GCC AI Obligation Register

What every Gulf regulator now requires of enterprise AI.

A cited, versioned index of the instruments in force across the six GCC states. Free to use. Every entry links to the primary source.

Coverage

Jurisdictions

Coverage is tiered by how far we have verified it. We publish the tier so you know what our answer is worth.

Mapped

United Arab Emirates

Federal Decree-Law 45 of 2021 on personal data protection · CBUAE Model Management Standards · CBUAE Guidance Note on consumer protection and the responsible adoption and use of AI and ML (February 2026)

Mapped

DIFC

Data Protection Regulations, Consolidated Version No. 2 — Regulation 10 on personal data processed through autonomous and semi-autonomous systems: deployer and operator obligations, design requirements, forming certification regime

Mapped

Saudi Arabia

Personal Data Protection Law and its Implementing Regulation · SDAIA AI Ethics Principles — four risk tiers, lifecycle controls · SAMA market-risk capital framework, model validation standards

Watched, not heldSDAIA National AI Risk Management Framework — announced July 2026; we have not obtained the document, so we make no claim about what it requires.
Tracked

Qatar

QCB Artificial Intelligence Guideline (September 2024) — held and monitored; the published PDF is a scanned image, so we have not yet summarised its requirements

Watched, not heldNCSA Guidelines for Secure Usage and Adoption of AI.
Tracked

Oman

MTCIT General Policy for the Safe and Ethical Use of AI Systems (April 2025) — published in Arabic only; summaries would be our translation, so none is published yet

Tracked

Bahrain · Kuwait · ADGM

Bahrain — iGA General Policy for the Use of AI (May 2025), binding on government entities, not on private financial institutions · Kuwait — no AI-specific instrument for financial institutions · ADGM — the FSRA Open Regulation AI initiative is an initiative, not a rule

How to read the tiers

We publish what we have verified, and what we have not.

Verified

Counsel-reviewed and applicability rules tested. No jurisdiction carries this tier until that review is done — the tier is earned, not asserted.

Mapped

Instruments held and summarised. Applicability drafted but not counsel-verified. We state the verification step before advising.

Tracked

Instruments listed and monitored for change. No applicability rules yet. We will say so rather than guess.

Most competitors publish only what they cover. We publish the gaps as well, because a register you cannot calibrate is a register you cannot rely on.
What the register is not

An index, not an opinion.

What it does

Points you at the source

Each entry states what an instrument demands, its force, its status, its dates and who it reaches — in our words, with short attributed quotations and a link to the official text.

What it does not do

Tell you whether it applies to you

Applicability depends on your entity, jurisdiction, licence, data and use cases. That determination is a separate, deterministic process — start it with the diagnostic.

NoteAinoteq provides regulatory information and structured analysis. It does not provide legal advice. The official source prevails in the event of any discrepancy.
Run the ten-minute diagnostic