Table of Contents
A government can keep its data inside its borders and still have limited control over its AI.
The AI infrastructure may be local, but the cloud provider, AI model, GPUs or critical software may still be controlled or supplied by foreign companies. If one of those dependencies becomes unavailable, the government may have limited ability to switch providers without disrupting essential services.
That is the question behind Sovereign AI.
Across the GCC, governments are investing heavily in AI infrastructure, models, cloud capacity and regulation, but they are taking different paths.
Saudi Arabia is building across the AI stack. The UAE is focusing on control over critical AI infrastructure and regulated use. Qatar is developing selective strategic capabilities. Oman is combining local capabilities with cloud and data governance. Kuwait is building local AI infrastructure through global partnerships while its AI governance framework develops.
The difference is important because Sovereign AI is not about eliminating foreign technology. It is about deciding which parts of the AI stack a country needs to control, which dependencies it can accept, and how resilient those dependencies are.
Sovereign AI is a question of control
The AI stack can be viewed through four layers:
Infrastructure: data centers, compute, chips and cloud.
Data: where information is stored, processed and governed.
Models: the AI models themselves, including who develops, trains, controls and updates them.
Applications: the systems that make decisions or deliver government services.
A country does not need complete control over every layer to have meaningful sovereignty.
Instead, the strategic question is:
Which layers carry the greatest risk, and how much control is enough at each one?
GCC’s five major markets are answering that question differently.
Saudi Arabia: Build the stack
Saudi Arabia is arguably taking the most expansive approach.
Rather than focusing on one part of the AI ecosystem, the Kingdom is attempting to build capabilities across the value chain through government-backed investment.
A central part of that effort is HUMAIN, a Public Investment Fund-owned Saudi AI company launched in May 2025 to build and operate capabilities across the AI stack. Its scope spans next-generation data centers, cloud and computing infrastructure, AI models and applications.
HUMAIN and NVIDIA announced plans for AI factories in Saudi Arabia with projected capacity of up to 500 MW over five years, powered by hundreds of thousands of NVIDIA GPUs. The first phase includes an 18,000-GPU NVIDIA GB300 Grace Blackwell system.
That infrastructure is only one part of the strategy. Saudi Arabia is also developing national AI governance capabilities. The Saudi Data and Artificial Intelligence Authority’s National AI Risk Management Framework provides a methodology for identifying, assessing, treating and monitoring AI risks, linking AI deployment to reliability, responsible use and governance.
The Saudi approach is therefore about more than hosting AI locally.
It is about building enough compute, models, applications, talent and governance capacity that the Kingdom has meaningful control over the systems it considers strategically important.
In Sovereign AI terms, Saudi Arabia is trying to build the stack.
UAE: Control the critical layers
Rather than attempting to build every component domestically, UAE is placing particular emphasis on controlling the layers that matter most to critical sectors.
A strong example is financial services.
In February 2026, the Central Bank of the UAE announced a partnership with Core42 to develop what it described as a dedicated sovereign financial cloud ecosystem. The initiative is designed around isolated infrastructure, data sovereignty, operational resilience and continuous availability of critical financial services.
At the same time, the Central Bank has been tightening expectations around how financial institutions use AI. Its AI guidance addresses issues including transparency, accountability, explainability, bias and data privacy.
The broader regulatory approach is important for Sovereign AI because it goes beyond asking where an AI system is hosted. CBUAE expects institutions to maintain oversight of AI systems and manage risks associated with third-party providers. The underlying principle is clear: outsourcing an AI capability does not outsource responsibility for it.
That gives the UAE a different model of sovereignty. The objective is not necessarily to own every layer. It is to control the critical layers and the dependencies around them.
Qatar: Build selective strategic capabilities
Qatar is pursuing a more selective model.
The country is investing heavily in AI infrastructure, but it is doing so through strategic partnerships rather than attempting to recreate the entire AI ecosystem domestically.
One of the clearest examples is Qai, an AI company and Qatar Investment Authority subsidiary. In December 2025, Qai and Brookfield announced a $20 billion joint venture focused on AI infrastructure in Qatar and selected international markets. The partnership includes plans for fully integrated AI facilities and an integrated compute center.
Qai’s role is particularly relevant. It is designed to develop, operate and invest in AI infrastructure, technologies and systems while working with global technology firms and research institutions.
Qatar is also building governance around AI deployment. Qatar Central Bank introduced AI guidelines in 2024 covering areas including governance, risk and security management, fairness, reliability, transparency and data protection.
The result is a model built around strategic capabilities and trusted deployment.
Qatar does not need to control everything to strengthen its position. It needs enough AI infrastructure, expertise and governance to ensure that the AI capabilities most important to the country remain reliable and controllable.
Oman: Localize and govern the cloud
Oman’s approach is particularly interesting because it shows that Sovereign AI does not have to mean building everything from scratch.
Oman has been developing national AI capabilities through its National Program for AI and Advanced Digital Technologies, aligned with Oman Vision 2040. The program focuses on AI adoption, local capabilities, AI infrastructure, research and human-centered governance.
The country has also established a broader policy framework for safe and ethical AI. But one of the most important developments for Sovereign AI came in 2026 with Oman’s Cloud Computing First Policy. The policy requires government entities, apart from security and military agencies, to prioritize cloud-based solutions and use licensed providers while complying with cybersecurity, data protection and risk-management requirements. It also establishes controls for data hosted inside and outside Oman. Government entities are required to classify data before storing or processing it in cloud environments, while cloud providers must obtain approved certifications.
Oman is also developing domestic AI capabilities, including Moeen AI, a locally developed language model designed to support government work such as document analysis, summarization, translation and content generation, while keeping the model and its AI infrastructure within Oman.
So, Oman’s model combines local capabilities, controlled cloud adoption and data governance.
Kuwait: Partner to localize
Kuwait is at an earlier stage, but its direction is becoming clearer.
The country’s draft National AI Strategy 2025–2028 proposes work across government, healthcare, energy, education, transport and public safety, alongside AI governance, privacy, security, AI infrastructure and workforce development.
Kuwait has been working with Microsoft and its government technology bodies on an AI-powered Azure region, alongside an AI Innovation Center and Cloud Center of Excellence.
This points to a different route toward sovereignty.
Kuwait is not trying to become independent of global technology providers. Instead, it is looking to localize AI infrastructure and capabilities through partnerships while developing the governance needed to manage those dependencies.
That distinction will become increasingly important as AI becomes embedded in government services.
Five countries. Five paths to control.
The GCC does not have one Sovereign AI model. It has several.
But none requires complete technological isolation. For most countries, that is neither realistic nor necessary. Advanced AI still depends on globally concentrated semiconductor supply chains, cloud platforms, specialized expertise and frontier models. The more useful question is therefore not whether a country can control everything, but which dependencies it can afford to have and which it cannot.
Before deploying a critical AI system, governments should ask:
- Where does the data go?
- Who controls the AI infrastructure and underlying model?
- Can the system be audited, interrupted or replaced?
- What happens if access is suddenly restricted?
- Which AI capabilities must remain available during a geopolitical or commercial disruption?
These questions turn Sovereign AI from a technology ambition into a risk and resilience decision.
That is the broader GCC lesson. Saudi Arabia, the UAE, Qatar, Oman and Kuwait are taking different paths because they do not need the same level of control over every layer of AI.
The strategies differ. The direction does not: AI is becoming too important for governments to leave critical technological dependencies unexamined.
Table of Contents
Share this article
Get insights like this in your inbox
Practical guidance on secure, governed and high-performing AI.
No spam. Unsubscribe anytime.