What Qatar and Saudi Arabia Already Expect from AI Governance
Qatar Central Bank has a binding AI Guideline in force since September 2024. Saudi Arabia governs AI agents through existing cybersecurity frameworks instead. The distinction matters for anyone deploying agents in Gulf financial institutions.
When people talk about AI regulation, the conversation usually goes straight to Brussels. The EU AI Act gets the headlines, and many companies still behave as if serious governance requirements are something to prepare for later.
That is a risky assumption in the Gulf, particularly for financial institutions.
Qatar has already put specific AI obligations in front of QCB-licensed entities. Saudi Arabia is taking a different route, using existing cybersecurity and risk frameworks to shape how institutions should govern AI systems. The two approaches are not interchangeable, but both point to the same conclusion: regulated companies need evidence of how AI is being used, what it is allowed to do, and who remains accountable when something goes wrong.
Qatar: a specific AI guideline for regulated institutions
The Qatar Central Bank issued its Artificial Intelligence Guideline on 4 September 2024. It applies to QCB-licensed entities that develop, procure, outsource, operate, or provide AI systems. It is not simply a voluntary set of principles.
The guideline covers board and senior-management accountability, AI governance, an AI register, risk classification, human oversight, data governance, security, documentation, monitoring, and customer transparency. High-risk AI systems require prior QCB approval, including relevant training, validation, and testing information.
For a bank or fintech experimenting with autonomous agents, those requirements have immediate operational consequences.
An AI register cannot remain a list of model names in a policy document. It needs to reflect the systems actually operating in the business: the agents, the tools they can call, the data they can access, and the actions they can take.
Human oversight also has to mean more than saying that a person is "in the loop." If an agent wants to move money, change a customer record, approve an exception, or access sensitive information, the institution needs a defined process for deciding when a human must review the action and what happens while that review is pending.
The same is true of monitoring and documentation. A regulated firm needs to reconstruct what an agent attempted, which policy applied, whether the action was allowed or stopped, and what evidence supports that decision. Retrospective screenshots and manually assembled reports are a weak foundation for that control.
Qatar's message is direct: AI governance belongs inside the institution's operating model, risk processes, and accountability structure now.
Saudi Arabia: existing cybersecurity obligations still apply
Saudi Arabia's position needs to be described precisely.
SAMA has not published an AI-specific guideline that mirrors Qatar's QCB document. Saudi institutions do have the mandatory SAMA Cyber Security Framework, alongside broader expectations around technology risk, operational resilience, data protection, and control effectiveness.
The practical question is not whether an older framework uses the phrase "autonomous AI agent." It is whether an institution can reasonably argue that a system capable of making decisions, calling APIs, handling customer data, or triggering operational actions falls outside its existing security and risk controls.
That argument will become increasingly difficult to sustain.
A Saudi bank or fintech evaluating agentic systems still has to consider access control, segregation of duties, data handling, third-party risk, logging, incident response, change management, and accountability. AI does not remove those obligations. In some cases, it makes the control problem harder because an agent can act across multiple tools and make decisions at machine speed.
That differs from Qatar. Qatar has a named AI guideline with specific approval, registration, human-oversight, and audit-reporting requirements. Saudi institutions are more likely to begin by mapping AI use cases to existing cybersecurity and technology-risk obligations, while watching for more explicit supervisory guidance.
Blurring those situations into a single claim that "the GCC now has AI regulation" makes for a good headline, but it is poor compliance analysis. The distinction matters to anyone buying or implementing governance infrastructure.
What this means in practice
A regulated institution does not only need to know whether an AI model is accurate. It needs to know what the system can do after deployment. Which actions are permitted? Which require approval? What happens when a prompt attempts to override policy? How are API permissions, personal data, spending limits, and sensitive workflows controlled? Can the institution produce reliable evidence for an auditor or regulator without reconstructing events by hand?
That is the gap between model governance and agent governance.
Model governance focuses heavily on the model: its training, testing, performance, bias, and explainability. Agent governance must also deal with the actions around the model. An agent may be technically impressive and still be unsafe if it can access the wrong system, exceed its authority, expose personal information, or take an irreversible action without review.
Qatar gives compliance teams a specific AI framework to map against. Saudi Arabia gives them a strong reason to apply existing cybersecurity and technology-risk controls to new AI capabilities before those capabilities become embedded in production workflows.
In both markets, a credible governance programme needs three things: visibility into the agents actually running, controls that can intervene before a risky action executes, and evidence that shows what happened.
At Gateplex, we provide that operational control layer. Gateplex evaluates agent actions against configurable policies before execution and returns an ALLOW, FLAG, or BLOCK verdict, with an audit record for the decision. Our 30-day Shadow Compliance Audit is designed to run alongside existing agent traffic and identify policy gaps, risky action patterns, per-agent risk, and missing evidence.
The regulatory details differ between Doha and Riyadh. The direction is similar. Institutions deploying AI agents will increasingly be expected to demonstrate control, not merely describe their intentions.
The window question
The EU AI Act's Annex III obligations apply from December 2027, more than a year out. Qatar's requirement is already live. That gap between "developing" and "already in force" is not a small detail. It is the difference between a regulatory story we tell to create urgency and a regulatory fact a compliance officer at a QCB-licensed institution is already living with today.
Sources
- Qatar Central Bank, "Artificial Intelligence Guideline," issued September 4, 2024, Annex 160 to the QCB Instructions to Banks 2024: annex160.pdf
- Regulations.AI, "Qatar Central Bank Artificial Intelligence Guideline for QCB-licensed Entities," published June 13, 2026: RAI-QA-NA-QCBAIXX-2024
- Qatar Central Bank, Annual Report 2024, published October 28, 2025: QCB Annual Report 2024
- Saudi Central Bank, "Cyber Security Framework," issued May 24, 2017, status in force: SAMA Rulebook
- Gateplex, product and deployment information, accessed August 24, 2026: gateplex.ai