Register last reviewed in full on 2026-09-14 · 2 entries below are deliberate negative findings — a jurisdiction with no instrument — and are not counted in the totals.
Every entry links to the issuing authority's own document where one is publicly available. Where it is not, the entry says so and why, rather than linking a third-party copy.
United Arab Emirates
الإمارات العربية المتحدة13UAE Information Assurance Regulationلائحة ضمان المعلومات
v1.1 · March 2020
TDRA, with policy leadership at the UAE Cyber Security Council (standard originated with NESA, now the Signals Intelligence Agency)
Binds all UAE government entities and entities identified as critical under the CIIP Policy; adoption highly recommended for everyone else. Six management control families and nine technical families, across four priority tiers.
Some published summaries quote 188 controls (136 mandatory) and an “IAS v2.0”; neither appears in an official source. The current instrument is the IAR v1.1.
MandatoryWho signsRegulator assesses
CadencePeriodic reporting; no fixed cadence in the document
DomainCyber security
Personal Data Protection Lawقانون حماية البيانات الشخصية
Federal Decree-Law 45/2021
UAE Artificial Intelligence and Data Authority (established 14 June 2026, absorbing the Data Office); executive regulations under the law are still awaited
In force since 2 January 2022 and extraterritorial — it reaches processors outside the UAE handling UAE residents' data. But the Executive Regulations have still not been issued, so the penalty regime and transfer mechanics are not operable. DIFC, ADGM, government, health and banking data are carved out to their own regimes.
No establishing decree number has been published for the new Authority, and its regulatory powers over the private sector are unconfirmed.
In force, pendingWho signsNo assessment regime
CadenceNot yet defined
DomainData protection
Abu Dhabi Healthcare Information and Cyber Security Standardمعيار معلومات الرعاية الصحية والأمن السيبراني بأبوظبي
DOH/SD/ICSO/ADHICS/V2/2024
Department of Health – Abu Dhabi
V2 published May 2024, effective August 2024. Binds any entity that generates, accesses, stores, uses, processes or transmits health information in Abu Dhabi — facilities, payers, technology and service providers alike — and is tied to DoH licensing and Malaffi integration. Mandates an Information Security Governance Committee, a Health Information Infrastructure Protection workgroup and a CISO. Compliance due within six months of programme induction. Read our ADHICS V2 guide
MandatoryWho signsIndependent audit or function
CadenceIndependent audit at least annually
DomainCyber security, Sector-specific
Federal Law on ICT in Health Fieldsالقانون الاتحادي لتقنية المعلومات والاتصالات في المجالات الصحية
Federal Law 2/2019
Ministry of Health and Prevention
Prohibits processing or storing health data outside the UAE where the health service is provided in the UAE, with narrow emirate-level exceptions. Abu Dhabi's patient data privacy standard reinforces it. This is a delivery-model constraint, not a paperwork one: patient data cannot go onto a foreign consultant's systems.
MandatoryWho signsNo assessment regime
DomainData protection, Sector-specific
DESC Information Security Regulationلائحة أمن المعلومات لمركز دبي للأمن الإلكتروني
ISR
Dubai Electronic Security Center
Binds Dubai government and semi-government entities and extends to their contractors, employees and consultants. Thirteen domains across governance, operation and assurance. Recent editions are understood to add SOC requirements and Zero Trust, but we cannot attribute that to a numbered version — see below.
DESC publishes the ISR without a version number or date, and releases documents only on email request, so no precise version or release date can be confirmed publicly.
MandatoryWho signsIndependent audit or function
CadencePer DESC certification scheme
DomainCyber security
DESC Cloud Service Provider, Data Centre and SOC Security Standardsمعايير مركز دبي لأمن مزوّدي الخدمات السحابية ومراكز البيانات ومراكز العمليات
Dubai Electronic Security Center
Compliance is mandatory for any provider wishing to offer cloud, data centre or SOC services to Dubai government and semi-government entities. Certification runs through accredited certification bodies; existing ISO/IEC 27001 and 27017 certification is recognised without re-audit — ISO/IEC 27002 is the control guidance behind them rather than a standard an organisation can be certified against. DESC also publishes IoT, biomedical device, ICS and connected vehicle standards.
MandatoryWho signsAccredited external assessor
CadenceAnnual surveillance audit; three-yearly recertification
DomainCyber security, Sector-specific
DIFC Data Protection Lawقانون حماية البيانات في مركز دبي المالي العالمي
DIFC Law 5/2020, as amended by Law 1/2025
DIFC Commissioner of Data Protection
The July 2025 amendment created a private right of action — data subjects may sue controllers and processors directly in the DIFC Courts for financial loss and for distress, without going to the Commissioner first. Failing to complete the annual DPO-requirement assessment attracts a fine of up to USD 25,000; the DPIA breach fine rose to USD 50,000.
MandatoryWho signsSelf-assessment
CadenceAnnual assessment of whether a DPO is required
DomainData protection
DIFC Regulation 10 — autonomous and semi-autonomous systemsاللائحة العاشرة لمركز دبي المالي العالمي — الأنظمة ذاتية التشغيل وشبه الذاتية
Regulation 10 · in force September 2023, rev. 03 August 2024
DIFC Commissioner of Data Protection
The only AI-specific rule in the UAE that binds across sectors rather than inside one — the Abu Dhabi Responsible AI Standard is mandatory too, but only in healthcare. Among the first sub-national AI data rules anywhere. Requires a designated Deployer and Operator, transparency about whether processing is human-initiated or autonomous, and registers of use cases and of compliance with applicable audit and certification requirements. High-risk systems must either be restricted to human-defined purposes or have an Autonomous Systems Officer appointed. General certification requirements were anticipated during 2026 — this is where a Gulf certification mandate is most likely to appear first. Read our Regulation 10 guide
MandatoryWho signsSelf-assessment
CadenceContinuous; registers maintained
DomainAI governance, Data protection
ADGM Data Protection Regulationsلوائح حماية البيانات في سوق أبوظبي العالمي
2021, consolidated February 2024
ADGM Office of Data Protection
Every ADGM-registered entity processing personal data must register as a data controller and renew annually. Maximum fine USD 28 million. Supplementary rules issued September 2025 clarify lawful bases for special-category data in insurance and vulnerable-person safeguarding.
The linked text is the August 2021 update. ADGM's consolidated February 2024 version could not be accessed for this review, so the consolidation has not been verified in full.
MandatoryWho signsSelf-assessment
CadenceAnnual controller registration
DomainData protection
Responsible Artificial Intelligence Standardمعيار الذكاء الاصطناعي المسؤول
DoH/ST/DDGO/RAI/V1/2025 · October 2025
Department of Health – Abu Dhabi
The most operationally demanding AI instrument in the UAE, and sanctionable under the Abu Dhabi healthcare disciplinary regulations. Four pillars — core foundations, data management, risk management, AI literacy — across the full lifecycle from inception to decommissioning, covering clinical, financial, administrative and research use, built in-house or bought in. Notably it cites neither ISO/IEC 42001 nor the NIST AI RMF.
MandatoryWho signsSelf-assessment
CadenceRevision due October 2026
DomainAI governance, Sector-specific
Guidance Note on Responsible Adoption and Use of AI by Licensed Financial Institutionsإرشادات التبنّي والاستخدام المسؤول للذكاء الاصطناعي لدى المؤسسات المالية المرخّصة
February 2026
Central Bank of the UAE
Non-binding, but it establishes clear regulatory expectations for banks and insurers: board accountability, bias stress-testing, transparency in high-impact decisions, human oversight calibrated to risk, and third-party vendor due diligence. Points institutions to the UAE AI Charter and the Central Bank's own model management standards rather than to any international standard.
The Central Bank rulebook page shows an inconsistent issue date; confirm the date against the rulebook PDF before relying on it.
VoluntaryWho signsSelf-assessment
CadenceContinuous monitoring expected
DomainAI governance, Sector-specific
UAE Charter for the Development and Use of Artificial Intelligenceميثاق الإمارات لتطوير الذكاء الاصطناعي واستخدامه
10 June 2024
Ministry of Cabinet Affairs
Twelve principles including safety, algorithmic bias, data privacy, transparency, human oversight, and governance and accountability. A policy instrument with no enforcement mechanism — but the reference point that the Central Bank guidance and most UAE sectoral AI material builds on.
VoluntaryWho signsNo assessment regime
DomainAI governance
National Cyber Security Accreditation Programالبرنامج الوطني لاعتماد الأمن السيبراني
UAE Cyber Security Council
Establishes evaluation and accreditation of government entities, cyber security service providers and training organisations. Unaccredited providers are restricted from serving critical infrastructure — a direct driver of demand for accredited third-party assessors.
Launch date, mandatory scope, categories and application process are all unconfirmed; the detail sits in a policy document that is not publicly available. Confirm with the regulator before relying on it.
MandatoryWho signsAccredited external assessor
CadencePer accreditation scheme
DomainCyber security
Saudi Arabia
المملكة العربية السعودية10Essential Cybersecurity Controlsالضوابط الأساسية للأمن السيبراني
ECC-2:2024
National Cybersecurity Authority
The baseline all other NCA control sets build on. Binds government entities and their contractors, and private-sector owners and operators of critical national infrastructure. The NCA has publicly committed to conducting over 7,000 cyber security assessments of national entities, run through the Haseen national portal. Read our ECC-2:2024 guide
MandatoryWho signsRegulator assesses
CadenceNCA assessment programme
DomainCyber security
Cloud Cybersecurity Controlsضوابط الأمن السيبراني للحوسبة السحابية
CCC-2:2024
National Cybersecurity Authority
Applies to both cloud service providers and cloud service tenants. The 2024 revision reflects Saudi data-localisation requirements.
MandatoryWho signsRegulator assesses
CadencePer NCA programme
DomainCyber security
Critical Systems Cybersecurity Controlsضوابط الأمن السيبراني للأنظمة الحساسة
CSCC-1:2019
National Cybersecurity Authority
Thirty-two main controls and seventy-three sub-controls across governance, defence, resilience, and third-party and cloud. Applies to national critical systems.
MandatoryWho signsRegulator assesses
CadencePer NCA programme
DomainCyber security
Operational Technology Cybersecurity Controlsضوابط الأمن السيبراني للتقنيات التشغيلية
OTCC-1:2022
National Cybersecurity Authority
Covers ICS and OT environments, and ships with a methodology and mapping annex plus a spreadsheet assessment and compliance tool. The NCA also publishes data, telework, social media account and cryptographic control sets.
MandatoryWho signsRegulator assesses
CadencePer NCA programme
DomainCyber security
Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entitiesضوابط الأمن السيبراني لمنشآت القطاع الخاص غير الحرجة
NCNICC-1:2025
National Cybersecurity Authority
The most significant Saudi development for ordinary private business. Large entities — over 250 staff or revenue above SAR 200m — face 22 sub-components and 65 essential controls including an independent cyber security function with periodic review, audit and compliance oversight. Smaller entities face 13 sub-components and 26 controls, some recommended rather than mandatory.
Reference number corrected from NCINCC to NCNICC against the NCA's own page, which was published on 28 December 2025 and exists in Arabic only — there is no English landing page on the NCA domain at the time of review.
MandatoryWho signsIndependent audit or function
CadencePeriodic review; no compliance deadline published
DomainCyber security
Cyber Security Frameworkإطار الأمن السيبراني
v1.0 · May 2017
Saudi Central Bank (SAMA)
Binds banks, insurers and reinsurers, financing companies, credit bureaus and financial market infrastructure. A six-level maturity model where member organisations must reach at least level 3, “structured and formalised”. SAMA conducts its own reviews and assigns the maturity level. The Cyber Resilience Fundamental Requirements of January 2022 sit alongside it as a licensing-stage requirement, not a replacement.
SAMA's own documents could not be accessed for this review; the version, date and maturity threshold here are from secondary sources.
Sector-bindingWho signsIndependent audit or function
CadenceAnnual penetration test of internet-facing services; regular independent audits
DomainCyber security, Sector-specific
Personal Data Protection Lawنظام حماية البيانات الشخصية
Royal Decree M/19, amended M/148
SDAIA
Fully enforceable since 14 September 2024, and enforcement is real rather than theoretical: 48 enforcement decisions had been announced by mid-January 2026. Fines to SAR 5 million, doubled for repeat violations, with publication of final penalties. A DPO is mandatory for public bodies, for large-scale systematic monitoring, and for large-scale special-category processing, under qualification rules issued in August 2024.
MandatoryWho signsMandated officer
CadenceRegistration on the National Data Governance Platform
DomainData protection
No official linkSDAIA does not publish a directly linkable copy on its own domain, so no official link is given.
National AI Risk Management Frameworkالإطار الوطني لإدارة مخاطر الذكاء الاصطناعي
2026
SDAIA
Applies to public and private entities. Five phases from context definition through risk identification across seven categories, assessment on a four-by-four likelihood and impact matrix, treatment, and monitoring. A sovereign framework: it makes no reference to ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF or the EU AI Act. SDAIA's AI Ethics Principles and its generative AI guidelines for government sit alongside it, all voluntary.
Sources conflict on the date — one gives April 2026 publication, the official news agency a July 2026 launch.
VoluntaryWho signsSelf-assessment
CadenceMonitoring and review phase built into the framework
DomainAI governance
No official linkAnnounced through the Saudi Press Agency; we found no page for the framework on SDAIA's own domain.
Haseen registration for cyber security service providersالتسجيل في منصة حصين لمزوّدي خدمات الأمن السيبراني
Mandatory from 1 August 2022
National Cybersecurity Authority
Any entity providing cyber security solutions, services or products in the Kingdom must register. Managed SOC licensing runs on top, with Saudi ownership thresholds and a regional headquarters requirement at tier 1. Legal analysis concludes that firms previously delivering in-scope cyber services into the Kingdom from overseas can no longer lawfully do so.
MandatoryWho signsNo assessment regime
CadenceRegistration, then per licence
DomainCyber security
Regulatory Framework for Licensing Cybersecurity Services, Products and Solutionsالإطار التنظيمي لترخيص خدمات ومنتجات وحلول الأمن السيبراني
RFCS-1:2026 (draft)
National Cybersecurity Authority
Consulted on from 25 February to 26 March 2026. Covers five domains and over a hundred services, explicitly including consulting and assessments. As drafted it would require a Saudi legal entity; 75% Saudi ownership and SAR 10m capital to serve government or critical infrastructure; full in-Kingdom data residency with no access from outside; and NCA qualification certificates for staff. Licence fees from SAR 50,000 to SAR 1,000,000.
Not law. On the NCA's own site it appears only as a public consultation, now closed, and it is absent from the authority's register of issued frameworks. No official document states in terms that it is not in force, so treat the draft status as inferred from where the NCA publishes it. The highest-priority item on this register to monitor.
DraftWho signsAccredited external assessor
CadenceFive-year licence term proposed
DomainCyber security
Qatar
دولة قطر5National Information Assurance Standardمعيار ضمان المعلومات الوطني
v2.1
National Cyber Security Agency
One of the clearest mandated-external-auditor regimes in the Gulf. Certification runs in four phases: scope and documentation, audit planning with an accredited auditor, compliance audit and controls assessment by that auditor with the report submitted to the NCSA's governance and assurance division, then the certification decision. Binds government entities, critical information infrastructure operators across energy, water, telecoms, finance, health and transport, and service providers accessing those entities' information assets.
MandatoryWho signsAccredited external assessor
CadenceCertificate valid three years, with an annual maintenance audit
DomainCyber security
NISCF Audit Standard and General Policy for National Certificationمعيار التدقيق والسياسة العامة لمنح الشهادات الوطنية ضمن الإطار الوطني
NCSA-NISCF-AUD-STND-V3.0
National Cyber Security Agency
The component documents of the National Information Security Compliance Framework that govern how an audit is conducted and how certification is granted. The NCSA accredits service providers by category — advisory, audit and penetration testing among them — and firms announce accreditation publicly because it gates the work.
The full accreditation category list, eligibility criteria and whether advisory accreditation is strictly mandatory could not be verified from public sources. Confirm with the NCSA directly.
MandatoryWho signsAccredited external assessor
CadencePer certification cycle
DomainCyber security
National Data Classification Policyالسياسة الوطنية لتصنيف البيانات
v3.0
National Cyber Security Agency
Three risk tiers — low, medium and high — determining the technical and administrative controls required. Mandatory for government entities and institutions, and the practical starting point for any Qatari assessment.
MandatoryWho signsSelf-assessment
DomainData protection
No official linkA site migration at the agency broke the published links to this policy, and we found no current copy on its own domain.
Law on Protecting Personal Data Privacyقانون حماية خصوصية البيانات الشخصية
Law 13/2016
NCSA, with guidelines from the Compliance and Data Protection Department at MCIT
Effective 2017 and the first GCC data protection law. No extraterritorial application and no adequacy or standard-clause mechanism — transfers are permitted unless they breach the law or cause serious damage. Sensitive data covering health, religion, criminal records and children requires prior written permission from MCIT. Enforcement is administrative and non-public; no widely reported public actions in the last two years.
MandatoryWho signsNo assessment regime
DomainData protection
Artificial Intelligence Guideline for QCB Licensed Entitiesإرشادات الذكاء الاصطناعي للجهات المرخّصة من مصرف قطر المركزي
4 September 2024
Qatar Central Bank
The most prescriptive AI rule anywhere in the GCC, and binding. Prior QCB approval is required for new or materially modified high-risk AI systems — before deployment and before signing purchase, licensing or outsourcing agreements. Licensed entities must maintain an AI register covering every system, its risk classification, provider, human-oversight protocol and contract dates; must separate training, validation and testing datasets with bias testing; and must report serious AI incidents to the QCB.
Sector-bindingWho signsRegulator assesses
CadenceAI register disclosable annually on request
DomainAI governance, Sector-specific
No official linkThe document sits on the Central Bank's own site, but the server's certificate chain is incomplete, so the link cannot be verified.
Oman
سلطنة عُمان3Personal Data Protection Lawقانون حماية البيانات الشخصية
Royal Decree 6/2022 · Executive Regulations MD 34/2024 · amended by RD 68/2026
Ministry of Transport, Communications and IT — Personal Data Protection Centre
Enforceable since 5 February 2026 — the single most important Oman date. The DPO mandate is unconditional, which makes it the strongest in the GCC, and the regulator prefers the officer to be physically located in Oman. A ministerial permit is required for genetic, biometric, health, racial origin, sexual life, political or religious belief and criminal record data, though since Royal Decree 68/2026 (in force 7 September 2026) not for an employer’s own staff data or security-camera footage. The same amendment extends the law to processing outside Oman and adds a right to object to solely automated decisions. Administrative fines are modest at up to OMR 2,000 per violation, but the law carries fines of up to OMR 500,000 for its most serious offences; the real leverage is suspension of processing permits.
MandatoryWho signsMandated officer
CadenceBreach notification within 72 hours; data subject requests within 45 days
DomainData protection
General Policy for the Safe and Ethical Use of Artificial Intelligence Systemsالسياسة العامة للاستخدام الآمن والأخلاقي لأنظمة الذكاء الاصطناعي
1 April 2025
Ministry of Transport, Communications and IT
A framework policy tied to Oman Vision 2040, establishing operational expectations for state entities and regulated sectors. A policy instrument, not legislation.
VoluntaryWho signsNo assessment regime
DomainAI governance
No national private-sector cyber security control setلا توجد مجموعة ضوابط أمن سيبراني وطنية للقطاع الخاص
Ministry of Transport, Communications and IT
A deliberate negative entry. Oman publishes government-facing guidance — a cyber security governance guideline, a security assessment services standard, basic controls guidelines and a classification guide — but no single named mandatory national framework for the private sector equivalent to the Saudi ECC or the Qatar NIA. Vendors who claim otherwise are wrong, and saying so is a credibility signal.
No such instrument appears in the MTCIT library. The new Cybercrime Law of June 2026 is not freely available, so its obligations for organisations have not been confirmed.
Research observationWho signsNo assessment regime
DomainCyber security
GCC-wide and extraterritorial
إقليمي وعابر للحدود4ISO/IEC 42001 — AI management systemsISO/IEC 42001 — أنظمة إدارة الذكاء الاصطناعي
International standard; no Gulf accreditation scheme identified
No Gulf regulator mandates it, and no Gulf instrument checked even references it — not the Central Bank of the UAE guidance, not the Abu Dhabi Responsible AI Standard, not the SDAIA risk framework, not the Dubai AI Seal. That is precisely what makes it useful: it is the only neutral layer that spans six sovereign frameworks. Gulf adoption so far is government-led — SDAIA, Dubai Culture, GDRFA Dubai, the UAE Ministry of Interior — with certificates issued by international bodies under foreign accreditation. DIFC Regulation 10 is the only instrument creating a certification-shaped obligation, and it does not name a standard.
VoluntaryWho signsAccredited external assessor
CadenceThree-year certification cycle with surveillance
DomainAI governance
Guiding Manual on the Ethics of Artificial Intelligence Use in the GCCالدليل الاسترشادي لأخلاقيات استخدام الذكاء الاصطناعي في دول مجلس التعاون
2025
Ministerial Committee for eGovernment, Cooperation Council for the Arab States of the Gulf
The only supranational GCC AI instrument identified, and under-discussed in market commentary. Principles of human autonomy, system safety and reliability, justice and non-discrimination, and privacy and data security, framed explicitly around shared Gulf values.
VoluntaryWho signsNo assessment regime
DomainAI governance
No official linkNamed in GCC Secretariat material but not published on a Council domain; member-state copies exist.
EU AI Act — extraterritorial reachقانون الاتحاد الأوروبي للذكاء الاصطناعي — الأثر خارج الحدود
Regulation (EU) 2024/1689
European Commission / national market surveillance authorities
Reaches third-country providers and deployers where the output of the AI system is used in the EU — so a Gulf firm selling into Europe is in scope regardless of establishment. The transparency obligations covering chatbot disclosure and synthetic content marking took effect on 2 August 2026 and bind now. AI systems already on the market before that date have until 2 December 2026 to add machine-readable marking of AI-generated output. Following the Digital Omnibus agreement, high-risk obligations under Annex III were deferred to December 2027 and Annex I to August 2028 — a delay, not relief. Much circulating Gulf commentary predates the deferral and is out of date.
MandatoryWho signsSelf-assessment
CadencePhased
DomainAI governance
No GCC-wide binding instrument, adequacy mechanism or mutual recognitionلا توجد أداة مُلزِمة على مستوى دول المجلس، ولا آلية كفاية، ولا اعتراف متبادل
—
The organising fact of this register. Each state's regime stands alone. Bahrain's transfer whitelist includes Gulf states, but Saudi, the UAE, Qatar and Oman each run separate transfer regimes, and no certificate issued under one regime is recognised by another. Multi-country groups comply country by country. The observable direction of travel is shared even though the instruments are not: data localisation for government and financial data, maturity models rather than pass or fail, licensed assessor ecosystems, and a shift from voluntary frameworks to licensing-linked mandates.
Research observationWho signsNo assessment regime
DomainCyber security, Data protection
No instruments match those filters.