The Gulf is the most ambitious AI theatre in the world. It is also, measured properly, one of the most fragmented. Not fragmented in the loose sense that countries differ, which is true everywhere, but in the specific sense that a company deploying one system across the six states must satisfy nine separate data-protection rulebooks, six different answers to whether data may leave, and not one binding rule about the AI itself.
I want to be precise about that, because “fragmentation” is usually asserted and rarely counted. What follows is drawn from our GCC AI Regulatory Tracker, where every entry is sourced to the primary instrument it rests on.
Nine rulebooks, six states
Six countries do not produce six regimes. They produce nine, because three of them host financial free zones that legislate their own data protection law inside the national border.
The United Arab Emirates alone runs three: the federal PDPL, the DIFC’s Data Protection Law in Dubai, and the ADGM’s regulations in Abu Dhabi. Qatar runs two, the national PDPPL and the QFC’s regulations. A bank with offices in Dubai and Abu Dhabi is operating under two different privacy regulators in one country, and neither of them is the federal one.
Green blocks are financial free zones that legislate their own data protection law inside the national border, with their own regulator and their own appeal route. A company operating in Dubai and Abu Dhabi answers to two privacy regulators in one country, and neither is the federal one.
One bloc, sixty-eight places
The second divergence is capability, and it is wider than the first. On the Oxford Insights Government AI Readiness Index, Saudi Arabia ranks 15th in the world and Kuwait 83rd. That is a sixty-eight place spread inside a customs union of six states with a shared language, a shared currency peg and a common market.
The practical consequence is that pan-Gulf AI policy has no natural centre of gravity. A regional standard written to suit the frontier states would be unimplementable in the others; one written to be universally achievable would not bind the states that matter most. That is the real obstacle to harmonisation, and it is rarely named.
Bars show the underlying index score, not the rank, so the gaps are true to the data. Sixty-eight places separate the top and bottom of a single customs union. Any regional AI standard has to clear that spread, which is why none has been written.
Everyone has a data law. Nobody has an AI law.
Here is the finding I did not expect when we built the tracker, and the one I would put in front of any minister in the region. Across all six states, data protection is now in force and enforceable in some form. Across all six states, AI governance is soft law: strategies, charters, ethics principles, policies for the government sector. Not one binding general AI statute exists in the Gulf as of August 2026.
That is not a criticism. There is a defensible case for governing AI through existing instruments and sectoral regulators rather than a horizontal statute, and several serious jurisdictions are making it. But it means something specific for anyone deploying: your AI exposure in the Gulf today is data-protection exposure. The transfer rule, the localisation condition and the lawful-basis question are the binding constraints. The AI ethics charter is not.
The six transfer regimes are where that bites. Saudi Arabia operates a standing Transfer Regulation with localisation pressure in sensitive sectors. Bahrain uses an adequacy whitelist. Oman requires consent plus adequacy. Qatar’s rule is unusually permissive. Kuwait repealed its tiered localisation policy in 2024 and kept disclosure duties. The UAE’s federal transfer articles remain dormant while sectoral localisation binds regardless.
Six states, six architectures, one deployment. That is the tax, and it is paid in legal review rather than licence fees, which is why it rarely appears in a business case.
Enforcement is where the map lies
A regime on paper and a regime in practice are different objects, and the gap between them is the most useful thing in the tracker. Ranked by published enforcement activity, the Gulf looks nothing like it does ranked by legal force.
Counts are not like for like: the DIFC figure is fine decision notices in 2025, Saudi Arabia’s is violation decisions announced in February 2026, and Qatar publishes no fine amounts. They are placed together because the shape is the finding. The most active data-protection enforcer in the Gulf governs a few square kilometres of Dubai.
Two lessons follow. The first is that the DIFC, a jurisdiction of a few square kilometres, is by a wide margin the most active data-protection enforcer in the region. The second is that three states have issued no public decisions at all, which a deploying company should read as latency rather than permission. Oman’s law only became fully enforceable in February 2026. Silence in 2026 is not a forecast for 2027.
What to do about it
The standard response is to wait for harmonisation from above. I think that is the wrong instinct, and slow. The more useful move is to work the problem from below, in three steps.
Map the divergences precisely, and separate the deliberate from the accidental. Some Gulf differences are real policy choices, made for reasons a government can defend: Saudi localisation in sensitive sectors is a sovereignty position, not an oversight. Others are drafting artefacts, where two states wanted the same outcome and reached it through incompatible mechanics. The second category is cheap to reconcile and would signal far more than it costs.
Design deployments that survive the divergence rather than assume it away. That means data residency decided per workload rather than per company, transfer mechanisms selected before architecture is fixed, and a register of which jurisdiction each model and each dataset actually sits in. Retrofitting this after a regulator asks is the expensive path, and I have not seen it done cheaply.
Treat the free zones as the fast lane they are. The DIFC, ADGM and QFC have their own laws, their own regulators and, in the DIFC’s case, a binding rule on autonomous systems that no Gulf national law yet matches. Oman has gone further and created an AI Special Zone outright. For a company that needs regulatory clarity before it needs scale, the zone is often the shortest route to a defensible deployment.
The Gulf’s AI ambition is real, funded and moving faster than any comparable region. Its regulatory plumbing has not kept pace, and the gap is now measurable rather than anecdotal. Closing it is plumbing work: unglamorous, technical, and precisely the kind of hard, multi-objective, deeply institutional problem this Institute was founded to take on.