Confidential — Internal Use Only

GCC AI Compliance
Gap Analysis & Action Plan

PureBrain / Pure Technology · Prepared by Prodigy · April 9, 2026

44
Total Gaps
26
Critical
11
High
24
Action Items

⚠ Executive Summary

PureBrain currently has significant compliance gaps across all three GCC jurisdictions (Qatar, KSA, UAE). The platform runs on Cloudflare Pages (US infrastructure) with Anthropic Claude API — neither configured for GCC data residency. There is no consent management system, no AI register, no audit trail infrastructure, and no human-override mechanism. Operating in the GCC without addressing these gaps exposes PureBrain to fines of $275K–$1.37M+ per violation (Qatar), SAR 20M+ (KSA), and direct civil litigation (UAE DIFC). The single highest-leverage first step is engaging GCC legal counsel immediately.

Critical — Blocks market entry or immediate fine risk
High — Required before first GCC customer
Medium — Required within 90 days of launch
Low — Monitoring / documentation
Qatar
11
7 Critical2 High2 Med
Saudi Arabia
13
5 Critical4 High3 Med
UAE
12
8 Critical3 High1 Med
Cross-Cutting
8
6 Critical2 High
Qatar

Qatar — Gap Analysis

Data Protection (PDPPL, Law 13/2016)

RequirementCurrent StateGapSeverity
Data localization: sensitive data on servers in QatarCloudflare Pages (US CDN). Anthropic Claude API (US).No Qatar data residency. All data processed in US.Critical
Cloud provider must guarantee Qatari data residencyNo contractual data residency guarantee in place.Cloudflare and Anthropic have no GCC-specific residency SLA for PureBrain.Critical
Explicit, purpose-bound consent mechanismsNo consent management system. Basic contact forms only.No CMP (Consent Management Platform) deployed.Critical
Consent must be revocable by end userNo revocation mechanism exists.No consent withdrawal flow or preference center.Critical

Qatar Central Bank (Financial AI)

RequirementCurrent StateGapSeverity
Mandatory AI register — ALL deployed AI systems documentedNo AI register exists.No inventory of AI systems, models, or use cases.Critical
QCB pre-approval BEFORE any new AI deploymentNo QCB engagement initiated.Cannot deploy financial AI in Qatar without this.Critical
High-risk AI: separate QCB authorizationNo risk classification framework.No classification methodology for AI risk levels.Critical

Cybersecurity (NCSA)

RequirementCurrent StateGapSeverity
NCSA cybersecurity framework complianceNo NCSA audit or assessment completed.No gap assessment against NCSA framework.High
Expect audits — 100+ entities, 54K participantsNo audit readiness posture.No audit documentation, no designated security contact.High

AI Ethics (MCIT, May 2025)

RequirementCurrent StateGapSeverity
AI ethics guidelines (aligned with Islamic ethical principles)No ethics documentation exists.No ethics framework aligned with MCIT/Islamic principles.Medium
Documentation of ethical compliance postureNone.No ethics statement, policy, or audit trail.Medium
Saudi Arabia

Saudi Arabia (KSA) — Gap Analysis

Data Protection (PDPL, enforceable Sept 2023)

RequirementCurrent StateGapSeverity
Full PDPL compliance (48 enforcement decisions in year one)No PDPL compliance assessment done.No data mapping, no processing records, no DPA.Critical
Explicit, purpose-bound, revocable consentNo CMP deployed.Same as Qatar — no consent system exists.Critical
Data processing documentation and records (ROPA)No records of processing activities.ROPA does not exist.Critical

Cybersecurity (ECC-2)

RequirementCurrent StateGapSeverity
108 mandatory cybersecurity controlsNo ECC-2 assessment done.Unknown how many of 108 controls are currently met.High
All cybersecurity roles staffed by Saudi nationals (Saudization)No KSA office or local staff.Cannot fulfill Saudization requirement without local hire or partner.High
Audit readiness for ECC-2 complianceNone.No compliance documentation or evidence package.High

SAMA (Financial Services AI)

RequirementCurrent StateGapSeverity
AI explainability for credit/automated decision models — plain languageClaude API is a black-box LLM. No explainability layer.Cannot explain AI decisions in plain language as required.Critical
Human-in-the-loop: humans must be able to override any high-impact decisionNo override mechanism in any PureBrain portal.No human review queue or override button exists.Critical

SDAIA AI Ethics + Data Embassy Framework

RequirementCurrent StateGapSeverity
Fairness, accountability, transparency documented and demonstrableNo documentation exists.No AI fairness assessment or accountability framework.Medium
Determine which Data Embassy configuration applies (Private/Extended/Virtual)Not assessed.No determination of which configuration applies to PureBrain.Medium
Sovereign data processing enclave (cross-border operations)No sovereign enclave.Cross-border data processing has no compliant enclave.Medium
Monitor KSA Dedicated AI Law (in development)Not tracked.No monitoring assigned for SDAIA publications.Low
UAE

UAE — Gap Analysis

Federal PDPL (Jan 1, 2027 deadline)

RequirementCurrent StateGapSeverity
Compliance roadmap in place for Jan 2027No roadmap exists.No plan, no timeline, no owner assigned.High
Consent mechanisms aligned with federal requirementsNo CMP.Shared gap with Qatar/KSA — no consent system.High
Data processing documentationNone.No ROPA for UAE operations.High

DIFC (Dubai International Financial Centre, amended July 8, 2025)

RequirementCurrent StateGapSeverity
Private right of action — data subjects can sue directly for damages incl. emotional distressNo litigation-ready data handling procedures.Exposure to civil claims including emotional distress damages.Critical
Extraterritorial jurisdiction — applies even if not physically in DIFCNo legal assessment of DIFC applicability.Any UAE customer in DIFC zone = full DIFC rules apply.Critical
Litigation-ready data handling and breach response proceduresNo incident response plan.No breach notification process, no legal counsel on retainer.Critical

ADGM (Abu Dhabi Global Market, effective Jan 31, 2026)

RequirementCurrent StateGapSeverity
24-hour mandatory incident reporting capabilityNo incident detection or escalation pipeline.Cannot meet 24-hour window without monitoring infrastructure.Critical
Cyber risk framework complianceNo ADGM-specific assessment.No compliance posture for ADGM.High

Child Digital Safety Law (effective Jan 1, 2026)

RequirementCurrent StateGapSeverity
Age verification system for users under 18No age verification on any PureBrain product.Cannot onboard UAE users without age verification gate.Critical
Guardian/parental consent mechanism for users under 13None.No parental consent flow exists.Critical
Data handling differentiation for minorsSingle data handling policy — no minor-specific controls.No differentiation in data handling for users under 18.Critical

UAE AI Charter (12 Principles) + Triple Compliance Warning

RequirementCurrent StateGapSeverity
Alignment with 12 guiding principles of UAE AI Charter (June 2024)Not assessed.No self-assessment against UAE AI Charter.Medium
If operating across UAE free zones: comply with Federal PDPL + DIFC + ADGM simultaneouslyNot assessed — no legal counsel mapping per jurisdiction.Each has own definitions, enforcement body, and penalties. No mapped counsel.Critical
Cross-Cutting

Cross-Cutting — All Three Countries

RequirementCurrent StateGapSeverity
Complete audit trail — always on, not generated on demandNo persistent audit logging across any PureBrain system.No audit trail infrastructure of any kind.Critical
Human override capability — actual button, not theoreticalNo human override in any portal or AI workflow.No override UI, no review queue, no escalation path.Critical
Data residency proof — demonstrate which country holds which client's data RIGHT NOWNo data residency visibility. Cloudflare/Anthropic process globally.Cannot demonstrate per-country data location.Critical
Three separate consent frameworks operating simultaneouslyZero consent frameworks in place.Need Qatar + KSA + UAE consent frameworks — none exist.Critical
Risk classification for each AI system (high-risk vs. standard)No risk classification system.No AI risk register or classification methodology.High
Pre-approval documentation ready for Qatar and KSA regulatorsNot started.No regulatory filings or pre-approval packages prepared.Critical
No unified GCC playbook — each country tracked independentlyNo country-specific compliance tracking.Single undifferentiated approach. Must split into 3.High
Legal representation or registered agent in each jurisdictionNone confirmed in Qatar, KSA, or UAE.No GCC legal representation in any jurisdiction.Critical

Master Action Item List

1

Engage GCC legal counsel — registered agents in Qatar, KSA, UAE

Cannot operate or file pre-approvals without legal presence. Find firms with GCC AI regulatory expertise. Budget for 3 separate retainers.

All 3 countries

CriticalImmediate
2

Appoint internal GCC Compliance Lead

All 44 gaps need a single internal owner. This person coordinates legal counsel, tech teams, and tracks progress per country.

All 3 countries

CriticalImmediate
3

Build AI System Register — inventory every AI model, use case, and data flow

Document every AI system deployed across PureBrain products: model used, purpose, data inputs/outputs, risk level, jurisdiction. Required for QCB pre-approval in Qatar.

All 3 countries

CriticalWeek 1–2
4

Implement Consent Management Platform (CMP) — 3 separate frameworks

Build or integrate a CMP with purpose-bound, revocable consent for Qatar (PDPPL), KSA (PDPL), and UAE (Federal PDPL + DIFC + ADGM) simultaneously. Each requires separate consent language and withdrawal flows.

All 3 countries

CriticalWeek 2–4
5

Implement always-on audit trail infrastructure

Deploy tamper-proof logging for all AI decisions, data access events, and user actions. Must be always-on — not generated on demand. Store per-jurisdiction. Required across all 3 GCC countries.

All 3 countries

CriticalWeek 2–4
6

Build human override mechanism — literal UI button/review queue

Any AI-generated high-impact decision must have a human review step with an actual override capability. Deploy in all PureBrain portals. Required by Qatar QCB, KSA SAMA, and UAE ADGM.

All 3 countries

CriticalWeek 2–4
7

Migrate to GCC-compliant data residency infrastructure

Evaluate Cloudflare for Business/Enterprise (UAE/KSA edge nodes), Azure UAE North, or AWS Bahrain. Get contractual data residency guarantees. Critical for Qatar (no exceptions allowed) and KSA.

Qatar, KSA

CriticalWeek 3–6
8

Initiate QCB pre-approval process for Qatar

No deployment of financial AI in Qatar without QCB pre-approval. Prepare submission package: AI register, risk assessment, data residency proof, ethics documentation. Engage legal counsel before filing.

Qatar only

CriticalWeek 2 (start)
9

Commission KSA PDPL compliance assessment

Data mapping, ROPA creation, gap analysis against all 48+ KSA enforcement precedents. Engage KSA-qualified legal firm. Output: full compliance gap report and remediation plan.

KSA only

CriticalWeek 2–3
10

Build AI explainability layer for automated decision models

Wrap Claude API responses with plain-language decision summaries. Log explanation per transaction. Required by KSA SAMA for credit-scoring and automated decisions. Consider structured output formats.

KSA (SAMA)

CriticalWeek 4–8
11

Commission DIFC legal assessment for UAE

Determine if any current/future UAE customers fall under DIFC jurisdiction (extraterritorial — doesn't require physical presence). Prepare breach response procedures and litigation-ready data handling policies.

UAE only

CriticalWeek 1–2
12

Build 24-hour incident response pipeline (ADGM)

Deploy monitoring, alerting, escalation, and regulatory notification capability capable of meeting ADGM's 24-hour mandatory reporting window. Requires SecOps tooling and designated incident owner.

UAE (ADGM)

CriticalWeek 3–6
13

Implement age verification system for UAE

Gate for users under 18 with age verification. Parental consent flow for users under 13. Separate data handling policy for minors. Required by UAE Child Digital Safety Law (effective Jan 1, 2026 — already in force).

UAE only

CriticalWeek 3–5
14

Create Records of Processing Activities (ROPA) for KSA and UAE

Document all data processing operations: purpose, legal basis, data categories, recipients, retention periods, cross-border transfers. Separate ROPA for each jurisdiction.

KSA, UAE

HighWeek 3–4
15

Commission ECC-2 gap assessment (108 controls) for KSA

Assess current state against all 108 mandatory KSA cybersecurity controls. Output: compliance percentage, prioritized remediation list, estimated effort.

KSA only

HighWeek 3–4
16

Identify Saudi national(s) for cybersecurity roles (Saudization)

Either hire KSA-national cybersecurity staff locally or partner with a KSA-registered cybersecurity firm that fulfills the Saudization requirement on PureBrain's behalf.

KSA only

HighMonth 2
17

Build UAE Federal PDPL compliance roadmap (Jan 2027 deadline)

Assign owner, define milestones, allocate budget. Jan 2027 is achievable but requires starting now. Map all required changes: consent, ROPA, DPO assessment, data flows.

UAE only

HighMonth 1
18

Build separate compliance tracker per country

No unified GCC playbook — each country has its own definitions, enforcement body, and penalties. Three independent trackers with their own milestones, owners, and status dashboards.

All 3 countries

HighWeek 1
19

Self-assess against UAE AI Charter 12 principles

Document alignment and gaps against each of the 12 UAE AI Charter guiding principles. Produces the ethics compliance posture required for UAE market entry.

UAE only

MediumMonth 2
20

Self-assess against Qatar MCIT AI Ethics guidelines (Islamic principles)

Document alignment with MCIT ethics framework. Produces ethics compliance documentation required for Qatar market entry and QCB pre-approval submission.

Qatar only

MediumMonth 2
21

Assess KSA Data Embassy Framework (3 configurations)

Determine which of the three configurations (Private, Extended, Virtual) applies to PureBrain's cross-border operations. Engage legal counsel with SDAIA expertise.

KSA only

MediumMonth 2
22

Build SDAIA fairness, accountability, transparency documentation

Document AI fairness methodology, accountability chain, and transparency mechanisms for KSA SDAIA requirements. Must be demonstrable — not just written policy.

KSA only

MediumMonth 2
23

Monitor KSA Dedicated AI Law development

Assign tracking owner. Subscribe to SDAIA publications and regulatory announcements. When published, this law will create additional obligations beyond current requirements.

KSA only

LowOngoing
24

Monitor Council of Europe AI Treaty for GCC harmonization

Track potential future harmonization between Council of Europe AI Treaty and GCC country frameworks. Could simplify multi-jurisdiction compliance if GCC countries ratify.

All 3 countries

LowOngoing