
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The EU AI Office, the UK's sectoral approach, and how the UAE and Saudi Arabia are building AI governance — a working map of who enforces what.
"AI regulation" isn't one thing, and treating it like one is the most common mistake in an early-stage AI governance program. The EU, the UK, the UAE, and Saudi Arabia — the jurisdictions most relevant to an EMEA-operating organization — have each built a genuinely different model, with different enforcement mechanisms and different penalties for getting it wrong. Here's what each one actually does, not the version that gets flattened into "AI regulation is coming."
The EU AI Act is a single, comprehensive, legally binding law with a risk-based classification system — and as of August 2, 2026, it's not theoretical anymore. The European Commission's AI Office began direct enforcement against general-purpose AI models on that date, with the power to request technical documentation, run evaluations, demand corrective steps, and issue fines. Everything else — AI systems that aren't general-purpose foundation models — falls to national competent authorities in each member state instead. Penalties are tiered by violation type: up to €35 million or 7% of global annual turnover for the most serious violations (prohibited AI practices), against a lower €15 million or 3% tier specifically for transparency-obligation failures. One law, but not one flat penalty — which tier applies depends entirely on what was actually violated.
The UK deliberately didn't follow the EU's model. Its approach, set out in a March 2023 white paper, is principles-based and non-statutory: five cross-cutting principles (safety, transparency, fairness, accountability, contestability) that existing sectoral regulators — the ICO, FCA, PRA, MHRA, and Ofcom among them — are expected to apply within their own domains, rather than one central AI law. There's no UK equivalent of the EU AI Act's binding foundation-model obligations; frontier AI labs operate instead under voluntary commitments overseen by the UK's AI Safety Institute. The practical effect for a UK-regulated organization is more flexibility, but also more fragmentation — figuring out which regulator's guidance actually applies to a specific AI use case is a genuinely harder question than it is under the EU's single law.
Neither the UAE nor Saudi Arabia has passed anything resembling the EU AI Act, but both are actively building real governance infrastructure, faster than most outside observers give them credit for.
The UAE combines several layers rather than one law: the non-binding UAE Charter for AI (2024) sets national principles, while DIFC's Regulation 10 — the first AI-specific binding regulation in the wider Middle East, Africa, and South Asia region — reached full enforcement on January 1, 2026, imposing specific duties on entities deploying autonomous or semi-autonomous systems that process personal data within the DIFC free zone specifically. The Central Bank of the UAE added its own layer in February 2026 with AI/ML guidance for financial institutions covering governance, bias testing, transparency, and human oversight.
Saudi Arabia centralizes AI governance through the Saudi Data and AI Authority (SDAIA) rather than spreading it across sector regulators — fitting, given the Kingdom designated 2026 its "Year of Artificial Intelligence." SDAIA's stack includes its AI Ethics Principles (updated 2025), Generative AI Guidelines (2024), and a four-level AI Adoption Framework maturity model (September 2024), alongside its ongoing role operationalizing enforcement of the Kingdom's PDPL.
An organization operating across the EU, UK, UAE, and Saudi Arabia genuinely faces four different regimes — one binding and centrally enforced, one principles-based and regulator-fragmented, and two still actively under construction with a mix of binding free-zone rules and non-binding national guidance. There's no single global AI compliance checklist that covers all four honestly. What does travel across all of them is the underlying risk-management discipline: NIST's AI Risk Management Framework and ISO/IEC 42001 both function as jurisdiction-agnostic engines for actually managing AI risk, regardless of which specific law or guidance sits on top in a given market.
If you're operating — or planning to operate — an AI system across more than one of these jurisdictions, the practical first step is mapping which specific obligation actually applies to your specific system in each market, not assuming one region's rules cover another. Our Cybersecurity Consulting team helps build that map against your real deployment, and for the data-protection side specifically, our EMEA Compliance Map covers the UAE, Saudi Arabia, Qatar, and 27 European countries' underlying data-protection regimes these AI rules sit alongside.
Tell us about your environment and goals — we'll help you scope the right engagement.