Skip to content
← All Board Briefs
Operational Frameworks 5 min read

AI Law in Morocco: Legal Framework and Stakes

Morocco has no dedicated AI law yet. Here is the applicable legal framework, real business risks, and what is being prepared.

Naïm Bentaleb

Naïm Bentaleb

AI Strategy & Governance Advisor

What Is AI Law in Morocco? Legal Framework and Stakes

Morocco does not yet have a specific artificial intelligence law. The applicable legal framework rests on existing texts: Law 09-08 on personal data protection, Law 05-20 on cybersecurity, and the orientations of the Morocco Digital 2030 Strategy. Regulatory work is underway, but no dedicated AI legislation is yet in force.


What Exists Today

Morocco is not in a legal vacuum. Several texts already govern AI uses, even without naming them explicitly.

Law 09-08 on Personal Data

This is the most directly applicable text. Any AI solution that collects, processes, or analyzes personal data of Moroccan citizens falls under this law. The National Commission for the Control of Personal Data Protection (CNDP) is the supervisory authority. It has already published recommendations on data use in automated systems.

For an HR director deploying a CV screening tool or a candidate evaluation system, this law applies. Consent, processing purpose, and data subjects’ right of access are real obligations, not theoretical ones.

Law 05-20 on Cybersecurity

Adopted in 2020, it creates a framework for information system security for vital infrastructure operators. Companies integrating AI into critical infrastructure, whether energy, finance, or telecommunications, have enhanced security obligations. The General Directorate of Information Systems Security (DGSSI) is the competent authority.

Morocco Digital 2030 Strategy

This is not a law. It is a government orientation framework. It sets ambitions for digitizing public administration, developing digital skills, and making Morocco attractive for technology investments. AI is mentioned as a lever, without associated specific regulation.


What Is Being Built

Morocco is watching. And it is not alone in feeling its way.

At the African level, few countries have adopted dedicated AI legislation. Countries like Rwanda and Kenya have moved faster on specific AI frameworks. Egypt has published a national AI strategy with more detailed governance mechanisms. Morocco sits in the upper tier of the continent: it has an operational data protection authority, a recent cybersecurity law, and a national digital strategy. What it still lacks is a dedicated AI regulatory layer.

In Europe, the AI Act is now in force. Moroccan companies operating with European partners or exporting services to the EU are already indirectly affected. If your client is Belgian or French, their Moroccan supplier must align.

This is something I observe directly in projects I run between Casablanca and Brussels: compliance with the European AI Act is becoming a contractual requirement, even for providers outside the EU.

I have built a diagnostic framework to help executives assess their AI regulatory exposure, on both the Moroccan and European sides. Download the AI Board Pack 2026.


What This Means Concretely for Your Business

Three Real Risks Today

First risk: ungoverned AI. Teams using consumer AI tools to process client or HR data without internal policy. The CNDP can intervene. This is not hypothetical.

Second risk: responsibility and accountability when automated decisions go wrong. If an AI system rejects a loan, screens out a candidate, or generates a medical recommendation, who is responsible? Current Moroccan law does not clearly answer this question. In case of dispute, common law applies, with all the uncertainty that entails.

Third risk: misalignment with your European partners. As I analyzed in my piece on AI’s role in business, AI governance requirements are now flowing up through contractual chains. Your European client will soon ask for a documented AI policy.

What You Should Do Now

First, map your current AI use cases and identify which ones process personal data. Second, check your compliance with Law 09-08 for those uses. Third, if you have European clients, read the AI Act risk categories and determine where your tools sit.

This is not a six-month project. An initial diagnostic can be done in a few weeks.

If you want to structure this quickly, request an AI regulatory diagnostic.


Morocco vs Other African Countries: Where Do Things Stand?

Morocco has the foundations. Recent signals show that use is accelerating: players like Maroc Cloud are deploying AI tools in enterprise settings, and infrastructure partnerships are forming to build the necessary computing capacity. Regulation will need to keep pace.

As I analyzed in my article on AI tools for businesses in 2026, the question is no longer whether AI is entering Moroccan organizations. It already has. The question is whether executives have a framework to govern it.


FAQ

Does a specific AI law exist in Morocco?

No. As of August 2026, Morocco does not have a dedicated artificial intelligence law. Uses are governed by Law 09-08 on personal data, Law 05-20 on cybersecurity, and common contract and civil liability law.

Does the EU AI Act apply to Moroccan companies?

Not directly. But if your company provides services to clients established in the European Union, or if your AI tools process data of European residents, you are indirectly affected. Your European clients may impose contractual requirements aligned with the AI Act.

What is the CNDP’s role in AI regulation?

The CNDP is the competent authority for everything related to personal data, including in AI systems. It can audit, sanction, and issue recommendations. It is currently the most active institution on AI questions in Morocco, even though its mandate does not cover AI in its entirety.

When will Morocco have an AI law?

No official date has been announced. Morocco’s regional African dynamic and its international commitments, particularly its partnerships with the EU, should accelerate this work in the coming years. In the meantime, the existing framework applies.

Share this brief

Next Step

Ready to structure AI governance in your organization?

Start with an AI Governance Sprint – a 2-3 week diagnostic that gives you a clear action plan.