“Not applicable” is an answer
Ask most enterprises which AI rules bind them and you get one of two replies: a shrug, or a list of everything anyone has ever published. Both are expensive. The first delays the programme; the second builds it at three times the size it needs to be.
There is a reason for the shrug. Applicability in the Gulf is not a property of a company — it is a property of a legal entity, in a jurisdiction, holding a licence, doing a particular thing with particular data. A group with a mainland UAE trading arm, a DIFC-licensed advisory business and a Saudi joint venture does not have one obligation set. It has three, and they overlap only partly.
Why the safe answer is the expensive one
Faced with that, the defensible-looking move is to apply the strictest requirement everywhere. It feels conservative. In practice it means building model validation for systems nobody supervises, writing registers nobody will read, and appointing roles the entity does not need — while the one obligation that genuinely bites goes unnoticed, because it was buried in a list of forty.
An obligation set you cannot justify line by line is not a compliance position. It is a budget.
What a determination has to produce
A determination is worth something only if every line carries the clause that puts it there, and if it is willing to say no. Four outcomes, not two: applicable, with the trigger; conditionally applicable, with the condition stated plainly, so you know what would change the answer; not applicable, with the reason; and watchlist, for what is proposed but not yet in force.
The third of those is the one that saves money, and it is the one nobody wants to sign. Telling a client that a rule does not reach them is a position you have to be prepared to defend to their regulator. That is precisely why it is worth paying for, and why it cannot be produced by a model that infers an answer from patterns. Applicability is deterministic or it is worthless.
The order matters
Discovery before determination sounds sensible — find the systems, then work out the rules. It is backwards. Which questions are worth asking about a system depends on which obligations reach the entity that runs it. Start from the obligations and the inventory scopes itself. Start from the inventory and you catalogue everything, learn nothing, and still have to do the determination afterwards.