AI Regulations in the
Middle East
The UAE created a federal AI authority in June 2026, Saudi Arabia declared its Year of AI, and the Gulf's central banks are putting AI expectations in writing. Here is what is in force, what is coming, and how to prepare. The CBUAE, SDAIA, and UAE PDPL frameworks are already live in the Modulos library.
Why AI Regulations in the Middle East Matter
Governments across the GCC are investing heavily in artificial intelligence and pairing that investment with stricter oversight. Regulators are responding with new laws and supervisory expectations on data privacy, ethics, and accountability.
Compliance isn't optional. Violations can lead to serious consequences:
Penalties up to SAR 5M under the Saudi PDPL and proposed criminal penalties, including prison terms, under Bahrain’s draft AI law
Disqualification from public tenders and CBUAE supervisory findings for financial institutions
Delays in financing, product launches, and loss of market access
Staying ahead of local laws while aligning with global AI standards like ISO 42001, is now critical for any AI-driven organization operating in the region.
Jurisdictions compared, from the UAE to Egypt
Saudi PDPL violation decisions in a single year
Requirements across the region’s frameworks, live in Modulos
Central bank with binding AI rules today: Qatar’s QCB
Where the Region Stands
The Gulf moved fast in 2026. These are the developments that change what your compliance program has to answer for.
AI takes a seat in the UAE Cabinet
A National AI System joins the UAE Cabinet as an advisory member, providing real-time policy analysis to ministers and federal boards.
CBUAE Guidance Note
AI/ML expectations for CBUAE-licensed financial institutions, from board accountability to kill-switch capability.
The UAE gets a federal AI regulator
The Federal Authority for Artificial Intelligence and Data consolidates the AI Office, TDRA’s digital-government arm, and the Emirates Data Office. Four days later, DIFC opened consultation on AI-focused amendments to its data protection rules.
Saudi Arabia launches its AI risk framework
SDAIA launches the National AI Risk Management Framework: one national methodology for identifying, treating, and monitoring AI risk across government and private entities.
Saudi text-and-data-mining exception
The new copyright law permits reproduction of lawfully published works for AI development without the author’s permission, 180 days after its February publication.
No date yet: Bahrain's 38-article AI proposal was endorsed by the Shura Council in April 2024, has faced pushback in the Council of Representatives, and was not enacted as of July 2026.
AI takes a seat in the UAE Cabinet
A National AI System joins the UAE Cabinet as an advisory member, providing real-time policy analysis to ministers and federal boards.
CBUAE Guidance Note
AI/ML expectations for CBUAE-licensed financial institutions, from board accountability to kill-switch capability.
The UAE gets a federal AI regulator
The Federal Authority for Artificial Intelligence and Data consolidates the AI Office, TDRA’s digital-government arm, and the Emirates Data Office. Four days later, DIFC opened consultation on AI-focused amendments to its data protection rules.
Saudi Arabia launches its AI risk framework
SDAIA launches the National AI Risk Management Framework: one national methodology for identifying, treating, and monitoring AI risk across government and private entities.
Saudi text-and-data-mining exception
The new copyright law permits reproduction of lawfully published works for AI development without the author’s permission, 180 days after its February publication.
Bahrain's AI statute is still in parliament
Endorsed by the Shura Council in April 2024 as a legislative proposal, faced pushback in the Council of Representatives, and was not enacted as of July 2026.
AI Regulations by Country
Each jurisdiction takes its own path. Qatar's central bank has issued binding AI rules for financial institutions and the UAE's has set supervisory expectations, Saudi Arabia pairs a national governance ecosystem with real PDPL enforcement, Egypt has published its governance roadmap, and Bahrain's proposed statute is still in parliament.
On 14 June 2026, the UAE announced the Federal Authority for Artificial Intelligence and Data, consolidating the federal AI Office, TDRA's digital-government arm, and the Emirates Data Office into a single body reporting to the Cabinet, chaired by Omar Sultan Al Olama, the Minister of State for AI. It joins Abu Dhabi's AI and Advanced Technology Council (AIATC, Law No. 3 of 2024) and the Regulatory Intelligence Office (2025), which embeds AI in the law-making process itself. Core binding legislation remains Federal Decree-Law No. 45/2021 on data protection (PDPL) and Federal Decree-Law No. 34/2021 on cybercrime; the UAE Charter for AI (June 2024) sets out 12 non-binding principles including safety, transparency, and human oversight.
Since January 2026, a National AI System sits as an advisory member of the Cabinet and the boards of federal entities, providing real-time policy analysis. There is still no horizontal AI statute: the UAE regulates AI through this layered structure rather than an EU-style act.
CBUAE AI Guidance for Financial Institutions
Issued February 2026 · Applies to all licensed financial institutions
The Central Bank of the UAE published a Guidance Note on the responsible adoption and use of AI/ML by all licensed financial institutions (LFIs), including banks, insurance providers, exchange houses, and payment service providers. Published in the official CBUAE Rulebook, it carries strong supervisory expectation despite using "should" language.
This guidance ships in Modulos as a paired organization and application framework: 26 requirements with 22 UAE-specific controls, scoped to onshore LFIs (DIFC and ADGM fall under their own regimes). Read the UAE Consumer AI framework docs
The free zones add binding layers of their own: DIFC's Regulation 10, which governs personal data processed through autonomous and semi-autonomous systems and is administered by the DIFC Commissioner of Data Protection, has been in force since September 2023 and enforced through thematic reviews, one of the region's few AI-specific rules with teeth. On 18 June 2026, DIFC opened a consultation on amended Data Protection Regulations that would strengthen Regulation 10 and add a new Regulation 11 empowering the Commissioner to recognize AI accreditation and certification schemes. ADGM maintains its own data protection and technology governance framework.
Saudi Arabia has designated 2026 as the "Year of Artificial Intelligence," with the Saudi Data and Artificial Intelligence Authority (SDAIA) leading national AI governance. SDAIA achieved ISO 42001 certification in July 2024, one of the first government agencies to do so.
The binding layer is the Personal Data Protection Law (PDPL, in force since September 2023, fines up to SAR 5M), and it is enforced: SDAIA's committees issued 48 decisions confirming PDPL violations in the year to early 2026. Around it sit SDAIA's AI Ethics Principles (updated 2025), the Generative AI Guidelines (updated 2025), and the AI Adoption Framework with four maturity levels (September 2024). These AI frameworks are non-binding, but SDAIA accreditation increasingly carries weight in government procurement.
In 2026, SDAIA launched the National AI Risk Management Framework (SDAIA-P145): one national methodology for identifying, assessing, treating, and monitoring AI risk, built around a likelihood-impact matrix and applied proportionally to an entity's sector, size, and maturity. The Arabic text is authoritative, with an English executive summary. Modulos ships it as 25 requirements with 20 new controls.
From 12 August 2026, a new copyright law permits reproduction of lawfully published works for AI development without the author's permission, within statutory limits on source and purpose, one of the region's first text-and-data-mining exceptions. The Draft Global AI Hub Law (2025), still at consultation stage, proposes "Virtual," "Extended," and "Private" hubs for international data hosting.
Qatar holds a distinction most coverage misses: the Qatar Central Bank's AI guidelines (September 2024) are the region's only legally binding AI-specific rules issued by a national regulator, covering QCB-licensed financial institutions (QFC firms answer to their own regulators). Institutions need a defined AI strategy, risk assessments, prescribed disclosure, and approval for high-risk AI: results go to the regulator, and fully autonomous systems are gated before launch.
Qatar's Ministry of Communications issued Principles and Guidelines for Ethical AI Development and Deployment (2025). A dedicated AI law is under consideration, and the Qatar Financial Markets Authority (QFMA) announced plans for draft AI regulations in capital markets (May 2025).
Bahrain is the furthest along in the GCC toward a standalone AI statute, but the road has been slow. A 38-article legislative proposal was endorsed by the Shura Council in April 2024 and referred to the government for formal drafting; it has since faced pushback in the Council of Representatives, where the government proposed a regulatory sandbox instead, and had not been enacted as of July 2026. If passed, it would carry criminal penalties, with prison terms of up to three years in the Shura text (a separate 2025 lower-house proposal went further).
The General Policy for the Use of AI (Version 1.0, May 2025) is Bahrain's first binding policy for government entities. The Central Bank of Bahrain regulates automated financial advice through its digital financial advice directives, and its supervisory reviews extend to AI use.
Egypt governs AI through its National AI Strategy (second edition, 2025 to 2030) under the National Council for Artificial Intelligence, whose mandate expanded to quantum and emerging technologies in January 2026, and the Ministry of Communications and Information Technology, alongside the Egyptian Charter for Responsible AI. The data layer is the Personal Data Protection Law (Law 151/2020), whose executive regulations arrived in November 2025 with a one-year grace period, so full enforcement begins in November 2026.
Dedicated AI legislation remains planned rather than imminent: the March 2026 National AI Governance Framework foresees a possible AI act in a later phase, with a separate data-governance track advancing in parallel. Egypt's strategy places particular weight on Arabic-language models and building regional AI capacity, which shapes how it approaches both regulation and procurement.
Oman's National AI Policy entered into force on 9 April 2025, issued by the Ministry of Transport, Communications and IT (MTCIT). A policy instrument rather than a statute, it is nonetheless mandatory within its scope: in-scope entities must apply governance standards, conduct regular assessments, maintain documentation, and submit compliance reports upon request. The National Program for AI and Advanced Digital Technologies (2024-2026) supports implementation.
On 30 April 2026, a Royal Decree established an AI Special Zone in Muscat with tax and customs incentives for AI investment. Amendments to Oman's Personal Data Protection Law covering automated processing and data retention cleared the Council of Oman in May 2026 and now await royal promulgation, a sign the data layer is catching up with the AI strategy.
AI Regulations Across the Gulf
Every jurisdiction here combines binding data protection law with AI frameworks, sector guidance, and procurement requirements. The matrix separates what binds today from what is policy and what is still pending, because that difference decides your obligations.
| Country | Data protection | National AI framework | Financial-sector AI rules | Horizontal AI statute |
|---|---|---|---|---|
| UAE | PDPL 45/2021 · DIFC Reg 10 (free zone) | AI Charter · Federal Authority (Jun 2026) | CBUAE Guidance Note (Feb 2026) | None · layered regime |
| Saudi Arabia | PDPL · SAR 5M fines · 48 decisions | SDAIA Ethics · GenAI · Risk Framework (P145) | — | Hub Law draft · TDM exception 12 Aug 2026 |
| Qatar | Data Privacy Law 13/2016 | MCIT Ethical AI Principles (2025) | QCB Guidelines · high-risk approval gates | Under consideration |
| Bahrain | PDPL 30/2018 | General Policy for AI Use · binds gov entities | CBB digital-advice directives | 38-article law in parliament |
| Egypt | PDPL 151/2020 · full enforcement Nov 2026 | Strategy 2.0 · Responsible AI Charter | — | Planned · Mar 2026 roadmap |
| Oman | Data protection decrees | National AI Policy · mandatory in scope | — | None announced |
The central-bank wave
The Central Banks Moved First
While horizontal AI statutes are still drafts, the Gulf's financial supervisors already put their AI expectations in writing. If you run AI in a licensed financial institution, these are the documents your program will be examined against.
Qatar Central Bank
AI Guidelines for licensed financial institutions
- Approval gates for high-risk AI, strictest when fully autonomous
- A defined AI strategy and documented risk assessments
- Prescribed disclosure about AI systems in use
Central Bank of the UAE
Guidance Note on AI/ML in the CBUAE Rulebook
- Board accountability and a complete AI model inventory
- Annual bias testing, human review, opt-out where feasible
- Kill-switch capability to cease AI use immediately
Central Bank of Bahrain
Directives on digital financial advice
- Written expectations for automated financial advice
- Supervisory reviews extend to AI and RPA use
Running AI in a bank or insurer? See how one control set serves financial supervisors across markets
Shared AI Governance Trends in the Gulf
Despite different regulatory timelines, three currents run through every jurisdiction on this page:
Privacy by design
Most data protection laws in the region are modeled on GDPR, requiring clear consent, transparency, and data minimization. A "low-risk" AI system that touches personal data still carries the full weight of PDPL obligations.
Ethics in public procurement
In the UAE, Saudi Arabia, and Bahrain, ethical AI practices are increasingly tied to supplier eligibility. Ethics self-assessments and accreditations carry growing weight in tenders, so governance work converts directly into market access.
ISO 42001 as the shared baseline
Agencies like Emirates Health Services and Saudi Arabia's SDAIA are early adopters of ISO 42001, and certification is emerging as the region's trusted signal of AI governance readiness, especially in government tenders.
How Gulf Rules Define AI Risk
The Gulf has no binding EU-style risk law. SDAIA's AI Ethics Principles sketch a four-tier classification, from unacceptable down to little risk, but as non-binding guidance. Where risk carries legal consequences, it is defined in sector rules and in data protection law. These are the definitions that exist.
CBUAE Guidance Note
CBUAE-licensed financial institutions
Defines "high-impact decisions": any AI determination that materially affects a customer's access to financial products or services.
Brings heightened disclosure, human review, and consideration of consumer opt-out.
QCB AI Guidelines
QCB-licensed financial institutions
Classifies AI systems by risk: high-risk systems submit training, validation, and testing results for approval, and fully autonomous ones are gated before launch.
The strictest gate in the region: for fully autonomous systems, approval comes before go-live.
PDPL regimes
UAE, Saudi Arabia, Qatar, Bahrain, Egypt, Oman
Data protection laws attach duties to the processing of personal data, whatever the AI system's risk label.
A "low-risk" chatbot handling customer data still carries full PDPL obligations.
Elsewhere the frameworks grade organizations, not systems: SDAIA's AI Adoption Framework measures maturity levels, and Oman's National AI Policy requires assessments without a classification scheme. If your AI also reaches EU persons, the EU AI Act's own categories apply on top; that law has no "medium risk" tier either.
In the platform today
Middle East Frameworks, Ready in Modulos
These are not summaries on a shelf. Each framework ships in the Modulos library as versioned requirement templates mapped to shared controls, so evidence collected on a shared control serves every framework that maps it. The documentation is public: read exactly what each requirement asks before you ever talk to us.
UAE Consumer AI
CBUAE Guidance Note on AI/ML for licensed financial institutions
26 requirements · 22 UAE-specific controls
Scoped to onshore LFIs: DIFC and ADGM fall under their own regimes, and the docs say so.
Read the framework docsSaudi AI Risk Management
SDAIA National AI Risk Management Framework (SDAIA-P145)
25 requirements · 20 new controls
The Arabic text is authoritative; requirements apply proportionally to sector, size, and maturity.
Read the framework docsUAE PDPL
Federal Decree-Law No. 45 of 2021 on the protection of personal data
18 requirements · mapped to 65 controls
The Executive Regulation is still pending, and the docs flag exactly which duties it will pin down.
Read the framework docsUAE AI Ethics
UAE AI Office Ethics Principles and Guidelines
8 principles · translated to controls and evidence
A working guide from the eight principles to the concrete controls that satisfy them.
Read the framework docsOperating under Qatar's QCB guidelines? A QCB-specific template is not in the library yet. ISO/IEC 42001, the standard SDAIA itself certified against, gives QCB programs a governance backbone, and Modulos ships it in full.
Browse the framework libraryYour AI Compliance Roadmap for the Middle East
Five steps from an unmapped AI estate to audit-ready, each tied to the Gulf rule that asks for it.
Document every AI system and use case, then risk-rate each one. The CBUAE expects a complete model inventory with name, purpose, and risk rating, and the PDPL layers of the UAE, Saudi Arabia, and Egypt attach duties wherever personal data flows.
In Modulos: a living AI registry with lifecycle stage and risk rating per system.

Use ISO/IEC 42001 as the governance backbone and extend existing ISO 27001 structures to the AI lifecycle. It is the standard the region’s own institutions reach for: SDAIA certified against it, and Emirates Health Services runs its AI governance on it.
In Modulos: one control set mapped across ISO 42001 and the frameworks that reuse it.

The UAE AI Office publishes an AI Ethics Self-Assessment, Dubai runs the tiered Dubai AI Seal certification, and SDAIA offers a self-assessment against its Ethics Principles. Voluntary for most buyers, they decide real tenders: Dubai now requires the Seal for government AI contracting.
In Modulos: assessment workflows that keep the answers and the supporting evidence together.

The CBUAE expects bias testing at least annually or on material model change, and QCB-licensed institutions maintain documented risk assessments. Track drift, bias metrics, and data quality as ongoing evidence rather than an annual scramble.
In Modulos: risk and performance dashboards with history an examiner can walk through.

Qatar’s QCB reviews high-risk AI, taking training, validation, and testing results for approval and gating fully autonomous systems before launch. Audit-ready evidence packages answer that today, and ISO/IEC 42001 certification differentiates in competitive tenders.
In Modulos: evidence packages traceable from each artifact back to the requirement that asked for it.

Trusted by 200+ organizations
Modulos customers include aDigital, SCSK, ETH, PwC, Berner Fachhochschule, Mobile Health, Serai, CertX, JobCloud, Xayn, Beyond Gravity, Armasuisse.

Regional Advisory
Modulos works with advisory partners across the region, including PwC Middle East, on AI governance programmes aligned to UAE and Saudi regulatory frameworks. See the partner ecosystem
Gartner Magic Quadrant
Named in the inaugural Magic Quadrant™ for AI Governance Platforms
Published by Gartner® on 16 June 2026. Read the full announcement.
Gartner, Magic Quadrant for AI Governance Platforms, Lauren Kornutick, Sumit Agarwal, Priya Sundararaman, Nader Henein, Brandon Medford, 16 June 2026. GARTNER is a registered trademark and service mark, and MAGIC QUADRANT is a registered trademark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
FAQ about Middle East AI Regulations
The UAE combines federal data protection (PDPL, Decree-Law 45/2021), the UAE Charter for AI (2024, non-binding), and sector-specific guidance. In June 2026 the UAE announced the Federal Authority for Artificial Intelligence and Data as a single Cabinet-level regulator. For financial institutions, the CBUAE published a Guidance Note on AI/ML in February 2026 covering governance, bias testing, transparency, and human oversight. DIFC and ADGM maintain separate frameworks, and DIFC Regulation 10 on personal data processed through autonomous systems has been in force since September 2023.
The Federal Authority for Artificial Intelligence and Data, announced on 14 June 2026, consolidates the federal AI Office, the digital-government arm of TDRA, and the Emirates Data Office into one body reporting to the Cabinet, chaired by Omar Sultan Al Olama, the Minister of State for AI. Sector regulators keep their mandates: the CBUAE for financial institutions, AIATC in Abu Dhabi, and the free-zone authorities in DIFC and ADGM.
The CBUAE Guidance Note (February 2026) applies to financial institutions licensed and supervised by the CBUAE. Key expectations include board-level accountability for AI outcomes, a complete AI model inventory, annual bias testing, human review of AI-generated decisions, consideration of consumer opt-out for high-impact decisions, kill-switch capability, and third-party vendor due diligence. While framed as guidance, it is published in the official Rulebook and carries strong supervisory expectation.
Saudi Arabia’s AI governance is led by SDAIA, which issues non-binding AI Ethics Principles, Generative AI Guidelines, and an AI Adoption Framework. The PDPL (in force since September 2023) provides mandatory data protection with penalties up to SAR 5M, and SDAIA’s committees issued 48 decisions confirming violations in the year to early 2026. In 2026, SDAIA launched the National AI Risk Management Framework (SDAIA-P145), one national methodology for identifying, assessing, treating, and monitoring AI risk. From 12 August 2026, a new copyright law permits reproduction of lawfully published works for AI development within statutory limits, one of the region’s first text-and-data-mining exceptions. Saudi Arabia designated 2026 as the Year of AI.
Not yet mandated, but it is rapidly becoming the governance baseline. SDAIA achieved ISO 42001 certification in July 2024, and Emirates Health Services uses it as their AI governance standard. Institutions across the Gulf increasingly adopt ISO 42001, and certification provides a competitive advantage in government tenders.
It can. The EU AI Act applies when your system’s output is used in the EU or your AI-powered products and services are offered to EU customers, regardless of where the system is hosted. Many Gulf organizations are aligning with both regional and EU requirements to serve international markets.
Bahrain, on paper: a 38-article legislative proposal was endorsed by the Shura Council in April 2024 and referred for government drafting, with criminal penalties including multi-year prison terms. It has since faced pushback in the Council of Representatives and had not been enacted as of July 2026. Meanwhile Qatar already has the region’s only binding AI-specific rules issued by a national regulator, through the central bank’s guidelines for QCB-licensed financial institutions.
PDPL (Personal Data Protection Law) focuses on data privacy, consent, and handling, similar to GDPR. AI-specific frameworks (like SDAIA Ethics Principles, CBUAE AI Guidance, or Qatar’s QCB guidelines) address broader concerns: algorithmic fairness, model explainability, human oversight, bias testing, and AI governance. Both may apply to your AI systems simultaneously.
High-risk typically includes AI used in healthcare decisions, financial services (credit scoring, insurance, loan applications), criminal justice, critical infrastructure, or systems that significantly affect individuals’ rights. The CBUAE guidance specifically defines "high-impact decisions" as any AI determination that materially affects a customer’s access to financial products or services, and Qatar’s QCB requires high-risk AI systems to submit training, validation, and testing results for approval, with fully autonomous systems gated before launch.
Start documenting your AI systems and their risk levels now. Regulators generally look favorably on organizations that demonstrate good-faith compliance efforts. Penalties vary: Saudi PDPL penalties reach SAR 5M and are being imposed, Bahrain’s proposed AI law includes criminal penalties, and the CBUAE can raise non-compliance during supervisory examinations. The regulatory environment is tightening, not loosening.
Four frameworks are in the Modulos library today: the CBUAE Guidance Note on AI/ML for licensed financial institutions (26 requirements with 22 new UAE-specific controls), the SDAIA National AI Risk Management Framework SDAIA-P145 (25 requirements with 20 new controls), the UAE PDPL, Federal Decree-Law 45/2021 (18 requirements mapped to 65 controls), and the UAE AI Ethics Principles as a principles-to-controls guide. Each comes with full documentation at docs.modulos.ai, and requirements are mapped to shared controls, so evidence collected on a shared control is reused across frameworks like ISO 42001.
Yes. Modulos is available as SaaS, private cloud, or VPC deployment, so organizations subject to data-residency or localization expectations can run the platform inside their own environment and region. Deployment options are described in detail on the Modulos deployment page.
Ready to Simplify AI Compliance in the Gulf?
The CBUAE Guidance Note, SDAIA's National AI Risk Management Framework, the UAE PDPL, and the UAE AI Ethics Principles are already in the Modulos framework library, documented publicly and mapped to shared controls. Book a demo to see your obligations as one program instead of four.
