Comparison
Gulf banking AI rules, side by side
Qatar, Saudi Arabia, UAE, compared on the same dimensions, each against the EU AI Act baseline. For an institution operating across more than one of these markets, the useful question is not what each regime says but where they diverge.
Qatar
Four separate QCB approval gates stand between a Qatari bank and a live high-risk AI system, which amounts to a pre-authorization regime.
Binding
Primary source · verified September 1, 2026
Saudi Arabia
There is no SAMA AI rulebook. SDAIA's instruments reach banks through a 2021 SAMA circular.
Indirect
Absence not conclusively verified · verified August 31, 2026
United Arab Emirates
The CBUAE Guidance Note is voluntary on its face and examinable in practice.
Supervisory expectation
Primary source · verified August 31, 2026
How to read this grid
Three of 17 dimensions below are covered for all three jurisdictions. Not analyzed means exactly that: the dimension has not yet been worked through for that jurisdiction. It never means no requirement exists. Where a regime genuinely imposes nothing, the cell says so in words.
| Dimension | Qatar | Saudi Arabia | UAE |
|---|---|---|---|
| Risk tiers and who assigns them | A mandatory floor of three categories at §9.7. Two track Annex III closely enough that an EU mapping largely carries over. Already covered by EU work | No risk tiering binding on banks was identified as of August 31, 2026. The draft Responsible AI Policy is reported to propose four levels (critical, high, limited and low), a structure close enough to the EU model that an existing EU classification would largely survive the mapping. EU is stricter | No statutory list. The institution rates the risk of each AI system itself under §8(d), and the inventory duty under §2(f) covers all AI models and systems regardless of rating. Extends EU work |
| Recurring disclosure to the supervisor | The full Register goes to the QCB annually and on request, with the high-risk criteria used and a risk and impact assessment. No EU equivalent | No registration duty binding on banks was identified as of August 31, 2026. The draft policy is reported to propose mandatory registration for certain AI applications, which would be a new duty for private institutions rather than a transfer of EU work. Does not map | Neither regime requires it. The inventory duty under §2(f) is internal, and the Guidance Note does not require it to be filed with the CBUAE on any cycle. This dimension has been assessed and found empty on both sides. Does not map |
| When it bites | In force since 4 September 2024 under §1, roughly three years ahead of the EU timetable. | Neither identified as of August 31, 2026. A search of the SAMA Rulebook and of English-language secondary reporting found no AI-specific instrument binding on banks and no AI-specific compliance date. SDAIA has issued AI-specific guidance, but it was not confirmed against primary Arabic-language sources for this entry and is not addressed to banks. What does bind are the data protection and cybersecurity obligations reaching banks through SAMA Circular 43045328, in force since 2021 and examinable now. | Guidance is live now and shapes what examiners ask in the current supervision cycle. There is no transition period because there is no new binding rule to transition to. |
| What falls inside the regime2 of 3 | §9.7.3 makes processing sensitive personal information a mandatory high-risk trigger in its own right, so systems an EU mapping leaves outside the perimeter fall inside it here. No EU equivalent | No sector-specific AI instrument binding on banks was identified as of August 31, 2026, in a search of the SAMA Rulebook and of English-language secondary reporting. Requirements arrive through data protection and cybersecurity frameworks that were not written with AI systems in mind. Does not map | Not analyzed |
| Regulator sign-off before launch2 of 3 | Four separate QCB approval gates: training, validation and testing results for any new high-risk system (§14.1); high-risk AI procurement before contract signature (§11.2); launch as Provider or material modification (§11.1); and any fully autonomous system whatever its risk rating (§13.5.1, §13.6.1). No EU equivalent | Not analyzed | Neither regime requires it. The Guidance Note contains no approval gate: nothing requires the CBUAE to see or approve an AI system before it is deployed, or before a vendor contract is signed. This dimension has been assessed and found empty on both sides. Does not map |
| Vendor diligence and contracts2 of 3 | §15.1 expects the Provider to supply development, testing and performance data by contract, and §15.2 requires the Entity to make that full range of data available to the QCB. No EU equivalent | Not analyzed | Annual cybersecurity reviews of procured AI by independent qualified third parties, documented procurement justification, contractual audit and information rights, and an explicit expectation to avoid single-vendor concentration. No EU equivalent |
| Bias testing2 of 3 | §15.7 prescribes the method: test the model on different demographic groups to see whether any group is systematically advantaged or disadvantaged. Extends EU work | Not analyzed | Explicit cadence: once a year, and again on any upgrade, material change, or new model. Extends EU work |
| Internal register of AI systems1 of 3 | Not analyzed | Not analyzed | An inventory of every AI model, system or technology developed or deployed, with name, purpose and risk rating as minimum metadata. No EU equivalent |
| Provider and deployer roles1 of 3 | §14.3 is a close analogue: a User that materially changes an AI Model with a view to placing it on the market under its own name or trademark is considered a Provider. §2 adds that a substantially modified system is a new system, ending the previous life cycle. Already covered by EU work | Not analyzed | Not analyzed |
| Concentration and exit planning1 of 3 | The register must rate each high-risk vendor system's substitutability as easy, difficult or impossible and name an alternate provider, with contracts carrying data-wipe exit clauses and a QCB audit right over the provider. No EU equivalent | Not analyzed | Not analyzed |
| Human oversight1 of 3 | Not analyzed | Not analyzed | Three named operating modes, applied across consumer-facing AI, with the fully autonomous mode confined to low-risk non-material processes. Substantively close to Article 14, applied to a wider set of systems. Already covered by EU work |
| Limits on autonomous operation1 of 3 | Fully autonomous high-risk systems need built-in guard rails the AI cannot override, reviewed on schedule or on external volatility spikes, with limits linked to warning levels or auto-close routines. Drafted with algorithmic trading in view. Extends EU work | Not analyzed | Not analyzed |
| Security controls1 of 3 | Named and testable: attack surface examination, protection against integrity attacks, query attacks and prompt injection, a data loss prevention tool, and content anomaly detection. Extends EU work | Not analyzed | Not analyzed |
| Disclosure to customers1 of 3 | Not analyzed | Not analyzed | Plain-language, accurate disclosures in Arabic and English, with telephone support in the major languages of the UAE, and a duty to check understandability. No EU equivalent |
| Contestability and recourse1 of 3 | §21.2 requires a two-choice process: supply data to alter the system and resubmit, or request human review. The resubmission limb has no EU analogue. Extends EU work | Not analyzed | Not analyzed |
| Underlying data protection regime1 of 3 | Not analyzed | The Personal Data Protection Law, reaching supervised financial institutions through SAMA Circular 43045328. Different text, similar function: it is the binding floor under any AI system processing personal data. Already covered by EU work | Not analyzed |
| Waivers and exemptions1 of 3 | §23 provides a formal route: request a waiver from a specific requirement with a documented business case, subject to QCB approval, recorded with an expiration date. No EU equivalent | Not analyzed | Not analyzed |
Each cell states what the jurisdiction requires; the tag says how that compares with work already done for the EU AI Act. Full EU-side wording, clause citations and primary sources are on the individual entries. This comparison is provided for informational purposes and does not constitute legal advice.
Operating across more than one of these markets?
The divergences above are where multi-market institutions lose time: one AI system, three supervisors, three different answers about what evidence is required. The Diagnostic maps your systems against every market you serve and returns the gaps in priority order.
Request the Diagnostic