The Gulf is the most ambitious AI theatre in the world. It is also, measured properly, one of the most fragmented. Not fragmented in the loose sense that countries differ, which is true everywhere, but in the specific sense that a company deploying one system across the six states must satisfy nine separate data-protection rulebooks, six different answers to whether data may leave, and not one binding rule about the AI itself.

I want to be precise about that, because “fragmentation” is usually asserted and rarely counted. What follows is drawn from our GCC AI Regulatory Tracker, where every entry is sourced to the primary instrument it rests on.

Nine rulebooks, six states

Six countries do not produce six regimes. They produce nine, because three of them host financial free zones that legislate their own data protection law inside the national border.

The United Arab Emirates alone runs three: the federal PDPL, the DIFC’s Data Protection Law in Dubai, and the ADGM’s regulations in Abu Dhabi. Qatar runs two, the national PDPPL and the QFC’s regulations. A bank with offices in Dubai and Abu Dhabi is operating under two different privacy regulators in one country, and neither of them is the federal one.

One bloc, sixty-eight places

The second divergence is capability, and it is wider than the first. On the Oxford Insights Government AI Readiness Index, Saudi Arabia ranks 15th in the world and Kuwait 83rd. That is a sixty-eight place spread inside a customs union of six states with a shared language, a shared currency peg and a common market.

The practical consequence is that pan-Gulf AI policy has no natural centre of gravity. A regional standard written to suit the frontier states would be unimplementable in the others; one written to be universally achievable would not bind the states that matter most. That is the real obstacle to harmonisation, and it is rarely named.

Everyone has a data law. Nobody has an AI law.

Here is the finding I did not expect when we built the tracker, and the one I would put in front of any minister in the region. Across all six states, data protection is now in force and enforceable in some form. Across all six states, AI governance is soft law: strategies, charters, ethics principles, policies for the government sector. Not one binding general AI statute exists in the Gulf as of August 2026.

That is not a criticism. There is a defensible case for governing AI through existing instruments and sectoral regulators rather than a horizontal statute, and several serious jurisdictions are making it. But it means something specific for anyone deploying: your AI exposure in the Gulf today is data-protection exposure. The transfer rule, the localisation condition and the lawful-basis question are the binding constraints. The AI ethics charter is not.

The six transfer regimes are where that bites. Saudi Arabia operates a standing Transfer Regulation with localisation pressure in sensitive sectors. Bahrain uses an adequacy whitelist. Oman requires consent plus adequacy. Qatar’s rule is unusually permissive. Kuwait repealed its tiered localisation policy in 2024 and kept disclosure duties. The UAE’s federal transfer articles remain dormant while sectoral localisation binds regardless.

Six states, six architectures, one deployment. That is the tax, and it is paid in legal review rather than licence fees, which is why it rarely appears in a business case.

Enforcement is where the map lies

A regime on paper and a regime in practice are different objects, and the gap between them is the most useful thing in the tracker. Ranked by published enforcement activity, the Gulf looks nothing like it does ranked by legal force.

Two lessons follow. The first is that the DIFC, a jurisdiction of a few square kilometres, is by a wide margin the most active data-protection enforcer in the region. The second is that three states have issued no public decisions at all, which a deploying company should read as latency rather than permission. Oman’s law only became fully enforceable in February 2026. Silence in 2026 is not a forecast for 2027.

What to do about it

The standard response is to wait for harmonisation from above. I think that is the wrong instinct, and slow. The more useful move is to work the problem from below, in three steps.

Map the divergences precisely, and separate the deliberate from the accidental. Some Gulf differences are real policy choices, made for reasons a government can defend: Saudi localisation in sensitive sectors is a sovereignty position, not an oversight. Others are drafting artefacts, where two states wanted the same outcome and reached it through incompatible mechanics. The second category is cheap to reconcile and would signal far more than it costs.

Design deployments that survive the divergence rather than assume it away. That means data residency decided per workload rather than per company, transfer mechanisms selected before architecture is fixed, and a register of which jurisdiction each model and each dataset actually sits in. Retrofitting this after a regulator asks is the expensive path, and I have not seen it done cheaply.

Treat the free zones as the fast lane they are. The DIFC, ADGM and QFC have their own laws, their own regulators and, in the DIFC’s case, a binding rule on autonomous systems that no Gulf national law yet matches. Oman has gone further and created an AI Special Zone outright. For a company that needs regulatory clarity before it needs scale, the zone is often the shortest route to a defensible deployment.

The Gulf’s AI ambition is real, funded and moving faster than any comparable region. Its regulatory plumbing has not kept pace, and the gap is now measurable rather than anecdotal. Closing it is plumbing work: unglamorous, technical, and precisely the kind of hard, multi-objective, deeply institutional problem this Institute was founded to take on.