Empowering
Global
Talent
MG Consulting Group

Your CTO just approved an AI-powered applicant tracking system that screens résumés, ranks candidates, and schedules interviews. The vendor said it’s fully compliant. Your CEO wants it live next month.
Then you read that Saudi Arabia’s SDAIA launched a National AI Risk Management Framework on July 14, 2026. The UAE consolidated its AI and data regulators into a single Cabinet-level authority on June 14. Qatar’s Central Bank requires documented risk assessments for any AI used in hiring decisions by licensed financial institutions.
The main point here? It is that the gap between “we bought it” and “we are allowed to use it” is widening across the GCC.
AI governance compliance is not a layer to add after procurement. It belongs in the procurement decision, the vendor contract, and the HR operating model — before deployment, not after a regulator asks for documentation that doesn’t exist.
This article maps the AI governance policies that directly affect HR functions in every GCC state, what they specifically require of HR leaders, where to find the documents, and how likely they are to change.
In every GCC jurisdiction with AI governance, employment-related AI systems are classified as high-risk because they affect individuals’ economic circumstances, legal rights, and career trajectories.
This includes applicant tracking systems that auto-screen résumés, video interview analyzers that assess tone and facial expressions, predictive attrition models that flag flight risks, performance management tools that recommend promotions, and internal chatbots that handle grievances or benefits queries.
What this classification triggers depends on the country, but the pattern is consistent:
Now, there is a misconception that vendor compliance equals organizational compliance. It does not.
Every framework places due diligence obligations on the deploying entity. And the documentation the regulators are beginning to request — Impact Assessments, model inventories, bias testing results, human review protocols — lives in the HR function.
And that also includes accountability when these are missing.
So if, for example, your ATS algorithm produces a discriminatory shortlist, you are the one regulators hold accountable, not just the vendor.
Saudi Arabia is the most immediate illustration of what that accountability looks like when a regulator is actively looking for it.
SDAIA issued 48 confirmed PDPL violation decisions during 2025, confirmed by IAPP and Clyde & Co from SDAIA’s official announcement.
The four violation categories those decisions covered — unlawful data processing, unauthorized disclosure, failure to implement technical and organizational safeguards, and non-consensual marketing communications — are all live risks in an AI-enabled HR function.
Most HR tech stacks carry at least one of them.
Saudi Arabia’s AI governance framework is the most actively enforced in the GCC and the fastest-moving. Two significant instruments arrived in 2026 alone:
What HR leaders must do:
| Requirement | What it means in practice |
|---|---|
| AI Ethics Impact Assessment | Document the AI system’s purpose, data sources, model owner, risk rating, testing results, known limitations, and monitoring plan before deployment |
| Fairness and bias mitigation | Test hiring algorithms for discriminatory outcomes across gender, nationality, and other protected categories. Maintain documented evidence |
| Transparency and explainability | Be able to explain the logic behind any AI-influenced rejection, promotion, or performance rating. Black-box systems are non-compliant |
| Human oversight | High-risk systems require a human-in-the-loop review step. Fully automated employment decisions without human intervention carry unacceptable risk under the framework |
| Responsible AI Officer | Appoint a designated officer accountable for AI ethics compliance within the organization |
| Model documentation and logging | Maintain model cards, dataset records, and decision audit trails throughout the system lifecycle |
Non-compliance penalties: PDPL fines up to SAR 5 million for general violations; up to SAR 3 million plus two years’ imprisonment for violations involving sensitive personal data. Non-compliance can also trigger loss of government contract eligibility and escalation to sectoral regulators.
Where to access the documents: SDAIA website — AI Ethics Principles, SDAIA-P145 Risk Management Framework, Generative AI Guidelines; National Data Management Office (NDMO) — data classification standards and governance frameworks.
Will it change? Consistently and quickly. Saudi Arabia designated 2026 the Year of Artificial Intelligence. SDAIA-P145 is weeks old. Expect annual updates, sector-specific addenda for employment AI, and a dedicated AI statute that will bring binding legal force to frameworks currently classified as guidance.
The intersection of AI governance and workforce structure in Saudi Arabia is particularly concentrated because Saudization and workforce localization requirements already constrain how HR leaders build their teams. Algorithmic compliance on top of nationalization targets means Saudi HR functions now operate under dual regulatory pressure — one framework governing who they can hire, another governing how any AI system involved in that decision must be documented and monitored.
Saudi Arabia’s enforcement is established. The UAE’s is just beginning.
For four years, the UAE’s Personal Data Protection Law existed without an active enforcement engine. The Federal Authority for Artificial Intelligence and Data, established by Cabinet on June 14, 2026, changed that.
The Authority consolidates three previously separate bodies — the UAE AI Office, TDRA’s digital government sector, and the Emirates Data Office — under a single Cabinet-level regulator.
Critically, the Emirates Data Office had never become fully operational before the consolidation; June 14 is the first time the UAE PDPL has had an unambiguous, active supervisory authority for the private sector.
The PDPL — in force since 2022 but largely unenforced in the private sector — now has an institutional home with a clear enforcement mandate. Implementing Regulations haven’t been published yet, but the body now exists to publish and enforce them.
Organizations that have been deferring UAE compliance on the assumption that enforcement was unclear should revisit that position.
The policy stack:
What HR leaders must do:
| Requirement | What it means in practice |
|---|---|
| Board-level accountability | CBUAE-licensed firms must have board-level accountability for all AI/ML systems. HR leaders must report AI-influenced employment metrics to the board |
| AI model inventory | Maintain a complete inventory of all AI systems by name, purpose, and risk rating — including every HR tech vendor using AI in their platform |
| Annual bias testing | Mandatory for financial institutions. Test HR systems annually or on any material model change for discriminatory outcomes |
| Human review of AI decisions | AI-generated employment decisions must be subject to documented human review |
| Kill-switch capability | Organizations must be able to cease an AI system immediately if it produces harmful or biased outcomes |
| Third-party vendor due diligence | Auditing vendor compliance is an organizational obligation — vendor certification alone doesn’t satisfy it |
| Arabic and English disclosure | Where AI influences employment decisions, disclosure requirements apply in both languages |
Non-compliance consequences: CBUAE supervisory action for financial institutions, including licensing restrictions. DIFC enforcement through thematic reviews, with an active enforcement record. Loss of government and semi-government contract eligibility across the UAE.
Where to access the documents: CBUAE Rulebook — Guidance Note on AI/ML; DIFC Data Protection Commissioner — Regulation 10 and Consultation Paper No. 3 of 2026 on the proposed Regulation 11.
Will it change? The June 2026 consolidation is a foundation, not a ceiling. DIFC’s Regulation 11 consultation closed July 18, 2026 — binding AI accreditation requirements for DIFC entities are expected before the end of 2026, and a federal horizontal AI statute is probable within 12 to 18 months. For HR leaders, the more immediate pressure is the convergence of AI governance and Emiratisation: the labor law compliance risks in the UAE already carry real penalty exposure — when AI systems influence who gets hired or promoted in a firm subject to the 10% Emiratisation target, that exposure compounds.
The four remaining GCC states sit at four different points on the AI compliance Middle East maturity spectrum. Qatar has binding sector-specific rules in force. Bahrain has a standalone AI law pending enactment. Oman enacted its national AI policy in April 2025. Kuwait is in the strategy phase. The compliance urgency differs accordingly.
The Qatar Central Bank AI Guidelines (September 2024) are currently the most technically demanding binding AI instrument among the smaller GCC states.
For QCB-licensed financial institutions, they require pre-deployment approval gates for high-risk AI systems, documented risk assessments, human review of AI-influenced employment decisions, and annual bias testing.
For HR leaders at QCB-licensed institutions who haven’t mapped their hiring AI systems to these guidelines: the guidance doesn’t ask for intent to comply. It asks for documented evidence that compliance exists. A broader horizontal AI law covering non-financial sector employers is probable within 12 to 24 months.
A 38-article AI Regulation Law was approved unanimously by Bahrain’s Shura Council in April 2024 and remains under review by the Council of Representatives as of July 2026.
If enacted, it would introduce the region’s first standalone AI-specific criminal penalties — fines up to BD 2,000 and up to three years’ imprisonment for violations.
The General Policy for the Use of AI (Version 1.0, May 2025) is already binding for government entities. Financial sector HR leaders in Bahrain waiting for the Council of Reprlesentatives vote are already behind — Central Bank precedent for AI risk assessment has been set, and precedent in the GCC tends to accelerate enactment rather than wait for it. Access: Central Bank of Bahrain.
Oman’s National AI Policy entered into force on April 9, 2025, establishing a governance framework for the development and use of AI systems.
The Personal Data Protection Law came into full effect on February 5, 2026. Both frameworks are new, and implementation guidance is still emerging.
HR leaders in Oman are at the start of a compliance build, not the end. Monitor developments at the Ministry of Transport, Communications and IT (MTCIT).
Kuwait’s National AI Strategy 2025–2028 sets direction but hasn’t produced binding AI-specific regulation yet. The PDPL came into full effect February 26, 2025, but currently applies only to CITRA-licensed organizations.
Kuwait is the lowest immediate compliance pressure in the GCC for most HR leaders — but the Strategy explicitly warns of bias, discrimination, and privacy risks from weak AI governance. Binding regulation is anticipated between 2027 and 2028.
The compliance requirements differ across all six states — but eight questions apply regardless of which jurisdiction an HR function operates in, and an inability to answer any of them represents active regulatory exposure.
Before any AI system touches an employment decision — hiring, performance evaluation, promotion, or termination — an HR leader in the GCC should be able to answer these eight questions.
For organizations operating across multiple GCC jurisdictions, some HR leaders find it more efficient to bring in external HR consultancy support for the initial compliance mapping phase — particularly where the same AI system needs to satisfy SDAIA, CBUAE, and DIFC requirements simultaneously.
A single cross-jurisdictional framework is significantly more defensible than three separate ad-hoc compliance reviews.
The eight questions above reveal where the gaps are. The steps below close them.
Start with the inventory Audit every AI-enabled tool in the HR tech stack — ATS platforms, video interview analyzers, performance management systems, employee chatbots, predictive attrition models. For each one, document the vendor, the stated purpose, the data processed, and the countries of operation. Without a complete inventory, every subsequent step is guesswork.
Risk-rate everything you find Using the frameworks above, classify each system. Anything affecting hiring, promotion, performance evaluation, or termination qualifies as high-risk in Saudi Arabia and is likely high-risk in every other GCC jurisdiction with guidance. Flag anything that can’t immediately produce bias testing results or model documentation.
Close the gaps If bias testing results are absent, request them from the vendor or commission independent testing. If human review protocols don’t exist, design and document them. If the organization operates in Saudi Arabia and lacks an AI Ethics Impact Assessment for any high-risk HR system, draft it now — SDAIA-P145 provides the methodology and the structure.
Appoint and train Designate a Responsible AI Officer or equivalent. Train the HR team on what algorithmic bias looks like in practice, and on how to document human review decisions in a way that satisfies a regulatory request. Organizations that integrate employee data protection GCC obligations into their HR operating design — rather than treating them as a procurement checklist — are the ones that can produce the documentation when SDAIA or CBUAE examiners request it.
Set up ongoing monitoring These frameworks are changing quarterly, not annually. SDAIA updates its maturity models regularly. The UAE’s Federal Authority will issue new guidance as it becomes operational. DIFC’s Regulation 11 will produce binding requirements before the end of 2026. Bahrain’s AI Regulation Law could pass at any point. Assigning someone to track regulatory updates in every jurisdiction where the organization operates is no longer optional.
The work above often requires specialized skills that don’t yet exist in-house — particularly AI risk assessment methodology and cross-border data governance mapping. Some organizations find it more effective to engage contract specialists like MGCG for the initial inventory and remediation phase, then transition to permanent governance roles once the compliance framework is established.
This keeps the project moving without adding permanent headcount before the full scope of obligations is understood.
The GCC is no longer in the voluntary AI ethics phase. Saudi Arabia’s SDAIA framework is actively enforced. The UAE has its first functioning AI supervisory authority. Qatar’s Central Bank rules carry real penalties for financial sector employers. Bahrain’s standalone AI law is closer to enactment than any other dedicated AI statute in the region.
For HR leaders, the question is no longer “Can this tool screen résumés faster?” It’s “Can we prove that this tool screens résumés fairly, transparently, and with human oversight — and can we produce that documentation when a regulator asks?”
The organizations that built governance first are the ones moving faster now, because they face fewer deployment blockers and no remediation cost.
If you are auditing your HR AI stack in 2026, start with the inventory. The compliance documentation comes next.
Yes, in Saudi Arabia and most other GCC states. The Saudi PDPL has explicit extraterritorial reach — it applies to any entity processing Saudi residents’ data, regardless of where that processing physically occurs. The same principle applies in Bahrain, Qatar, and Oman.
It depends on scale and nature of processing. The Saudi PDPL’s Executive Regulations require DPO appointment where core activities involve large-scale processing of sensitive personal data, or where the organization systematically monitors individuals at scale. For most HR functions processing payroll records, medical data, performance records, and biometric access data at significant scale, the requirement is likely triggered.
Legal in all GCC states, but conditionally. The condition that applies across every jurisdiction with AI governance guidance is documented human oversight. Fully automated employment decisions — without a genuine human review step — carry high regulatory risk in Saudi Arabia, in the UAE under both the Federal PDPL and DIFC Data Protection Law, and in Qatar for financial sector employers under QCB guidelines.
The trajectory is clearly in that direction. Saudi Arabia’s SDAIA framework is already effectively mandatory for government contractors and any entity under SDAIA supervisory oversight. In the UAE, the June 2026 consolidation signals a shift from guidance to enforcement. Bahrain’s standalone AI Regulation Law, when enacted, will introduce the first legally binding AI-specific criminal penalties in the GCC.
Saudi Arabia, for breadth of scope; Qatar, for financial sector depth. Saudi Arabia’s SDAIA framework is the most comprehensive and actively enforced — 48 confirmed PDPL violation decisions during 2025, with SDAIA-P145 raising the documentation bar further. For HR leaders in financial services, Qatar’s Central Bank AI Guidelines are the most technically demanding binding instrument in the region.