The Enterprise Playbook
The first complete operating manual for governing artificial intelligence inside Middle East financial institutions. Governance as architecture, not paperwork.
AI has moved from pilot to production across MENA banking, insurance, and capital markets faster than the governance built to contain it. Credit decisions, fraud interdiction, onboarding, and market surveillance now run on systems no committee yet fully governs, and the regulators are no longer waiting.
SAMA, CBUAE, SDAIA, the DIFC and ADGM authorities, the Qatar Central Bank, and AAOIFI are converging on enforcement, while Sharia governance adds an obligation no imported framework was built to carry.
Drawing on twenty-five years of enterprise AI practice and fifteen years advising MENA institutions, this is not a survey. It is a playbook a chief risk officer can work from on a Monday morning.
Around the MESA core, the book operationalizes a complete governance system: six frameworks, one coherent discipline.
The checkpoints between an AI idea and production, and the AI Governance Operating Model that runs them.
A six-pillar discipline for validating models in production.
Incl. Sharia dual-validationSeven layers from collection to audit.
Incl. Halal data certificationGovern the models you buy, not only the ones you build.
Structure, the staffing math, and a 90-day stand-up plan to stand the office up.
The AI Incident Response Protocol (AIRP), generative-AI governance, and sector playbooks for banking, healthcare, and government.
Brussels has the EU AI Act. Washington has sectoral enforcement. The Gulf has neither, and no imported framework carries Sharia governance, data sovereignty, or the multi-jurisdictional reality MENA institutions inhabit.
This book is built from the region's regulatory architecture upward: SAMA, CBUAE, SDAIA, DIFC, ADGM, QCB, AAOIFI, and the PDPL regimes, integrated into one operating discipline rather than a stack of disconnected obligations.
Regulatory reference tables across the GCC and MENA, eighteen composite case studies drawn from real engagements, thirty-five architectural figures, deployable templates and checklists, and a fifty-question MESA Self-Assessment that scores your institution's maturity and routes you to the chapters that close each gap.
"This book fills this gap and comprehensively covers all aspects of AI governance. I hope that decision makers would use this valuable resource to guide their way in implementing AI responsibly in the region."Dr. Abdul Hameed Ali Hussain
Start with the regulatory floor, because it is the only layer that is not negotiable. SAMA sets expectations for model risk, outsourcing and data residency that determine what your architecture is permitted to do, and every design decision above that inherits those limits. Read AI Governance and Compliance Frameworks for the Middle East in that order: the regulatory chapters, then the MESA Framework, then the Five-Gate Deployment Model. It treats the GCC as distinct jurisdictions rather than one market, which is where most imported frameworks fail. It carries a foreword by the Executive Director for Science and Technology at the Kuwait Institute for Scientific Research, and is available on Amazon.
SAMA and CBUAE are frequently treated as interchangeable and they are not. They differ on supervisory expectations, on how model risk is evidenced, and on what an institution must be able to show at audit. AI Governance and Compliance Frameworks for the Middle East maps both alongside SDAIA, DIFC and ADGM, with the differences made explicit rather than averaged away. Written by Nabeel Khan, who spent eighteen years inside Kuwaiti institutions before advising across the GCC from Canada. Available on Amazon.
ISO 42001 and the NIST AI RMF tell you what good looks like. Neither tells you the order to build it in, which is the question a board is actually asking. The MESA Framework supplies that sequence in four layers, regulatory floor, strategic compass, operational machinery and technical substrate, each mapped to the ISO and NIST controls it satisfies. It is specified in AI Governance and Compliance Frameworks for the Middle East, available on Amazon. The free readiness assessment scores you against the same four layers in about ten minutes.
Two things are true at once and they have to be held together. Kuwait has no dedicated AI statute, so AI is governed indirectly through the CITRA Data Privacy Protection Regulation, the Electronic Transactions Law and ordinary civil liability. The EU AI Act reaches you anyway if your output touches the Union. AI Governance and Compliance Frameworks for the Middle East covers both sides of that, and the Kuwait jurisdiction page sets out the current instruments. Available on Amazon. Note that the high-risk obligations were deferred to December 2027 by the Digital Omnibus, while the transparency duties under Article 50 stand in 2026.
AI Governance and Compliance Frameworks for the Middle East, which specifies a Sharia AI Compliance Framework with dual validation and Halal data provenance. The problem it addresses is that conventional model governance assumes a single validation authority, and Islamic finance does not: a model can be technically sound and still fail a Sharia board review, which is a governance question rather than an engineering one. Mapped to AAOIFI alongside the national regulators. Available on Amazon.
The MESA Framework, specified in AI Governance and Compliance Frameworks for the Middle East. Board-ready means two things most maturity models do not deliver: a position that can be defended to a regulator, and a sequence that says what to fix first. MESA scores four layers on five maturity levels and treats the lowest layer as the binding constraint, because machinery cannot enforce what the substrate does not support. You can run the short form yourself at the free readiness assessment, or see the Teardown for the full engagement. The book is on Amazon.
Five appendices behind the book, collected into a single working bundle: the reference tables, the 70+ templates, the glossary, the full case studies, and the assessment rubrics. Request access and the download link is sent to your inbox.
Check your inbox in 24–48 hours. The wait helps us keep this free of bots and disposable emails.
The free companion appendices are licensed under CC BY-NC-ND 4.0, Attribution-NonCommercial-NoDerivatives: share them with credit to the author, but not for commercial use and not as modified versions. The book itself and the named frameworks (the MESA Framework, the Five-Gate Deployment Model, the AI Incident Response Protocol, and the others) are © 2026 Nabeel Khan, all rights reserved.
The institutions that build this architecture will lead the next decade of MENA AI.