• | 9:00 am

The Gulf wants to own its AI future, not rent it

As GCC countries invest in sovereign AI, the Gulf is seeking greater control over its data, cloud infrastructure, and critical AI systems.

The Gulf wants to own its AI future, not rent it
[Source photo: Krishna Prasad/Fast Company Middle East]

A company in the Gulf can keep its AI data inside national borders and still rely on an external vendor to run the system.

In a July 2026 IBM study, 80% of surveyed UAE executives said moving their core AI systems to another vendor would take at least six months. 88% said switching their primary AI provider or model would be difficult.

That is a problem for a region spending heavily on technological independence. Governments across the Gulf are building data centers and developing their own AI models. 

But the chips powering these facilities come from foreign suppliers, and global cloud companies remain central to their operations.

A country can own a data center and keep sensitive information within its borders, yet still depend on an outside company to operate essential systems. If that supplier becomes unavailable, local ownership offers little protection.

Farid Zahran, Senior Managing Director, AI and Digital Transformation at FTI Consulting, doesn’t believe complete technological independence is realistic.

“No country owns the full AI stack. Advanced chips are designed in the United States and made mostly in Taiwan, so self-sufficiency is not a realistic test.”

The bigger question, he says, is which parts of the technology countries need to control themselves.

OWNING DOESN’T MEAN CONTROL

The Gulf’s AI investments are expanding computing capacity, but they also reveal how closely the region’s ambitions remain tied to international technology companies.

The UAE’s Stargate project brings together G42, OpenAI, Oracle, Nvidia, Cisco, and SoftBank. The planned one-gigawatt AI cluster in Abu Dhabi illustrates how regional investment and foreign technology are becoming closely connected.

While these partnerships let countries use advanced technology without building everything from scratch, Zahran says infrastructure ownership doesn’t guarantee control over what happens inside it.

For the Gulf, he identifies four key areas: where sensitive data is stored, which laws govern it, who operates the infrastructure, and who owns the models and applications that process national information.

A data center might sit within national borders, but a foreign provider could still control the software or administrative access needed to operate it.

Zahran says that countries also need to keep encryption keys and administrative access locally, secure reliable chip supplies, and retain ownership of their data and applications. Without these protections, they risk investing in infrastructure that remains dependent on decisions made elsewhere.

“Data center investment is necessary but does not secure sovereignty by itself.”

Rotem Alaluf, Founder and CEO of Wand AI, believes countries should focus on retaining control over how technology operates rather than trying to manufacture every component themselves.

“Sovereignty is not technological isolation; the region can use global chips, models and cloud infrastructure while still controlling the systems that turn them into productive capacity.”

For Alaluf, the important distinction is between purchasing foreign technology and allowing an external company to control how that technology performs essential work.

Yasser Shawky, Vice President EMEA South at Informatica, frames the same problem in terms of data rather than infrastructure. 

“Knowing where data is stored is important, but countries also need visibility and control over how that data is processed, transformed, governed and ultimately used by AI systems,” Shawky says.

He says countries don’t need to develop every component of their AI systems themselves. 

Instead, they need to ensure they can change technology providers without losing control of their data or the knowledge they’ve accumulated.

THE RISK OF DEPENDENCE

An AI system that answers customer questions is pretty straightforward. But what happens when it starts handling invoices, approving requests, or doing tasks inside a company’s own software?

As businesses introduce AI agents that can complete work independently, they also create new forms of dependence on the platforms running them.

Alaluf says the concern isn’t simply which company supplies the underlying AI model. Organizations must also consider who controls an agent’s identity, permissions, memory, and records of previous actions.

Over time, these systems can accumulate valuable knowledge about how a business operates. If that information remains tied to a foreign platform, switching providers could mean losing more than access to a software product.

Alaluf says that businesses should be able to change providers, inspect an agent’s actions, and revoke its permissions without rebuilding their operations from the beginning.

The issue is especially relevant for Gulf countries seeking to use AI across essential public services and major industries.

“The resilience test is simple: if one provider becomes unavailable, does the economy experience friction or paralysis?,” Alaluf says.

The same concern applies to the hardware powering AI infrastructure. Advanced chips remain subject to export rules set by the governments of the countries supplying them. Changes to those rules can affect the technology available to regional companies.

In July 2026, the US Department of Commerce eased certain export controls on the UAE, allowing its government and approved companies to receive advanced computing equipment without individual licenses under specified conditions.

This decision made it easier to get advanced AI chips and servers. It also showed how international rules can shape the region’s ability to grow its computing power. Zahran points out another problem: relying on just a few tech providers can give those companies significant power over prices and how products are developed.

He explains that using multiple vendors, adopting models that organizations can run themselves, and negotiating clear exit rights can reduce these risks.

Alaluf believes the bigger concern is letting foreign platforms control the systems that do essential work.

Importing a component is different from needing a supplier’s continued permission to operate an important part of a business.

And for governments and companies, that could determine how much control they retain as AI becomes more deeply embedded in their operations.

KEEPING DATA LOCAL

For organizations handling sensitive information, relying on foreign cloud providers creates another concern: what happens to their data when AI processes it?

Businesses can retain greater control by running AI on their own infrastructure rather than sending information to external cloud services, says Muhammed Khalid, CEO and Founder of Abu Dhabi-based AI company AIREV, which Core42, a subsidiary of the G42 Group, backs.

“Foreign chips are not the problem. Being forced to send your data to someone else’s cloud to process it is.”

Even when information remains within a country, businesses must understand who can access it and who controls the technology that processes it.

Khalid believes regional companies can develop more of the software needed to manage these activities locally. “Platforms matter more than models here. Foundation models are becoming interchangeable, while the layer that decides how agents behave, where data stays and who answers for the results is where the lasting value sits.”

Local companies can build applications and security tools that give greater control over their operations.

Shawky makes a related point from the governance side. 

He explains that sovereignty depends less on which company processes the data than on whether a consistent governance layer sits above that provider, one that determines how sensitive data is discovered, accessed, and used, regardless of who operates the underlying infrastructure.

“The key is to separate sovereignty over data from dependence on any single infrastructure or technology provider,” he says.

Building that layer, he adds, requires strong metadata management, lineage tracking, and access controls robust enough that a government can swap providers without rebuilding its underlying data architecture.

BUILDING LOCAL EXPERTISE

The region is already developing AI technology beyond physical infrastructure. Projects like Falcon and Jais in the UAE and ALLaM in Saudi Arabia show growing efforts to create AI models that fit local languages and needs.

These developments give regional organizations more opportunities to develop AI rather than relying exclusively on imported products.

Zahran believes local research capabilities and intellectual property are essential to sustaining technological independence.

“Local talent, intellectual property, and research determine whether sovereignty lasts.”

Gulf countries can purchase advanced computing equipment through international partnerships, but developing the specialists needed to operate it requires sustained investment.

Universities can support that process through research and technical education. Private companies provide the practical experience needed to turn research into working products.

The region’s AI market is growing rapidly. Grand View Research projects it will reach $265 billion by 2033. But the region’s growing demand for AI doesn’t automatically translate into more opportunities for local technology companies.

For regional AI developers, however, technical capability is only part of the challenge.

AIREV says its OnDemand platform, developed in Abu Dhabi, serves more than four million users and supports over 300 agents across more than 50 languages.

Despite developing technology locally, the company identifies customer trust as a major obstacle when competing with established international suppliers. “Regional companies usually have to prove themselves twice before a government or large enterprise will sign anything, however good the product is,” says Khalid.

Building domestic expertise will have limited value if regional companies cannot find opportunities to test their products and demonstrate their reliability.

Shawky offers a more optimistic view on the region’s talent pipeline than the trust gap Khalid describes. 

He points to an established customer base across the UAE, Saudi Arabia, and Qatar that has adopted national data management strategies, which he says has helped build a pool of skilled local talent in step with adoption.

“Rather than a gap holding the region back, we’re seeing the skills base grow in step with the pace of adoption,” Shawky says.

He adds that the clearest room for growth is in foundational disciplines – data governance, data quality management, and metadata and lineage tracking – rather than in model development or AI engineering, since these are what let organizations trust their data enough to deploy AI on it.

WHAT REAL SOVEREIGNTY REQUIRES

Zahran proposes separating AI applications by sensitivity rather than treating every system as equally critical.

Under this approach, national security systems, citizen information, and critical infrastructure would operate on nationally managed infrastructure, with encryption keys held domestically.

Less sensitive commercial applications could continue using global cloud services hosted within the Gulf, subject to applicable local laws. The approach recognizes that different applications carry different risks. A business automating routine administrative work doesn’t necessarily require the same safeguards as a government agency handling confidential information.

For organizations, the key questions are what they need to control and whether they can keep running if an outside dependency changes.

Alaluf believes the region could eventually create economic value by developing locally governed AI agents that businesses can deploy across different platforms. But this opportunity depends on keeping control over the knowledge these systems gather, instead of letting it stay locked in foreign software.

“Sovereignty does not mean eliminating external dependencies; it means deciding what those dependencies are allowed to stop.”

The test will be practical: can a government or business enforce its rules, switch suppliers, and keep a critical system running without losing access to its data, models, or accumulated knowledge? Those choices will determine how much of its AI future it actually owns.

 

  Be in the Know. Subscribe to our Newsletters.

ABOUT THE AUTHOR

More

More Top Stories:

FROM OUR PARTNERS