العربية

Reference · Free to use · Reviewed quarterly

Gulf regulations, instrument by instrument

The cyber security, data protection and AI instruments we have verified across the six Gulf states — who issues each one, whether it binds you, who is allowed to sign the audit, and how often. Where a regulator does not publish a document openly, we say so rather than implying the register is exhaustive.

Answer a few quick questions and the checker filters this register to the instruments that reach your organisation, grouped by how they bind you. Try the checker

undefined

Why this exists

There is no GCC-wide cyber security or data protection instrument, no adequacy mechanism, and no mutual recognition of certificates. Each state's regime stands alone, so a group operating in three Gulf states complies three times — against three registers, with three different rules about who may sign.

We keep this register because we need it ourselves. It is ungated, it carries its review date, and where something could not be verified against the issuing authority it says so rather than smoothing it over.

38instruments tracked across six states
29binding on someone today
8require an accredited or external assessor
11touch AI — none of which name a standard
Jurisdiction
Domain
Status

Register last reviewed in full on 2026-09-14 · 2 entries below are deliberate negative findings — a jurisdiction with no instrument — and are not counted in the totals.
Every entry links to the issuing authority's own document where one is publicly available. Where it is not, the entry says so and why, rather than linking a third-party copy.

United Arab Emirates

الإمارات العربية المتحدة13

UAE Information Assurance Regulationلائحة ضمان المعلومات
v1.1 · March 2020

TDRA, with policy leadership at the UAE Cyber Security Council (standard originated with NESA, now the Signals Intelligence Agency)

Binds all UAE government entities and entities identified as critical under the CIIP Policy; adoption highly recommended for everyone else. Six management control families and nine technical families, across four priority tiers.

Some published summaries quote 188 controls (136 mandatory) and an “IAS v2.0”; neither appears in an official source. The current instrument is the IAR v1.1.

Mandatory
Who signsRegulator assesses
CadencePeriodic reporting; no fixed cadence in the document
DomainCyber security
Official sourcetdra.gov.aechecked 2026-09-14

Personal Data Protection Lawقانون حماية البيانات الشخصية
Federal Decree-Law 45/2021

UAE Artificial Intelligence and Data Authority (established 14 June 2026, absorbing the Data Office); executive regulations under the law are still awaited

In force since 2 January 2022 and extraterritorial — it reaches processors outside the UAE handling UAE residents' data. But the Executive Regulations have still not been issued, so the penalty regime and transfer mechanics are not operable. DIFC, ADGM, government, health and banking data are carved out to their own regimes.

No establishing decree number has been published for the new Authority, and its regulatory powers over the private sector are unconfirmed.

In force, pending
Who signsNo assessment regime
CadenceNot yet defined
DomainData protection
Official sourceuaelegislation.gov.aechecked 2026-09-14

Abu Dhabi Healthcare Information and Cyber Security Standardمعيار معلومات الرعاية الصحية والأمن السيبراني بأبوظبي
DOH/SD/ICSO/ADHICS/V2/2024

Department of Health – Abu Dhabi

V2 published May 2024, effective August 2024. Binds any entity that generates, accesses, stores, uses, processes or transmits health information in Abu Dhabi — facilities, payers, technology and service providers alike — and is tied to DoH licensing and Malaffi integration. Mandates an Information Security Governance Committee, a Health Information Infrastructure Protection workgroup and a CISO. Compliance due within six months of programme induction. Read our ADHICS V2 guide

Mandatory
Who signsIndependent audit or function
CadenceIndependent audit at least annually
DomainCyber security, Sector-specific
Official sourcedoh.gov.aechecked 2026-09-14

Federal Law on ICT in Health Fieldsالقانون الاتحادي لتقنية المعلومات والاتصالات في المجالات الصحية
Federal Law 2/2019

Ministry of Health and Prevention

Prohibits processing or storing health data outside the UAE where the health service is provided in the UAE, with narrow emirate-level exceptions. Abu Dhabi's patient data privacy standard reinforces it. This is a delivery-model constraint, not a paperwork one: patient data cannot go onto a foreign consultant's systems.

Mandatory
Who signsNo assessment regime
DomainData protection, Sector-specific
Official sourceuaelegislation.gov.aechecked 2026-09-14

DESC Information Security Regulationلائحة أمن المعلومات لمركز دبي للأمن الإلكتروني
ISR

Dubai Electronic Security Center

Binds Dubai government and semi-government entities and extends to their contractors, employees and consultants. Thirteen domains across governance, operation and assurance. Recent editions are understood to add SOC requirements and Zero Trust, but we cannot attribute that to a numbered version — see below.

DESC publishes the ISR without a version number or date, and releases documents only on email request, so no precise version or release date can be confirmed publicly.

Mandatory
Who signsIndependent audit or function
CadencePer DESC certification scheme
DomainCyber security
Official sourcedesc.gov.aechecked 2026-09-14

DESC Cloud Service Provider, Data Centre and SOC Security Standardsمعايير مركز دبي لأمن مزوّدي الخدمات السحابية ومراكز البيانات ومراكز العمليات

Dubai Electronic Security Center

Compliance is mandatory for any provider wishing to offer cloud, data centre or SOC services to Dubai government and semi-government entities. Certification runs through accredited certification bodies; existing ISO/IEC 27001 and 27017 certification is recognised without re-audit — ISO/IEC 27002 is the control guidance behind them rather than a standard an organisation can be certified against. DESC also publishes IoT, biomedical device, ICS and connected vehicle standards.

Mandatory
Who signsAccredited external assessor
CadenceAnnual surveillance audit; three-yearly recertification
DomainCyber security, Sector-specific
Official sourcedesc.gov.aechecked 2026-09-14

DIFC Data Protection Lawقانون حماية البيانات في مركز دبي المالي العالمي
DIFC Law 5/2020, as amended by Law 1/2025

DIFC Commissioner of Data Protection

The July 2025 amendment created a private right of action — data subjects may sue controllers and processors directly in the DIFC Courts for financial loss and for distress, without going to the Commissioner first. Failing to complete the annual DPO-requirement assessment attracts a fine of up to USD 25,000; the DPIA breach fine rose to USD 50,000.

Mandatory
Who signsSelf-assessment
CadenceAnnual assessment of whether a DPO is required
DomainData protection
Official sourceassets.difc.comchecked 2026-09-14

DIFC Regulation 10 — autonomous and semi-autonomous systemsاللائحة العاشرة لمركز دبي المالي العالمي — الأنظمة ذاتية التشغيل وشبه الذاتية
Regulation 10 · in force September 2023, rev. 03 August 2024

DIFC Commissioner of Data Protection

The only AI-specific rule in the UAE that binds across sectors rather than inside one — the Abu Dhabi Responsible AI Standard is mandatory too, but only in healthcare. Among the first sub-national AI data rules anywhere. Requires a designated Deployer and Operator, transparency about whether processing is human-initiated or autonomous, and registers of use cases and of compliance with applicable audit and certification requirements. High-risk systems must either be restricted to human-defined purposes or have an Autonomous Systems Officer appointed. General certification requirements were anticipated during 2026 — this is where a Gulf certification mandate is most likely to appear first. Read our Regulation 10 guide

Mandatory
Who signsSelf-assessment
CadenceContinuous; registers maintained
DomainAI governance, Data protection
Official sourceassets.difc.comchecked 2026-09-14

ADGM Data Protection Regulationsلوائح حماية البيانات في سوق أبوظبي العالمي
2021, consolidated February 2024

ADGM Office of Data Protection

Every ADGM-registered entity processing personal data must register as a data controller and renew annually. Maximum fine USD 28 million. Supplementary rules issued September 2025 clarify lawful bases for special-category data in insurance and vulnerable-person safeguarding.

The linked text is the August 2021 update. ADGM's consolidated February 2024 version could not be accessed for this review, so the consolidation has not been verified in full.

Mandatory
Who signsSelf-assessment
CadenceAnnual controller registration
DomainData protection
Official sourceassets.adgm.comchecked 2026-09-14

Responsible Artificial Intelligence Standardمعيار الذكاء الاصطناعي المسؤول
DoH/ST/DDGO/RAI/V1/2025 · October 2025

Department of Health – Abu Dhabi

The most operationally demanding AI instrument in the UAE, and sanctionable under the Abu Dhabi healthcare disciplinary regulations. Four pillars — core foundations, data management, risk management, AI literacy — across the full lifecycle from inception to decommissioning, covering clinical, financial, administrative and research use, built in-house or bought in. Notably it cites neither ISO/IEC 42001 nor the NIST AI RMF.

Mandatory
Who signsSelf-assessment
CadenceRevision due October 2026
DomainAI governance, Sector-specific
Official sourcedoh.gov.aechecked 2026-09-14

Guidance Note on Responsible Adoption and Use of AI by Licensed Financial Institutionsإرشادات التبنّي والاستخدام المسؤول للذكاء الاصطناعي لدى المؤسسات المالية المرخّصة
February 2026

Central Bank of the UAE

Non-binding, but it establishes clear regulatory expectations for banks and insurers: board accountability, bias stress-testing, transparency in high-impact decisions, human oversight calibrated to risk, and third-party vendor due diligence. Points institutions to the UAE AI Charter and the Central Bank's own model management standards rather than to any international standard.

The Central Bank rulebook page shows an inconsistent issue date; confirm the date against the rulebook PDF before relying on it.

Voluntary
Who signsSelf-assessment
CadenceContinuous monitoring expected
DomainAI governance, Sector-specific
Official sourcerulebook.centralbank.aechecked 2026-09-14

UAE Charter for the Development and Use of Artificial Intelligenceميثاق الإمارات لتطوير الذكاء الاصطناعي واستخدامه
10 June 2024

Ministry of Cabinet Affairs

Twelve principles including safety, algorithmic bias, data privacy, transparency, human oversight, and governance and accountability. A policy instrument with no enforcement mechanism — but the reference point that the Central Bank guidance and most UAE sectoral AI material builds on.

Voluntary
Who signsNo assessment regime
DomainAI governance
Official sourceuaelegislation.gov.aechecked 2026-09-14

National Cyber Security Accreditation Programالبرنامج الوطني لاعتماد الأمن السيبراني

UAE Cyber Security Council

Establishes evaluation and accreditation of government entities, cyber security service providers and training organisations. Unaccredited providers are restricted from serving critical infrastructure — a direct driver of demand for accredited third-party assessors.

Launch date, mandatory scope, categories and application process are all unconfirmed; the detail sits in a policy document that is not publicly available. Confirm with the regulator before relying on it.

Mandatory
Who signsAccredited external assessor
CadencePer accreditation scheme
DomainCyber security
Official sourceu.aechecked 2026-09-14

Saudi Arabia

المملكة العربية السعودية10

Essential Cybersecurity Controlsالضوابط الأساسية للأمن السيبراني
ECC-2:2024

National Cybersecurity Authority

The baseline all other NCA control sets build on. Binds government entities and their contractors, and private-sector owners and operators of critical national infrastructure. The NCA has publicly committed to conducting over 7,000 cyber security assessments of national entities, run through the Haseen national portal. Read our ECC-2:2024 guide

Mandatory
Who signsRegulator assesses
CadenceNCA assessment programme
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Cloud Cybersecurity Controlsضوابط الأمن السيبراني للحوسبة السحابية
CCC-2:2024

National Cybersecurity Authority

Applies to both cloud service providers and cloud service tenants. The 2024 revision reflects Saudi data-localisation requirements.

Mandatory
Who signsRegulator assesses
CadencePer NCA programme
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Critical Systems Cybersecurity Controlsضوابط الأمن السيبراني للأنظمة الحساسة
CSCC-1:2019

National Cybersecurity Authority

Thirty-two main controls and seventy-three sub-controls across governance, defence, resilience, and third-party and cloud. Applies to national critical systems.

Mandatory
Who signsRegulator assesses
CadencePer NCA programme
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Operational Technology Cybersecurity Controlsضوابط الأمن السيبراني للتقنيات التشغيلية
OTCC-1:2022

National Cybersecurity Authority

Covers ICS and OT environments, and ships with a methodology and mapping annex plus a spreadsheet assessment and compliance tool. The NCA also publishes data, telework, social media account and cryptographic control sets.

Mandatory
Who signsRegulator assesses
CadencePer NCA programme
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Cybersecurity Controls for Non-Critical National Infrastructure Private Sector Entitiesضوابط الأمن السيبراني لمنشآت القطاع الخاص غير الحرجة
NCNICC-1:2025

National Cybersecurity Authority

The most significant Saudi development for ordinary private business. Large entities — over 250 staff or revenue above SAR 200m — face 22 sub-components and 65 essential controls including an independent cyber security function with periodic review, audit and compliance oversight. Smaller entities face 13 sub-components and 26 controls, some recommended rather than mandatory.

Reference number corrected from NCINCC to NCNICC against the NCA's own page, which was published on 28 December 2025 and exists in Arabic only — there is no English landing page on the NCA domain at the time of review.

Mandatory
Who signsIndependent audit or function
CadencePeriodic review; no compliance deadline published
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Cyber Security Frameworkإطار الأمن السيبراني
v1.0 · May 2017

Saudi Central Bank (SAMA)

Binds banks, insurers and reinsurers, financing companies, credit bureaus and financial market infrastructure. A six-level maturity model where member organisations must reach at least level 3, “structured and formalised”. SAMA conducts its own reviews and assigns the maturity level. The Cyber Resilience Fundamental Requirements of January 2022 sit alongside it as a licensing-stage requirement, not a replacement.

SAMA's own documents could not be accessed for this review; the version, date and maturity threshold here are from secondary sources.

Sector-binding
Who signsIndependent audit or function
CadenceAnnual penetration test of internet-facing services; regular independent audits
DomainCyber security, Sector-specific
Official sourcerulebook.sama.gov.sachecked 2026-09-14

Personal Data Protection Lawنظام حماية البيانات الشخصية
Royal Decree M/19, amended M/148

SDAIA

Fully enforceable since 14 September 2024, and enforcement is real rather than theoretical: 48 enforcement decisions had been announced by mid-January 2026. Fines to SAR 5 million, doubled for repeat violations, with publication of final penalties. A DPO is mandatory for public bodies, for large-scale systematic monitoring, and for large-scale special-category processing, under qualification rules issued in August 2024.

Mandatory
Who signsMandated officer
CadenceRegistration on the National Data Governance Platform
DomainData protection
No official linkSDAIA does not publish a directly linkable copy on its own domain, so no official link is given.

National AI Risk Management Frameworkالإطار الوطني لإدارة مخاطر الذكاء الاصطناعي
2026

SDAIA

Applies to public and private entities. Five phases from context definition through risk identification across seven categories, assessment on a four-by-four likelihood and impact matrix, treatment, and monitoring. A sovereign framework: it makes no reference to ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF or the EU AI Act. SDAIA's AI Ethics Principles and its generative AI guidelines for government sit alongside it, all voluntary.

Sources conflict on the date — one gives April 2026 publication, the official news agency a July 2026 launch.

Voluntary
Who signsSelf-assessment
CadenceMonitoring and review phase built into the framework
DomainAI governance
No official linkAnnounced through the Saudi Press Agency; we found no page for the framework on SDAIA's own domain.

Haseen registration for cyber security service providersالتسجيل في منصة حصين لمزوّدي خدمات الأمن السيبراني
Mandatory from 1 August 2022

National Cybersecurity Authority

Any entity providing cyber security solutions, services or products in the Kingdom must register. Managed SOC licensing runs on top, with Saudi ownership thresholds and a regional headquarters requirement at tier 1. Legal analysis concludes that firms previously delivering in-scope cyber services into the Kingdom from overseas can no longer lawfully do so.

Mandatory
Who signsNo assessment regime
CadenceRegistration, then per licence
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Regulatory Framework for Licensing Cybersecurity Services, Products and Solutionsالإطار التنظيمي لترخيص خدمات ومنتجات وحلول الأمن السيبراني
RFCS-1:2026 (draft)

National Cybersecurity Authority

Consulted on from 25 February to 26 March 2026. Covers five domains and over a hundred services, explicitly including consulting and assessments. As drafted it would require a Saudi legal entity; 75% Saudi ownership and SAR 10m capital to serve government or critical infrastructure; full in-Kingdom data residency with no access from outside; and NCA qualification certificates for staff. Licence fees from SAR 50,000 to SAR 1,000,000.

Not law. On the NCA's own site it appears only as a public consultation, now closed, and it is absent from the authority's register of issued frameworks. No official document states in terms that it is not in force, so treat the draft status as inferred from where the NCA publishes it. The highest-priority item on this register to monitor.

Draft
Who signsAccredited external assessor
CadenceFive-year licence term proposed
DomainCyber security
Official sourcenca.gov.sachecked 2026-09-14

Qatar

دولة قطر5

National Information Assurance Standardمعيار ضمان المعلومات الوطني
v2.1

National Cyber Security Agency

One of the clearest mandated-external-auditor regimes in the Gulf. Certification runs in four phases: scope and documentation, audit planning with an accredited auditor, compliance audit and controls assessment by that auditor with the report submitted to the NCSA's governance and assurance division, then the certification decision. Binds government entities, critical information infrastructure operators across energy, water, telecoms, finance, health and transport, and service providers accessing those entities' information assets.

Mandatory
Who signsAccredited external assessor
CadenceCertificate valid three years, with an annual maintenance audit
DomainCyber security
Official sourcencsa.gov.qachecked 2026-09-14

NISCF Audit Standard and General Policy for National Certificationمعيار التدقيق والسياسة العامة لمنح الشهادات الوطنية ضمن الإطار الوطني
NCSA-NISCF-AUD-STND-V3.0

National Cyber Security Agency

The component documents of the National Information Security Compliance Framework that govern how an audit is conducted and how certification is granted. The NCSA accredits service providers by category — advisory, audit and penetration testing among them — and firms announce accreditation publicly because it gates the work.

The full accreditation category list, eligibility criteria and whether advisory accreditation is strictly mandatory could not be verified from public sources. Confirm with the NCSA directly.

Mandatory
Who signsAccredited external assessor
CadencePer certification cycle
DomainCyber security
Official sourcencsa.gov.qachecked 2026-09-14

National Data Classification Policyالسياسة الوطنية لتصنيف البيانات
v3.0

National Cyber Security Agency

Three risk tiers — low, medium and high — determining the technical and administrative controls required. Mandatory for government entities and institutions, and the practical starting point for any Qatari assessment.

Mandatory
Who signsSelf-assessment
DomainData protection
No official linkA site migration at the agency broke the published links to this policy, and we found no current copy on its own domain.

Law on Protecting Personal Data Privacyقانون حماية خصوصية البيانات الشخصية
Law 13/2016

NCSA, with guidelines from the Compliance and Data Protection Department at MCIT

Effective 2017 and the first GCC data protection law. No extraterritorial application and no adequacy or standard-clause mechanism — transfers are permitted unless they breach the law or cause serious damage. Sensitive data covering health, religion, criminal records and children requires prior written permission from MCIT. Enforcement is administrative and non-public; no widely reported public actions in the last two years.

Mandatory
Who signsNo assessment regime
DomainData protection
Official sourcehukoomi.gov.qachecked 2026-09-14

Artificial Intelligence Guideline for QCB Licensed Entitiesإرشادات الذكاء الاصطناعي للجهات المرخّصة من مصرف قطر المركزي
4 September 2024

Qatar Central Bank

The most prescriptive AI rule anywhere in the GCC, and binding. Prior QCB approval is required for new or materially modified high-risk AI systems — before deployment and before signing purchase, licensing or outsourcing agreements. Licensed entities must maintain an AI register covering every system, its risk classification, provider, human-oversight protocol and contract dates; must separate training, validation and testing datasets with bias testing; and must report serious AI incidents to the QCB.

Sector-binding
Who signsRegulator assesses
CadenceAI register disclosable annually on request
DomainAI governance, Sector-specific
No official linkThe document sits on the Central Bank's own site, but the server's certificate chain is incomplete, so the link cannot be verified.

Kuwait

دولة الكويت2

Cyber and Operational Resilience Frameworkإطار المرونة السيبرانية والتشغيلية
CORF v1.0 · 3 December 2025

Central Bank of Kuwait

Replaces the CBK Cybersecurity Framework of February 2020 and binds every CBK-regulated entity — Kuwaiti and foreign banks, finance and exchange companies, e-payment operators, credit information companies and open banking providers. Twenty-seven domains, ninety-three sub-domains and 876 controls on a five-level maturity scale, with full compliance required before an entity can claim baseline or above. Annual engagement with CBK-approved independent assessors is mandatory, with results submitted in prescribed formats.

Sector-binding
Who signsAccredited external assessor
CadenceTier 1 annual · Tier 2 every 18 months · Tier 3 two-yearly, plus annual self-assessment
DomainCyber security, Sector-specific
Official sourcecbk.gov.kwchecked 2026-09-14

Data Privacy Protection Regulationلائحة حماية خصوصية البيانات
Amended by Decision 26/2024

CITRA

The 2024 amendment narrowed the regulation so that it now applies only to CITRA-licensed telecom and internet providers. Kuwait has no comprehensive general data protection law; the Electronic Transactions Law of 2014 is the baseline for anyone handling electronic records. Note that the data classification policy was repealed in February 2024, removing Kuwait's tiered sensitivity framework — a reversal frequently mis-stated in vendor material.

Sector-binding
Who signsNo assessment regime
CadenceCITRA inspection of licensees
DomainData protection
No official linkCITRA publishes the regulation as an image-only scan, so we could not confirm the copy is the version amended by Decision 26/2024.

Bahrain

مملكة البحرين3

CBB Rulebook cyber security modulesوحدات الأمن السيبراني في دليل قواعد مصرف البحرين المركزي
e.g. Volume 4, Module RM-9

Central Bank of Bahrain

The most prescriptive mandated-external-assessor rule verified anywhere in the GCC. Requires a qualified CISO with authority to implement the cyber security strategy; penetration testing by internal and external independent third parties using grey box and black box approaches, with the external party changed at least every two years; and incident reporting on a punishing clock — the CBB notified within one hour by phone, an initial report within two hours, and a detailed root-cause report within ten calendar days.

Sector-binding
Who signsExternal, rotated
CadenceAnnual, tested each June, reported to the CBB by 30 September
DomainCyber security, Sector-specific
Official sourcecbb.gov.bhchecked 2026-09-14

Personal Data Protection Lawقانون حماية البيانات الشخصية
Law 30/2018

Ministry of Justice, acting for the Authority under Royal Decree 78/2019

The clearest statutory basis in the GCC for an external data protection officer. A DPO is mandatory for all licensed financial institutions and optional elsewhere — but DPOs must be accredited and appear on the Authority's register, with defined qualification criteria for external appointees. Transfers are permitted to 83 whitelisted countries. Penalties are criminal, up to a year's imprisonment. The permanent independent authority envisaged by the law has still not been established.

Mandatory
Who signsMandated officer
CadenceNotification of processing requiring prior authorisation
DomainData protection
Official sourcepdp.gov.bhchecked 2026-09-14

General Policy for the Use of Artificial Intelligenceالسياسة العامة لاستخدام الذكاء الاصطناعي
v1.0 · launched 27 July 2025

Information & eGovernment Authority

Adopted alongside the GCC ethics manual. A separate draft AI regulation law — 38 articles, approved by the Shura Council in April 2024, proposing mandatory licensing from a new Artificial Intelligence Unit — remains unenacted and must not be presented as law.

Voluntary
Who signsNo assessment regime
DomainAI governance
Official sourceiga.gov.bhchecked 2026-09-14

Oman

سلطنة عُمان3

Personal Data Protection Lawقانون حماية البيانات الشخصية
Royal Decree 6/2022 · Executive Regulations MD 34/2024 · amended by RD 68/2026

Ministry of Transport, Communications and IT — Personal Data Protection Centre

Enforceable since 5 February 2026 — the single most important Oman date. The DPO mandate is unconditional, which makes it the strongest in the GCC, and the regulator prefers the officer to be physically located in Oman. A ministerial permit is required for genetic, biometric, health, racial origin, sexual life, political or religious belief and criminal record data, though since Royal Decree 68/2026 (in force 7 September 2026) not for an employer’s own staff data or security-camera footage. The same amendment extends the law to processing outside Oman and adds a right to object to solely automated decisions. Administrative fines are modest at up to OMR 2,000 per violation, but the law carries fines of up to OMR 500,000 for its most serious offences; the real leverage is suspension of processing permits.

Mandatory
Who signsMandated officer
CadenceBreach notification within 72 hours; data subject requests within 45 days
DomainData protection
Official sourcemtcit.gov.omchecked 2026-09-30

General Policy for the Safe and Ethical Use of Artificial Intelligence Systemsالسياسة العامة للاستخدام الآمن والأخلاقي لأنظمة الذكاء الاصطناعي
1 April 2025

Ministry of Transport, Communications and IT

A framework policy tied to Oman Vision 2040, establishing operational expectations for state entities and regulated sectors. A policy instrument, not legislation.

Voluntary
Who signsNo assessment regime
DomainAI governance
Official sourcemtcit.gov.omchecked 2026-09-14

No national private-sector cyber security control setلا توجد مجموعة ضوابط أمن سيبراني وطنية للقطاع الخاص

Ministry of Transport, Communications and IT

A deliberate negative entry. Oman publishes government-facing guidance — a cyber security governance guideline, a security assessment services standard, basic controls guidelines and a classification guide — but no single named mandatory national framework for the private sector equivalent to the Saudi ECC or the Qatar NIA. Vendors who claim otherwise are wrong, and saying so is a credibility signal.

No such instrument appears in the MTCIT library. The new Cybercrime Law of June 2026 is not freely available, so its obligations for organisations have not been confirmed.

Research observation
Who signsNo assessment regime
DomainCyber security

GCC-wide and extraterritorial

إقليمي وعابر للحدود4

ISO/IEC 42001 — AI management systemsISO/IEC 42001 — أنظمة إدارة الذكاء الاصطناعي

International standard; no Gulf accreditation scheme identified

No Gulf regulator mandates it, and no Gulf instrument checked even references it — not the Central Bank of the UAE guidance, not the Abu Dhabi Responsible AI Standard, not the SDAIA risk framework, not the Dubai AI Seal. That is precisely what makes it useful: it is the only neutral layer that spans six sovereign frameworks. Gulf adoption so far is government-led — SDAIA, Dubai Culture, GDRFA Dubai, the UAE Ministry of Interior — with certificates issued by international bodies under foreign accreditation. DIFC Regulation 10 is the only instrument creating a certification-shaped obligation, and it does not name a standard.

Voluntary
Who signsAccredited external assessor
CadenceThree-year certification cycle with surveillance
DomainAI governance
Official sourceiso.orgchecked 2026-09-14

Guiding Manual on the Ethics of Artificial Intelligence Use in the GCCالدليل الاسترشادي لأخلاقيات استخدام الذكاء الاصطناعي في دول مجلس التعاون
2025

Ministerial Committee for eGovernment, Cooperation Council for the Arab States of the Gulf

The only supranational GCC AI instrument identified, and under-discussed in market commentary. Principles of human autonomy, system safety and reliability, justice and non-discrimination, and privacy and data security, framed explicitly around shared Gulf values.

Voluntary
Who signsNo assessment regime
DomainAI governance
No official linkNamed in GCC Secretariat material but not published on a Council domain; member-state copies exist.

EU AI Act — extraterritorial reachقانون الاتحاد الأوروبي للذكاء الاصطناعي — الأثر خارج الحدود
Regulation (EU) 2024/1689

European Commission / national market surveillance authorities

Reaches third-country providers and deployers where the output of the AI system is used in the EU — so a Gulf firm selling into Europe is in scope regardless of establishment. The transparency obligations covering chatbot disclosure and synthetic content marking took effect on 2 August 2026 and bind now. AI systems already on the market before that date have until 2 December 2026 to add machine-readable marking of AI-generated output. Following the Digital Omnibus agreement, high-risk obligations under Annex III were deferred to December 2027 and Annex I to August 2028 — a delay, not relief. Much circulating Gulf commentary predates the deferral and is out of date.

Mandatory
Who signsSelf-assessment
CadencePhased
DomainAI governance
Official sourceeur-lex.europa.euchecked 2026-09-14

No GCC-wide binding instrument, adequacy mechanism or mutual recognitionلا توجد أداة مُلزِمة على مستوى دول المجلس، ولا آلية كفاية، ولا اعتراف متبادل

—

The organising fact of this register. Each state's regime stands alone. Bahrain's transfer whitelist includes Gulf states, but Saudi, the UAE, Qatar and Oman each run separate transfer regimes, and no certificate issued under one regime is recognised by another. Multi-country groups comply country by country. The observable direction of travel is shared even though the instruments are not: data localisation for government and financial data, maturity models rather than pass or fail, licensed assessor ecosystems, and a shift from voluntary frameworks to licensing-linked mandates.

Research observation
Who signsNo assessment regime
DomainCyber security, Data protection

How to read it

Status is legal force, not market practice

  • Mandatory binds everyone in scope.
  • Sector-binding binds a defined sector or entity type.
  • In force, pending means the law is live but the mechanism that makes it operable has not been issued.
  • Voluntary is a policy instrument with no enforcement mechanism.
  • Draft is not law and must never be presented to a client as one.

Who signs is the column that costs money

  • Where an accredited or approved external assessor is required, no amount of readiness work substitutes for engaging one.
  • In several regimes that assessor must hold a local licence, which is a market-entry question, not a compliance one.
  • An independent function is weaker: internal, but separated from the operations it reviews.
  • We will tell you which of these applies before you sign anything.

On verification

Compiled from the issuing authorities' own publications wherever they publish one. Items marked with a warning could not be verified against a primary source and must be confirmed before they are relied on. Several regulators — Qatar's NCSA, the Qatar Central Bank and the Saudi central bank rulebook — do not make every document publicly available, so their entries here are a verified sample rather than a complete register.

Which of these binds you?

A scoping call establishes the answer, and stops the work you do not owe. It takes about twenty minutes and costs nothing.