Blog

From experimentation to structure: Bringing AI governance to the Gulf 


What does it take to turn AI from scattered experimentation into something an organization can actually control?

Last week, we explored this question across three countries. The Swiss Cyber Institute delivered a series of AI Governance Masterclasses in Doha on 18 May, Riyadh on 19 May, and Abu Dhabi on 21 May 2026. Each session brought together decision-makers from compliance, risk, legal, and technology, all facing the same underlying challenge: AI is already in use, but governance is not.

Behind these three days stood weeks of preparation, alignment, and iteration. Our objective was to create a working environment where participants could move from abstract understanding to concrete structure.

Explore selected moments from the AI Governance Roadshow in our event photo album.

What organizations revealed before the sessions began

Ahead of the masterclasses, we conducted a pre-survey with 55 participants across Qatar, Saudi Arabia, and the UAE. The results were consistent across countries and industries. The average AI governance maturity score was 1.58 out of 5.

In practical terms, this places most organizations between informal discussion and early development. Not a single organization reported a mature, implemented governance structure across the key domains.

The most pressing concerns were equally aligned:

  • A lack of strategic direction and prioritization
  • Exposure to new forms of risk such as data leakage and prompt injection
  • A shortage of skills within teams responsible for managing AI systems

At the same time, adoption is already widespread. Around 90% of organizations are using or exploring AI in some form, often within selected functions rather than as a core capability. This creates a structural gap between usage and control.

The underlying issue is not technical

Across all three cities, we observed a pattern. Teams are experimenting with AI tools. Business units integrate automation into workflows. Technical teams deploy models in production environments. The pace of adoption is high, often driven by efficiency gains and competitive pressure.

When the discussion turns to governance, uncertainty appears:

  • Who approves new AI use cases?
  • Which tools are allowed internally?
  • How are risks classified and monitored?
  • Who carries final accountability?

Most organizations do not lack AI initiatives. They lack ownership and structure.

The absence of clear answers introduces operational risk. Real-world cases illustrate the consequences: confidential data shared with external models, regulatory interventions, or systems producing unintended outcomes due to missing controls.

These are not edge cases. They reflect systemic gaps.

Why we focused on governance

The decision to center the masterclasses on AI governance was deliberate.

Many organizations have already invested in tools and use cases. Fewer have invested in the structures that make these initiatives sustainable. Without governance, even well-designed AI systems operate in isolation, without clear boundaries or accountability.

Governance introduces structure. It defines what is permitted, what requires approval, and who is responsible for decisions. It creates a common language between legal, risk, and technical teams. Most importantly, it allows organizations to move from isolated use cases to coordinated implementation.

This is not specific to one region or one sector. It is a structural challenge affecting organizations globally.

From frameworks to application

The masterclass was designed around application. Participants were introduced to established frameworks such as NIST AI RMF and ISO/IEC 42001. These frameworks provide a necessary foundation, but their value lies in application. The core of each session focused on translating these standards into concrete organizational structures.

Working in guided exercises, participants mapped their own AI use cases, assessed risk levels, and defined accountability. Using structured tools such as the AI system register and risk triage worksheet, they developed a first version of their governance setup during the session itself.

The goal was not completeness. It was clarity. By the end of the workshop, each participant had a tangible output: a defined use case, an initial risk classification, a named owner, and a clear next step.

This shift from abstraction to action is where governance begins to take shape.

A practical approach to a complex problem

AI governance is often perceived as complex and resource-intensive. In practice, the first step is far more focused.

The approach applied in the masterclass reduces complexity into a sequence:

  1. Identify what exists
  2. Define risk
  3. Sssign ownership
  4. Establish initial rules

This approach reflects how we work more broadly with clients, often through phased implementation models such as a 90-day roadmap that moves organizations from initial assessment to a defensible governance baseline.

The emphasis remains consistent: practical application, measurable progress, and clear ownership.

What remained after the sessions

The most valuable outcomes were not limited to the workshop outputs. Participants left with a shared understanding of where they stand and what needs to be done next. More importantly, they gained a structured way to approach AI governance internally.

“Governance begins when responsibility becomes explicit.”

Across all three cities, discussions continued beyond the sessions. Organizations are actively looking for ways to move from initial drafts to implementation.

From masterclass to implementation: AI Governance 360

The masterclasses reflect only one part of a broader approach.

AI governance requires more than a single workshop. It involves assessment, design, implementation, and continuous improvement. Each organization starts from a different point, but the objective remains consistent: build a governance system that works in practice.

With AI Governance 360 Services, the Swiss Cyber Institute supports organizations across this entire process:

  • assessing current maturity and identifying gaps
  • defining governance structures and responsibilities
  • developing policies and internal framework aligned with NIST and ISO
  • supporting implementation across teams
  • training stakeholders and building internal capability

If you are ready to move from awareness to implementation, get in touch with us.

Subscribe for updates