§ 01GCC

GCC

AI governance across Kuwait, the UAE, Qatar and Saudi Arabia

There is one fact that reorders most Gulf AI governance conversations, and it is easy to say and uncomfortable to sit with: no GCC state has a binding horizontal AI statute. Not one.

Every Gulf jurisdiction governs artificial intelligence through data protection law plus sectoral supervision, and the AI-specific instruments that exist are mostly guidance. This is the same shape as Canada, where AIDA died and OSFI carried the weight instead. It means a group operating across the Gulf is not tracking four AI acts. It is tracking four data protection regimes, four supervisors, and a small number of genuinely binding free-zone rules, and it has to build one operating model that satisfies the strictest of each.

Written by Nabeel Khan, author of AI Governance & Compliance Frameworks for the Middle East · seven years in Kuwait government, the Council of Ministers and the Ministry of Planning · author of the MESA Framework · engagements are taken personally through iSystematic, not staffed to a bench
§ 02What applies

What is actually in force.

Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.

Kuwait
CITRA, the DPPR and CBK supervisionData protection through CITRA’s Data Privacy Protection Regulation, with financial supervision from the Central Bank of Kuwait and the Wolooj sandbox as the route for supervised experimentation. No AI statute. The Kuwait page covers what applies and what a regulator asks to see.
UAE
DIFC Regulation 10 and the CBUAE guidance noteThe most developed AI-specific instrument in the Gulf, and it is a free-zone rule rather than a federal one. DIFC Regulation 10 has been in full enforcement since 1 January 2026, with an AI register, certification and an Autonomous Systems Officer for high-risk processing. The CBUAE issued its AI and machine-learning guidance note on 23 February 2026, supervisory rather than binding. No federal AI act. The UAE page has the detail.
Saudi Arabia
SDAIA guidance and PDPL enforcementThe strongest national AI institution and no binding AI statute. SDAIA sets direction through ethics principles, generative-AI guidance and an adoption framework, all non-binding, while the PDPL carries enforcement with 48 decisions across 2025 and 2026. SAMA has no dedicated AI standard. The Saudi page has the detail.
Qatar
QCB and the national AI strategyFinancial supervision through the Qatar Central Bank alongside the national data privacy law. No AI statute. The Qatar page covers what applies.
§ 03What does not apply

The rule that does not exist.

The practical consequence for a group is that the compliance question is the wrong first question. Build the control plane once and prove it four times. An institution that treats each jurisdiction as a separate programme will maintain four inventories that disagree, and the disagreement will surface during an examination rather than before it. An institution that builds one governed control plane, tagged by which instrument each piece of evidence answers to, produces the Kuwait answer, the DIFC answer, the Saudi answer and the Qatar answer from a single source. The second approach is also the only one that survives adding a fifth jurisdiction.

Two more layers reach the Gulf from outside and are routinely missed. The EU AI Act applies wherever output reaches the European Union regardless of where the institution sits. And for Islamic financial institutions, Sharia governance imposes a dual-validation requirement that no Western framework addresses, which is one of the reasons the published book exists.

§ 04Questions

The questions a board actually asks.

Is there a GCC AI law?

No. No Gulf state has a binding horizontal AI statute, and there is no GCC-level AI act. Every jurisdiction governs artificial intelligence through data protection law and sectoral supervision, and the AI-specific instruments that do exist are mostly guidance rather than law. The significant exception is DIFC Regulation 10, which is binding, and is a free-zone rule rather than a national one. Getting this right is the difference between a governance programme aimed at real evidence and one aimed at a statute nobody has passed.

Which GCC jurisdiction has the strictest AI rules today?

The DIFC, and it is not close. Regulation 10 has been in full enforcement since 1 January 2026 and carries concrete artefacts: a maintained register of AI systems, notices, certification, and an Autonomous Systems Officer where processing is high risk. Nothing at national level in any Gulf state currently reaches that specificity. For a group deciding where to set its internal bar, Regulation 10 is the sensible one to build to, because meeting it generally means meeting the rest.

We operate in more than one Gulf country. Do we need separate programmes?

No, and running separate programmes is the more expensive mistake. The instruments differ in what they demand as evidence, not in what good governance looks like: an inventory, a risk rating, a validation record, a human accountable for each decision, and a way to explain an outcome to the person affected. Build that once as a control plane the platform enforces, tag each artefact with the instrument it answers to, and each jurisdiction becomes a report rather than a project. Four hand-maintained inventories will disagree, and you will find out when it is expensive.

Does the EU AI Act reach a Gulf institution?

Yes, wherever output reaches the European Union, and this is the layer most often missed in Gulf programmes because it appears in no local rulebook. Article 50 transparency duties have been in force since 2 August 2026, and the Annex III high-risk obligations moved to 2 December 2027. A Gulf bank serving European customers, or a group with a European entity, is inside it regardless of what CITRA, the CBUAE, SDAIA or the QCB require.

What about Sharia governance and Islamic finance?

It is a real requirement that no Western AI framework addresses, and it is not a formality. An Islamic financial institution deploying AI faces a dual-validation problem: the model has to satisfy the ordinary model-risk standard and the Sharia governance standard, and the second one asks questions about the permissibility of the decision and the provenance of the data that the first never poses. Halal data lineage is the practical expression of it. This is covered in the published book and it is one of the areas where general-purpose AI governance advice runs out.

Who does this work, and how?

Nabeel Khan, personally, through iSystematic rather than staffed to a bench. The relevant background is seven years inside the Kuwaiti state, at the Council of Ministers and the Ministry of Planning, followed by enterprise architecture in regulated sectors across North America, and a published book on AI governance for Middle East financial institutions. Engagements start with a free thirty-minute Fit Call that qualifies the work in both directions and sometimes ends in a referral elsewhere. The flagship is the AI Governance Teardown, a fixed-scope, fixed-fee, two-week, MESA-scored examination delivered board-ready.

Governance an examiner can follow, in the jurisdiction that actually binds you.

Fin · GCC
Book the 30-minute Fit Call →