Skip to content
← All Board Briefs
Operational Frameworks 5 min read

AI Law in Morocco: Complete Guide 2026

No specific AI law in Morocco yet. Here is the real framework: Law 09-08, CNDP, public AI orientations, and concrete obligations for executives in 2026.

Naïm Bentaleb

Naïm Bentaleb

AI Strategy & Governance Advisor

What Is AI Law in Morocco? Complete Guide 2026

Morocco has no specific artificial intelligence law yet. The legal framework rests on Law 09-08 on personal data protection, the Penal Code for digital offenses, and public AI orientations whose exact scope remains to be clarified. Companies therefore operate in a partial legal vacuum, with real obligations but a still-fragmented sectoral regulatory landscape.

An Existing Framework, But Not Designed for AI

Morocco did not wait for an AI law to create legal obligations on the subject. Several existing texts already apply, directly or indirectly.

Law 09-08 is the central text. It governs the collection, processing, and storage of personal data. The National Commission for the Control of Personal Data Protection (CNDP) is the supervisory authority. AI systems that process personal data — automated recruitment tools, conversational agents, customer profiling systems — fall within its scope. The exact extent of this obligation depending on the type of processing should be verified directly with the CNDP or specialized legal counsel.

A recent signal illustrates the stakes: according to a study cited by CIO Mag, 42% of AI users in Moroccan companies import complete documents into uncontrolled external tools. The exact context of this study is not specified, but the trend it describes is consistent with what I observe in the projects I work on. It is a compliance risk that few companies have formalized.

The Moroccan Penal Code covers attacks on computer systems and digital fraud. These provisions apply to damages caused by AI systems, even if the text does not explicitly mention AI.

Morocco has expressed public ambitions regarding artificial intelligence within its development vision. But available strategic orientation documents do not constitute law. They set directions, not obligations. They open public funding and partnerships without creating legal liability for companies.

This is where executives need to be clear-eyed: public orientations create opportunities to access markets and support programs. They do not protect against risks from poorly governed AI deployments.

If you are a CHRO or CEO and want to structure your AI governance approach before regulation forces you to, request a free diagnostic.

What Companies Must Do Today

In the absence of specific AI legislation, responsibility and accountability fall on executives. Here is what is required now.

Verify Declaration Obligations with the CNDP

Law 09-08 provides for declaration or prior authorization obligations for certain personal data processing activities. AI systems that analyze CVs, customer behavior, or sensitive data potentially fall within this scope. The exact nature of the obligation depends on the type of processing: consulting the CNDP or legal counsel for each use case is recommended.

Document Algorithmic Decisions

Law 09-08 provides rights for individuals whose data is processed, including against automated decisions. If your AI system makes decisions affecting individuals — credit refusals, candidate selection, pricing — you must be able to explain and challenge those decisions. This is an obligation, not an option.

Govern the Use of External Tools

The CIO Mag signal is a concrete warning. When an employee uploads a client contract into ChatGPT or a similar tool, the data leaves the company’s perimeter. Responsibility for internal governance and usage compliance remains with the organization. An internal AI usage policy is no longer optional.

As I explained in my analysis on integrating AI into recruitment, risks in HR processes are often the first to materialize, precisely because the data involved is sensitive.

What Is Coming: The European AI Act as a Signal

Morocco is not in the European Union. But Moroccan companies that process data of European residents may be subject to GDPR, depending on the targeting and establishment conditions applicable to their situation. The European AI Act, whose application is progressive, points in the same direction.

Moroccan offshoring companies serving European clients will face contractual pressure to demonstrate compliance with AI Act requirements. It is already appearing in certain tenders.

Morocco will sooner or later need to align its legislation. Companies that anticipate this convergence will have a real competitive advantage in European markets.

For more on the skills to develop in this context, read my analysis on training to work with AI in 2026.

For a complete AI governance framework designed for executives, download the Board Pack AI 2026.

FAQ

Does Morocco have a specific AI law in 2026?

No. There is no law dedicated to artificial intelligence in Morocco at this time. The applicable framework rests on Law 09-08 on personal data protection, the Penal Code for digital offenses, and sectoral texts. Public orientations exist, but they do not constitute binding regulation.

Which authority oversees AI use in Morocco?

The CNDP (National Commission for the Control of Personal Data Protection) is the competent authority for everything related to personal data processing, including automated processing. It can sanction companies that do not comply with Law 09-08.

Can a Moroccan company be subject to European GDPR?

It depends on the situation. A Moroccan company that actively targets European Union residents or processes their data in an offshoring context may be subject to GDPR, depending on the application conditions defined by the regulation. Specialized legal advice is recommended to assess each situation.

What does a company risk by using AI without governance in Morocco?

It faces CNDP sanctions for non-compliant personal data processing, liability for contested automated decisions, and contractual penalties from European clients subject to the AI Act. Reputational risk compounds the legal risk.

Share this brief

Next Step

Ready to structure AI governance in your organization?

Start with an AI Governance Sprint – a 2-3 week diagnostic that gives you a clear action plan.