Shadow AI
Tools adopted by teams, and features enabled by default inside software you already bought. The most common finding in a first discovery exercise, and the reason an inventory has to be technical as well as declared.
What we solve
Adoption is running well ahead of governance in most organisations across the Gulf. The first problem is almost never policy — it is that nobody can list the AI systems already in the estate.
Most first discovery exercises find three to five times what the organisation expected.
Boards across the region are asking the same two questions this year: are we behind on AI, and are we exposed by it. Both are usually answered with a policy document, which is the wrong artefact. A policy written over an estate nobody has inventoried governs nothing.
The organisations that are furthest ahead did the unglamorous thing first. They found the AI already running — the tools a team adopted, the features a vendor switched on, the model someone built in a business unit — and only then decided what to permit, what to control and what to stop.
That is where we start, and it is why our first deliverable is an inventory rather than a framework.
Five stages, operating continuously rather than as an annual assessment. Each writes to the same control library and evidence base as your cyber and privacy programme.
Eight exposures that show up repeatedly, in roughly this order.
Tools adopted by teams, and features enabled by default inside software you already bought. The most common finding in a first discovery exercise, and the reason an inventory has to be technical as well as declared.
Confidential, regulated or personal data entering a third-party model through a prompt, a plugin or an integration — often with no record that it happened.
Performance degrading quietly after go-live, or behaving differently on a population it was not evaluated against. The failure mode nobody is monitoring for.
Your supplier swaps or updates the underlying model and your risk position changes without a change request being raised anywhere in your organisation.
Credit, pricing, hiring, claims and access decisions carry privacy obligations, explainability expectations and a reversal path that has to exist.
Where an AI system can act — call a tool, send a message, change a record — its blast radius is the permissions you gave it.
Training data rights, output ownership and the contamination risk of generated content entering products or filings.
The question that ends most board discussions: when the model is wrong, who was accountable, and can you show what they approved?
Advisory, implementation and managed operation — the same three modes as the rest of the practice.
AI regulation in this region is moving from principles to expectations to enforceable requirements. Indicative; applicability is confirmed per client during scoping.
| Instrument | What it is | What it means operationally | Market |
|---|---|---|---|
| ISO/IEC 42001:2023 | AI management system | The certifiable standard. Policy, roles, objectives, risk assessment, controls and internal audit — structured so the AI management system shares evidence with your ISMS rather than duplicating it. | International |
| NIST AI Risk Management Framework | Govern, Map, Measure, Manage | The neutral spine we use when several regimes apply at once, and the one most technology teams already recognise. | International |
| SDAIA AI Ethics Principles and Generative AI guidelines | Saudi Arabia | Principles-based expectations on fairness, transparency, accountability and human oversight, with guidance on generative AI use in government and regulated entities. | KSA |
| NCA and sector expectations | Saudi Arabia | AI systems in scope carry the same cybersecurity control expectations as any other system — plus the data controls that govern what the model is trained and run on. | KSA |
| UAE AI Charter and national AI strategy | United Arab Emirates | Federal direction on responsible AI, alongside sector guidance and the AI governance expectations emerging from financial and health supervisors. | UAE |
| Financial supervisor expectations | GCC central banks | Model risk management, explainability, human oversight and outsourcing expectations where AI supports credit, fraud, AML or customer decisions. | GCC |
| EU AI Act | Extraterritorial reach | Applies to Gulf organisations placing AI systems on the EU market or whose output is used in the EU. Risk-tiered obligations with real deadlines and real penalties. | EU |
| UK approach and ICO guidance | United Kingdom | A regulator-led model rather than a single statute, with ICO guidance on AI and data protection doing most of the operational work. | UK |
| Privacy law, everywhere | PDPL and GDPR | Training data, inference data and automated decision-making are all personal data questions before they are AI questions. Lawful basis, transparency and the right not to be subject to solely automated decisions apply regardless of the model. | All markets |
Most organisations do not need a two-year programme. They need to know what they have, stop the two things that are genuinely dangerous, and put a governed door in front of everything new.
Technical and declared inventory of the AI estate. Classification by use case, data, affected parties and decision impact. The findings conversation is usually the moment the programme gets funded.
The small number of use cases carrying real exposure get assessed and controlled first. Everything else is registered and permitted to continue under monitoring, because stopping all of it is neither necessary nor survivable politically.
An intake and approval path for new AI use cases, with risk tiers, evidence requirements and named approvers. From this point the estate stops growing ungoverned.
ISO/IEC 42001 structures stood up on the controls now in place, sharing evidence with the ISMS. Certification readiness if you want it; a defensible position either way.
Drift, vendor change and new adoption tracked. AI risk reported to the board in the same currency as every other risk.
We are asking you to trust our AI governance. It is reasonable to test it.
How AI governance fits a transformation programme · Quantifying AI exposure in USD