Every instrument that binds an AI system across the Gulf and the wider region, in one place. The matrix below is the working index: 56 rows covering data protection, AI-specific rules, sectoral supervision and Sharia standards, filterable by jurisdiction and searchable by text.
Beneath it sit the seven authored table sets in full: the jurisdictional comparison across twenty-five dimensions, the global regimes comparison, penalty schedules, the use-case to regime cross-reference, the authority catalogue and the 2018 to 2027 timeline.
These dates move. They were correct at the book's release lock. Verify each one against the regulator before you rely on it, and read the maintenance notes at the end of the tables.
| Jurisdiction | Regulator | Framework / Instrument | Scope | Status |
|---|---|---|---|---|
| UAE | UAE Data Office | Federal Decree-Law No. 45 of 2021 (PDPL) | Data | In force |
| UAE | Telecommunications and Digital Government Regulatory Authority (TDRA) | Digital and telecom-adjacent data protection | Data | In force |
| UAE (DIFC) | Dubai Financial Services Authority (DFSA) | DIFC Regulation 10 (autonomous conduct) | Capital Markets | In force |
| UAE (DIFC) | DIFC Commissioner of Data Protection | DIFC data protection | Data | In force |
| UAE (ADGM) | ADGM Financial Services Regulatory Authority (FSRA) | ADGM AI guidance | Capital Markets | Developing |
| UAE (ADGM) | ADGM Office of Data Protection | ADGM data protection | Data | In force |
| UAE | Central Bank of the UAE (CBUAE) | CBUAE Model Management Standards (MMS) | Banking | In force |
| UAE | Securities and Commodities Authority (SCA) | SCA algorithmic trading rules | Capital Markets | In force |
| UAE | Government of the UAE | UAE National AI Strategy 2031 | Government | In force |
| UAE | Government of Dubai | Dubai AI Roadmap | Government | In force |
| Saudi Arabia | Saudi Data and AI Authority (SDAIA) | PDPL (Royal Decree M/19 of 2021, amended 2023) | Data | In force |
| Saudi Arabia | Saudi Data and AI Authority (SDAIA) | SDAIA AI Ethics Principles | Cross-sector | In force |
| Saudi Arabia | Saudi Data and AI Authority (SDAIA) | SDAIA Generative AI Guidelines (2024) | Cross-sector | Guidance |
| Saudi Arabia | Saudi Central Bank (SAMA) | SAMA AI Guidelines for Financial Institutions | Banking | Guidance |
| Saudi Arabia | Capital Markets Authority (CMA) | CMA algo-trading rules | Capital Markets | In force |
| Saudi Arabia | National Cybersecurity Authority (NCA) | Cybersecurity, including AI security | Cross-sector | In force |
| Saudi Arabia | Government of Saudi Arabia | Vision 2030 AI agenda | Government | In force |
| Qatar | National Data Privacy Office (NDPO), within the NCSA | Law No. 13 of 2016 (PDPPL) | Data | In force |
| Qatar | Qatar Central Bank (QCB) | QCB AI Governance Framework (2024) | Banking | In force |
| Qatar | Qatar Financial Markets Authority (QFMA) | Securities and algo-trading | Capital Markets | In force |
| Qatar (QFC) | Qatar Financial Centre Regulatory Authority (QFCRA) | QFC financial services | Capital Markets | In force |
| Qatar | Government of Qatar | Qatar National AI Strategy | Government | In force |
| Bahrain | Personal Data Protection Authority (PDPA) | Personal Data Protection Law (Law No. 30 of 2018) | Data | In force |
| Bahrain | Central Bank of Bahrain (CBB) | CBB AI Risk Management Framework (2024) | Banking | In force |
| Bahrain | Government of Bahrain | National AI Strategy | Government | In force |
| Kuwait | Communication and Information Technology Regulatory Authority (CITRA) | Data Privacy Protection Regulation (CITRA 2021) | Data | In force |
| Kuwait | Central Bank of Kuwait (CBK) | CBK Banking Technology Standards | Banking | In force |
| Kuwait | Capital Markets Authority (CMA Kuwait) | CMA algo-trading rules | Capital Markets | In force |
| Kuwait | Government of Kuwait | Kuwait Vision 2035 AI agenda | Government | Developing |
| Oman | Ministry of Transport, Communications and IT (MTCIT) | Royal Decree 6 of 2022 (PDPL) | Data | In force |
| Oman | Central Bank of Oman (CBO) | CBO AI Governance | Banking | Developing |
| Oman | Government of Oman | Oman Vision 2040 AI agenda | Government | Developing |
| Egypt | Personal Data Protection Center (PDPC, under MCIT) | Law No. 151 of 2020 (PDPL) | Data | In force |
| Egypt | Central Bank of Egypt (CBE) | CBE AI experimentation | Banking | Developing |
| Egypt | Government of Egypt | National AI Strategy 2025-2030 | Government | In force |
| Jordan | Personal Data Protection Council (under MoDEE) | Law No. 24 of 2023 (Data Protection Law) | Data | In force |
| Jordan | Central Bank of Jordan (CBJ) | CBJ AI guidance | Banking | Developing |
| Jordan | Government of Jordan | Jordan AI Strategy 2023-2027 | Government | In force |
| EU | European Commission AI Office; national notified bodies | Regulation (EU) 2024/1689 (AI Act) | Cross-sector | In force |
| EU | European Data Protection Board; national DPAs | GDPR | Data | In force |
| US | OCC; Federal Reserve; FDIC | SR 11-7 (model risk) | Banking | In force |
| US | SEC; FINRA | Securities and algo-trading | Capital Markets | In force |
| US | FTC; CFPB | FTC Section 5 | Cross-sector | In force |
| US | EEOC | Employment AI fairness | Cross-sector | In force |
| US | FDA | Medical device AI (SaMD) | Healthcare | In force |
| US | NIST | NIST AI RMF (voluntary) | Cross-sector | Guidance |
| China | Cyberspace Administration of China (CAC) | PIPL (2021) | Data | In force |
| China | Cyberspace Administration of China (CAC) | Generative AI Interim Measures (2023) | Cross-sector | In force |
| China | Cyberspace Administration of China (CAC) | Data Security Law (2021) | Data | In force |
| China | Cyberspace Administration of China (CAC) | Cybersecurity Law (2017) | Cross-sector | In force |
| UK | Information Commissioner's Office (ICO); FCA; MHRA; CMA; Ofqual | Pro-innovation regulatory approach (white paper 2023) | Cross-sector | Guidance |
| Islamic finance | AAOIFI | Sharia accounting and governance standards | Sharia | In force |
| Islamic finance | IFSB | Islamic financial services standards | Sharia | In force |
| International standards | ISO/IEC | ISO/IEC 42001:2023 | Cross-sector | In force |
| International | OECD | OECD AI Principles (2019, refreshed 2024) | Cross-sector | Guidance |
| International | UNESCO | UNESCO Recommendation on Ethics of AI (2021) | Cross-sector | Guidance |
No instrument matches that filter.
The matrix maps the six core MENA jurisdictions (UAE, Saudi Arabia, Qatar, Bahrain, Kuwait, Oman, Egypt, Jordan) across twenty-five compliance dimensions. The dimensions cover the data protection foundation, the AI-specific provisions, the supervisory architecture, and the operational obligations the institutions operating in each jurisdiction must satisfy.
| Dimension | UAE | Saudi Arabia | Qatar | Bahrain | Kuwait | Oman | Egypt | Jordan |
|---|---|---|---|---|---|---|---|---|
| Primary data protection law | Federal Decree-Law No. 45 of 2021 (PDPL) | PDPL (Royal Decree M/19 of 2021, amended 2023) | Law No. 13 of 2016 (PDPPL) | Personal Data Protection Law (Law No. 30 of 2018) | Data Privacy Protection Regulation (CITRA Decision 26/2024) | Royal Decree 6 of 2022 (PDPL) | Law No. 151 of 2020 (PDPL) | Law No. 24 of 2023 (Data Protection Law) |
| Effective date | January 1, 2022 | September 14, 2023 (full enforcement March 2024) | December 29, 2016 | August 1, 2019 | February 19, 2024 | February 13, 2023 | October 14, 2020 | March 17, 2024 |
| Primary regulator | UAE Data Office (federal); TDRA (telecom-adjacent) | SDAIA (Saudi Data and AI Authority) | National Data Privacy Office (NDPO), within the National Cyber Security Agency (NCSA) | Personal Data Protection Authority | Communication and Information Technology Regulatory Authority | Ministry of Transport, Communications and IT | Personal Data Protection Center (under MCIT) | Personal Data Protection Council (under MoDEE) |
| Extraterritorial scope | Yes. Applies to processing of UAE-resident personal data regardless of controller location | Yes. Applies to processing of Saudi-resident personal data regardless of location | Yes for Qatari personal data | Limited extraterritoriality | Limited extraterritoriality | Yes for Omani personal data | Yes for Egyptian personal data | Yes for Jordanian personal data |
| Lawful basis model | Six bases (consent, contract, legal obligation, vital interest, public interest, legitimate interest) | Six bases (consent-primary) | Six bases | Six bases | Consent-primary | Six bases | Six bases (GDPR-aligned) | Six bases (GDPR-aligned) |
| Consent standard | Explicit, specific, informed, affirmative | Explicit, specific, informed (legitimate interest requires impact assessment) | Explicit, specific, informed | Explicit | Explicit | Explicit | Explicit | Explicit |
| Data subject rights | Seven (access, correction, erasure, objection, restriction, portability, transparency) | Seven | Seven | Six | Six | Seven | Six (access, correction, deletion, objection, portability, transparency) | Six |
| Data localization | No general mandate; sector-specific (CBUAE banking data preferences) | Yes. Mandatory localization for personal data of Saudi residents (PDPL Article 29) | No general mandate; sectoral preferences | No general mandate | No general mandate | No general mandate | No general mandate | No general mandate |
| Cross-border transfer mechanism | Adequacy assessment by UAE Data Office; SCCs; BCRs; explicit consent | SDAIA-approved transfer mechanisms; adequacy whitelist; SCCs; explicit consent | Adequacy assessment; contractual safeguards; consent | Adequacy assessment; contractual safeguards | Contractual safeguards; consent | Adequacy assessment; contractual safeguards; consent | Contractual safeguards; consent for non-adequate jurisdictions | Contractual safeguards; consent for non-adequate jurisdictions |
| Breach notification timeline | 72 hours to UAE Data Office and affected data subjects | 72 hours to SDAIA and affected data subjects | 72 hours to the NDPO and affected data subjects | 72 hours to PDPA | 72 hours to CITRA | 72 hours to MTCIT | 72 hours to PDPC | 72 hours to PDPC |
| Dimension | UAE | Saudi Arabia | Qatar | Bahrain | Kuwait | Oman | Egypt | Jordan |
|---|---|---|---|---|---|---|---|---|
| Primary AI policy instrument | UAE National AI Strategy 2031; DIFC Regulation 10; ADGM AI guidance; Dubai AI Roadmap | SDAIA AI Ethics Principles; SDAIA Generative AI Guidelines (2024); Vision 2030 AI agenda | Qatar National AI Strategy; QCB AI Governance Framework (2024) | National AI Strategy; CBB AI Risk Management Framework (2024) | Kuwait Vision 2035 AI agenda (developing) | Oman Vision 2040 AI agenda (developing) | National AI Strategy 2025-2030 | Jordan AI Strategy 2023-2027 |
| AI-specific binding rules | DIFC Regulation 10 (autonomous conduct); CBUAE Model Management Standards (MMS) | SDAIA AI Ethics Principles (binding for government and high-risk); SAMA AI guidelines for banking | QCB AI Governance Framework (banking); PDPPL automated decision rules | CBB AI Risk Management Framework; PDPL automated decision provisions | Developing; CMA algo-trading rules | Developing | Developing; PDPL automated decision provisions | Developing; DP Law automated decision provisions |
| Explainability requirement | Required for DIFC autonomous conduct; CBUAE MMS Tier 1/2; SDAIA Tier alignment | Required for SDAIA Tier 1 and Tier 2 AI systems | Required for QCB-supervised AI; PDPPL automated decisions | Required for CBB-supervised AI | Required for CMA algo-trading | Emerging | Emerging | Emerging |
| Fairness testing | Required for high-risk systems (DIFC, CBUAE, ADGM) | Mandatory for SDAIA Tier 1 and Tier 2 | Required for QCB consumer-facing AI | Required for CBB consumer-facing AI | Required for CMA-supervised algo systems | Emerging | Emerging | Emerging |
| Human oversight | Required (DIFC Regulation 10) for material decisions | Required for SDAIA Tier 1 and Tier 2 | Required (QCB Framework) for material decisions | Required (CBB Framework) | Required for CMA-supervised systems | Emerging | Emerging | Emerging |
| Automated decision opt-out | Required (DIFC Regulation 10) | Required for high-risk SDAIA-supervised systems | Required (PDPPL) | Required (PDPL) | Limited | Required (PDPL) | Required (PDPL) | Required (DP Law) |
| Sharia-AI overlay | Applicable for Islamic finance institutions (AAOIFI/IFSB) | Applicable; AAOIFI alignment standard | Applicable; AAOIFI alignment | Applicable; AAOIFI alignment | Applicable; AAOIFI alignment | Applicable; AAOIFI alignment | Limited Islamic finance sector | Limited Islamic finance sector |
| Dimension | UAE | Saudi Arabia | Qatar | Bahrain | Kuwait | Oman | Egypt | Jordan |
|---|---|---|---|---|---|---|---|---|
| Sectoral banking regulator | CBUAE | SAMA | QCB | CBB | CBK | CBO | CBE | CBJ |
| Banking AI directive | CBUAE Model Management Standards (MMS) | SAMA AI Guidelines for Financial Institutions | QCB AI Governance Framework | CBB AI Risk Management Framework | CBK Banking Technology Standards | CBO AI Governance (developing) | CBE AI experimentation (developing) | CBJ AI guidance (developing) |
| DPIA requirement | Required for high-risk processing | Required (Tier 1/2) | Required for high-risk processing | Required for high-risk processing | Recommended | Required for high-risk processing | Required for high-risk processing | Required for high-risk processing |
| DPO requirement | Mandatory for designated entities; recommended for others | Mandatory for controllers processing sensitive data at scale | Mandatory for public bodies and large processors | Recommended | Recommended | Recommended | Mandatory for public bodies and large processors | Mandatory for public bodies and large processors |
| Registration with regulator | Required for designated processing activities | Required for high-risk controllers (SDAIA registration) | Required for designated processing | Required for designated processing | Not required | Required for designated processing | Required for licensed activities | Required for licensed activities |
| Maximum administrative fine | AED 5 million (PDPL); higher for sectoral violations | SAR 5 million (PDPL); SAR 50,000 for non-material breaches | QAR 5 million (PDPPL) | BHD 1 million (PDPL) | KWD 500,000 | OMR 500,000 (PDPL) | EGP 5 million (PDPL) | JOD 1 million (DP Law) |
| Criminal liability | Available for serious violations | Available; up to 2 years imprisonment for sensitive data misuse | Available for serious violations | Available | Limited | Available | Available; up to 5 years for sensitive data misuse | Available for serious violations |
| Supervisory style | Engagement-receptive; principles-based; advisory dialogue available | Engagement-receptive; rules-based posture in financial sector; SDAIA proactive consultation | Engagement-receptive; principles-based | Engagement-receptive; rules-based in banking | Developing; engagement-receptive | Engagement-receptive; developing | Developing; engagement increasingly receptive | Developing; engagement increasingly receptive |
The matrix is the navigation aid. The chapters specify what the matrix indexes. The institution operating across multiple jurisdictions calibrates discipline to the strictest applicable obligation per dimension, then operationalizes the calibrated discipline as the regional baseline the MESA framework Chapter 4 specifies sustains.
Three operational notes anchor the matrix interpretation. The first note is the consent-standard convergence. The eight frameworks converge on explicit, specific, informed consent as the operational consent standard. The convergence enables a single consent-management discipline to satisfy all eight perimeters through the strictest formulation. The institutions operating across multiple perimeters operationalize one consent posture rather than eight. The second note is the breach-notification convergence. The 72-hour breach notification timeline is shared across UAE, Saudi Arabia, Qatar, Bahrain, Kuwait, Oman, Egypt, and Jordan. The shared timeline enables a single incident-response discipline to satisfy all eight perimeters through the cadence the strictest timeline requires. The discipline the Chapter 13 Data Governance Stack specifies operationalizes the convergence. The third note is the data-localization divergence. Saudi Arabia is the binding localization outlier. The Saudi data architecture must accommodate the localization. The non-Saudi data architecture can flow under safeguards. The Chapter 9 Cross-Border AI Architecture Patterns operationalize the divergence through the Sovereign Silos, Federated, and Regional Hub patterns the multi-jurisdictional institution selects from.
The matrix is not the discipline. The matrix is the dimensional map the discipline operates against. The institution that mistakes the matrix for the discipline produces compliance documentation without the operational substrate the supervisor inspects through the documentation. The institution that operates the discipline against the matrix produces the operational substrate the documentation traces and the supervisor recognizes.
The global regimes are the extraterritorial reality MENA institutions operating internationally inhabit. The matrix maps five regimes across ten dimensions.
| Dimension | EU AI Act | US Sectoral | China | UK | International Standards (ISO/IEC 42001, OECD, UNESCO) |
|---|---|---|---|---|---|
| Primary instrument | Regulation (EU) 2024/1689 (AI Act); GDPR | NIST AI RMF (voluntary); EEOC, SEC, FDA, OCC, FRB sectoral guidance; SR 11-7 (model risk); FTC Section 5 | Cybersecurity Law (2017); Data Security Law (2021); PIPL (2021); Generative AI Interim Measures (2023) | Pro-innovation regulatory approach (white paper 2023); ICO data protection; sectoral regulators | ISO/IEC 42001:2023; OECD AI Principles (2019, refreshed 2024); UNESCO Recommendation on Ethics of AI (2021) |
| Effective date | August 1, 2024 (phased through August 2, 2027) | NIST AI RMF January 2023; sectoral varies | PIPL November 1, 2021; Generative AI Measures August 15, 2023 | Pro-innovation approach 2023 (non-binding); GDPR-UK ongoing | ISO/IEC 42001 December 2023; OECD 2019; UNESCO 2021 |
| Risk classification | Unacceptable; High-Risk; Limited-Risk; Minimal-Risk; General Purpose AI (GPAI) | Sectoral; SR 11-7 tiered model risk | Filing-required generative AI; security assessment trigger for personal info; sensitive personal information separate | Risk-based; principles-led; sector regulator discretion | Risk-management based; voluntary certification |
| Extraterritorial reach | Yes. Applies to providers and deployers whose AI system output is used in EU regardless of location | Limited. Sectoral reach (US-listed entities, US-domiciled financial institutions) | Yes. PIPL applies to processing of Chinese personal information for service to or analysis of Chinese individuals from abroad | Limited. UK GDPR territorial scope | Voluntary; reach via procurement, insurance, audit citation |
| Documentation requirement | Article 11 technical documentation (high-risk); model card (GPAI) | NIST AI RMF Govern/Map/Measure/Manage; SR 11-7 model documentation; sectoral file requirements | Generative AI service filing; security assessment documentation; PIPIA (Personal Information Impact Assessment) | DPIAs under UK GDPR; sectoral documentation | ISO/IEC 42001 management system documentation; OECD/UNESCO self-attestation |
| Human oversight | Required (Article 14) for high-risk systems | Required by SR 11-7 for material model use; required by EEOC for employment decisions | Required for generative AI service provision (content moderation); required for sensitive personal information processing | Required by sectoral regulators (FCA, MHRA, Ofqual) | Recommended (ISO/IEC 42001 clause 8); core OECD/UNESCO principle |
| Maximum penalty | EUR 35 million or 7 percent of global annual turnover (prohibited practices); EUR 15 million or 3 percent (other violations); EUR 7.5 million or 1 percent (information violations) | Sectoral; SEC penalties unlimited; FTC penalties USD 51,744 per violation (2024 adjusted); OCC enforcement actions | CNY 50 million or 5 percent of preceding year's annual turnover (PIPL); criminal liability available | UK GDPR: GBP 17.5 million or 4 percent of global turnover | Non-enforcement; certification withdrawal |
| Audit and certification | Conformity assessment (high-risk); notified body designation | Sectoral examinations; SR 11-7 independent validation; SOC reporting | CAC security assessment; algorithm filing | ICO investigations; sectoral examinations | ISO/IEC 42001 third-party certification |
| Cross-border transfer regime | Schrems II framework; SCCs; BCRs; adequacy decisions | Sectoral; CFIUS for sensitive transactions; bulk data executive order | CAC security assessment; certification; SCCs approved by CAC | UK adequacy framework; IDTAs; UK SCCs | OECD Cross-Border Privacy Rules; APEC alignment |
| Supervisory style | Rules-based; conformity assessment; enforcement-heavy | Principles-based with sectoral specificity; enforcement through examinations | Rules-based; security-centric; state-strategic | Pro-innovation; principles-based; regulator-flexible | Voluntary; market-driven |
The global regimes are not optional for MENA institutions serving international markets. The EU AI Act reaches MENA institutions whose AI system output is used in the EU. PIPL reaches MENA institutions processing Chinese personal information. American sectoral discipline reaches MENA institutions with US-listed exposure. The extraterritorial reality is the current operational condition the institutions operating across the perimeters inhabit.
Where most observers see five distinct global regimes, I see one convergence vocabulary the international standards layer (ISO/IEC 42001, OECD, UNESCO) increasingly codifies and the regional regimes increasingly translate. The institution that built MESA discipline against the convergence vocabulary operates across the regimes through the structural commonality. The institution that built compliance against the regimes one at a time operates against the divergence at each perimeter and accumulates the operational overhead the convergence would have absorbed.
Penalty is not punishment. It is the cost calibration the supervisory framework applies to the gap between the discipline the institution declared and the discipline the operational substrate produced.
The penalty schedules support the materiality analysis the institutions operating across the regulatory landscape conduct. The schedules are inputs to the risk-tolerance calibration the Chapter 14 Vendor Risk Lifecycle specifies, the financial-impact dimension the Chapter 12 Governance Office Blueprint incorporates, and the cost-of-non-compliance analysis the Chapter 11 MRM Stack supports.
| Violation category | Penalty range (AED) | Penalty range (USD equivalent) | Supervisory action available |
|---|---|---|---|
| Processing personal data without lawful basis | AED 250,000 to 5,000,000 | USD 68,000 to 1,360,000 | Cease-and-desist; data deletion order |
| Failure to obtain valid consent | AED 250,000 to 2,000,000 | USD 68,000 to 545,000 | Reprocessing under valid basis required |
| Breach notification failure (72-hour rule) | AED 100,000 to 1,000,000 | USD 27,000 to 272,000 | Public notification order |
| Cross-border transfer without safeguards | AED 250,000 to 5,000,000 | USD 68,000 to 1,360,000 | Transfer suspension order |
| Data security inadequacy | AED 100,000 to 2,000,000 | USD 27,000 to 545,000 | Remediation order; security audit |
| Data subject rights obstruction | AED 100,000 to 1,000,000 | USD 27,000 to 272,000 | Rights enforcement order |
| DIFC Regulation 10 violation (autonomous conduct) | Up to AED 5,000,000 per violation; aggregate up to AED 35,000,000 | Up to USD 1,360,000 per violation; aggregate USD 9,500,000 | DFSA enforcement; license suspension available |
| CBUAE MMS violation | Up to AED 10,000,000 per violation | Up to USD 2,720,000 | Banking license action; model deployment suspension |
| SCA algorithmic trading violation | AED 50,000 to 10,000,000 | USD 13,600 to 2,720,000 | Trading suspension; license action |
| Violation category | Penalty range (SAR) | Penalty range (USD equivalent) | Supervisory action available |
|---|---|---|---|
| Processing sensitive personal data without basis | SAR 1,000,000 to 5,000,000 + up to 2 years imprisonment | USD 267,000 to 1,333,000 | Cease-and-desist; data deletion |
| Cross-border transfer without SDAIA approval | SAR 1,000,000 to 5,000,000 | USD 267,000 to 1,333,000 | Transfer suspension |
| Failure to localize personal data (PDPL Article 29) | SAR 500,000 to 3,000,000 | USD 133,000 to 800,000 | Localization order |
| Consent violation | SAR 500,000 to 3,000,000 | USD 133,000 to 800,000 | Reprocessing requirement |
| Breach notification failure | SAR 100,000 to 1,000,000 | USD 27,000 to 267,000 | Public notification |
| Data subject rights obstruction | SAR 100,000 to 1,000,000 | USD 27,000 to 267,000 | Rights enforcement |
| SAMA banking AI violation | SAR 1,000,000 to 10,000,000 per violation | USD 267,000 to 2,667,000 | Banking license action; deployment suspension |
| SDAIA AI Ethics Principles violation (Tier 1/2) | SAR 500,000 to 5,000,000 | USD 133,000 to 1,333,000 | Deployment prohibition |
| CMA algo-trading violation | SAR 100,000 to 10,000,000 | USD 27,000 to 2,667,000 | Trading suspension |
| Violation category | Penalty range (QAR) | Penalty range (USD equivalent) | Supervisory action available |
|---|---|---|---|
| Processing without lawful basis | QAR 1,000,000 to 5,000,000 | USD 275,000 to 1,375,000 | Cease-and-desist |
| Cross-border transfer without safeguards | QAR 500,000 to 5,000,000 | USD 137,000 to 1,375,000 | Transfer suspension |
| Breach notification failure | QAR 200,000 to 1,000,000 | USD 55,000 to 275,000 | Public notification |
| Consent violation | QAR 500,000 to 3,000,000 | USD 137,000 to 825,000 | Reprocessing requirement |
| Data subject rights obstruction | QAR 100,000 to 1,000,000 | USD 27,000 to 275,000 | Rights enforcement |
| QCB AI Framework violation | QAR 500,000 to 5,000,000 | USD 137,000 to 1,375,000 | Banking license action |
| Qatar Exchange algo-trading violation | QAR 100,000 to 5,000,000 | USD 27,000 to 1,375,000 | Trading suspension |
| Violation category | Penalty range (BHD) | Penalty range (USD equivalent) | Supervisory action available |
|---|---|---|---|
| Processing without lawful basis | BHD 50,000 to 1,000,000 | USD 132,500 to 2,650,000 | Cease-and-desist |
| Consent violation | BHD 20,000 to 500,000 | USD 53,000 to 1,325,000 | Reprocessing requirement |
| Breach notification failure | BHD 10,000 to 300,000 | USD 26,500 to 795,000 | Public notification |
| Data subject rights obstruction | BHD 10,000 to 300,000 | USD 26,500 to 795,000 | Rights enforcement |
| CBB AI Risk Management violation | Up to BHD 1,000,000 | Up to USD 2,650,000 | Banking license action |
| Violation category | Penalty range (KWD) | Penalty range (USD equivalent) | Supervisory action available |
|---|---|---|---|
| Processing without consent | KWD 50,000 to 500,000 | USD 163,000 to 1,627,000 | Cease-and-desist |
| Data security failure | KWD 20,000 to 300,000 | USD 65,000 to 976,000 | Remediation order |
| Breach notification failure | KWD 10,000 to 200,000 | USD 32,500 to 651,000 | Public notification |
| CMA algo-trading violation | KWD 50,000 to 500,000 | USD 163,000 to 1,627,000 | Trading suspension |
| Jurisdiction | Maximum administrative fine | Criminal liability | Notes |
|---|---|---|---|
| Oman | OMR 500,000 (USD 1,300,000) | Available for sensitive data misuse | PDPL effective 2023; supervisory architecture developing |
| Egypt | EGP 5,000,000 (USD 100,000); higher for sensitive data (up to EGP 10,000,000) | Available; up to 5 years for sensitive data misuse; up to 3 years for cross-border violations | PDPL effective 2020; PDPC operational |
| Jordan | JOD 1,000,000 (USD 1,410,000) | Available for serious violations | DP Law effective 2024; supervisory architecture developing |
| Regime | Maximum penalty | Notes |
|---|---|---|
| EU AI Act | EUR 35,000,000 or 7 percent of global annual turnover (prohibited practices); EUR 15,000,000 or 3 percent (high-risk violations); EUR 7,500,000 or 1 percent (information violations) | Whichever is higher; applies to GPAI providers and high-risk deployers |
| GDPR (EU) | EUR 20,000,000 or 4 percent of global annual turnover | Whichever is higher |
| US FTC Section 5 | USD 51,744 per violation (2024 adjusted) | Per-violation calculation can aggregate substantially |
| US SR 11-7 (banking) | Not directly fined; enforcement through examination findings, MOUs, consent orders | Capital surcharges available |
| China PIPL | CNY 50,000,000 or 5 percent of preceding year's annual turnover | Whichever is higher; criminal liability available |
| China Generative AI Measures | CNY 100,000 to 1,000,000; service suspension; criminal liability | Plus content remediation orders |
| UK GDPR | GBP 17,500,000 or 4 percent of global turnover | Whichever is higher |
| ISO/IEC 42001 | Certification withdrawal | Non-enforcement; market consequence through procurement |
The penalty schedules are inputs, not endpoints. The institution that operates against the penalty schedule rather than against the discipline the schedule indexes will discover that the schedule moved while the discipline did not. The discipline operating against the substrate the schedule indexes survives the schedule revisions the regulatory evolution will continue to produce.
The use case is the operational unit the discipline applies to. The matrix supports the use-case approval discipline Chapter 11 specifies through the MRM Stack and the Tier 1, Tier 2, Tier 3 classification the Governance Office Blueprint Chapter 12 operationalizes.
| AI use case | UAE applicable regimes | Saudi applicable regimes | Qatar applicable regimes | Egypt applicable regimes | Global applicable regimes | Typical risk tier |
|---|---|---|---|---|---|---|
| Credit scoring (retail lending) | PDPL; DIFC Reg 10 (if DIFC); CBUAE MMS; Sharia (Islamic finance) | PDPL; SAMA AI Guidelines; SDAIA Tier 1/2; Sharia | PDPPL; QCB AI Framework | PDPL; CBE guidance (developing) | EU AI Act (Annex III high-risk); US ECOA/Reg B; SR 11-7; ISO/IEC 42001 | Tier 1 |
| Anti-money-laundering monitoring | PDPL; CBUAE MMS | PDPL; SAMA AI Guidelines | PDPPL; QCB AI Framework | PDPL | EU AI Act (limited risk); US BSA/AML; FATF; ISO/IEC 42001 | Tier 2 |
| Fraud detection | PDPL; CBUAE MMS | PDPL; SAMA AI Guidelines | PDPPL; QCB AI Framework | PDPL; CBE experimentation | EU AI Act (limited risk); sectoral; ISO/IEC 42001 | Tier 2 |
| Insurance underwriting | PDPL; CBUAE (insurance); Sharia (Takaful) | PDPL; SAMA AI Guidelines; Sharia | PDPPL; QCB Insurance | PDPL | EU AI Act (Annex III high-risk for life and health insurance); state insurance law; ISO/IEC 42001 | Tier 1 |
| Insurance claims automation | PDPL; CBUAE (insurance) | PDPL; SAMA AI Guidelines | PDPPL; QCB Insurance | PDPL | EU AI Act (high-risk for life and health); state insurance law | Tier 1 |
| Algorithmic trading | PDPL; SCA | PDPL; CMA | PDPPL; Qatar Exchange | PDPL; FRA | EU MiFID II; US SEC Reg ATS; SR 11-7 | Tier 1 |
| Robo-advisory (wealth management) | PDPL; SCA | PDPL; CMA; SDAIA Tier 2 | PDPPL; QFMA | PDPL; FRA | EU MiFID II; US SEC Investment Advisers Act | Tier 1 |
| Customer service chatbot (non-decisional) | PDPL | PDPL; SDAIA Tier 3 | PDPPL | PDPL | EU AI Act (limited risk if transparency); ISO/IEC 42001 | Tier 3 |
| Customer service chatbot (decisional) | PDPL; DIFC Reg 10 (if applicable) | PDPL; SDAIA Tier 1/2 | PDPPL; sectoral | PDPL | EU AI Act (limited to high-risk depending on decision domain) | Tier 2 |
| Generative AI for content production | PDPL | PDPL; SDAIA Generative AI Guidelines | PDPPL | PDPL | EU AI Act (limited risk; transparency obligations); China Generative AI Measures (if China-facing) | Tier 3 |
| Generative AI for legal or medical advice | PDPL; sectoral (DHA for health) | PDPL; SDAIA Tier 1/2; MoH | PDPPL; MoPH | PDPL; MoH | EU AI Act (high-risk in healthcare and legal); FDA (medical devices) | Tier 1 |
| HR resume screening | PDPL | PDPL; SDAIA Tier 1 | PDPPL | PDPL | EU AI Act (Annex III high-risk for employment); US EEOC; NYC Local Law 144 | Tier 1 |
| HR performance management | PDPL | PDPL; SDAIA Tier 1 | PDPPL | PDPL | EU AI Act (Annex III high-risk); US EEOC | Tier 1 |
| Biometric identification (facial recognition) | PDPL; sectoral | PDPL; SDAIA Tier 1; NCA | PDPPL | PDPL | EU AI Act (Annex III high-risk; some prohibited); US state laws (IL BIPA, TX) | Tier 1 |
| Predictive maintenance (industrial) | Sectoral (energy, manufacturing) | Sectoral | Sectoral | Sectoral | ISO/IEC 42001; sectoral | Tier 3 |
| Marketing personalization | PDPL | PDPL; SDAIA Tier 3 | PDPPL | PDPL | EU AI Act (limited risk); GDPR (Article 22 if automated) | Tier 3 |
| Pricing optimization (consumer) | PDPL; SCA (if securities-adjacent) | PDPL; SDAIA Tier 2 | PDPPL | PDPL | EU AI Act (limited risk); FTC unfairness | Tier 2 |
| Predictive policing or social scoring | Prohibited absent specific authority | Prohibited absent specific authority; SDAIA Tier 1 (if authorized) | Prohibited absent specific authority | Prohibited absent specific authority | EU AI Act (prohibited or restricted) | Prohibited or Tier 1 |
| Educational scoring or admissions | PDPL; sectoral (ADEK, KHDA) | PDPL; MoE; SDAIA Tier 1 | PDPPL; MoEHE | PDPL; MoE | EU AI Act (Annex III high-risk for education) | Tier 1 |
| Healthcare diagnostic AI | PDPL; sectoral (DHA, DoH, MoHAP) | PDPL; MoH; SDAIA Tier 1 | PDPPL; MoPH | PDPL; MoH | EU AI Act (high-risk); FDA SaMD; MDR | Tier 1 |
| Sharia screening (Islamic finance products) | AAOIFI; IFSB; PDPL | AAOIFI; IFSB; PDPL; SAMA | AAOIFI; IFSB; PDPPL; QCB | Limited applicability | AAOIFI; IFSB | Tier 1 |
The matrix is the operational vocabulary for the use-case approval committee. The institution operates against the matrix to identify the applicable regulatory regimes per use case, then operationalizes the discipline the regimes require through the MRM Stack the Chapter 11 specifies and the Governance Office Blueprint the Chapter 12 operationalizes.
Four use-case classifications deserve specific operational note. The first classification is the Tier 1 high-stakes consumer-facing AI (credit scoring, insurance underwriting, healthcare diagnostic, HR resume screening, biometric identification, educational scoring). These use cases attract the strictest convergent obligations across MENA, EU, and US regimes. The discipline calibrated to EU AI Act Annex III high-risk obligations the Chapter 2 specifies satisfies most other regimes by transitivity. The second classification is the algorithmic trading and securities-adjacent AI. These use cases attract sectoral securities-regulator obligations across SCA, CMA Saudi Arabia, QFMA, CMA Kuwait, FRA Egypt, and SEC. The discipline calibrated to SR 11-7 model risk management satisfies most regimes structurally. The third classification is the Sharia-AI overlay for Islamic finance products. These use cases attract the AAOIFI and IFSB standards in addition to the conventional regimes. The Chapter 7 Sharia AI Governance specifies the discipline. The fourth classification is the generative AI for content production and the customer-service chatbot use cases. These use cases attract transparency obligations under EU AI Act limited-risk provisions, SDAIA Generative AI Guidelines, and China Generative AI Measures (if China-facing). The discipline calibrated to disclosure and content-moderation obligations the Chapter 17 Agentic AI Integration specifies satisfies the convergent transparency requirement.
The matrix is the input. The use-case approval committee is the operational discipline. The Tier classification (Tier 1, Tier 2, Tier 3) the Governance Office Blueprint Chapter 12 operationalizes is the structural output the matrix produces. The institution that operates the matrix without the committee produces classification without discipline. The institution that operates the committee without the matrix produces discipline without dimensional grounding. Both are required, integrated through the operational cadence the Chapter 12 specifies.
The supervisory dialogue is conducted with named authorities. The catalogue specifies the authorities by jurisdiction with the supervisory style the institution operationalizes engagement against.
| Jurisdiction | Authority | Domain | Website | Supervisory style |
|---|---|---|---|---|
| UAE (federal) | UAE Data Office | Federal data protection | dataoffice.gov.ae | Principles-based; engagement-receptive; advisory dialogue available |
| UAE (telecom-adjacent) | Telecommunications and Digital Government Regulatory Authority (TDRA) | Digital and telecom-adjacent data protection | tdra.gov.ae | Principles-based; engagement-receptive |
| UAE (DIFC) | Dubai Financial Services Authority (DFSA) | DIFC financial services and autonomous conduct | dfsa.ae | Rules-based; enforcement-engaged; principles-based dialogue available |
| UAE (DIFC data) | DIFC Commissioner of Data Protection | DIFC data protection | difc.ae | Principles-based; engagement-receptive |
| UAE (ADGM) | ADGM Financial Services Regulatory Authority (FSRA) | ADGM financial services | adgm.com | Principles-based; rules-based in banking adjacency |
| UAE (ADGM data) | ADGM Office of Data Protection | ADGM data protection | adgm.com | Principles-based; engagement-receptive |
| UAE (banking) | Central Bank of the UAE (CBUAE) | Banking, insurance, payment systems | centralbank.ae | Rules-based; engagement-receptive; MMS supervisory dialogue established |
| UAE (securities) | Securities and Commodities Authority (SCA) | Securities and algorithmic trading | sca.gov.ae | Rules-based; enforcement-engaged |
| Saudi Arabia (data and AI) | Saudi Data and AI Authority (SDAIA) | National AI governance, data, PDPL | sdaia.gov.sa | Rules-based; engagement-receptive; proactive consultation; Tier classification engagement |
| Saudi Arabia (banking) | Saudi Central Bank (SAMA) | Banking, insurance, payment systems | sama.gov.sa | Rules-based; engagement-receptive; sandbox available |
| Saudi Arabia (capital markets) | Capital Markets Authority (CMA) | Securities, algo-trading | cma.org.sa | Rules-based; enforcement-engaged |
| Saudi Arabia (cyber) | National Cybersecurity Authority (NCA) | Cybersecurity, including AI security | nca.gov.sa | Rules-based; enforcement-engaged |
| Qatar (data) | National Data Privacy Office (NDPO), within the National Cyber Security Agency (NCSA) | Data protection (PDPPL enforcement) | ndpo.gov.qa | Principles-based; engagement-receptive |
| Qatar (banking) | Qatar Central Bank (QCB) | Banking, insurance, payment systems | qcb.gov.qa | Rules-based; engagement-receptive |
| Qatar (markets) | Qatar Financial Markets Authority (QFMA) | Securities and algo-trading | qfma.org.qa | Rules-based |
| Qatar (QFC) | Qatar Financial Centre Regulatory Authority (QFCRA) | QFC financial services | qfcra.com | Principles-based; engagement-receptive |
| Bahrain (data) | Personal Data Protection Authority (PDPA) | Data protection | pdp.gov.bh | Principles-based; engagement-receptive |
| Bahrain (banking) | Central Bank of Bahrain (CBB) | Banking, insurance, capital markets | cbb.gov.bh | Rules-based; engagement-receptive; sandbox available |
| Kuwait (telecom) | Communication and Information Technology Regulatory Authority (CITRA) | Data privacy, digital regulation | citra.gov.kw | Principles-based; developing |
| Kuwait (banking) | Central Bank of Kuwait (CBK) | Banking | cbk.gov.kw | Rules-based |
| Kuwait (markets) | Capital Markets Authority (CMA Kuwait) | Securities | cma.gov.kw | Rules-based |
| Oman (data) | Ministry of Transport, Communications and IT (MTCIT) | Data protection | mtcit.gov.om | Principles-based; developing |
| Oman (banking) | Central Bank of Oman (CBO) | Banking | cbo.gov.om | Rules-based; engagement-receptive |
| Egypt (data) | Personal Data Protection Center (PDPC, under MCIT) | Data protection | mcit.gov.eg | Principles-based; engagement increasingly receptive |
| Egypt (banking) | Central Bank of Egypt (CBE) | Banking | cbe.org.eg | Rules-based; AI experimentation engagement available |
| Jordan (data) | Personal Data Protection Council (under MoDEE) | Data protection | modee.gov.jo | Principles-based; developing |
| Jordan (banking) | Central Bank of Jordan (CBJ) | Banking | cbj.gov.jo | Rules-based |
| EU (AI Act) | European Commission AI Office; national notified bodies | EU AI Act enforcement | digital-strategy.ec.europa.eu | Rules-based; conformity assessment |
| EU (data) | European Data Protection Board; national DPAs | GDPR enforcement | edpb.europa.eu | Rules-based; enforcement-engaged |
| US (banking) | OCC; Federal Reserve; FDIC | Banking, including SR 11-7 model risk | occ.gov; federalreserve.gov; fdic.gov | Principles-based with sectoral specificity; examination-driven |
| US (markets) | SEC; FINRA | Securities and algo-trading | sec.gov; finra.org | Rules-based; enforcement-engaged |
| US (consumer) | FTC; CFPB | Consumer protection, fairness | ftc.gov; consumerfinance.gov | Principles-based with enforcement focus |
| US (employment) | EEOC | Employment AI fairness | eeoc.gov | Principles-based; enforcement-engaged |
| US (health) | FDA | Medical device AI (SaMD) | fda.gov | Rules-based |
| US (AI standards) | NIST | NIST AI RMF (voluntary) | nist.gov | Voluntary; market-driven |
| China | Cyberspace Administration of China (CAC) | PIPL, Generative AI, security assessment | cac.gov.cn | Rules-based; security-centric; state-strategic |
| UK | Information Commissioner's Office (ICO); FCA; MHRA; CMA; Ofqual | Sectoral; ICO leads on data | ico.org.uk; fca.org.uk | Pro-innovation; principles-based |
| Islamic finance | AAOIFI | Sharia accounting and governance | aaoifi.com | Standard-setting; certification-based |
| Islamic finance | IFSB | Islamic financial services standards | ifsb.org | Standard-setting; principles-based |
| International standards | ISO/IEC | ISO/IEC 42001 and adjacent | iso.org | Voluntary; certification-based |
| International | OECD | OECD AI Principles | oecd.ai | Voluntary; soft-law |
| International | UNESCO | Recommendation on Ethics of AI | unesco.org | Voluntary; soft-law; member-state adopted |
The authorities catalogue is the supervisory-engagement map. The institution that has cultivated relationships with the relevant authorities operates within the supervisory dialogue. The institution that has not operates against the supervisory inquiry when it arrives without the relationship the dialogue would have produced.
The regulatory landscape is not static. The timeline indexes the key dates and milestones across the 2018 through 2027 horizon the institutions operating across the regulatory evolution must plan against.
| Year | Jurisdiction | Milestone | Operational implication |
|---|---|---|---|
| 2018 | EU | GDPR effective May 25, 2018 | First binding rights-based data protection regime with extraterritorial reach |
| 2018 | Bahrain | PDPL effective August 1, 2019 (enacted 2018) | First GCC binding data protection law |
| 2020 | Egypt | PDPL effective October 14, 2020 | First MENA non-GCC GDPR-influenced binding framework |
| 2020 | Saudi Arabia | SDAIA established | National AI authority operational |
| 2021 | Saudi Arabia | PDPL issued (Royal Decree M/19) | Framework published; phased implementation |
| 2021 | Kuwait | Data Privacy Protection Regulation (CITRA) | Framework operational |
| 2021 | UAE | PDPL (Federal Decree-Law 45) issued | Federal framework published |
| 2021 | China | PIPL effective November 1, 2021 | Personal information protection framework with extraterritorial reach |
| 2021 | UNESCO | Recommendation on Ethics of AI adopted | All 193 member states soft-law baseline |
| 2022 | UAE | PDPL effective January 1, 2022 | Federal data protection operational |
| 2022 | Oman | PDPL issued (Royal Decree 6 of 2022) | Framework published |
| 2022 | Jordan | DP Law enacted (Law No. 24, replaced earlier draft Law 15 of 2022) | Framework published |
| 2023 | Saudi Arabia | PDPL effective September 14, 2023 | Framework operational with phased enforcement |
| 2023 | Oman | PDPL effective February 13, 2023 | Framework operational |
| 2023 | US | NIST AI RMF published January 2023 | Voluntary US AI governance baseline |
| 2023 | China | Generative AI Interim Measures effective August 15, 2023 | First binding generative AI framework |
| 2023 | International | ISO/IEC 42001 published December 2023 | First international AI management system standard |
| 2023 | Jordan | AI Strategy 2023-2027 published | National AI agenda |
| 2024 | Saudi Arabia | PDPL full enforcement March 2024; SDAIA Generative AI Guidelines | Enforcement maturity advancing |
| 2024 | EU | EU AI Act in force August 1, 2024 | Phased applicability through August 2028 (Digital Omnibus deferral, 2026) |
| 2024 | Qatar | QCB AI Governance Framework | Banking AI binding framework |
| 2024 | Bahrain | CBB AI Risk Management Framework | Banking AI binding framework |
| 2024 | OECD | AI Principles refreshed | Updated global ethical baseline |
| 2024 | Jordan | DP Law effective March 17, 2024 | Framework operational |
| 2025 | EU AI Act | Prohibited practices applicable February 2, 2025; GPAI obligations applicable August 2, 2025 | First binding AI Act obligations effective |
| 2025 | UAE | UAE Data Office operationalization advancing; DIFC Regulation 10 enforcement maturing | Supervisory dialogue cadence increasing |
| 2025 | Egypt | National AI Strategy 2025-2030 published | National AI agenda |
| 2025 | Saudi Arabia | SDAIA AI Ethics Principles enforcement advancing; SAMA AI guidelines for financial institutions | Banking AI supervisory dialogue mature |
| 2026 | EU AI Act | Digital Omnibus defers high-risk obligations; Article 50 transparency and Article 4 AI-literacy remain on schedule | High-risk deadlines moved to December 2027 (Annex III) and August 2028 (Annex I) |
| 2026 | MENA | Sharia-AI overlay (AAOIFI-aligned) governance discipline maturing across Islamic finance institutions | Sharia compliance discipline operational for AI |
| 2026 | UAE | CBUAE Model Management Standards enforcement maturing; ADGM AI guidance maturing | Banking and ADGM AI supervisory dialogue mature |
| 2026 | Saudi Arabia | SDAIA Tier 1/2 supervisory dialogue at full cadence | High-risk AI supervisory engagement operational |
| 2026 | Qatar | QCB AI Framework enforcement maturing; PDPPL refresh anticipated | Supervisory dialogue advancing |
| 2027 | EU AI Act | Stand-alone Annex III high-risk obligations applicable December 2, 2027; AI embedded in regulated products (Annex I) applicable August 2, 2028 | High-risk providers and deployers under binding obligations |
| 2027 | GCC-wide | Anticipated MRM harmonization initiatives; standardized fairness reporting expected | Cross-jurisdictional discipline convergence |
| 2027 | Jordan | AI Strategy execution phase concluding; supervisory framework anticipated maturation | AI-specific supervisory architecture |
The timeline is the strategic-planning input. The institution that has built discipline against the timeline operates ahead of the regulatory evolution. The institution that has not operates against each new milestone as a surprise the operational substrate is not prepared for.
The tables are not finished documents. They are the operational substrate the institutional discipline must maintain through the supervisory cycles.
The discipline operates through four practices.
The first practice is quarterly review by the Governance Office Chapter 12 specifies. The review examines each table for regulatory changes, supervisory guidance, enforcement developments, and milestone advancement. The review output is a table-revision log the discipline operates against.
The second practice is supervisory-engagement integration. The relationships the Section A.5 catalogue indexes are the source of regulatory intelligence the tables capture. The supervisory dialogue is not an isolated function. It is the input the table-maintenance discipline depends on.
The third practice is cross-jurisdictional reconciliation. The institutions operating across multiple jurisdictions reconcile the table entries against the operational discipline applied per jurisdiction. The reconciliation surfaces the discipline asymmetries the multi-jurisdictional architecture must accommodate.
The fourth practice is the operational vocabulary calibration. The terms the tables use must match the terms the supervisory dialogue uses. The calibration is conducted by the operational compliance function and validated through the supervisory engagement.
Where most observers see reference tables, I see the operational vocabulary the institutional discipline depends on for the supervisory dialogue.
Stillness is not inactivity. It is the calibration that exposes the gap between the regulatory landscape the institution last documented and the regulatory landscape the supervisory dialogue currently inhabits. The institutions that have built table-maintenance discipline operate within the regulatory reality the supervisor inhabits. The institutions that have not operate against the regulatory landscape the deck described before the supervisory landscape moved.
This companion appendix is licensed CC BY-NC-ND 4.0, Attribution-NonCommercial-NoDerivatives: share it with credit to the author, but not for commercial use and not as a modified version. The book itself and the named frameworks (the MESA Framework, the Five-Gate Deployment Model, the AI Incident Response Protocol and the others) are © 2026 Nabeel Khan, all rights reserved.
The regulatory floor is the layer that is not negotiable.