GCC AI Sovereignty Is No Longer About Data Location. It Is About Who Holds Control
Roland Berger asserts that AI sovereignty in the GCC is no longer defined by data residency. Instead, true autonomy depends on the management of encryption keys, identity frameworks, and operational governance of AI systems.

GCC AI sovereignty and operational control over data infrastructure in the Gulf region
Across the GCC, the debate around AI sovereignty has long been framed as a data question: where are servers located, does data leave the country, and are residency requirements being met? These are important questions, but according to a new analysis by Roland Berger Middle East, they represent only the surface of a far deeper problem. The real question, as Nizar Hneini, Senior Partner and Managing Director at Roland Berger Middle East, puts it, is not where data is stored but who can access it, administer it, move it, and modify it, and under whose law they operate when they do.
That distinction is becoming increasingly urgent across the Gulf. Regional instability, accelerating AI adoption, and growing dependence on foreign technology vendors have pushed governments and enterprises to reconsider what digital sovereignty actually requires in practice. Storing data locally is necessary but not sufficient. A foreign jurisdiction can still reach locally-hosted data under instruments such as the US CLOUD Act, provided that encryption keys, identity management, and access governance sit offshore. Data residency, without operational control, is compliance theatre.
The problem runs deeper still at what Hneini describes as the operational layer, an area that is frequently overlooked in sovereignty discussions. Patching schedules, software upgrades, model updates, and incident response that are executed remotely by foreign vendors represent a transfer of operational authority that no data residency policy addresses. The same applies to centralised AI model hubs, which impose update cycles, policy changes, and performance standards entirely outside local control. As the UAE Cyber Factory's launch this week made clear in the context of critical national infrastructure, operational authority over systems, not just physical location, defines genuine resilience under pressure.
Hugo Carreira, Principal at Roland Berger Middle East, frames the challenge as one of enforceable design decisions across every layer of the stack. A sovereign AI environment requires contracts that limit cross-border data transfers and restrict subcontractors, in-country compute with genuine disaster recovery capability, and, critically, local control over identity management, privileged access, cryptographic key management, logging, audit evidence, and incident response. These functions cannot be contracted to a foreign managed service and still be called sovereign. The growing focus on identity as a control plane across GCC enterprises underscores this point: access governance is not a peripheral security concern. It is the mechanism through which operational authority is either maintained or ceded.
For GCC enterprises, this translates into a concrete priority: procurement governance. Supplier frameworks that limit over-concentration in vendors subject to foreign jurisdiction are not theoretical safeguards. They are practical constraints on the accumulation of dependency that compounds silently over time, becoming visible only when continuity is threatened.
Early-stage examples of this architectural shift are beginning to emerge in the region. Platforms such as MetisJean's JEAN are positioning operational governance: audit evidence, identity enforcement, and policy validation: as the foundation layer rather than an afterthought, building the kind of control architecture that procurement frameworks alone cannot deliver.
At the national level, the analysis points to shared platforms and AI factories as a mechanism for reducing reliance on any single commercial provider, while creating infrastructure conditions that support broader and more equitable adoption across the economy. The parallel for global reference frameworks is instructive: where markets such as France, the United States, Singapore, and Japan have embedded sovereignty into procurement and assurance mechanisms, through FedRAMP, SecNumCloud, ISMAP, and MTCS, the GCC has policy direction in place but remains, in Roland Berger's assessment, structurally ready and operationally behind. The gap is in execution. Translating policy ambition into enforceable procurement standards and control architectures is where the region's strategic readiness remains incomplete.
Arabic data represents a structural bottleneck that compounds this challenge. Only around 15 per cent of Arabic text available online is clean enough for model training, meaning global AI systems cannot easily close Arabic language performance gaps without curated, regionally-governed datasets. Ministries and public institutions hold large, untapped Arabic corpora across legal, administrative, and healthcare domains. Making that data available in a properly structured and governed form would materially improve both model performance and regional relevance, reducing dependence on generic global systems not designed for Gulf-specific contexts.
For SMEs, the model Roland Berger advocates depends on shared national platforms that smaller businesses can connect to, with packaged adoption mechanisms including implementation bundles, financing, and pre-qualified tools that reduce governance burden without sacrificing control.
The strategic conclusion is unambiguous. Operational control over AI systems is the defining capability priority for GCC organisations over the next two years. Data governance without enforcement fails. Compute without control is exposed to licensing, supply, and dependency risk. As Carreira summarises: jurisdiction follows the operator, not the server. The servers, it turns out, were always the easy part.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.