AI Regulation Tracker / Cybersecurity guidance
Qatar's cyber agency, not its data regulator, set the baseline AI deployers are measured against
Qatar's National Cyber Security Agency issued Guidelines for Secure Adoption and Usage of Artificial Intelligence, version 1.0. They sit alongside the data protection law and are referenced by Qatar's own national AI strategy.
Why the cyber agency owns this
Most jurisdictions route AI oversight through a data protection authority or a new AI office. Qatar did not. The National Cyber Security Agency issued the operative guidance, which tells you how the state frames the risk: AI is treated first as an attack surface and an assurance problem, and only then as a rights problem.
That framing has a practical consequence. The questions you will be asked are security questions before they are fairness questions.
What the guidelines address
They cover secure deployment of AI systems and the risks the agency considers critical, including privacy violations, AI bias, security vulnerabilities and compliance challenges, with particular attention to sectors where AI processes personal data such as finance, healthcare and law enforcement.
How they interact with the PDPPL
The binding instrument for personal data in Qatar is the Personal Data Privacy Protection Law, Law No. 13 of 2016, which predates the current wave of generative AI deployment by several years and was not drafted with model training in mind. The NCSA guidelines do not replace it. They describe how to deploy AI securely while meeting its requirements, which is why practitioner guides cite the two together rather than treating the guidance as freestanding.
The distinction matters if you are assessing exposure. A breach of the guidelines is not automatically a breach of law. A breach of the PDPPL is.
Where this sits in the Gulf
Gulf states have converged on guidance-first AI governance issued by security or data authorities, with binding AI statutes still absent.
| Jurisdiction | Lead body for AI guidance | Binding AI statute | Underlying data law |
|---|---|---|---|
| Qatar | National Cyber Security Agency | None | PDPPL, Law No. 13 of 2016 |
| Saudi Arabia | SDAIA | None | Personal Data Protection Law |
| UAE | National AI and data authorities; Central Bank for finance | None | Federal data protection law |
| Morocco | CNDP | None | Law 09-08 |
What this means for a firm deploying AI in Doha
The practical read is that your AI assurance evidence should be framed in security terms. Model inventory, access control, logging, vendor assurance and incident response are the vocabulary the NCSA works in, and a deployer who can produce that documentation is speaking the regulator's language.
Bias sits in an unusual position here. It is named as a critical risk in guidance issued by a cyber security authority rather than an equality regulator, which means you may be asked to evidence bias testing as part of a security and assurance review rather than a discrimination review. The artefacts are similar; the framing and the audience are not.
Sector supervision still applies on top. Financial institutions answer to the central bank's own AI expectations, and health deployments carry their own oversight. The NCSA guidance is a floor across the economy, not a ceiling or a substitute.
The version number is also information. Version 1.0 of a national guidance document usually means the authority expects to revise it as deployment patterns become clearer, and it means early adopters are effectively helping set the baseline. Firms that engage now, rather than waiting for a version 2.0 that reads more like a rulebook, tend to end up with a posture that survives the revision.
What the guidelines do not do
They do not create a licensing or registration regime for AI systems. They do not set administrative fines of their own. They are version 1.0, which signals expected revision rather than a settled framework. And they do not displace sectoral supervision, including the central bank's own expectations for financial institutions.
Frequently asked questions
Are the NCSA AI guidelines legally binding in Qatar?
They are guidance rather than statute. The binding obligations for personal data come from the PDPPL, Law No. 13 of 2016. In practice the guidelines are the baseline organisations are assessed against for secure AI adoption.
Who issued them?
Qatar's National Cyber Security Agency, not the data protection authority and not a dedicated AI regulator.
Which sectors do they emphasise?
Sectors where AI processes personal data, with finance, healthcare and law enforcement singled out.
Does Qatar have an AI law?
No dedicated binding AI statute. Governance runs through this guidance, the PDPPL, and sectoral supervision such as central bank expectations for financial institutions.
What evidence should a deployer be ready to produce?
Security and assurance artefacts: an inventory of AI systems in use, access controls, logging and monitoring, vendor and model assurance, incident response covering AI-specific failure modes, and documentation of bias testing. The guidance frames bias as a critical risk, so bias evidence may be requested as part of a security review rather than a separate discrimination assessment.
Do the guidelines apply to systems that do not process personal data?
The guidance addresses secure adoption and usage of AI generally, with particular emphasis on contexts where personal data is involved. Systems outside personal-data processing still fall within the security framing, but the PDPPL overlay that creates binding legal duties does not attach.
Last verified: July 27, 2026