You are running more AI than you think.
Your regulator is about to ask. We determine exactly which AI obligations apply to your organisation across the GCC — and which do not — then find every AI system you are running, show you the gaps, and produce the evidence.
Every Gulf regulator now has rules for AI. Few enterprises know which ones reach them.
Between February and August 2026, the UAE, Saudi Arabia, Qatar and Oman each issued binding or supervisory AI obligations. They demand the same five things in different words — and almost nobody can produce them:
An inventory. A risk assessment per system. Independent validation or prior approval. Human oversight. And a periodic report to somebody.
We tell you what applies, find what you run, and prove it is governed.
Independent AI governance for regulated enterprises across the GCC. We do not sell AI platforms, and we do not build the systems we assess.
Applicability Determination
Which obligations reach your entity, which do not, and why — every line citing a clause, in two weeks.
- Entity, jurisdiction & licence analysis
- Applicable · conditional · not applicable
- Watchlist for proposed instruments
- Scoped programme, not a checklist
Regulatory Readiness Assessment
Every AI system you run — declared, detected and embedded — classified by risk and mapped to your obligations.
- Enterprise AI inventory
- Risk classification per system
- Control gap assessment
- Remediation roadmap
Continuous Governance
Governance decays. New systems appear, models change, and regulations move. We keep the picture true.
- Inventory & drift monitoring
- Regulatory change alerts
- Evidence expiry tracking
- Quarterly board reporting
Every determination is grounded in the GCC obligation register — cited to the clause, versioned, and open for you to check.
The GCC AI Obligation Register
A cited, versioned index of the AI instruments in force across the six GCC states — what each one demands, whom it reaches, and where the official text sits. Free to use, and we publish our coverage gaps alongside our coverage.
Six states, nine legal systems
UAE federal with DIFC and ADGM, Saudi Arabia, Qatar, Oman, Bahrain and Kuwait — each tiered by how far we have verified it.
Cited, not summarised
Every entry links to the official text, with force, status and effective dates stated.
Versioned
Superseded instruments stay reachable and marked. Changes are logged publicly, never applied silently.
Gaps published too
We list what we do not hold. A register you cannot calibrate is a register you cannot rely on.
Determination first. Always.
Most AI governance work catalogues systems and then asks which rules might apply. We start from the obligations, because that is what decides which questions are worth asking.
Establish what applies
Your entity, jurisdictions, licences, data and AI use cases resolve to a cited obligation set — applicable, conditional, not applicable, and watchlist.
Find what you actually run
Declared through interviews, detected through read-only connectors, inferred from the software estate. Then risk-classified and tested against the evidence you hold.
Close it and keep it closed
Every gap gets an owner, a date and a target architecture. Then attestations expire, systems change, and the picture stays true.
The most valuable answer is often which rules do not reach you.
The method behind every engagement.
Determine, discover, assess and remediate — one connected path from your regulatory position to evidence a board can rely on.
Why we can find the AI you did not buy as AI.
An AI inventory is a systems problem before it is a governance problem. Most of the exposure sits inside software nobody procured as AI.
Assurance without the sales agenda.
Ainoteq is deliberately focused on governance and applicability. We don't resell licenses, we take no commission from any AI platform or model provider, and we don't provide an independent opinion on any system we have built — so the advice you get is about what's right for you, not what's easy to bill.
That independence is not a marketing line. Regulators require validators to be independent of development, and the refusals below are how we keep that true.
What actually applies to us?
Your entity, jurisdictions and use cases — resolved to a cited obligation set, including what does not reach you.
What AI are we actually running?
Declared, detected and embedded — including the AI that arrived inside software you already bought.
Where are the gaps?
Controls tested against the evidence you hold, with every finding owned and dated.
How do we stay ready?
Attestations expire, systems change and regulations move. We tell you which of yours a change touches.
Not sure what applies to you?
Tell us about your entity, your jurisdictions and what you are running. We will tell you whether an Applicability Determination is the right first step — no pitch, no obligation.