gcc-ai-regulation-comparison

By July 25th, 2026compliant-growth11 min read

AI Regulation in the GCC: A Country-by-Country Comparison

AI regulation in the GCC is developing rapidly, but each member state is moving at its own pace and with its own priorities. There is no single regional AI law. Instead, organisations deploying AI across the Gulf face a patchwork of national strategies, sector-specific rules, ethics frameworks, and emerging regulatory instruments. Understanding the differences is essential for compliance, especially if you operate in multiple jurisdictions.

United Arab Emirates: AI Charter and Sector Regulation

The UAE has the most advanced AI governance infrastructure in the region. The UAE AI Strategy 2031 and the establishment of the Artificial Intelligence, Digital Economy, and Remote Work Applications Office signal a strong central commitment. However, AI regulation in the UAE operates at two levels: federal guidance and sector-specific rules.

AI Charter and Ethics. The UAE has published an AI Ethics Charter and an AI Ethics Toolkit for organisations developing or deploying AI. These are voluntary but influential, and they set expectations for transparency, fairness, accountability, and human oversight. The UAE government also released the “UAE Charter for the Development and Use of AI”, which applies to all entities developing or using AI in the UAE.

Sector-specific AI regulation. Sector regulators are where AI regulation becomes mandatory. The Dubai Health Authority (DHA) regulates AI in healthcare, including diagnostic algorithms and clinical decision support systems. The Securities and Commodities Authority (SCA) addresses AI in financial services, particularly robo-advisory and automated trading. The Dubai International Financial Centre (DIFC) has issued an AI ethics framework for regulated firms within its jurisdiction.

Data protection linkage. The UAE’s Federal Data Protection Law (Federal Decree-Law 45 of 2021) applies to AI systems that process personal data. AI systems making automated decisions that produce legal effects or significantly affect individuals are subject to specific transparency and objection rights. This is directly relevant for AI marketing, credit scoring, and recruitment tools operating in the UAE.

Saudi Arabia: SDAIA and the National AI Strategy

The Saudi Data and AI Authority (SDAIA) is the primary body responsible for AI governance in the Kingdom. Established in 2019, SDAIA oversees data, AI, and national digital transformation. Saudi Arabia’s AI approach is more centralised than the UAE’s, with SDAIA driving both policy and enforcement.

AI Ethics Principles. SDAIA published the AI Ethics Principles in 2023, covering fairness, transparency, accountability, privacy, safety, and human oversight. These principles apply to all AI systems developed or deployed in Saudi Arabia. While the principles are framed as guidance, SDAIA has the authority to enforce compliance, particularly for government entities and critical national infrastructure.

National strategy alignment. Saudi Arabia’s AI regulation is closely tied to Vision 2030 and the National Strategy for Data and AI (NSDAI). The strategy targets Saudi Arabia becoming a top-15 AI nation by 2030. This means AI regulation in Saudi Arabia is as much about enabling innovation as it is about controlling risk.

Personal Data Protection Law (PDPL). Saudi Arabia’s PDPL, which came into full effect in 2023, has significant implications for AI. Automated decision-making that uses personal data requires a legal basis, and individuals have the right to object to automated decisions. Organisations using AI for recruitment, credit assessment, or marketing in Saudi Arabia must ensure their AI processing is covered under one of the PDPL’s lawful bases.

Sector oversight. The Saudi Central Bank (SAMA) and the Capital Market Authority (CMA) have issued guidance on AI in financial services. The Saudi Food and Drug Authority (SFDA) regulates AI in healthcare and medical devices. These sector rules may impose additional requirements beyond SDAIA’s principles.

Bahrain: CBB AI Guidance and National Strategy

Bahrain has taken a measured, business-friendly approach to AI regulation. The Central Bank of Bahrain (CBB) is the most active regulator on AI within the financial sector, while the national AI strategy provides broader guidance.

National AI Strategy. Bahrain launched its National AI Strategy in 2021, focusing on AI adoption in government, financial services, logistics, and healthcare. The strategy emphasises ethical AI but does not create binding legal obligations outside existing regulatory frameworks.

CBB AI requirements. The CBB has issued guidance on the use of AI and machine learning in regulated financial institutions. This covers model risk management, explainability, governance, and customer protection. Any bank or insurance company in Bahrain using AI for credit decisions, fraud detection, or customer scoring must comply with the CBB’s expectations on model validation and transparency.

Personal Data Protection Law (PDPL). Bahrain’s PDPL, enacted in 2018 and enforced by the Personal Data Protection Authority (PDPA), applies to AI systems processing personal data. Automated decision-making provisions require that individuals be informed when a decision is made solely by automated means and that they have the right to human intervention. The PDPA’s enforcement actions in recent years have focused on transparency and consent, which directly affects AI-driven marketing and profiling.

Qatar: National AI Strategy and Emerging Framework

Qatar is in the early stages of formal AI regulation. The Qatar National AI Strategy, launched in 2019, sets out goals for AI adoption in healthcare, education, energy, and transport. However, binding AI-specific regulation is limited.

Qatar’s approach currently relies on existing legal frameworks. The Qatar Financial Centre Regulatory Authority (QFCRA) regulates AI in financial services within the QFC. The Ministry of Communications and Information Technology (MCIT) oversees AI ethics guidelines. For most organisations, compliance with the Qatar Data Protection Law (Law 13 of 2016) is the primary AI regulatory obligation, particularly where AI involves automated decision-making or profiling of individuals.

Qatar is expected to introduce more comprehensive AI regulation in line with its National Vision 2030, but at present the framework is less developed than in the UAE, Saudi Arabia, or Bahrain.

Kuwait and Oman: Early-Stage AI Governance

Kuwait and Oman are the least advanced in AI regulation among the GCC states. Neither country has a dedicated AI law or a specific AI regulator.

Kuwait. Kuwait’s Central Agency for Information Technology (CAIT) has issued general guidance on AI ethics and data governance, but there is no binding AI-specific regulation. The Kuwait Data Privacy Law (Law 20 of 2014) applies to AI systems that process personal data. Automated decision-making is not explicitly addressed in the law, creating uncertainty for organisations deploying AI in Kuwait. This is expected to change as Kuwait updates its data protection framework.

Oman. Oman has published a National AI and Advanced Digital Technology Strategy, but implementation is in early stages. The Oman Data Protection Law (Royal Decree 6/2022) provides some guardrails for AI processing of personal data. Organisations deploying AI in Oman should follow the data protection law’s requirements on consent, purpose limitation, and data subject rights, but there is currently no AI-specific regulator or enforcement body.

GCC AI Regulation Comparison Table

CountryPrimary AI AuthorityBinding AI Regulation?Sector-Specific RulesAI Ethics Framework?Data Protection Impact on AI
UAEAI Office, sector regulators (DHA, SCA, VARA)Partial (sector-specific)Yes (health, finance, virtual assets)Yes (AI Charter, DIFC Ethics)Federal Decree-Law 45 of 2021 applies to AI with personal data
Saudi ArabiaSDAIAPartial (ethics principles with enforcement power)Yes (SAMA, CMA, SFDA)Yes (SDAIA AI Ethics Principles)PDPL 2023, automated decision-making rights
BahrainNational AI Strategy, CBBLimited (CBB financial sector only)Yes (CBB for financial institutions)Yes (National AI Strategy ethics)PDPL 2018, automated decision-making provisions
QatarMCIT, QFCRANo dedicated AI lawLimited (QFC financial services)Guidelines onlyData Protection Law 13/2016 applies
KuwaitCAITNo dedicated AI lawNoneGuidance onlyData Privacy Law 20/2014, no explicit AI provisions
OmanNational AI StrategyNo dedicated AI lawNoneIn developmentData Protection Law 6/2022 applies

Compliance Requirements for GCC AI Deployments

Despite the differences, common compliance themes apply across all six GCC states:

Compliance AreaRequirementGCC Status
Data protection impact assessment (DPIA)Assess AI risks to personal data before processingRequired in UAE, Saudi, Bahrain; recommended in others
Automated decision-making transparencyInform individuals when AI makes automated decisionsExplicit in UAE, Saudi, Bahrain PDPLs
Human oversightMeaningful human review of critical AI decisionsRequired in UAE and Saudi ethics frameworks
AI model explainabilityAbility to explain how AI reaches decisionsExpected in financial services across all GCC
Bias and fairness testingTest AI models for discriminatory outcomesRequired by SDAIA, UAE AI Charter, CBB guidance
AI risk assessmentDocument and treat AI-specific risksExpected under ISO 42001 alignment; emerging as best practice

Organisations operating across multiple GCC states should implement a baseline AI governance programme that meets the highest common denominator (UAE and Saudi requirements) and then adapt for local variances. This approach ensures compliance in the more regulated jurisdictions while covering the essentials in Kuwait, Oman, and Qatar.

Future Developments

Several trends will shape AI regulation in the GCC over the next two to three years:

  • Convergence towards international standards. The GCC states are closely watching the EU AI Act, and several (particularly the UAE and Saudi Arabia) are expected to introduce legislation that aligns with its risk-based framework, adapted for regional priorities
  • Increased enforcement. As AI adoption grows, regulators will move from guidance to enforcement. Early enforcement is likely in financial services and healthcare, where AI risk is most visible
  • ISO 42001 alignment. The UAE and Saudi Arabia are expected to reference or require ISO 42001 (AI management system) as a compliance mechanism, similar to how ISO 27001 is referenced in cybersecurity regulation
  • AI liability frameworks. Civil liability for AI-caused harm is under discussion in several GCC states, particularly for autonomous systems in transportation and healthcare
  • Cross-border AI data flows. As AI models increasingly rely on cross-border data, the interaction between AI regulation and data transfer restrictions under PDPLs and the UAE Federal Data Protection Law will become a critical compliance issue

Frequently Asked Questions

Is there a single GCC-wide AI law?

No. There is no GCC-wide AI regulation. Each member state has its own approach, ranging from comprehensive ethics frameworks (UAE, Saudi Arabia) to early-stage strategies (Kuwait, Oman). Organisations must comply with the laws of each country where they operate.

Does the EU AI Act apply to GCC companies?

Yes, if your AI system affects individuals in the EU or is placed on the EU market. The EU AI Act has extraterritorial scope similar to GDPR. Any GCC company developing or deploying AI that processes EU resident data or provides AI services to the EU market must comply.

Which GCC country has the strictest AI regulation?

The UAE has the most comprehensive AI governance framework, combining federal ethics guidance with sector-specific regulation in health, finance, and virtual assets. Saudi Arabia’s SDAIA has strong enforcement authority but currently focuses more on government and critical infrastructure. For financial services, Bahrain’s CBB rules are the most prescriptive.

Do I need ISO 42001 to deploy AI in the GCC?

Not yet. ISO 42001 is not currently mandated by any GCC state, but the UAE and Saudi Arabia are expected to reference it as a compliance benchmark. Adopting ISO 42001 voluntarily positions your organisation ahead of expected regulatory requirements and demonstrates AI governance maturity to clients and partners.

How do GCC data protection laws affect AI?

All GCC data protection laws apply to AI systems that process personal data. The key AI-relevant provisions are automated decision-making rights (UAE, Saudi, Bahrain), data protection impact assessment requirements, and cross-border data transfer restrictions that affect AI training and inference across borders.

What are the penalties for non-compliance with AI regulation in the GCC?

Penalties vary by country and regulator. Under Saudi’s PDPL, fines can reach SAR 20 million (approximately USD 5.3 million) for serious violations. UAE data protection violations carry fines of up to AED 20 million. Sector regulators such as the CBB, SAMA, and CMA can impose sanctions including fines, licence restrictions, and public censure. Enforcement is increasing across the region.

Navigate GCC AI Regulation with Bitrixme

AI regulation in the GCC is fragmented and evolving. Keeping pace requires dedicated attention to regulatory developments in each jurisdiction, combined with a practical understanding of how AI governance frameworks like ISO 42001 integrate with local requirements. Bitrixme advises organisations across the GCC on AI compliance, from risk assessment and policy development to regulatory engagement. Contact us to discuss your AI governance needs.