Reference
AI Regulation Tracker
One entry per jurisdiction and sector. What applies, what it rests on, who supervises it, and what to do first.
Every entry carries a verification date and its primary sources. Each one also carries the dimension most sources leave out: for an institution that has already built to the EU AI Act, what this jurisdiction adds, what it drops, and what it asks for differently.
Comparison
Gulf banking AI rules, side by side →
UAE, Qatar and Saudi Arabia on the same dimensions, each against the EU AI Act baseline. For multi-market institutions, the divergences are the whole question.
Four entries
Qatar · Banking and financial services
Four separate QCB approval gates stand between a Qatari bank and a live high-risk AI system, which amounts to a pre-authorization regime.
United Arab Emirates · Banking and financial services
The CBUAE Guidance Note is voluntary on its face and examinable in practice.
Morocco · Cross-sector
No AI statute. Law 09-08 already governs AI processing of personal data, and the CNDP has said so in its own words.
Saudi Arabia · Banking and financial services
There is no SAMA AI rulebook. SDAIA's instruments reach banks through a 2021 SAMA circular.
What the delta labels mean
- Already covered by EU work
- An EU AI Act or GDPR program satisfies this dimension as built.
- Extends EU work
- The EU program is the right foundation but this jurisdiction requires more on this dimension.
- No EU equivalent
- This jurisdiction imposes something the EU regime does not, requiring new work.
- EU is stricter
- The EU regime imposes more on this dimension than this jurisdiction does.
- Does not map
- The two regimes cannot be compared on this dimension, because what sits on one or both sides is unadopted, undated, or otherwise not yet a thing to compare against. Not to be used where one side simply imposes nothing and the other imposes something clear: that is EU is stricter.
How entries get added
An entry is published when the underlying research has already been done for client work, and when every requirement on it has been read in the issuing authority’s own text or explicitly marked as resting on secondary reporting. Nothing is drafted speculatively. A thin tracker that is right is worth more than a complete one that is not.
Findings that something does not exist are handled two ways, because they are two different claims. An absence inside a document read cover to cover is a positive finding about that document, and it is stated plainly. An absence across a jurisdiction’s whole body of law is a claim about the completeness of a search, which no citation can settle, so it is scoped on the page to what was searched and when.
Each entry shows the date its sources were last checked, and every entry is reviewed at least quarterly. An entry is also re-verified when an instrument it cites is known to have changed. Where a claim rests on secondary reporting, or on the absence of a finding rather than the presence of one, the entry says so at the top rather than in a footnote.
The tracker tells you what applies. The Diagnostic tells you what you’re running.
The Diagnostic maps your AI systems against the requirements in the markets you serve, and returns the gaps in priority order with the evidence a supervisor would ask for.
Request the Diagnostic