Empowering

Global

Talent

MG Consulting Group

Key Takeaways

  • AI governance for GCC HR functions is not one framework — it’s six regulatory stacks at six different stages of maturity, and they interact every time an HR system crosses a border or processes data in a shared service centre.
  • The binding obligations are already live. Saudi Arabia’s SDAIA is actively enforcing, the UAE now has its first functioning AI supervisory authority, and Qatar’s Central Bank rules carry real penalties for financial sector employers.
  • Employment-related AI systems — hiring algorithms, performance analytics, attrition models, employee monitoring tools — are classified as high-risk in every GCC jurisdiction with AI governance guidance. That classification mandates documentation, human oversight, and bias-testing requirements before deployment, not after.
  • Vendor compliance isn’t organizational compliance. Every GCC framework places due diligence obligations on the deploying entity. An ATS that produces a discriminatory shortlist creates liability for the organization that deployed it, not just the vendor that built it.


    GCC AI Governance Policies

    Your CTO just approved an AI-powered applicant tracking system that screens résumés, ranks candidates, and schedules interviews. The vendor said it’s fully compliant. Your CEO wants it live next month.

    Then you read that Saudi Arabia’s SDAIA launched a National AI Risk Management Framework on July 14, 2026. The UAE consolidated its AI and data regulators into a single Cabinet-level authority on June 14. Qatar’s Central Bank requires documented risk assessments for any AI used in hiring decisions by licensed financial institutions.

    The main point here? It is that the gap between “we bought it” and “we are allowed to use it” is widening across the GCC. 

    AI governance compliance is not a layer to add after procurement. It belongs in the procurement decision, the vendor contract, and the HR operating model — before deployment, not after a regulator asks for documentation that doesn’t exist. 

    This article maps the AI governance policies that directly affect HR functions in every GCC state, what they specifically require of HR leaders, where to find the documents, and how likely they are to change.

Why HR Is a High-Risk AI Use Case by Default

In every GCC jurisdiction with AI governance, employment-related AI systems are classified as high-risk because they affect individuals’ economic circumstances, legal rights, and career trajectories.

This includes applicant tracking systems that auto-screen résumés, video interview analyzers that assess tone and facial expressions, predictive attrition models that flag flight risks, performance management tools that recommend promotions, and internal chatbots that handle grievances or benefits queries.

What this classification triggers depends on the country, but the pattern is consistent: 

  • Mandatory AI Ethics Impact Assessments before deployment (Saudi Arabia)
  • Board-level accountability and annual bias testing (UAE financial sector)
  • Pre-deployment approval gates and documented risk assessments (Qatar financial sector)
  • Human-in-the-loop review for every AI-influenced employment decision (all jurisdictions with guidance)
  • Documented explainability for any AI-influenced rejection, promotion, or performance rating

Now, there is a misconception that vendor compliance equals organizational compliance. It does not. 

Every framework places due diligence obligations on the deploying entity. And the documentation the regulators are beginning to request — Impact Assessments, model inventories, bias testing results, human review protocols — lives in the HR function. 

And that also includes accountability when these are missing.

So if, for example, your ATS algorithm produces a discriminatory shortlist, you are the one regulators hold accountable, not just the vendor.

Saudi Arabia is the most immediate illustration of what that accountability looks like when a regulator is actively looking for it.

Saudi Arabia — The Most Mature Framework

SDAIA issued 48 confirmed PDPL violation decisions during 2025, confirmed by IAPP and Clyde & Co from SDAIA’s official announcement. 

The four violation categories those decisions covered — unlawful data processing, unauthorized disclosure, failure to implement technical and organizational safeguards, and non-consensual marketing communications — are all live risks in an AI-enabled HR function. 

Most HR tech stacks carry at least one of them.

Saudi Arabia’s AI governance framework is the most actively enforced in the GCC and the fastest-moving. Two significant instruments arrived in 2026 alone:

    • SDAIA AI Ethics Principles: Classifies AI systems into four risk tiers. HR systems (hiring algorithms, performance management tools, workforce analytics platforms) typically fall into the high-risk category.
    • National AI Risk Management Framework, SDAIA-P145: A unified national methodology for identifying, assessing, treating, and monitoring AI risks across the full system lifecycle. Applies to public and private entities. Establishes a four-stage risk cycle: context and scope definition, risk identification and assessment, risk treatment, and continuous monitoring and review.
  • Personal Data Protection Law (PDPL): The foundation for PDPL HR compliance across the Kingdom. Governs automated profiling of employees and candidates, cross-border data flows, and sensitive data processing including biometric and health data.
  • Generative AI Guidelines: Covers large language models used in HR chatbots, internal helpdesks, and document generation tools.

What HR leaders must do:

Requirement What it means in practice
AI Ethics Impact Assessment Document the AI system’s purpose, data sources, model owner, risk rating, testing results, known limitations, and monitoring plan before deployment
Fairness and bias mitigation Test hiring algorithms for discriminatory outcomes across gender, nationality, and other protected categories. Maintain documented evidence
Transparency and explainability Be able to explain the logic behind any AI-influenced rejection, promotion, or performance rating. Black-box systems are non-compliant
Human oversight High-risk systems require a human-in-the-loop review step. Fully automated employment decisions without human intervention carry unacceptable risk under the framework
Responsible AI Officer Appoint a designated officer accountable for AI ethics compliance within the organization
Model documentation and logging Maintain model cards, dataset records, and decision audit trails throughout the system lifecycle

Non-compliance penalties: PDPL fines up to SAR 5 million for general violations; up to SAR 3 million plus two years’ imprisonment for violations involving sensitive personal data. Non-compliance can also trigger loss of government contract eligibility and escalation to sectoral regulators.

Where to access the documents: SDAIA website — AI Ethics Principles, SDAIA-P145 Risk Management Framework, Generative AI Guidelines; National Data Management Office (NDMO) — data classification standards and governance frameworks.

Will it change? Consistently and quickly. Saudi Arabia designated 2026 the Year of Artificial Intelligence. SDAIA-P145 is weeks old. Expect annual updates, sector-specific addenda for employment AI, and a dedicated AI statute that will bring binding legal force to frameworks currently classified as guidance.

The intersection of AI governance and workforce structure in Saudi Arabia is particularly concentrated because Saudization and workforce localization requirements already constrain how HR leaders build their teams. Algorithmic compliance on top of nationalization targets means Saudi HR functions now operate under dual regulatory pressure — one framework governing who they can hire, another governing how any AI system involved in that decision must be documented and monitored.

UAE — A Layered Regime Consolidating Fast

Saudi Arabia’s enforcement is established. The UAE’s is just beginning.

For four years, the UAE’s Personal Data Protection Law existed without an active enforcement engine. The Federal Authority for Artificial Intelligence and Data, established by Cabinet on June 14, 2026, changed that. 

The Authority consolidates three previously separate bodies — the UAE AI Office, TDRA’s digital government sector, and the Emirates Data Office — under a single Cabinet-level regulator. 

Critically, the Emirates Data Office had never become fully operational before the consolidation; June 14 is the first time the UAE PDPL has had an unambiguous, active supervisory authority for the private sector.

The PDPL — in force since 2022 but largely unenforced in the private sector — now has an institutional home with a clear enforcement mandate. Implementing Regulations haven’t been published yet, but the body now exists to publish and enforce them. 

Organizations that have been deferring UAE compliance on the assumption that enforcement was unclear should revisit that position.

The policy stack:

  • Federal Decree-Law No. 45/2021 on Personal Data Protection: The binding data protection layer, covering all employee and candidate data processing.
  • Federal Authority for Artificial Intelligence and Data (June 2026): The new unified federal regulator for AI oversight, data governance, and digital government.
  • UAE Charter for AI (2024): Twelve non-binding principles shaping procurement expectations and setting the baseline that binding regulations will build from.
  • CBUAE Guidance Note on AI/ML (February 23, 2026): Applies to all licensed financial institutions in the UAE. Published directly in the CBUAE Rulebook, it carries strong supervisory expectation despite guidance-level framing.
  • DIFC Regulation 10: Governs autonomous and semi-autonomous systems processing personal data within DIFC. The Commissioner has already enforced it. A 30-day consultation on Regulation 11 — which would empower the Commissioner to recognise AI accreditation and certification schemes — closed on July 18, 2026. Binding regulations are expected before the end of 2026.

What HR leaders must do:

Requirement What it means in practice
Board-level accountability CBUAE-licensed firms must have board-level accountability for all AI/ML systems. HR leaders must report AI-influenced employment metrics to the board
AI model inventory Maintain a complete inventory of all AI systems by name, purpose, and risk rating — including every HR tech vendor using AI in their platform
Annual bias testing Mandatory for financial institutions. Test HR systems annually or on any material model change for discriminatory outcomes
Human review of AI decisions AI-generated employment decisions must be subject to documented human review
Kill-switch capability Organizations must be able to cease an AI system immediately if it produces harmful or biased outcomes
Third-party vendor due diligence Auditing vendor compliance is an organizational obligation — vendor certification alone doesn’t satisfy it
Arabic and English disclosure Where AI influences employment decisions, disclosure requirements apply in both languages

Non-compliance consequences: CBUAE supervisory action for financial institutions, including licensing restrictions. DIFC enforcement through thematic reviews, with an active enforcement record. Loss of government and semi-government contract eligibility across the UAE.

Where to access the documents: CBUAE Rulebook — Guidance Note on AI/ML; DIFC Data Protection Commissioner — Regulation 10 and Consultation Paper No. 3 of 2026 on the proposed Regulation 11.

Will it change? The June 2026 consolidation is a foundation, not a ceiling. DIFC’s Regulation 11 consultation closed July 18, 2026 — binding AI accreditation requirements for DIFC entities are expected before the end of 2026, and a federal horizontal AI statute is probable within 12 to 18 months. For HR leaders, the more immediate pressure is the convergence of AI governance and Emiratisation: the labor law compliance risks in the UAE already carry real penalty exposure — when AI systems influence who gets hired or promoted in a firm subject to the 10% Emiratisation target, that exposure compounds.

Qatar, Bahrain, Kuwait, and Oman — The Spectrum from Binding to Emerging

The four remaining GCC states sit at four different points on the AI compliance Middle East maturity spectrum. Qatar has binding sector-specific rules in force. Bahrain has a standalone AI law pending enactment. Oman enacted its national AI policy in April 2025. Kuwait is in the strategy phase. The compliance urgency differs accordingly.

Qatar — binding for the financial sector

The Qatar Central Bank AI Guidelines (September 2024) are currently the most technically demanding binding AI instrument among the smaller GCC states. 

For QCB-licensed financial institutions, they require pre-deployment approval gates for high-risk AI systems, documented risk assessments, human review of AI-influenced employment decisions, and annual bias testing. 

For HR leaders at QCB-licensed institutions who haven’t mapped their hiring AI systems to these guidelines: the guidance doesn’t ask for intent to comply. It asks for documented evidence that compliance exists. A broader horizontal AI law covering non-financial sector employers is probable within 12 to 24 months.

Bahrain — pending legislation, immediate financial sector precedent

A 38-article AI Regulation Law was approved unanimously by Bahrain’s Shura Council in April 2024 and remains under review by the Council of Representatives as of July 2026. 

If enacted, it would introduce the region’s first standalone AI-specific criminal penalties — fines up to BD 2,000 and up to three years’ imprisonment for violations. 

The General Policy for the Use of AI (Version 1.0, May 2025) is already binding for government entities. Financial sector HR leaders in Bahrain waiting for the Council of Reprlesentatives vote are already behind — Central Bank precedent for AI risk assessment has been set, and precedent in the GCC tends to accelerate enactment rather than wait for it. Access: Central Bank of Bahrain.

Oman — frameworks just becoming enforceable

Oman’s National AI Policy entered into force on April 9, 2025, establishing a governance framework for the development and use of AI systems. 

The Personal Data Protection Law came into full effect on February 5, 2026. Both frameworks are new, and implementation guidance is still emerging. 

HR leaders in Oman are at the start of a compliance build, not the end. Monitor developments at the Ministry of Transport, Communications and IT (MTCIT).

Kuwait — strategy, no binding statute yet

Kuwait’s National AI Strategy 2025–2028 sets direction but hasn’t produced binding AI-specific regulation yet. The PDPL came into full effect February 26, 2025, but currently applies only to CITRA-licensed organizations. 

Kuwait is the lowest immediate compliance pressure in the GCC for most HR leaders — but the Strategy explicitly warns of bias, discrimination, and privacy risks from weak AI governance. Binding regulation is anticipated between 2027 and 2028.

The compliance requirements differ across all six states — but eight questions apply regardless of which jurisdiction an HR function operates in, and an inability to answer any of them represents active regulatory exposure.

The Cross-Cutting Compliance Checklist for HR Leaders

Before any AI system touches an employment decision — hiring, performance evaluation, promotion, or termination — an HR leader in the GCC should be able to answer these eight questions.

  1. Risk classification Does the system affect employment status, compensation, or career progression? If yes, assume high-risk classification across all GCC frameworks with AI governance guidance.
  2. Jurisdiction mapping Which GCC countries does the system operate in? Saudi and UAE rules may both apply simultaneously if the organization runs cross-border shared services or processes data from both markets on a single platform.
  3. Vendor due diligence Does the vendor provide model cards, bias testing results, and data processing agreements? Without these, demonstrating compliance to a regulator becomes the organization’s problem alone.
  4. Documentation readiness Can the HR function produce an AI Ethics Impact Assessment (Saudi Arabia), an AI Model Inventory (UAE financial sector), or a documented risk assessment (Qatar) if requested today? The gap GCC regulators most consistently find in HR functions is documentation — evidence that systems were assessed before deployment, not after a compliance question arrived.
  5. Human oversight protocol Is there a documented human review step for every AI-influenced employment decision? Is the reviewer trained to identify and override algorithmic bias — or is the review a formality?
  6. Candidate and employee disclosure Are candidates and employees informed that AI is used in decisions affecting them? Where required, is the disclosure available in Arabic?
  7. Kill-switch readiness Can the organization deactivate the AI system within 24 hours if it produces biased or harmful outcomes? Is there a documented escalation path that doesn’t depend on the vendor’s responsiveness?
  8. Data governance Does the AI system comply with local PDPL requirements in every jurisdiction it operates? Where is candidate and employee data stored and processed — and does that location trigger cross-border transfer obligations?

For organizations operating across multiple GCC jurisdictions, some HR leaders find it more efficient to bring in external HR consultancy support for the initial compliance mapping phase — particularly where the same AI system needs to satisfy SDAIA, CBUAE, and DIFC requirements simultaneously. 

A single cross-jurisdictional framework is significantly more defensible than three separate ad-hoc compliance reviews.

What to Do Next

The eight questions above reveal where the gaps are. The steps below close them.

Start with the inventory Audit every AI-enabled tool in the HR tech stack — ATS platforms, video interview analyzers, performance management systems, employee chatbots, predictive attrition models. For each one, document the vendor, the stated purpose, the data processed, and the countries of operation. Without a complete inventory, every subsequent step is guesswork.

Risk-rate everything you find Using the frameworks above, classify each system. Anything affecting hiring, promotion, performance evaluation, or termination qualifies as high-risk in Saudi Arabia and is likely high-risk in every other GCC jurisdiction with guidance. Flag anything that can’t immediately produce bias testing results or model documentation.

Close the gaps If bias testing results are absent, request them from the vendor or commission independent testing. If human review protocols don’t exist, design and document them. If the organization operates in Saudi Arabia and lacks an AI Ethics Impact Assessment for any high-risk HR system, draft it now — SDAIA-P145 provides the methodology and the structure.

Appoint and train Designate a Responsible AI Officer or equivalent. Train the HR team on what algorithmic bias looks like in practice, and on how to document human review decisions in a way that satisfies a regulatory request. Organizations that integrate employee data protection GCC obligations into their HR operating design — rather than treating them as a procurement checklist — are the ones that can produce the documentation when SDAIA or CBUAE examiners request it.

Set up ongoing monitoring These frameworks are changing quarterly, not annually. SDAIA updates its maturity models regularly. The UAE’s Federal Authority will issue new guidance as it becomes operational. DIFC’s Regulation 11 will produce binding requirements before the end of 2026. Bahrain’s AI Regulation Law could pass at any point. Assigning someone to track regulatory updates in every jurisdiction where the organization operates is no longer optional.

The work above often requires specialized skills that don’t yet exist in-house — particularly AI risk assessment methodology and cross-border data governance mapping. Some organizations find it more effective to engage contract specialists like MGCG for the initial inventory and remediation phase, then transition to permanent governance roles once the compliance framework is established. 

This keeps the project moving without adding permanent headcount before the full scope of obligations is understood.

Final Thoughts: The Shift from "AI-Enabled" to "AI-Compliant"

The GCC is no longer in the voluntary AI ethics phase. Saudi Arabia’s SDAIA framework is actively enforced. The UAE has its first functioning AI supervisory authority. Qatar’s Central Bank rules carry real penalties for financial sector employers. Bahrain’s standalone AI law is closer to enactment than any other dedicated AI statute in the region.

For HR leaders, the question is no longer “Can this tool screen résumés faster?” It’s “Can we prove that this tool screens résumés fairly, transparently, and with human oversight — and can we produce that documentation when a regulator asks?” 

The organizations that built governance first are the ones moving faster now, because they face fewer deployment blockers and no remediation cost.

If you are auditing your HR AI stack in 2026, start with the inventory. The compliance documentation comes next.

Frequently Asked Questions

Does the PDPL apply to employee data stored on a global HR platform with servers outside the GCC?

Yes, in Saudi Arabia and most other GCC states. The Saudi PDPL has explicit extraterritorial reach — it applies to any entity processing Saudi residents’ data, regardless of where that processing physically occurs. The same principle applies in Bahrain, Qatar, and Oman. 

Do I need a Data Protection Officer for Saudi Arabia HR operations?

It depends on scale and nature of processing. The Saudi PDPL’s Executive Regulations require DPO appointment where core activities involve large-scale processing of sensitive personal data, or where the organization systematically monitors individuals at scale. For most HR functions processing payroll records, medical data, performance records, and biometric access data at significant scale, the requirement is likely triggered. 

Is AI-assisted recruitment screening — automated CV shortlisting, AI interview scoring — legal across the GCC?

Legal in all GCC states, but conditionally. The condition that applies across every jurisdiction with AI governance guidance is documented human oversight. Fully automated employment decisions — without a genuine human review step — carry high regulatory risk in Saudi Arabia, in the UAE under both the Federal PDPL and DIFC Data Protection Law, and in Qatar for financial sector employers under QCB guidelines. 

Will the non-binding AI ethics frameworks eventually become mandatory?

The trajectory is clearly in that direction. Saudi Arabia’s SDAIA framework is already effectively mandatory for government contractors and any entity under SDAIA supervisory oversight. In the UAE, the June 2026 consolidation signals a shift from guidance to enforcement. Bahrain’s standalone AI Regulation Law, when enacted, will introduce the first legally binding AI-specific criminal penalties in the GCC. 

Which GCC state has the most immediate binding AI compliance requirements for HR leaders right now?

Saudi Arabia, for breadth of scope; Qatar, for financial sector depth. Saudi Arabia’s SDAIA framework is the most comprehensive and actively enforced — 48 confirmed PDPL violation decisions during 2025, with SDAIA-P145 raising the documentation bar further. For HR leaders in financial services, Qatar’s Central Bank AI Guidelines are the most technically demanding binding instrument in the region.

Let’s Unlock Potential Together.

Whenever you’re ready, we’re here to collaborate with you, fully committed to driving success and making a meaningful, lasting impact.