العربية

Free tool · 2 minutes

Which Gulf cyber, data and AI rules apply to you?

Seven questions, one list. Built on our regulations register: 40 instruments across the six GCC states, each linked to the issuing authority and checked by hand. Your answers are not sent to us.

Answer seven questions

1. Where do you operate, or serve people?

Choose every GCC state that applies.

2. Which best describes your organisation?
3. Do you process personal data about individuals there?

Customers, patients or staff all count.

4. Do you use or build AI that affects people?

For example screening, scoring, triage or customer chatbots.

5. Do you place AI on the EU market, or is its output used there?
6. Do you run operational technology (industrial control systems)?

How this works

The tool reads our live regulations register and applies rules about who each instrument binds. It separates what binds you directly from what reaches you through your clients’ contracts, and from what is voluntary. It cannot see licences, contracts or group structures, so treat the result as a starting list. We never assess work we have advised on, and we never sell the fix for anything we assess.

Questions

Is this legal advice?

No. It is a structured starting list drawn from regulators’ own texts. Where an answer depends on your licence, contracts or group structure, we say so and recommend a scoping call.

Is my data stored?

No. Your answers stay in your browser. They appear in the page address only so that you can copy and share the result.

How current is it?

The tool reads the regulations register on every use. The register is reviewed every quarter, and each entry shows the date its official source was last checked.

Want a second pair of eyes on the list?

Tell us what came up and where you operate. The first call is free, and we will tell you if an in-country licensed provider must do the work.