There is one fact that reorders most Gulf AI governance conversations, and it is easy to say and uncomfortable to sit with: no GCC state has a binding horizontal AI statute. Not one.
Every Gulf jurisdiction governs artificial intelligence through data protection law plus sectoral supervision, and the AI-specific instruments that exist are mostly guidance. This is the same shape as Canada, where AIDA died and OSFI carried the weight instead. It means a group operating across the Gulf is not tracking four AI acts. It is tracking four data protection regimes, four supervisors, and a small number of genuinely binding free-zone rules, and it has to build one operating model that satisfies the strictest of each.
Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.
The practical consequence for a group is that the compliance question is the wrong first question. Build the control plane once and prove it four times. An institution that treats each jurisdiction as a separate programme will maintain four inventories that disagree, and the disagreement will surface during an examination rather than before it. An institution that builds one governed control plane, tagged by which instrument each piece of evidence answers to, produces the Kuwait answer, the DIFC answer, the Saudi answer and the Qatar answer from a single source. The second approach is also the only one that survives adding a fifth jurisdiction.
Two more layers reach the Gulf from outside and are routinely missed. The EU AI Act applies wherever output reaches the European Union regardless of where the institution sits. And for Islamic financial institutions, Sharia governance imposes a dual-validation requirement that no Western framework addresses, which is one of the reasons the published book exists.
No. No Gulf state has a binding horizontal AI statute, and there is no GCC-level AI act. Every jurisdiction governs artificial intelligence through data protection law and sectoral supervision, and the AI-specific instruments that do exist are mostly guidance rather than law. The significant exception is DIFC Regulation 10, which is binding, and is a free-zone rule rather than a national one. Getting this right is the difference between a governance programme aimed at real evidence and one aimed at a statute nobody has passed.
The DIFC, and it is not close. Regulation 10 has been in full enforcement since 1 January 2026 and carries concrete artefacts: a maintained register of AI systems, notices, certification, and an Autonomous Systems Officer where processing is high risk. Nothing at national level in any Gulf state currently reaches that specificity. For a group deciding where to set its internal bar, Regulation 10 is the sensible one to build to, because meeting it generally means meeting the rest.
No, and running separate programmes is the more expensive mistake. The instruments differ in what they demand as evidence, not in what good governance looks like: an inventory, a risk rating, a validation record, a human accountable for each decision, and a way to explain an outcome to the person affected. Build that once as a control plane the platform enforces, tag each artefact with the instrument it answers to, and each jurisdiction becomes a report rather than a project. Four hand-maintained inventories will disagree, and you will find out when it is expensive.
Yes, wherever output reaches the European Union, and this is the layer most often missed in Gulf programmes because it appears in no local rulebook. Article 50 transparency duties have been in force since 2 August 2026, and the Annex III high-risk obligations moved to 2 December 2027. A Gulf bank serving European customers, or a group with a European entity, is inside it regardless of what CITRA, the CBUAE, SDAIA or the QCB require.
It is a real requirement that no Western AI framework addresses, and it is not a formality. An Islamic financial institution deploying AI faces a dual-validation problem: the model has to satisfy the ordinary model-risk standard and the Sharia governance standard, and the second one asks questions about the permissibility of the decision and the provenance of the data that the first never poses. Halal data lineage is the practical expression of it. This is covered in the published book and it is one of the areas where general-purpose AI governance advice runs out.
Nabeel Khan, personally, through iSystematic rather than staffed to a bench. The relevant background is seven years inside the Kuwaiti state, at the Council of Ministers and the Ministry of Planning, followed by enterprise architecture in regulated sectors across North America, and a published book on AI governance for Middle East financial institutions. Engagements start with a free thirty-minute Fit Call that qualifies the work in both directions and sometimes ends in a referral elsewhere. The flagship is the AI Governance Teardown, a fixed-scope, fixed-fee, two-week, MESA-scored examination delivered board-ready.
Governance an examiner can follow, in the jurisdiction that actually binds you.