
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

The rapid adoption of artificial intelligence (AI) across the Gulf Cooperation Council (GCC) is creating opportunities for innovation.
Summary
Still, it is also exposing organisations to a growing governance challenge that many boards have yet to recognise fully. According to Srdjan Babic, chief information and security officer (CISO) at Cybergate, the most significant cyber security risk facing organisations today is not ransomware, supply chain attacks or sophisticated malware, but the widening gap between AI deployment and the governance structures needed to manage it effectively. “The region’s rate of AI adoption has outpaced the rate at which organisations are governing it, and that gap is now the risk,” says Babic.
While ransomware groups have become more professionalised, supply chain compromises more frequent and social engineering attacks more convincing, Babic argues that AI introduces a fundamentally different challenge. “We see the same pattern repeatedly. A generative AI assistant is approved for a narrow, low-risk task such as drafting documents.
Within a few months, it is being used to screen job candidates or summarise contracts, with personal data being entered into prompts. Nobody decided that expansion should happen – it happened because nobody was watching for it,” he says. Babic describes this phenomenon as “ shadow AI ”, where employees expand the use of AI tools beyond their originally intended purpose without adequate oversight or governance controls.
The region’s rate of AI adoption has outpaced the rate at which organisations are governing it, and that gap is now the risk Srdjan Babic, Cybergate “AI adoption and security governance are often treated as two separate workstreams running on different clocks, when they are now the same risk surface,” he says. Security as an enabler of innovation As governments across the GCC nations continue investing heavily in digital transformation and national AI strategies, Babic challenges the common assumption that organisations must strike a balance between innovation and security. “I would push back on the word balance because it implies a trade-off between two competing goods.
Innovation without governance is not faster innovation – it is deferred cost,” he says. “What separates successful deployments from unsuccessful ones is rarely the technology itself. It is whether organisations have done the preparatory work around people, processes, data quality and governance.” He argues that many organisations are acquiring AI capabilities faster than they are building the assurance frameworks required to govern them.
“For the UAE and the wider Gulf, capability is being procured faster than the assurance substrate underneath it is being built. Sovereign capability without sovereign assurance is capability that somebody else will ultimately be better positioned to audit than you are.” AI amplifies both defence and risk Babic believes AI’s greatest value in cyber security lies in automating repetitive operational tasks to allow security professionals to focus on higher-value decision-making. “The genuine opportunity is in the unglamorous, high-volume work being handled well enough that scarce human judgement can be focused where it actually matters,” he says.
However, he warns that organisations risk creating new vulnerabilities if they deploy AI-driven security tools without first establishing clear governance structures. “The risk I would put first is organisations adopting AI defensively without having done the governance work first, so the tool meant to reduce risk becomes a new, ungoverned part of the attack surface itself.” The risk I would put first is organisations adopting AI defensively without having done the governance work first, so the tool meant to reduce risk becomes a new, ungoverned part of the attack surface itself Srdjan Babic, Cybergate According to Babic, the same weaknesses that often contribute to security incidents – poor data quality, unclear ownership and inadequate controls – are also among the primary reasons AI projects fail to deliver value. Why the skills gap remains Despite sustained investment in cyber security training programmes across the region, Babic says organisations continue to struggle because they are measuring participation rather than capability.
“There is a distinction between training that is recorded and competence that is measured,” he says. “A completion certificate proves attendance. It says nothing about whether that person would recognise a fraudulent payment request under pressure or identify when a fluent AI-generated answer is wrong.” He argues that organisations often assume that competency follows automatically from training completion, when evidence suggests otherwise.
“The fix is not a bigger training budget,” he says. “It is a discipline: measure actual behaviour, build the capability that is missing, and prove with evidence that it has improved.” Looking ahead, Babic believes the cyber security profession will increasingly require a broader set of skills that extend beyond technology expertise: “Analytical and critical thinking, calibrated judgement, governance literacy, adaptability and the ability to work across disciplines will become increasingly important.” AI literacy will also become a core competency, although Babic stresses that organisations are not necessarily seeking people who can build AI models. “They are hiring people who can use AI systems with judgement and understand where those systems are reliable and where they are not.” Boards need evidence, not policies As cyber risk becomes a board-level issue, Babic believes directors should focus less on technical details and more on whether governance mechanisms can be demonstrated through evidence.
“Boards do not need to become experts in model architectures or attack techniques,” he says. “They need answers that reveal whether risk management is real or merely assumed.” Among the questions boards should be asking are who oversees critical AI systems, whether oversight mechanisms have been exercised in practice, where training data originates and what evidence exists to demonstrate compliance. “If a regulator asked for our governance evidence tomorrow, what would we actually send them?
A weak answer is a policy document and a plan to assemble the rest. A strong answer is a named artefact that already exists,” says Babic. He adds that regulatory scrutiny is increasing globally, with governance and record-keeping becoming as important as technical controls.
“An accountability that cannot be delegated can only be discharged by evidence that it was exercised,” he says. The future CISO Looking towards 2030, Babic expects the CISO role to expand significantly beyond traditional information security responsibilities. “The CISO of 2030 is less a technology gatekeeper and more the executive who owns the organisation’s evidence base,” he says.
He expects increasing convergence between information security, AI governance and data management as organisations seek to meet evolving regulatory requirements. “The shift is from point-in-time attestation to continuous assurance. AI systems evolve, are retrained and acquire uses nobody planned for.
The challenge is maintaining continuous evidence that the organisation’s actual state matches what it claims.” For the GCC, Babic believes the defining challenge over the next five years will be ensuring governance frameworks mature at the same pace as national AI ambitions. “Capability can be procured in a quarter. Assurance cannot.
The organisations that treat that gap as the central risk between now and 2030 will be the ones best positioned for the future.” Read more about IT in the Middle East Saudi Arabia struggling to reach global leadership in deeptech : Petrostate monarchy trying to build surrogate industry made of foreign startups because its own ecosystem is immature. Vox pop on digital transformation across the Arab world : We asked exhibitors at UAE startup event Expand North Star about the challenges – from lack of fundamental infrastructure to first-world problems – faced by startups and digital businesses in the Middle East. Saudi plans to be an IT superpower, but challenges lie ahead – impressions of Saudi Arabia during Leap 2025: Big plans ahead, but challenges in physical and digital infrastructure, and in the transition from public to private sector dominance.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.