§ 01Appendix A

Regulatory reference tables

Every instrument that binds an AI system across the Gulf and the wider region, in one place. The matrix below is the working index: 56 rows covering data protection, AI-specific rules, sectoral supervision and Sharia standards, filterable by jurisdiction and searchable by text.

Beneath it sit the seven authored table sets in full: the jurisdictional comparison across twenty-five dimensions, the global regimes comparison, penalty schedules, the use-case to regime cross-reference, the authority catalogue and the 2018 to 2027 timeline.

These dates move. They were correct at the book's release lock. Verify each one against the regulator before you rely on it, and read the maintenance notes at the end of the tables.

Companion material to AI Governance & Compliance Frameworks for the Middle East by Nabeel Khan · release v3.2, locked 17 August 2026 · Appendix A · free, no registration
§ 02Master matrix

Every instrument, filterable.

JurisdictionRegulatorFramework / InstrumentScopeStatus
UAEUAE Data OfficeFederal Decree-Law No. 45 of 2021 (PDPL)DataIn force
UAETelecommunications and Digital Government Regulatory Authority (TDRA)Digital and telecom-adjacent data protectionDataIn force
UAE (DIFC)Dubai Financial Services Authority (DFSA)DIFC Regulation 10 (autonomous conduct)Capital MarketsIn force
UAE (DIFC)DIFC Commissioner of Data ProtectionDIFC data protectionDataIn force
UAE (ADGM)ADGM Financial Services Regulatory Authority (FSRA)ADGM AI guidanceCapital MarketsDeveloping
UAE (ADGM)ADGM Office of Data ProtectionADGM data protectionDataIn force
UAECentral Bank of the UAE (CBUAE)CBUAE Model Management Standards (MMS)BankingIn force
UAESecurities and Commodities Authority (SCA)SCA algorithmic trading rulesCapital MarketsIn force
UAEGovernment of the UAEUAE National AI Strategy 2031GovernmentIn force
UAEGovernment of DubaiDubai AI RoadmapGovernmentIn force
Saudi ArabiaSaudi Data and AI Authority (SDAIA)PDPL (Royal Decree M/19 of 2021, amended 2023)DataIn force
Saudi ArabiaSaudi Data and AI Authority (SDAIA)SDAIA AI Ethics PrinciplesCross-sectorIn force
Saudi ArabiaSaudi Data and AI Authority (SDAIA)SDAIA Generative AI Guidelines (2024)Cross-sectorGuidance
Saudi ArabiaSaudi Central Bank (SAMA)SAMA AI Guidelines for Financial InstitutionsBankingGuidance
Saudi ArabiaCapital Markets Authority (CMA)CMA algo-trading rulesCapital MarketsIn force
Saudi ArabiaNational Cybersecurity Authority (NCA)Cybersecurity, including AI securityCross-sectorIn force
Saudi ArabiaGovernment of Saudi ArabiaVision 2030 AI agendaGovernmentIn force
QatarNational Data Privacy Office (NDPO), within the NCSALaw No. 13 of 2016 (PDPPL)DataIn force
QatarQatar Central Bank (QCB)QCB AI Governance Framework (2024)BankingIn force
QatarQatar Financial Markets Authority (QFMA)Securities and algo-tradingCapital MarketsIn force
Qatar (QFC)Qatar Financial Centre Regulatory Authority (QFCRA)QFC financial servicesCapital MarketsIn force
QatarGovernment of QatarQatar National AI StrategyGovernmentIn force
BahrainPersonal Data Protection Authority (PDPA)Personal Data Protection Law (Law No. 30 of 2018)DataIn force
BahrainCentral Bank of Bahrain (CBB)CBB AI Risk Management Framework (2024)BankingIn force
BahrainGovernment of BahrainNational AI StrategyGovernmentIn force
KuwaitCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation (CITRA 2021)DataIn force
KuwaitCentral Bank of Kuwait (CBK)CBK Banking Technology StandardsBankingIn force
KuwaitCapital Markets Authority (CMA Kuwait)CMA algo-trading rulesCapital MarketsIn force
KuwaitGovernment of KuwaitKuwait Vision 2035 AI agendaGovernmentDeveloping
OmanMinistry of Transport, Communications and IT (MTCIT)Royal Decree 6 of 2022 (PDPL)DataIn force
OmanCentral Bank of Oman (CBO)CBO AI GovernanceBankingDeveloping
OmanGovernment of OmanOman Vision 2040 AI agendaGovernmentDeveloping
EgyptPersonal Data Protection Center (PDPC, under MCIT)Law No. 151 of 2020 (PDPL)DataIn force
EgyptCentral Bank of Egypt (CBE)CBE AI experimentationBankingDeveloping
EgyptGovernment of EgyptNational AI Strategy 2025-2030GovernmentIn force
JordanPersonal Data Protection Council (under MoDEE)Law No. 24 of 2023 (Data Protection Law)DataIn force
JordanCentral Bank of Jordan (CBJ)CBJ AI guidanceBankingDeveloping
JordanGovernment of JordanJordan AI Strategy 2023-2027GovernmentIn force
EUEuropean Commission AI Office; national notified bodiesRegulation (EU) 2024/1689 (AI Act)Cross-sectorIn force
EUEuropean Data Protection Board; national DPAsGDPRDataIn force
USOCC; Federal Reserve; FDICSR 11-7 (model risk)BankingIn force
USSEC; FINRASecurities and algo-tradingCapital MarketsIn force
USFTC; CFPBFTC Section 5Cross-sectorIn force
USEEOCEmployment AI fairnessCross-sectorIn force
USFDAMedical device AI (SaMD)HealthcareIn force
USNISTNIST AI RMF (voluntary)Cross-sectorGuidance
ChinaCyberspace Administration of China (CAC)PIPL (2021)DataIn force
ChinaCyberspace Administration of China (CAC)Generative AI Interim Measures (2023)Cross-sectorIn force
ChinaCyberspace Administration of China (CAC)Data Security Law (2021)DataIn force
ChinaCyberspace Administration of China (CAC)Cybersecurity Law (2017)Cross-sectorIn force
UKInformation Commissioner's Office (ICO); FCA; MHRA; CMA; OfqualPro-innovation regulatory approach (white paper 2023)Cross-sectorGuidance
Islamic financeAAOIFISharia accounting and governance standardsShariaIn force
Islamic financeIFSBIslamic financial services standardsShariaIn force
International standardsISO/IECISO/IEC 42001:2023Cross-sectorIn force
InternationalOECDOECD AI Principles (2019, refreshed 2024)Cross-sectorGuidance
InternationalUNESCOUNESCO Recommendation on Ethics of AI (2021)Cross-sectorGuidance
§ 03The seven table sets

The tables in full.

A.1

MENA Jurisdictional Comparison Matrix

The matrix maps the six core MENA jurisdictions (UAE, Saudi Arabia, Qatar, Bahrain, Kuwait, Oman, Egypt, Jordan) across twenty-five compliance dimensions. The dimensions cover the data protection foundation, the AI-specific provisions, the supervisory architecture, and the operational obligations the institutions operating in each jurisdiction must satisfy.

A.1.1 Data Protection Foundation (Dimensions 1 through 10)
DimensionUAESaudi ArabiaQatarBahrainKuwaitOmanEgyptJordan
Primary data protection lawFederal Decree-Law No. 45 of 2021 (PDPL)PDPL (Royal Decree M/19 of 2021, amended 2023)Law No. 13 of 2016 (PDPPL)Personal Data Protection Law (Law No. 30 of 2018)Data Privacy Protection Regulation (CITRA Decision 26/2024)Royal Decree 6 of 2022 (PDPL)Law No. 151 of 2020 (PDPL)Law No. 24 of 2023 (Data Protection Law)
Effective dateJanuary 1, 2022September 14, 2023 (full enforcement March 2024)December 29, 2016August 1, 2019February 19, 2024February 13, 2023October 14, 2020March 17, 2024
Primary regulatorUAE Data Office (federal); TDRA (telecom-adjacent)SDAIA (Saudi Data and AI Authority)National Data Privacy Office (NDPO), within the National Cyber Security Agency (NCSA)Personal Data Protection AuthorityCommunication and Information Technology Regulatory AuthorityMinistry of Transport, Communications and ITPersonal Data Protection Center (under MCIT)Personal Data Protection Council (under MoDEE)
Extraterritorial scopeYes. Applies to processing of UAE-resident personal data regardless of controller locationYes. Applies to processing of Saudi-resident personal data regardless of locationYes for Qatari personal dataLimited extraterritorialityLimited extraterritorialityYes for Omani personal dataYes for Egyptian personal dataYes for Jordanian personal data
Lawful basis modelSix bases (consent, contract, legal obligation, vital interest, public interest, legitimate interest)Six bases (consent-primary)Six basesSix basesConsent-primarySix basesSix bases (GDPR-aligned)Six bases (GDPR-aligned)
Consent standardExplicit, specific, informed, affirmativeExplicit, specific, informed (legitimate interest requires impact assessment)Explicit, specific, informedExplicitExplicitExplicitExplicitExplicit
Data subject rightsSeven (access, correction, erasure, objection, restriction, portability, transparency)SevenSevenSixSixSevenSix (access, correction, deletion, objection, portability, transparency)Six
Data localizationNo general mandate; sector-specific (CBUAE banking data preferences)Yes. Mandatory localization for personal data of Saudi residents (PDPL Article 29)No general mandate; sectoral preferencesNo general mandateNo general mandateNo general mandateNo general mandateNo general mandate
Cross-border transfer mechanismAdequacy assessment by UAE Data Office; SCCs; BCRs; explicit consentSDAIA-approved transfer mechanisms; adequacy whitelist; SCCs; explicit consentAdequacy assessment; contractual safeguards; consentAdequacy assessment; contractual safeguardsContractual safeguards; consentAdequacy assessment; contractual safeguards; consentContractual safeguards; consent for non-adequate jurisdictionsContractual safeguards; consent for non-adequate jurisdictions
Breach notification timeline72 hours to UAE Data Office and affected data subjects72 hours to SDAIA and affected data subjects72 hours to the NDPO and affected data subjects72 hours to PDPA72 hours to CITRA72 hours to MTCIT72 hours to PDPC72 hours to PDPC
A.1.2 AI-Specific Provisions (Dimensions 11 through 17)
DimensionUAESaudi ArabiaQatarBahrainKuwaitOmanEgyptJordan
Primary AI policy instrumentUAE National AI Strategy 2031; DIFC Regulation 10; ADGM AI guidance; Dubai AI RoadmapSDAIA AI Ethics Principles; SDAIA Generative AI Guidelines (2024); Vision 2030 AI agendaQatar National AI Strategy; QCB AI Governance Framework (2024)National AI Strategy; CBB AI Risk Management Framework (2024)Kuwait Vision 2035 AI agenda (developing)Oman Vision 2040 AI agenda (developing)National AI Strategy 2025-2030Jordan AI Strategy 2023-2027
AI-specific binding rulesDIFC Regulation 10 (autonomous conduct); CBUAE Model Management Standards (MMS)SDAIA AI Ethics Principles (binding for government and high-risk); SAMA AI guidelines for bankingQCB AI Governance Framework (banking); PDPPL automated decision rulesCBB AI Risk Management Framework; PDPL automated decision provisionsDeveloping; CMA algo-trading rulesDevelopingDeveloping; PDPL automated decision provisionsDeveloping; DP Law automated decision provisions
Explainability requirementRequired for DIFC autonomous conduct; CBUAE MMS Tier 1/2; SDAIA Tier alignmentRequired for SDAIA Tier 1 and Tier 2 AI systemsRequired for QCB-supervised AI; PDPPL automated decisionsRequired for CBB-supervised AIRequired for CMA algo-tradingEmergingEmergingEmerging
Fairness testingRequired for high-risk systems (DIFC, CBUAE, ADGM)Mandatory for SDAIA Tier 1 and Tier 2Required for QCB consumer-facing AIRequired for CBB consumer-facing AIRequired for CMA-supervised algo systemsEmergingEmergingEmerging
Human oversightRequired (DIFC Regulation 10) for material decisionsRequired for SDAIA Tier 1 and Tier 2Required (QCB Framework) for material decisionsRequired (CBB Framework)Required for CMA-supervised systemsEmergingEmergingEmerging
Automated decision opt-outRequired (DIFC Regulation 10)Required for high-risk SDAIA-supervised systemsRequired (PDPPL)Required (PDPL)LimitedRequired (PDPL)Required (PDPL)Required (DP Law)
Sharia-AI overlayApplicable for Islamic finance institutions (AAOIFI/IFSB)Applicable; AAOIFI alignment standardApplicable; AAOIFI alignmentApplicable; AAOIFI alignmentApplicable; AAOIFI alignmentApplicable; AAOIFI alignmentLimited Islamic finance sectorLimited Islamic finance sector
A.1.3 Supervisory Architecture and Operational Obligations (Dimensions 18 through 25)
DimensionUAESaudi ArabiaQatarBahrainKuwaitOmanEgyptJordan
Sectoral banking regulatorCBUAESAMAQCBCBBCBKCBOCBECBJ
Banking AI directiveCBUAE Model Management Standards (MMS)SAMA AI Guidelines for Financial InstitutionsQCB AI Governance FrameworkCBB AI Risk Management FrameworkCBK Banking Technology StandardsCBO AI Governance (developing)CBE AI experimentation (developing)CBJ AI guidance (developing)
DPIA requirementRequired for high-risk processingRequired (Tier 1/2)Required for high-risk processingRequired for high-risk processingRecommendedRequired for high-risk processingRequired for high-risk processingRequired for high-risk processing
DPO requirementMandatory for designated entities; recommended for othersMandatory for controllers processing sensitive data at scaleMandatory for public bodies and large processorsRecommendedRecommendedRecommendedMandatory for public bodies and large processorsMandatory for public bodies and large processors
Registration with regulatorRequired for designated processing activitiesRequired for high-risk controllers (SDAIA registration)Required for designated processingRequired for designated processingNot requiredRequired for designated processingRequired for licensed activitiesRequired for licensed activities
Maximum administrative fineAED 5 million (PDPL); higher for sectoral violationsSAR 5 million (PDPL); SAR 50,000 for non-material breachesQAR 5 million (PDPPL)BHD 1 million (PDPL)KWD 500,000OMR 500,000 (PDPL)EGP 5 million (PDPL)JOD 1 million (DP Law)
Criminal liabilityAvailable for serious violationsAvailable; up to 2 years imprisonment for sensitive data misuseAvailable for serious violationsAvailableLimitedAvailableAvailable; up to 5 years for sensitive data misuseAvailable for serious violations
Supervisory styleEngagement-receptive; principles-based; advisory dialogue availableEngagement-receptive; rules-based posture in financial sector; SDAIA proactive consultationEngagement-receptive; principles-basedEngagement-receptive; rules-based in bankingDeveloping; engagement-receptiveEngagement-receptive; developingDeveloping; engagement increasingly receptiveDeveloping; engagement increasingly receptive

The matrix is the navigation aid. The chapters specify what the matrix indexes. The institution operating across multiple jurisdictions calibrates discipline to the strictest applicable obligation per dimension, then operationalizes the calibrated discipline as the regional baseline the MESA framework Chapter 4 specifies sustains.

Three operational notes anchor the matrix interpretation. The first note is the consent-standard convergence. The eight frameworks converge on explicit, specific, informed consent as the operational consent standard. The convergence enables a single consent-management discipline to satisfy all eight perimeters through the strictest formulation. The institutions operating across multiple perimeters operationalize one consent posture rather than eight. The second note is the breach-notification convergence. The 72-hour breach notification timeline is shared across UAE, Saudi Arabia, Qatar, Bahrain, Kuwait, Oman, Egypt, and Jordan. The shared timeline enables a single incident-response discipline to satisfy all eight perimeters through the cadence the strictest timeline requires. The discipline the Chapter 13 Data Governance Stack specifies operationalizes the convergence. The third note is the data-localization divergence. Saudi Arabia is the binding localization outlier. The Saudi data architecture must accommodate the localization. The non-Saudi data architecture can flow under safeguards. The Chapter 9 Cross-Border AI Architecture Patterns operationalize the divergence through the Sovereign Silos, Federated, and Regional Hub patterns the multi-jurisdictional institution selects from.

The matrix is not the discipline. The matrix is the dimensional map the discipline operates against. The institution that mistakes the matrix for the discipline produces compliance documentation without the operational substrate the supervisor inspects through the documentation. The institution that operates the discipline against the matrix produces the operational substrate the documentation traces and the supervisor recognizes.

A.2

Global Regulatory Regimes Comparison

The global regimes are the extraterritorial reality MENA institutions operating internationally inhabit. The matrix maps five regimes across ten dimensions.

DimensionEU AI ActUS SectoralChinaUKInternational Standards (ISO/IEC 42001, OECD, UNESCO)
Primary instrumentRegulation (EU) 2024/1689 (AI Act); GDPRNIST AI RMF (voluntary); EEOC, SEC, FDA, OCC, FRB sectoral guidance; SR 11-7 (model risk); FTC Section 5Cybersecurity Law (2017); Data Security Law (2021); PIPL (2021); Generative AI Interim Measures (2023)Pro-innovation regulatory approach (white paper 2023); ICO data protection; sectoral regulatorsISO/IEC 42001:2023; OECD AI Principles (2019, refreshed 2024); UNESCO Recommendation on Ethics of AI (2021)
Effective dateAugust 1, 2024 (phased through August 2, 2027)NIST AI RMF January 2023; sectoral variesPIPL November 1, 2021; Generative AI Measures August 15, 2023Pro-innovation approach 2023 (non-binding); GDPR-UK ongoingISO/IEC 42001 December 2023; OECD 2019; UNESCO 2021
Risk classificationUnacceptable; High-Risk; Limited-Risk; Minimal-Risk; General Purpose AI (GPAI)Sectoral; SR 11-7 tiered model riskFiling-required generative AI; security assessment trigger for personal info; sensitive personal information separateRisk-based; principles-led; sector regulator discretionRisk-management based; voluntary certification
Extraterritorial reachYes. Applies to providers and deployers whose AI system output is used in EU regardless of locationLimited. Sectoral reach (US-listed entities, US-domiciled financial institutions)Yes. PIPL applies to processing of Chinese personal information for service to or analysis of Chinese individuals from abroadLimited. UK GDPR territorial scopeVoluntary; reach via procurement, insurance, audit citation
Documentation requirementArticle 11 technical documentation (high-risk); model card (GPAI)NIST AI RMF Govern/Map/Measure/Manage; SR 11-7 model documentation; sectoral file requirementsGenerative AI service filing; security assessment documentation; PIPIA (Personal Information Impact Assessment)DPIAs under UK GDPR; sectoral documentationISO/IEC 42001 management system documentation; OECD/UNESCO self-attestation
Human oversightRequired (Article 14) for high-risk systemsRequired by SR 11-7 for material model use; required by EEOC for employment decisionsRequired for generative AI service provision (content moderation); required for sensitive personal information processingRequired by sectoral regulators (FCA, MHRA, Ofqual)Recommended (ISO/IEC 42001 clause 8); core OECD/UNESCO principle
Maximum penaltyEUR 35 million or 7 percent of global annual turnover (prohibited practices); EUR 15 million or 3 percent (other violations); EUR 7.5 million or 1 percent (information violations)Sectoral; SEC penalties unlimited; FTC penalties USD 51,744 per violation (2024 adjusted); OCC enforcement actionsCNY 50 million or 5 percent of preceding year's annual turnover (PIPL); criminal liability availableUK GDPR: GBP 17.5 million or 4 percent of global turnoverNon-enforcement; certification withdrawal
Audit and certificationConformity assessment (high-risk); notified body designationSectoral examinations; SR 11-7 independent validation; SOC reportingCAC security assessment; algorithm filingICO investigations; sectoral examinationsISO/IEC 42001 third-party certification
Cross-border transfer regimeSchrems II framework; SCCs; BCRs; adequacy decisionsSectoral; CFIUS for sensitive transactions; bulk data executive orderCAC security assessment; certification; SCCs approved by CACUK adequacy framework; IDTAs; UK SCCsOECD Cross-Border Privacy Rules; APEC alignment
Supervisory styleRules-based; conformity assessment; enforcement-heavyPrinciples-based with sectoral specificity; enforcement through examinationsRules-based; security-centric; state-strategicPro-innovation; principles-based; regulator-flexibleVoluntary; market-driven

The global regimes are not optional for MENA institutions serving international markets. The EU AI Act reaches MENA institutions whose AI system output is used in the EU. PIPL reaches MENA institutions processing Chinese personal information. American sectoral discipline reaches MENA institutions with US-listed exposure. The extraterritorial reality is the current operational condition the institutions operating across the perimeters inhabit.

Where most observers see five distinct global regimes, I see one convergence vocabulary the international standards layer (ISO/IEC 42001, OECD, UNESCO) increasingly codifies and the regional regimes increasingly translate. The institution that built MESA discipline against the convergence vocabulary operates across the regimes through the structural commonality. The institution that built compliance against the regimes one at a time operates against the divergence at each perimeter and accumulates the operational overhead the convergence would have absorbed.

A.3

Penalty Schedules by Jurisdiction and Violation Type

Penalty is not punishment. It is the cost calibration the supervisory framework applies to the gap between the discipline the institution declared and the discipline the operational substrate produced.

The penalty schedules support the materiality analysis the institutions operating across the regulatory landscape conduct. The schedules are inputs to the risk-tolerance calibration the Chapter 14 Vendor Risk Lifecycle specifies, the financial-impact dimension the Chapter 12 Governance Office Blueprint incorporates, and the cost-of-non-compliance analysis the Chapter 11 MRM Stack supports.

A.3.1 UAE Penalty Schedule
Violation categoryPenalty range (AED)Penalty range (USD equivalent)Supervisory action available
Processing personal data without lawful basisAED 250,000 to 5,000,000USD 68,000 to 1,360,000Cease-and-desist; data deletion order
Failure to obtain valid consentAED 250,000 to 2,000,000USD 68,000 to 545,000Reprocessing under valid basis required
Breach notification failure (72-hour rule)AED 100,000 to 1,000,000USD 27,000 to 272,000Public notification order
Cross-border transfer without safeguardsAED 250,000 to 5,000,000USD 68,000 to 1,360,000Transfer suspension order
Data security inadequacyAED 100,000 to 2,000,000USD 27,000 to 545,000Remediation order; security audit
Data subject rights obstructionAED 100,000 to 1,000,000USD 27,000 to 272,000Rights enforcement order
DIFC Regulation 10 violation (autonomous conduct)Up to AED 5,000,000 per violation; aggregate up to AED 35,000,000Up to USD 1,360,000 per violation; aggregate USD 9,500,000DFSA enforcement; license suspension available
CBUAE MMS violationUp to AED 10,000,000 per violationUp to USD 2,720,000Banking license action; model deployment suspension
SCA algorithmic trading violationAED 50,000 to 10,000,000USD 13,600 to 2,720,000Trading suspension; license action
A.3.2 Saudi Arabia Penalty Schedule
Violation categoryPenalty range (SAR)Penalty range (USD equivalent)Supervisory action available
Processing sensitive personal data without basisSAR 1,000,000 to 5,000,000 + up to 2 years imprisonmentUSD 267,000 to 1,333,000Cease-and-desist; data deletion
Cross-border transfer without SDAIA approvalSAR 1,000,000 to 5,000,000USD 267,000 to 1,333,000Transfer suspension
Failure to localize personal data (PDPL Article 29)SAR 500,000 to 3,000,000USD 133,000 to 800,000Localization order
Consent violationSAR 500,000 to 3,000,000USD 133,000 to 800,000Reprocessing requirement
Breach notification failureSAR 100,000 to 1,000,000USD 27,000 to 267,000Public notification
Data subject rights obstructionSAR 100,000 to 1,000,000USD 27,000 to 267,000Rights enforcement
SAMA banking AI violationSAR 1,000,000 to 10,000,000 per violationUSD 267,000 to 2,667,000Banking license action; deployment suspension
SDAIA AI Ethics Principles violation (Tier 1/2)SAR 500,000 to 5,000,000USD 133,000 to 1,333,000Deployment prohibition
CMA algo-trading violationSAR 100,000 to 10,000,000USD 27,000 to 2,667,000Trading suspension
A.3.3 Qatar Penalty Schedule
Violation categoryPenalty range (QAR)Penalty range (USD equivalent)Supervisory action available
Processing without lawful basisQAR 1,000,000 to 5,000,000USD 275,000 to 1,375,000Cease-and-desist
Cross-border transfer without safeguardsQAR 500,000 to 5,000,000USD 137,000 to 1,375,000Transfer suspension
Breach notification failureQAR 200,000 to 1,000,000USD 55,000 to 275,000Public notification
Consent violationQAR 500,000 to 3,000,000USD 137,000 to 825,000Reprocessing requirement
Data subject rights obstructionQAR 100,000 to 1,000,000USD 27,000 to 275,000Rights enforcement
QCB AI Framework violationQAR 500,000 to 5,000,000USD 137,000 to 1,375,000Banking license action
Qatar Exchange algo-trading violationQAR 100,000 to 5,000,000USD 27,000 to 1,375,000Trading suspension
A.3.4 Bahrain Penalty Schedule
Violation categoryPenalty range (BHD)Penalty range (USD equivalent)Supervisory action available
Processing without lawful basisBHD 50,000 to 1,000,000USD 132,500 to 2,650,000Cease-and-desist
Consent violationBHD 20,000 to 500,000USD 53,000 to 1,325,000Reprocessing requirement
Breach notification failureBHD 10,000 to 300,000USD 26,500 to 795,000Public notification
Data subject rights obstructionBHD 10,000 to 300,000USD 26,500 to 795,000Rights enforcement
CBB AI Risk Management violationUp to BHD 1,000,000Up to USD 2,650,000Banking license action
A.3.5 Kuwait Penalty Schedule
Violation categoryPenalty range (KWD)Penalty range (USD equivalent)Supervisory action available
Processing without consentKWD 50,000 to 500,000USD 163,000 to 1,627,000Cease-and-desist
Data security failureKWD 20,000 to 300,000USD 65,000 to 976,000Remediation order
Breach notification failureKWD 10,000 to 200,000USD 32,500 to 651,000Public notification
CMA algo-trading violationKWD 50,000 to 500,000USD 163,000 to 1,627,000Trading suspension
A.3.6 Oman, Egypt, Jordan Penalty Schedules
JurisdictionMaximum administrative fineCriminal liabilityNotes
OmanOMR 500,000 (USD 1,300,000)Available for sensitive data misusePDPL effective 2023; supervisory architecture developing
EgyptEGP 5,000,000 (USD 100,000); higher for sensitive data (up to EGP 10,000,000)Available; up to 5 years for sensitive data misuse; up to 3 years for cross-border violationsPDPL effective 2020; PDPC operational
JordanJOD 1,000,000 (USD 1,410,000)Available for serious violationsDP Law effective 2024; supervisory architecture developing
A.3.7 Global Regime Penalty Comparison
RegimeMaximum penaltyNotes
EU AI ActEUR 35,000,000 or 7 percent of global annual turnover (prohibited practices); EUR 15,000,000 or 3 percent (high-risk violations); EUR 7,500,000 or 1 percent (information violations)Whichever is higher; applies to GPAI providers and high-risk deployers
GDPR (EU)EUR 20,000,000 or 4 percent of global annual turnoverWhichever is higher
US FTC Section 5USD 51,744 per violation (2024 adjusted)Per-violation calculation can aggregate substantially
US SR 11-7 (banking)Not directly fined; enforcement through examination findings, MOUs, consent ordersCapital surcharges available
China PIPLCNY 50,000,000 or 5 percent of preceding year's annual turnoverWhichever is higher; criminal liability available
China Generative AI MeasuresCNY 100,000 to 1,000,000; service suspension; criminal liabilityPlus content remediation orders
UK GDPRGBP 17,500,000 or 4 percent of global turnoverWhichever is higher
ISO/IEC 42001Certification withdrawalNon-enforcement; market consequence through procurement

The penalty schedules are inputs, not endpoints. The institution that operates against the penalty schedule rather than against the discipline the schedule indexes will discover that the schedule moved while the discipline did not. The discipline operating against the substrate the schedule indexes survives the schedule revisions the regulatory evolution will continue to produce.

A.4

AI Use Case to Regulatory Regime Cross-Reference Matrix

The use case is the operational unit the discipline applies to. The matrix supports the use-case approval discipline Chapter 11 specifies through the MRM Stack and the Tier 1, Tier 2, Tier 3 classification the Governance Office Blueprint Chapter 12 operationalizes.

AI use caseUAE applicable regimesSaudi applicable regimesQatar applicable regimesEgypt applicable regimesGlobal applicable regimesTypical risk tier
Credit scoring (retail lending)PDPL; DIFC Reg 10 (if DIFC); CBUAE MMS; Sharia (Islamic finance)PDPL; SAMA AI Guidelines; SDAIA Tier 1/2; ShariaPDPPL; QCB AI FrameworkPDPL; CBE guidance (developing)EU AI Act (Annex III high-risk); US ECOA/Reg B; SR 11-7; ISO/IEC 42001Tier 1
Anti-money-laundering monitoringPDPL; CBUAE MMSPDPL; SAMA AI GuidelinesPDPPL; QCB AI FrameworkPDPLEU AI Act (limited risk); US BSA/AML; FATF; ISO/IEC 42001Tier 2
Fraud detectionPDPL; CBUAE MMSPDPL; SAMA AI GuidelinesPDPPL; QCB AI FrameworkPDPL; CBE experimentationEU AI Act (limited risk); sectoral; ISO/IEC 42001Tier 2
Insurance underwritingPDPL; CBUAE (insurance); Sharia (Takaful)PDPL; SAMA AI Guidelines; ShariaPDPPL; QCB InsurancePDPLEU AI Act (Annex III high-risk for life and health insurance); state insurance law; ISO/IEC 42001Tier 1
Insurance claims automationPDPL; CBUAE (insurance)PDPL; SAMA AI GuidelinesPDPPL; QCB InsurancePDPLEU AI Act (high-risk for life and health); state insurance lawTier 1
Algorithmic tradingPDPL; SCAPDPL; CMAPDPPL; Qatar ExchangePDPL; FRAEU MiFID II; US SEC Reg ATS; SR 11-7Tier 1
Robo-advisory (wealth management)PDPL; SCAPDPL; CMA; SDAIA Tier 2PDPPL; QFMAPDPL; FRAEU MiFID II; US SEC Investment Advisers ActTier 1
Customer service chatbot (non-decisional)PDPLPDPL; SDAIA Tier 3PDPPLPDPLEU AI Act (limited risk if transparency); ISO/IEC 42001Tier 3
Customer service chatbot (decisional)PDPL; DIFC Reg 10 (if applicable)PDPL; SDAIA Tier 1/2PDPPL; sectoralPDPLEU AI Act (limited to high-risk depending on decision domain)Tier 2
Generative AI for content productionPDPLPDPL; SDAIA Generative AI GuidelinesPDPPLPDPLEU AI Act (limited risk; transparency obligations); China Generative AI Measures (if China-facing)Tier 3
Generative AI for legal or medical advicePDPL; sectoral (DHA for health)PDPL; SDAIA Tier 1/2; MoHPDPPL; MoPHPDPL; MoHEU AI Act (high-risk in healthcare and legal); FDA (medical devices)Tier 1
HR resume screeningPDPLPDPL; SDAIA Tier 1PDPPLPDPLEU AI Act (Annex III high-risk for employment); US EEOC; NYC Local Law 144Tier 1
HR performance managementPDPLPDPL; SDAIA Tier 1PDPPLPDPLEU AI Act (Annex III high-risk); US EEOCTier 1
Biometric identification (facial recognition)PDPL; sectoralPDPL; SDAIA Tier 1; NCAPDPPLPDPLEU AI Act (Annex III high-risk; some prohibited); US state laws (IL BIPA, TX)Tier 1
Predictive maintenance (industrial)Sectoral (energy, manufacturing)SectoralSectoralSectoralISO/IEC 42001; sectoralTier 3
Marketing personalizationPDPLPDPL; SDAIA Tier 3PDPPLPDPLEU AI Act (limited risk); GDPR (Article 22 if automated)Tier 3
Pricing optimization (consumer)PDPL; SCA (if securities-adjacent)PDPL; SDAIA Tier 2PDPPLPDPLEU AI Act (limited risk); FTC unfairnessTier 2
Predictive policing or social scoringProhibited absent specific authorityProhibited absent specific authority; SDAIA Tier 1 (if authorized)Prohibited absent specific authorityProhibited absent specific authorityEU AI Act (prohibited or restricted)Prohibited or Tier 1
Educational scoring or admissionsPDPL; sectoral (ADEK, KHDA)PDPL; MoE; SDAIA Tier 1PDPPL; MoEHEPDPL; MoEEU AI Act (Annex III high-risk for education)Tier 1
Healthcare diagnostic AIPDPL; sectoral (DHA, DoH, MoHAP)PDPL; MoH; SDAIA Tier 1PDPPL; MoPHPDPL; MoHEU AI Act (high-risk); FDA SaMD; MDRTier 1
Sharia screening (Islamic finance products)AAOIFI; IFSB; PDPLAAOIFI; IFSB; PDPL; SAMAAAOIFI; IFSB; PDPPL; QCBLimited applicabilityAAOIFI; IFSBTier 1

The matrix is the operational vocabulary for the use-case approval committee. The institution operates against the matrix to identify the applicable regulatory regimes per use case, then operationalizes the discipline the regimes require through the MRM Stack the Chapter 11 specifies and the Governance Office Blueprint the Chapter 12 operationalizes.

Four use-case classifications deserve specific operational note. The first classification is the Tier 1 high-stakes consumer-facing AI (credit scoring, insurance underwriting, healthcare diagnostic, HR resume screening, biometric identification, educational scoring). These use cases attract the strictest convergent obligations across MENA, EU, and US regimes. The discipline calibrated to EU AI Act Annex III high-risk obligations the Chapter 2 specifies satisfies most other regimes by transitivity. The second classification is the algorithmic trading and securities-adjacent AI. These use cases attract sectoral securities-regulator obligations across SCA, CMA Saudi Arabia, QFMA, CMA Kuwait, FRA Egypt, and SEC. The discipline calibrated to SR 11-7 model risk management satisfies most regimes structurally. The third classification is the Sharia-AI overlay for Islamic finance products. These use cases attract the AAOIFI and IFSB standards in addition to the conventional regimes. The Chapter 7 Sharia AI Governance specifies the discipline. The fourth classification is the generative AI for content production and the customer-service chatbot use cases. These use cases attract transparency obligations under EU AI Act limited-risk provisions, SDAIA Generative AI Guidelines, and China Generative AI Measures (if China-facing). The discipline calibrated to disclosure and content-moderation obligations the Chapter 17 Agentic AI Integration specifies satisfies the convergent transparency requirement.

The matrix is the input. The use-case approval committee is the operational discipline. The Tier classification (Tier 1, Tier 2, Tier 3) the Governance Office Blueprint Chapter 12 operationalizes is the structural output the matrix produces. The institution that operates the matrix without the committee produces classification without discipline. The institution that operates the committee without the matrix produces discipline without dimensional grounding. Both are required, integrated through the operational cadence the Chapter 12 specifies.

A.5

Regulatory Authority Catalogue

The supervisory dialogue is conducted with named authorities. The catalogue specifies the authorities by jurisdiction with the supervisory style the institution operationalizes engagement against.

JurisdictionAuthorityDomainWebsiteSupervisory style
UAE (federal)UAE Data OfficeFederal data protectiondataoffice.gov.aePrinciples-based; engagement-receptive; advisory dialogue available
UAE (telecom-adjacent)Telecommunications and Digital Government Regulatory Authority (TDRA)Digital and telecom-adjacent data protectiontdra.gov.aePrinciples-based; engagement-receptive
UAE (DIFC)Dubai Financial Services Authority (DFSA)DIFC financial services and autonomous conductdfsa.aeRules-based; enforcement-engaged; principles-based dialogue available
UAE (DIFC data)DIFC Commissioner of Data ProtectionDIFC data protectiondifc.aePrinciples-based; engagement-receptive
UAE (ADGM)ADGM Financial Services Regulatory Authority (FSRA)ADGM financial servicesadgm.comPrinciples-based; rules-based in banking adjacency
UAE (ADGM data)ADGM Office of Data ProtectionADGM data protectionadgm.comPrinciples-based; engagement-receptive
UAE (banking)Central Bank of the UAE (CBUAE)Banking, insurance, payment systemscentralbank.aeRules-based; engagement-receptive; MMS supervisory dialogue established
UAE (securities)Securities and Commodities Authority (SCA)Securities and algorithmic tradingsca.gov.aeRules-based; enforcement-engaged
Saudi Arabia (data and AI)Saudi Data and AI Authority (SDAIA)National AI governance, data, PDPLsdaia.gov.saRules-based; engagement-receptive; proactive consultation; Tier classification engagement
Saudi Arabia (banking)Saudi Central Bank (SAMA)Banking, insurance, payment systemssama.gov.saRules-based; engagement-receptive; sandbox available
Saudi Arabia (capital markets)Capital Markets Authority (CMA)Securities, algo-tradingcma.org.saRules-based; enforcement-engaged
Saudi Arabia (cyber)National Cybersecurity Authority (NCA)Cybersecurity, including AI securitynca.gov.saRules-based; enforcement-engaged
Qatar (data)National Data Privacy Office (NDPO), within the National Cyber Security Agency (NCSA)Data protection (PDPPL enforcement)ndpo.gov.qaPrinciples-based; engagement-receptive
Qatar (banking)Qatar Central Bank (QCB)Banking, insurance, payment systemsqcb.gov.qaRules-based; engagement-receptive
Qatar (markets)Qatar Financial Markets Authority (QFMA)Securities and algo-tradingqfma.org.qaRules-based
Qatar (QFC)Qatar Financial Centre Regulatory Authority (QFCRA)QFC financial servicesqfcra.comPrinciples-based; engagement-receptive
Bahrain (data)Personal Data Protection Authority (PDPA)Data protectionpdp.gov.bhPrinciples-based; engagement-receptive
Bahrain (banking)Central Bank of Bahrain (CBB)Banking, insurance, capital marketscbb.gov.bhRules-based; engagement-receptive; sandbox available
Kuwait (telecom)Communication and Information Technology Regulatory Authority (CITRA)Data privacy, digital regulationcitra.gov.kwPrinciples-based; developing
Kuwait (banking)Central Bank of Kuwait (CBK)Bankingcbk.gov.kwRules-based
Kuwait (markets)Capital Markets Authority (CMA Kuwait)Securitiescma.gov.kwRules-based
Oman (data)Ministry of Transport, Communications and IT (MTCIT)Data protectionmtcit.gov.omPrinciples-based; developing
Oman (banking)Central Bank of Oman (CBO)Bankingcbo.gov.omRules-based; engagement-receptive
Egypt (data)Personal Data Protection Center (PDPC, under MCIT)Data protectionmcit.gov.egPrinciples-based; engagement increasingly receptive
Egypt (banking)Central Bank of Egypt (CBE)Bankingcbe.org.egRules-based; AI experimentation engagement available
Jordan (data)Personal Data Protection Council (under MoDEE)Data protectionmodee.gov.joPrinciples-based; developing
Jordan (banking)Central Bank of Jordan (CBJ)Bankingcbj.gov.joRules-based
EU (AI Act)European Commission AI Office; national notified bodiesEU AI Act enforcementdigital-strategy.ec.europa.euRules-based; conformity assessment
EU (data)European Data Protection Board; national DPAsGDPR enforcementedpb.europa.euRules-based; enforcement-engaged
US (banking)OCC; Federal Reserve; FDICBanking, including SR 11-7 model riskocc.gov; federalreserve.gov; fdic.govPrinciples-based with sectoral specificity; examination-driven
US (markets)SEC; FINRASecurities and algo-tradingsec.gov; finra.orgRules-based; enforcement-engaged
US (consumer)FTC; CFPBConsumer protection, fairnessftc.gov; consumerfinance.govPrinciples-based with enforcement focus
US (employment)EEOCEmployment AI fairnesseeoc.govPrinciples-based; enforcement-engaged
US (health)FDAMedical device AI (SaMD)fda.govRules-based
US (AI standards)NISTNIST AI RMF (voluntary)nist.govVoluntary; market-driven
ChinaCyberspace Administration of China (CAC)PIPL, Generative AI, security assessmentcac.gov.cnRules-based; security-centric; state-strategic
UKInformation Commissioner's Office (ICO); FCA; MHRA; CMA; OfqualSectoral; ICO leads on dataico.org.uk; fca.org.ukPro-innovation; principles-based
Islamic financeAAOIFISharia accounting and governanceaaoifi.comStandard-setting; certification-based
Islamic financeIFSBIslamic financial services standardsifsb.orgStandard-setting; principles-based
International standardsISO/IECISO/IEC 42001 and adjacentiso.orgVoluntary; certification-based
InternationalOECDOECD AI Principlesoecd.aiVoluntary; soft-law
InternationalUNESCORecommendation on Ethics of AIunesco.orgVoluntary; soft-law; member-state adopted

The authorities catalogue is the supervisory-engagement map. The institution that has cultivated relationships with the relevant authorities operates within the supervisory dialogue. The institution that has not operates against the supervisory inquiry when it arrives without the relationship the dialogue would have produced.

A.6

Regulatory Timeline (2018 through 2027)

The regulatory landscape is not static. The timeline indexes the key dates and milestones across the 2018 through 2027 horizon the institutions operating across the regulatory evolution must plan against.

YearJurisdictionMilestoneOperational implication
2018EUGDPR effective May 25, 2018First binding rights-based data protection regime with extraterritorial reach
2018BahrainPDPL effective August 1, 2019 (enacted 2018)First GCC binding data protection law
2020EgyptPDPL effective October 14, 2020First MENA non-GCC GDPR-influenced binding framework
2020Saudi ArabiaSDAIA establishedNational AI authority operational
2021Saudi ArabiaPDPL issued (Royal Decree M/19)Framework published; phased implementation
2021KuwaitData Privacy Protection Regulation (CITRA)Framework operational
2021UAEPDPL (Federal Decree-Law 45) issuedFederal framework published
2021ChinaPIPL effective November 1, 2021Personal information protection framework with extraterritorial reach
2021UNESCORecommendation on Ethics of AI adoptedAll 193 member states soft-law baseline
2022UAEPDPL effective January 1, 2022Federal data protection operational
2022OmanPDPL issued (Royal Decree 6 of 2022)Framework published
2022JordanDP Law enacted (Law No. 24, replaced earlier draft Law 15 of 2022)Framework published
2023Saudi ArabiaPDPL effective September 14, 2023Framework operational with phased enforcement
2023OmanPDPL effective February 13, 2023Framework operational
2023USNIST AI RMF published January 2023Voluntary US AI governance baseline
2023ChinaGenerative AI Interim Measures effective August 15, 2023First binding generative AI framework
2023InternationalISO/IEC 42001 published December 2023First international AI management system standard
2023JordanAI Strategy 2023-2027 publishedNational AI agenda
2024Saudi ArabiaPDPL full enforcement March 2024; SDAIA Generative AI GuidelinesEnforcement maturity advancing
2024EUEU AI Act in force August 1, 2024Phased applicability through August 2028 (Digital Omnibus deferral, 2026)
2024QatarQCB AI Governance FrameworkBanking AI binding framework
2024BahrainCBB AI Risk Management FrameworkBanking AI binding framework
2024OECDAI Principles refreshedUpdated global ethical baseline
2024JordanDP Law effective March 17, 2024Framework operational
2025EU AI ActProhibited practices applicable February 2, 2025; GPAI obligations applicable August 2, 2025First binding AI Act obligations effective
2025UAEUAE Data Office operationalization advancing; DIFC Regulation 10 enforcement maturingSupervisory dialogue cadence increasing
2025EgyptNational AI Strategy 2025-2030 publishedNational AI agenda
2025Saudi ArabiaSDAIA AI Ethics Principles enforcement advancing; SAMA AI guidelines for financial institutionsBanking AI supervisory dialogue mature
2026EU AI ActDigital Omnibus defers high-risk obligations; Article 50 transparency and Article 4 AI-literacy remain on scheduleHigh-risk deadlines moved to December 2027 (Annex III) and August 2028 (Annex I)
2026MENASharia-AI overlay (AAOIFI-aligned) governance discipline maturing across Islamic finance institutionsSharia compliance discipline operational for AI
2026UAECBUAE Model Management Standards enforcement maturing; ADGM AI guidance maturingBanking and ADGM AI supervisory dialogue mature
2026Saudi ArabiaSDAIA Tier 1/2 supervisory dialogue at full cadenceHigh-risk AI supervisory engagement operational
2026QatarQCB AI Framework enforcement maturing; PDPPL refresh anticipatedSupervisory dialogue advancing
2027EU AI ActStand-alone Annex III high-risk obligations applicable December 2, 2027; AI embedded in regulated products (Annex I) applicable August 2, 2028High-risk providers and deployers under binding obligations
2027GCC-wideAnticipated MRM harmonization initiatives; standardized fairness reporting expectedCross-jurisdictional discipline convergence
2027JordanAI Strategy execution phase concluding; supervisory framework anticipated maturationAI-specific supervisory architecture

The timeline is the strategic-planning input. The institution that has built discipline against the timeline operates ahead of the regulatory evolution. The institution that has not operates against each new milestone as a surprise the operational substrate is not prepared for.

A.7

Operational Notes on Table Maintenance

The tables are not finished documents. They are the operational substrate the institutional discipline must maintain through the supervisory cycles.

The discipline operates through four practices.

The first practice is quarterly review by the Governance Office Chapter 12 specifies. The review examines each table for regulatory changes, supervisory guidance, enforcement developments, and milestone advancement. The review output is a table-revision log the discipline operates against.

The second practice is supervisory-engagement integration. The relationships the Section A.5 catalogue indexes are the source of regulatory intelligence the tables capture. The supervisory dialogue is not an isolated function. It is the input the table-maintenance discipline depends on.

The third practice is cross-jurisdictional reconciliation. The institutions operating across multiple jurisdictions reconcile the table entries against the operational discipline applied per jurisdiction. The reconciliation surfaces the discipline asymmetries the multi-jurisdictional architecture must accommodate.

The fourth practice is the operational vocabulary calibration. The terms the tables use must match the terms the supervisory dialogue uses. The calibration is conducted by the operational compliance function and validated through the supervisory engagement.

Where most observers see reference tables, I see the operational vocabulary the institutional discipline depends on for the supervisory dialogue.

Stillness is not inactivity. It is the calibration that exposes the gap between the regulatory landscape the institution last documented and the regulatory landscape the supervisory dialogue currently inhabits. The institutions that have built table-maintenance discipline operate within the regulatory reality the supervisor inhabits. The institutions that have not operate against the regulatory landscape the deck described before the supervisory landscape moved.

This companion appendix is licensed CC BY-NC-ND 4.0, Attribution-NonCommercial-NoDerivatives: share it with credit to the author, but not for commercial use and not as a modified version. The book itself and the named frameworks (the MESA Framework, the Five-Gate Deployment Model, the AI Incident Response Protocol and the others) are © 2026 Nabeel Khan, all rights reserved.

§ 04Stated limits

What these tables do not claim.

Read this before you rely on it

  • Regulatory dates and obligations were verified at the book’s release lock on 17 August 2026. Several were in flight at that date, including the EU AI Act Digital Omnibus publication and the UAE PDPL executive regulations, which were not gazetted. Verify before you rely on any row.
  • A table records what an instrument requires. It does not tell you how a supervisor will read your particular estate, which is the question that decides an examination.
  • Penalty schedules state statutory maxima. Enforcement practice across these jurisdictions is thinner than the statutes and moves faster.
  • Where a jurisdiction has no dedicated AI statute the table says so. That is a finding, not a gap in the research: AI is governed there through data protection, consumer and sectoral instruments instead.
  • This is reference material and advisory practice. It is not legal advice, and it does not substitute for your counsel or your regulator relationship.

The regulatory floor is the layer that is not negotiable.

Fin · Regulatory tables