AI Ethics Committees in the GCC: Structure and Governance
Artificial intelligence is reshaping industries across the Gulf Cooperation Council, from healthcare and finance to transport and energy. But as AI systems become more powerful, the ethical questions they raise become more urgent. Who is accountable when an AI makes a biased decision? How do you ensure transparency in a black-box model? What happens to data privacy when models are trained on vast datasets? The answer, increasingly, is an AI ethics committee. This article explores the structure, governance, and operational framework of AI ethics committees in the GCC, and explains why every organisation deploying AI should establish one. We cover committee composition, terms of reference, review processes, alignment with ISO 42001, and real case studies from the region.
What Is an AI Ethics Committee?
An AI ethics committee is a cross-functional governance body responsible for overseeing the ethical design, development, deployment, and monitoring of AI systems within an organisation. It serves as the deliberative body that evaluates AI use cases against ethical principles, identifies potential harms, and makes binding recommendations on whether and how AI should be deployed. The committee acts as a check against the commercial pressure to deploy AI quickly without adequate consideration of the ethical implications.
Unlike a traditional IT governance board, an AI ethics committee brings together diverse perspectives: technical, legal, regulatory, commercial, and social. This diversity is essential because AI ethics is rarely a technical problem alone – it involves trade-offs between competing values that require informed judgement. For example, a model that maximises fraud detection accuracy may also produce a higher rate of false positives that unfairly disadvantage certain customer groups. The committee’s role is to weigh these competing considerations and arrive at a balanced decision.
In the GCC context, AI ethics committees are becoming a regulatory expectation. The UAE’s Artificial Intelligence Act (draft), Saudi Arabia’s National Strategy for Data and AI (SDAIA), and Qatar’s National AI Strategy all encourage or mandate some form of ethical oversight for AI systems, particularly those affecting individuals’ rights or public safety. The UAE has gone furthest, with the Dubai AI Ethics Guidelines requiring all government entities to establish AI ethics review processes, while Abu Dhabi’s Department of Government Support has issued mandatory AI governance requirements for all emirate-level entities.
Committee Composition
The composition of an AI ethics committee determines its effectiveness. A poorly constituted committee may lack the expertise to evaluate technical risks, the authority to enforce decisions, or the independence to challenge commercial interests. Getting the composition right is therefore one of the most important steps in establishing the committee.
| Role | Responsibility | Suggested Background | Voting Rights |
|---|---|---|---|
| Chief Ethics Officer (Chair) | Chair the committee, escalate to board, approve final recommendations | Senior executive with ethics, legal, or compliance background | Yes (casting vote) |
| Data Protection Officer | Assess data privacy and DPIA implications of AI use cases | Certified DPO, GDPR and PDPL expertise | Yes |
| Head of AI or Data Science | Provide technical feasibility assessment and risk evaluation | Senior data scientist or ML engineer with 10+ years experience | Yes |
| Legal Counsel | Evaluate regulatory compliance, liability, and contractual implications | Technology lawyer with AI regulatory experience | Yes |
| Risk and Compliance Officer | Integrate AI ethics into enterprise risk management framework | Risk management professional, ISO 31000 or COSO certified | Yes |
| Independent Ethics Advisor | Provide external perspective, challenge groupthink, bring academic rigour | Academic ethicist or consultant with AI ethics specialisation | Yes |
| Business Stakeholder | Represent customer impact, operational feasibility, and commercial considerations | Product manager or business unit lead | No (advisory) |
| Communications Lead | Manage external disclosure, transparency reporting, and stakeholder engagement | Corporate communications or CSR professional | No (advisory) |
Committees should meet at least quarterly, with additional ad hoc sessions convened for high-risk AI use cases or in response to incidents. In Saudi Arabia and the UAE, leading organisations such as Saudi Aramco, ADNOC, and Dubai Police have published their committee structures as part of their responsible AI disclosures, providing useful benchmarks for other organisations establishing their own committees.
Terms of Reference
A clear terms of reference is essential for committee effectiveness. The ToR should be approved by the board or equivalent governing body and reviewed annually to reflect changes in regulation, technology, and organisational priorities. A well-drafted ToR provides the authority, clarity, and boundaries that enable the committee to function effectively.
The ToR should define:
- Mandate and scope – Which AI systems fall under the committee’s purview? Does it cover all AI use cases or only high-risk applications? Does it include procurements of third-party AI systems as well as internally developed ones?
- Authority – Can the committee block or halt AI deployments? What is the escalation path to the board? Can the committee overrule a business line’s decision to deploy?
- Decision-making process – Consensus-based, majority vote, or chair’s decision? How are dissenting views recorded? What quorum is required?
- Review frequency – How often does the committee review active AI systems? What triggers an unscheduled review? Typical triggers include incidents, regulatory changes, and significant model updates.
- Confidentiality and conflicts of interest – How are conflicts declared and managed? What information is confidential and how is it protected?
- Reporting obligations – To whom does the committee report? What metrics are tracked? How are decisions documented and communicated?
- Resource requirements – What budget and staff support does the committee have? Can it commission independent audits or external expert opinions?
The AI Ethics Review Process
The core function of an AI ethics committee is to conduct ethical reviews of AI use cases. A robust review process follows these stages, ensuring consistency, rigour, and accountability:
- Intake and triage – The AI project team submits an ethics intake form describing the use case, data sources, model type, intended impact, and risk self-assessment. The committee secretariat triages the submission into low, medium, or high risk based on pre-defined criteria such as the sensitivity of data involved, the potential for harm, and the degree of human oversight.
- Impact assessment – For medium and high-risk cases, a detailed AI Ethics Impact Assessment is conducted. The AEIA covers fairness and bias analysis, transparency and explainability, privacy and data protection, safety and reliability, accountability and human oversight, and societal impact. The assessment may be conducted by the committee directly or by an external reviewer commissioned by the committee.
- Committee deliberation – The committee reviews the AEIA, hears from the project team, and debates the ethical implications. The committee may request changes, additional analysis, or independent audit before making a decision. Deliberations are minuted, and dissenting views are recorded.
- Recommendation and approval – The committee issues one of three outcomes: approved, approved with conditions, or rejected. Conditions may include bias mitigation requirements, explainability obligations, human-in-the-loop safeguards, or ongoing monitoring commitments. Conditional approvals are subject to verification before full deployment.
- Post-deployment monitoring – Approved AI systems are subject to ongoing monitoring. The committee reviews incidents, drift, complaints, and audit findings on a regular basis. If a system begins to exhibit unexpected ethical issues, the committee can suspend deployment pending further review.
AI Ethics Principles in the GCC
GCC countries have adopted or proposed AI ethics principles that should inform committee decision-making. While there is significant overlap, there are also important differences in emphasis and scope. Committees operating across the region should be familiar with all three major frameworks:
| Principle | UAE AI Ethics Guidelines | Saudi AI Ethics Principles (SDAIA) | Qatar National AI Strategy |
|---|---|---|---|
| Fairness | Explicitly required with bias testing obligations | Required, with guidance on group fairness metrics | Required, with focus on equitable access |
| Transparency | Explainability required for all high-risk AI | Full disclosure of AI use expected | Encouraged, with model cards recommended |
| Accountability | Human oversight mandated for all AI decisions | Clear ownership and responsibility required | Human-in-the-loop for critical decisions |
| Privacy | GDPR+ standards with specific AI provisions | PDPL alignment with additional AI guidance | International best practice standards |
| Safety and security | Required with industry-specific standards | Required, aligned with ISO 27001 | Required, with AI-specific risk assessment |
| Human autonomy | Required for high-risk AI applications | Encouraged, with exceptions for efficiency | Required, particularly in public services |
| Inclusiveness | Encouraged with accessibility requirements | Encouraged with focus on Arabic language AI | Encouraged with multilingual considerations |
| Sustainability | Environmental impact of AI considered | Energy efficiency encouraged | Not explicitly addressed |
Compliance with ISO 42001
ISO 42001, the international standard for AI Management Systems (AIMS), provides a structured framework for AI governance that complements the work of ethics committees. Published in December 2023, ISO 42001 is the first international standard specifically designed for AI management, and it provides a certification pathway that many GCC organisations are beginning to pursue.
Clause 5.2 of ISO 42001 requires top management to establish an AI policy and assign responsibility for AI management, which naturally leads to the formation of a governance body such as an ethics committee. The standard’s requirements align closely with committee functions:
- Clause 6.1 – Actions to address AI risks and opportunities, corresponding to the committee’s risk assessment and impact evaluation function.
- Clause 7.5 – Competence and awareness, ensuring committee members have adequate AI literacy and stay current with developments.
- Clause 8.1 – Operational planning and control, covering the committee’s review and approval process for AI systems.
- Clause 9.1 – Monitoring, measurement, analysis, and evaluation, supporting the committee’s post-deployment monitoring responsibilities.
- Clause 10.1 – Nonconformity and corrective action, guiding the committee’s incident response and remediation processes.
Organisations that implement ISO 42001 alongside an AI ethics committee benefit from a structured management system framework that provides auditability, documentation, and continual improvement processes that the committee can leverage.
Reporting and Escalation
The AI ethics committee should report to the board of directors or an equivalent governance body. Reporting should cover both operational metrics and strategic insights, providing the board with a clear picture of the organisation’s AI ethics posture. Typical reporting includes:
- Number of AI use cases reviewed, approved, approved with conditions, or rejected during the period.
- Ethical incidents and near-misses involving AI systems, including root cause analysis and remediation actions.
- Changes to the ethical risk profile of the organisation’s AI portfolio.
- Emerging regulatory developments in the GCC and internationally, and their implications for the organisation.
- Training and awareness metrics across the organisation, including completion rates for mandatory AI ethics training.
- External communications regarding AI ethics, including transparency reports and regulatory submissions.
Case Studies from the GCC
Several GCC organisations have pioneered AI ethics committees, providing valuable lessons for others. Dubai Health Authority established an AI Ethics Committee in 2022 to oversee clinical AI applications, including diagnostic imaging, patient risk scoring, and treatment recommendation systems. The committee requires all clinical AI tools to undergo a four-stage review: data ethics, algorithmic fairness, clinical validation, and patient safety. Since its inception, the committee has reviewed over 30 AI applications and rejected six that failed to meet fairness thresholds or lacked sufficient clinical validation.
In Saudi Arabia, the Saudi Data and AI Authority (SDAIA) operates an AI Ethics Advisory Board that guides the national AI ethics framework and advises government entities. The board has published detailed guidance on AI in hiring, AI in healthcare, AI in criminal justice, and AI in education. Each guidance document includes practical checklists that organisations can use to self-assess their compliance with ethical principles.
Abu Dhabi’s Department of Government Support established an AI Governance Committee in 2023 to oversee AI adoption across all Abu Dhabi government entities. The committee has developed a mandatory AI governance framework that includes ethics review requirements, transparency reporting obligations, and annual audit cycles for all government AI systems.
Review Process Stages and Responsibilities
The AI ethics review process involves multiple stakeholders and operates on defined timelines. The following table summarises the key stages, responsible parties, and expected timeframes for each stage of the review:
| Stage | Responsible Party | Target Timeframe | Key Deliverable |
|---|---|---|---|
| Intake and triage | Committee Secretariat | 5 business days | Risk classification (low/medium/high) and assigned reviewer |
| Self-assessment | AI Project Team | 10 business days | Completed AI Ethics Self-Assessment Form |
| Impact assessment | Independent Reviewer or Committee | 15 business days | AI Ethics Impact Assessment report |
| Committee deliberation | Full Ethics Committee | Next scheduled meeting | Minuted decision with rationale |
| Condition verification | Committee Secretariat | Varies per condition | Evidence of condition satisfaction |
| Post-deployment monitoring | AI Project Team + Committee | Quarterly reviews | Monitoring report and incident log |
Frequently Asked Questions
Does my organisation need an AI ethics committee?
If your organisation develops, deploys, or procures AI systems that affect individuals’ rights, safety, or opportunities, an AI ethics committee is strongly recommended. Regulatory trends in the GCC increasingly expect such oversight, and the EU AI Act’s extraterritorial reach means that organisations doing business with European partners may be required to demonstrate ethical governance regardless of where they are based.
How many members should an AI ethics committee have?
Between five and nine members is typical. The committee must be large enough to include diverse expertise across technology, law, ethics, risk, and business but small enough to make decisions efficiently. At least one independent member who is not employed by the organisation is recommended to provide objectivity and challenge groupthink.
What is the difference between an AI ethics committee and a data protection committee?
A data protection committee focuses specifically on privacy and data handling under regulations such as the PDPL and GDPR. An AI ethics committee has a broader remit covering fairness, transparency, accountability, safety, and societal impact. The two committees should coordinate closely, and in smaller organisations they may be combined, but the scope of an AI ethics committee is substantially wider.
Can an AI ethics committee block an AI deployment?
Yes, if the committee has the authority defined in its terms of reference. Effective committees have the power to reject or conditionally approve AI use cases, with escalation to the board for disputed decisions. Without this authority, the committee risks becoming a rubber-stamping body that provides ethical cover without genuine oversight.
How does ISO 42001 relate to AI ethics committees?
ISO 42001 provides the management system framework within which an AI ethics committee operates. The committee serves as the governance body responsible for implementing the AI policy, conducting risk assessments, and ensuring compliance with the standard. ISO 42001 certification requires evidence that such a governance body is functioning effectively.
What training do committee members need?
Members should receive initial training in AI fundamentals, bias detection and mitigation, ethical frameworks (deontological, consequentialist, virtue ethics), relevant regulations (PDPL, EU AI Act, local AI laws), and the organisation’s AI governance policies. Annual refresher training is recommended, along with ad hoc briefings on emerging issues and regulatory changes.
Establish Your AI Ethics Committee with Bitrixme
Setting up an effective AI ethics committee requires careful planning, the right expertise, and alignment with both international standards and local regulatory expectations. Bitrixme helps GCC organisations design, constitute, and operationalise AI ethics committees that deliver real governance value, not just box-ticking. Our consultants combine AI technical expertise with deep knowledge of GCC regulatory frameworks and international standards including ISO 42001. Contact us today to learn how we can support your AI governance journey and help you build trust in your AI systems.