AI Governance Gaps in the Middle East
Last updated: 2026-08-15
AI governance in the Middle East has three recurring gaps: strategies that announce capability without an operating budget, procurement rules that were written for software rather than for systems that learn, and evaluation conducted in Modern Standard Arabic rather than in the dialects people actually use. Gulf and Levant states face these from very different starting positions.
Where AI governance in the Middle East is thin, how Gulf and Levant governments face different problems, and what inclusive AI governance means for the region.
AI Governance Gaps in the Middle East
Regional AI policy discussion tends to treat the Middle East as one market. It is not one market, and the governance problems differ so sharply between its parts that a single regional prescription helps almost nobody.
Three gaps that recur across the region
Strategy without an operating budget. National AI strategies are commonly announced with a capital figure attached: a data centre, a compute partnership, a national model. What is far rarer is a five-year operating cost covering power at realistic prices, hardware refresh, security operations, and staff at market rather than public-sector rates. Capital is funded easily. Year four is not. The five-year cost model structure sets out the lines that get omitted.
Procurement rules written for software. Most public procurement frameworks in the region were designed for systems whose behaviour is fixed at delivery. AI systems change when the vendor updates a model, and their performance depends on data the buyer supplies. Frameworks that lack a right to evaluation on the buyer's own data, a defined position on where inference happens, and a withdrawal clause leave the institution governing by hope after signature. Since most AI entering regional public administrations is bought rather than built, this gap matters more than any model development ethics debate.
Evaluation in the wrong Arabic. Systems are commonly evaluated in Modern Standard Arabic and deployed to populations who write and speak Levantine, Gulf, Egyptian, or Maghrebi varieties, frequently mixed with English or transliterated into Latin script. Reported accuracy is then an upper bound rather than an expectation. This is treated as a quality issue when it is a governance issue: a system that cannot understand a citizen excludes them from the service behind it.
Gulf and Levant: different problems, different sequences
The two contexts require different first moves, and copying between them produces waste in one direction and paralysis in the other.
Gulf states generally have capital, procurement capacity, and ambition to build sovereign capability. Their binding constraint is rarely money and usually institutional: decision rights over AI use are unsettled, evaluation capability lags acquisition, and the pace of adoption outruns the assurance function. The productive sequence there is governance first, so that capability already being acquired is subject to a decision process that exists.
Levant states, several rebuilding public administration after conflict or under severe fiscal constraint, face the opposite. Capability is being procured with limited assurance capacity, often donor-funded, and frequently with the vendor holding both the system and the expertise to evaluate it. The productive first move is not a national AI strategy but procurement discipline: a vendor assurance question set applied before contract, and a data residency position that is decided rather than inherited. The AI vendor assurance question set is written for precisely this asymmetry.
What travels between the two is not a strategy document but a method: decide which sovereignty layers must be held, which can be shared, and which dependencies are accepted deliberately. That is the argument of the sovereignty control ladder.
What inclusive AI governance means here
"Inclusive" in regional AI discussion is often read as consultation. The harder and more consequential reading is about who the systems work for.
Language inclusion is service inclusion. A public service delivered through a system evaluated only in Modern Standard Arabic works less well for the people least likely to have alternatives. Dialect coverage is not a refinement to add later; it determines who can use the service at all.
Non-citizens are inside the scope. The region hosts very large refugee and migrant populations who interact with public and humanitarian systems while having minimal standing to contest a decision. Governance that considers only citizens omits the group carrying the highest consequence from error. What that implies for design is set out in AI for humanitarian organisations.
Appeal routes are the test. The practical measure of inclusive governance is not whether a strategy mentions fairness, but whether a person affected by an automated decision can find out that a system was involved, and challenge the outcome with a named human. Very few regional frameworks currently establish that.
Where a government should start
Not with a strategy document. Start by establishing what AI is already running inside the administration, which almost always exceeds expectations because procured systems arrive embedded in wider products. Then attach decision rights and a consequence tier to each. Then apply assurance to what is being bought. A strategy written before that inventory exists describes an institution that does not match the one issuing it.
The regional context around this is on AI governance in the Arab region, and the general framework on public sector AI governance.
Written by Shahzad Asghar, Head of Data and Digital Solutions at UNESCWA. See all articles, the playbooks, and the templates.