العربية

Service · AI governance

Six AI frameworks. None of them name a standard.

Saudi wrote its own risk framework. Abu Dhabi Health wrote its own Responsible AI Standard. Qatar's central bank wrote a binding guideline. DIFC wrote Regulation 10. Not one of them tells you what to comply with — which is the whole problem, and the whole opportunity.

The gap, stated plainly

Eleven instruments in our register touch AI. We checked each one for a reference to an international standard. The Central Bank of the UAE guidance names none. The Abu Dhabi Responsible AI Standard names none — it cites OWASP and NIST only for secure code review. The Saudi National AI Risk Management Framework names none, and was deliberately built as a sovereign instrument rather than an adoption of ISO/IEC 23894 or the NIST AI RMF. The Dubai AI Seal names none.

DIFC Regulation 10 comes closest: it requires Deployers and Operators to maintain records of “compliance with applicable audit and certification requirements” — a certification-shaped obligation that does not say which certification. General certification requirements have been anticipated for that regime and had not been published at our last review.

So a group with AI systems in three Gulf states faces three sovereign frameworks, three vocabularies, and no common object to certify against. That is what a neutral management system is for. Not a badge — a crosswalk layer.

No Gulf regulator mandates ISO/IEC 42001, and we will not pretend otherwise

Some consultancies sell 42001 in this region as though it were a compliance requirement, or claim the UAE AI Charter maps directly onto its Annex A controls. The mapping is defensible as analysis; it is not a regulator's statement, and nobody should buy certification believing it discharges an obligation. Gulf adoption so far has been government-led — Saudi's data and AI authority, Dubai Culture, GDRFA Dubai, the UAE Ministry of Interior — with certificates issued by international bodies under foreign accreditation, because no local accredited scheme for the standard exists. Buy 42001 because it spans the frameworks and survives the next one. Not because a regulator asked.

What the engagement actually produces

Scoped to whichever instruments reach you. Most groups need two or three of these, not all five.

01

The crosswalk itself

Your management system mapped clause by clause to each Gulf instrument that binds you, with the gaps named and the duplication removed. The deliverable is a matrix your board and your regulator can both read.

ISO/IEC 42001SDAIA AI RMFDoH RAI V1
02

DIFC Regulation 10 readiness

Deployer and Operator designation, the transparency notices the regulation specifies, registers of use cases and data-sharing arrangements, and the high-risk route — either restriction to human-defined purposes or an Autonomous Systems Officer.

Regulation 10DIFC Law 5/2020
03

QCB high-risk approval pack

For QCB-licensed entities: the classification, the AI register, the human-oversight protocol and the evidence the Central Bank expects — assembled before you sign the vendor contract, not before you deploy.

QCB AI Guideline
04

AI impact and risk assessment

Assessment against the Saudi five-phase framework where it applies, and against your own risk appetite where it does not. Seven risk categories, a four-by-four matrix, and treatment decisions that survive a board challenge.

SDAIA AI RMFISO/IEC 23894
05

EU AI Act exposure

If your output reaches users in Europe you are in scope regardless of establishment. The transparency obligations covering chatbot disclosure and synthetic content marking are already in force; the high-risk deadlines were deferred, not removed.

Reg. (EU) 2024/1689Art. 50

Boundaries

What we do

  • Design and assess the management system, and write the crosswalk.
  • Prepare you for certification by an accredited body, and tell you which bodies operate here.
  • Sit on your side of the table during the certification audit.
  • Say when an instrument does not reach you, which is often the most valuable finding.

What we will not do

  • Certify you. We are not an accredited certification body and nobody advising you should also be signing your certificate.
  • Sell you a platform, or take commission from one.
  • Present ISO/IEC 42001 as a Gulf regulatory requirement.
  • Bid for the remediation work our own assessment generates.

Where this is heading

Two things are worth watching, because they would change the shape of this work. DIFC's anticipated certification requirements are the most likely place a Gulf certification mandate appears first. And the Saudi central bank has issued no AI instrument, while the UAE central bank issued guidance in February 2026 and Qatar's issued a binding guideline in September 2024 — which makes a Saudi financial-sector AI instrument a reasonable thing to prepare for rather than react to.

DIFC: Regulation 10 on AI systems

Read our Regulation 10 guide

Start with a scoping call

Tell us where your AI systems run and who your customers are. Which of the eleven instruments reach you is usually settled in one conversation.