The Gap Is Not Where You Think It Is

Updated: Sep 4
What NCSC CAF v4.0 Reveals About AI Assurance in the Gulf — And Why Saudi Arabia Already Holds the Better Text
PRAECEPTA Cybersecurity LLC — Thought Leadership Series
Riyadh · Dubai · Nairobi | September 2026
Executive Summary
A claim now circulating in regional security commentary runs roughly as follows: the NCSC's Cyber Assessment Framework v4.0 now covers AI risk, no GCC framework does, and that gap matters.
Both halves of that claim are wrong. The corrected version is considerably more useful.
CAF v4.0's AI content is modest. The NCSC's own headline changes are four: improved understanding of the attacker, secure software development, better security monitoring and threat hunting, and improved coverage of AI-related cyber risk. There is no AI objective, no AI principle, no standalone AI chapter. What exists is integrated language across existing outcomes, a light addition to risk management referencing new and emergent technologies, and one substantive new requirement — that where automated decision-making technologies are used, they are designed and applied with appropriate restrictions preventing their manipulation to take hostile action against systems supporting essential functions. That is a well-placed hook. It is not a governance regime.

The GCC is not empty — and in one case it is ahead. Saudi Arabia's National Cybersecurity Authority issued draft AI Cybersecurity Guidelines (AICG-1:2026), open for consultation from 5 July to 5 August 2026. It spans four cyber domains — governance, defence, resilience and third-party — across the full AI lifecycle from design and development through deployment, production and retirement, and it explicitly addresses both generative and agentic AI. Qatar Central Bank's 2024 AI Guideline is binding on regulated financial entities. CBUAE issued AI/ML guidance to licensed financial institutions in February 2025. SDAIA's AI Ethics Principles and Generative AI Guidelines have been operative since 2024.
On text alone, AICG-1:2026 is more detailed, more lifecycle-complete and more threat-current than anything in CAF v4.0.
So the gap is not coverage. It is three other things:
# | The real gap | Why it bites |
1 | Assurance | GCC AI instruments sit largely outside the mandatory baselines against which entities are actually assessed. CAF's single requirement sits inside one. |
2 | Threat framing | Most regional AI instruments treat AI as an ethics, privacy and consumer-protection problem. CAF treats it as an attack surface against essential functions. These generate different controls. |
3 | Convergence | No framework adequately addresses AI inside OT/ICS — and the Gulf's structural exposure is the largest in the world. |
Part One: The Assurance Gap
This is the decisive gap, and it is architectural rather than editorial.
CAF is not guidance. It is an assessment framework embedded in a supervisory relationship — outcome-based, evidenced, and used by competent authorities to form judgements about operators of essential services. When the NCSC threads AI risk through CAF outcomes, AI risk immediately acquires an assessor, an evidence expectation, an audit trail and a consequence.
Now examine the regional stack:
Jurisdiction | Mandatory cyber baseline | AI-specific instrument | Joined to the baseline? |
Saudi Arabia | ECC-2:2024 (government / CNI); NCNICC-1:2025 (non-critical private) | SDAIA AI Ethics Principles; SDAIA GenAI Guidelines (government and public); AICG-1:2026 | Architecturally yes; formally not yet. NCA states AICG-1:2026 applies requirements already defined in other NCA publications, in the AI context — a genuine overlay. Assessment status turns on final tier placement. |
UAE | UAE IA Regulation / NESA tiering; CBUAE Cybersecurity Framework | CBUAE AI/ML guidance (Feb 2025); policy activity via Cybersecurity Council, AI Office, Council for AI & Blockchain, Abu Dhabi AIATC | No. Sectoral and strategy-led; no binding cross-sector AI cyber instrument identified |
Qatar | NIA National Cybersecurity Framework | QCB AI Guideline 2024 (binding, financial sector); National AI Strategy and MCIT principles (voluntary) | Within the QCB perimeter only |
Bahrain / Kuwait / Oman | CBB Cybersecurity Framework; national equivalents | No national AI governance instrument identified in available sources | No — treat as indicative, not confirmed |
The pattern is unmistakable. The region has produced AI governance documents of respectable and in one case superior quality — but they largely inhabit a parallel universe to the control frameworks that carry supervisory teeth.
An entity in Riyadh can be fully ECC-2:2024 compliant while operating a materially insecure production model estate. An entity in Abu Dhabi can pass a NESA assessment without a single question asked about training-data lineage, model access control or agent credential scope.
The gap that matters is not "no AI coverage." It is AI coverage with no assurance mechanism attached. Ethics principles are not audited. Control baselines are.
Part Two: The Threat-Framing Gap
Read the regional instruments closely and a consistent conceptual posture emerges across most of them: AI is framed as something that might harm people — through bias, opacity, privacy erosion or poor consumer outcomes. Transparency, accountability, human oversight, fairness. All correct. All insufficient.
CAF v4.0's automated decision-making requirement adopts the inverse frame: AI is something an adversary manipulates to harm the essential function. The model is not the victim. The model is the vector.
That distinction determines which controls get built.
Frame | Controls it generates | Controls it omits |
AI as ethics / consumer risk | DPIAs, disclosure notices, human-in-the-loop policy, bias and fairness testing | Model access control, inference-path monitoring, data-poisoning detection, adversarial robustness testing, model supply-chain integrity, agent action-scoping |
AI as attack surface | Prompt-injection defence, output trust boundaries, model integrity verification, credential scoping for agents | Fairness, explainability obligations, consumer redress |
Most GCC-regulated entities are currently building the left column and calling it AI security. It is not. It is AI compliance. PRAECEPTA's assessment is that these are non-substitutable control sets, and conflating them is now the single most common AI-security failure mode we encounter in regional engagements.
Here Saudi Arabia separates itself decisively. AICG-1:2026 crosses the divide by design: its four domains are cyber domains, not ethics domains. Its explicit treatment of agentic AI as a distinct threat class is ahead of the UK — an agent holding tool access and standing credentials is a privilege-escalation and insider-threat problem, not a content-moderation problem. CAF v4.0 gestures at this through the automated decision-making clause; AICG-1:2026 names it. Its inclusion of retirement in lifecycle scope is a further sophistication: model decommissioning, weight destruction and embedding disposal are unaddressed almost everywhere else in global practice.
Part Three: The Convergence Gap
Here no framework is adequate, but the Gulf's structural exposure is the largest — for reasons unrelated to regulatory quality.
The region is deploying AI into industrial and critical-national contexts at a velocity no European operator is matching: sovereign compute build-out, AI-optimised grid and desalination operations, hydrocarbon predictive maintenance, autonomous port and border logistics, AI-mediated government service delivery. The AI is arriving inside Purdue Levels 2 and 3, not adjacent to them.
CAF v4.0's automated decision-making clause is the right instinct — it is essential-function-centric, which is precisely the correct lens for OT. But it is one requirement, not a control set. IEC 62443 has no AI concept. ECC-2:2024 has no AI concept. NIA has no AI concept.
The question none of them answers: when a poisoned model recommends a setpoint change, which safety instrumented function catches it, and who owns that control?
PRAECEPTA's working position — the deterministic envelope. AI in OT requires model outputs constrained by non-ML guardrails that sit inside the safety boundary and are never themselves AI-mediated. Model advisory; human or deterministic logic authoritative at every Level 1 and Level 0 write. This is an architectural constraint, not a procedural one, and no current framework mandates it.
The Signal in the Name
One detail deserves the attention of every CISO and regulator in the Gulf, and it has gone almost entirely unremarked.
In the NCA's own document taxonomy, the distinction between classes is the distinction between mandatory and advisory:
NCA document class | Examples | Force |
Controls | ECC-2:2024, CCC, DCC, OTCC, NCNICC-1:2025 | Mandatory; assessed |
Guidelines | IGCC and comparable | Advisory; not directly assessed |
AICG-1:2026 is titled Guidelines. The artefact published on the NCA's own content delivery network carries the filename AI_Cybersecurity_Controls_EN.pdf.
That inconsistency is either a drafting artefact or the visible trace of a live question about which tier AI requirements belong in. Its resolution determines the region's AI security trajectory:
Finalised as Guidelines — Saudi Arabia will hold the best-architected AI cyber overlay in the world, sitting in the advisory tier, unassessed. The assurance gap thesis is fully vindicated, and the Kingdom will have built the right instrument and declined to enforce it.
Finalised as Controls, or incorporated by reference into ECC and NCNICC assessment scope — Saudi Arabia closes the assurance gap before the United Kingdom does, and becomes the global reference case for AI cyber assurance.
The PRAECEPTA Prescription
For regulators
The design question is answered — copy it. AICG-1:2026 is the regional reference architecture: an AI overlay onto an existing mandatory baseline, full-lifecycle, with agentic AI named as a distinct threat class. That is structurally superior to CAF v4.0's integrated-language approach and to any standalone AI framework. UAE, Qatar, Bahrain, Kuwait and Oman should adapt, not author. Regional convergence on one structure is worth more than five bespoke ones.
Finish it. Our recommendation to the NCA is that AI cyber requirements belong in the assessed Controls tier, or be explicitly incorporated by reference into ECC and NCNICC assessment scope. The engineering is complete. The enforcement decision is not.
Bind the ethics track to the control track. Publish explicit, assessable SDAIA-to-ECC mappings and jurisdictional equivalents. Two parallel regimes produce two parallel evidence sets and one real gap.
Adopt the essential-function lens. CAF's framing travels better across sectors than a technology-classification lens, and ages more slowly.
For operators — do not wait for finalisation
Priority | Action | Rationale |
1 | Build an AI asset inventory: models, agents, embeddings, third-party inference endpoints | You cannot govern an uninventoried estate. Shadow AI is the dominant discovery finding in our regional engagements |
2 | Extend DSPM to training corpora, prompt logs and inference data | Residency and transfer obligations under KSA PDPL, UAE IA, DIFC DP Law 2020 and ADGM DP Regs 2021 attach to these datasets. Cross-border transfer exposure is commonly unassessed — flag now |
3 | Apply AICG-1:2026's four-domain, full-lifecycle structure voluntarily | It is the strongest available AI cyber structure and the likely basis of the final instrument. Early adoption is a defensible position regardless of tier outcome |
4 | Apply CAF v4.0's automated decision-making test to essential functions | Best-articulated public control on AI manipulation of critical systems |
5 | Threat-model agents as privileged identities — MITRE ATT&CK v15 plus adversarial-ML extension | Agentic compromise presents as legitimate authenticated activity and evades content-layer controls entirely |
6 | Extend SBOM and third-party processes to model provenance and integrity, per NIST SP 800-161r1 logic | Model supply chain is the least-governed dependency class in the region |
Conclusion
The original premise reaches the right conclusion by the wrong route. The gap matters — profoundly. But it is not that the Gulf has failed to write about AI risk. Saudi Arabia has written the better instrument. The gap is that the region's AI requirements sit predominantly in advisory tiers, framed for ethics committees rather than adversaries, while AI is deployed into critical national infrastructure faster than almost anywhere on earth.
CAF v4.0's contribution is not superior AI content. It is placement. One modest, well-sited AI requirement inside an enforced assessment framework outweighs a hundred pages of excellent unenforced guidance.
Saudi Arabia now holds the better text. Whether it also acquires the better placement is a decision, not a drafting exercise — and as at the date of this publication, that decision is undeclared.
This constitutes security architecture guidance, not legal advice. Engage qualified legal counsel in the relevant jurisdiction for binding interpretation of PDPL, UAE IA, DIFC, ADGM, NIA, CBB or NCA obligations




Comments