identified as of August 31, 2026. AI processing of personal data is governed by Law 09-08, which the CNDP confirmed in a March 2025 communiqué. A CNDP deliberation on AI processing is in preparation and a bill to establish a National Agency for AI Governance has been introduced but not adopted.
What does the CNDP require for automated decisions?
That citizens retain access to remedies. The CNDP states these processing operations require particular attention to integrity, transparency, fairness and readability, which in practice means an automated decision must be explainable enough to be challenged.
Does the EU AI Act apply to Moroccan companies?
It can. Article 2 reaches providers established outside the EU where the output of their AI system is used within the EU. For Moroccan offshoring, BPO and development operations serving European clients, EU obligations may bind before any Moroccan AI instrument exists.
If we comply with GDPR, are we covered in Morocco?
For what is in force today, largely yes. Law 09-08 was drafted on EU data protection principles and its automated decision provisions predate the GDPR. That alignment is why Morocco is the easiest MENA jurisdiction to reach from an existing European compliance program.
Verification notes
- The operative position on this page is primary-sourced: the CNDP communiqué of 18 March 2025 was read in full in the original French, and it is the basis for the statements that Law 09-08 governs AI processing, that automated decisions must remain contestable, and that a deliberation is in preparation. The Law 09-08 text itself was not separately reviewed.
- The forward-looking items rest on Tier 2 reporting and were not reviewed in primary form: Maroc IA 2030, the National Agency bill and its reported late 2026 launch, and the Digital X.0 framework law. Treat timelines in particular as indicative.
- The claim that no AI-specific law was identified is a negative one, and negatives of this kind rest on the search rather than on a source. The CNDP's statement that deliberation work has only been initiated supports the narrower point that the CNDP has not itself issued one; it does not establish that nothing AI-specific exists elsewhere in Moroccan law.
- This entry is cross-sector. Financial institutions in Morocco are additionally supervised by Bank Al-Maghrib, whose requirements are not covered here.
Last verified August 31, 2026 by Rabii Agoujgal.
This entry is provided for informational purposes and does not constitute legal advice. Applicability of any regulation, guidance, or standard discussed depends on the facts, deployment context, and relevant jurisdiction. Regulatory positions change; check the verification date before relying on this page.