REGULATIONS ACROSS REGIONS / BEGINNER

Qatar, Bahrain, Oman And Kuwait: What Has And Has Not Been Published

As of October 2026, no post-quantum instrument and no binding AI law were found in Qatar, Bahrain, Oman or Kuwait. Here is what still applies, which AI policies exist, and what to watch.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Two Gulf states have moved on post-quantum cryptography in writing. Saudi Arabia’s central bank has set dated duties for its financial institutions, and the UAE has a national encryption policy with a post-quantum section. The other four members of the Gulf Cooperation Council, Qatar, Bahrain, Oman and Kuwait, are harder to read from the outside.

This article reports what research for this group could and could not confirm, as of October 2026. The short answer is that no post-quantum or quantum-readiness instrument was found from any of the four states, their national cyber security agencies or their central banks. That is a statement about search coverage, not proof that nothing exists. Several official sites did not load or refused automated access, so this piece is written as a record of what is known and a list of what to watch, rather than a summary of rules.

AI is covered in its own section below. No binding AI law was found in any of the four states, though Qatar’s central bank, Bahrain and Oman have issued AI rules for parts of their economies.

What Was Searched

Research covered the national cyber security bodies and central banks of each state: Qatar’s National Cyber Security Agency (NCSA) and the Qatar Central Bank; Bahrain’s National Cyber Security Centre and the Central Bank of Bahrain; Oman’s Central Bank and its national cyber security function; and Kuwait’s Central Bank and National Cyber Security Center. The aim was to find any instrument that names post-quantum cryptography, quantum risk or a cryptographic inventory, and any general cyber rule with cryptography controls.

StateCyber Framework With Cryptography ControlsPost-Quantum InstrumentStatus Of What Was Found
QatarNCSA runs a National Information Assurance (NIA) certification scheme; the underlying text was not retrievedNone foundScheme confirmed on an official listing; content and legal force not verified
BahrainCentral Bank of Bahrain Rulebook not reviewed for this articleNone foundNot verified
OmanCentral bank and national cyber agency texts not retrievedNone foundNot verified
KuwaitCentral bank and national cyber agency texts not retrievedNone foundNot verified
Framework cards for four GCC states, as of October 2026. 'Not retrieved' means the official text could not be loaded for this article, not that it does not exist.

For Qatar, the NCSA’s website lists a National Information Assurance certification under its national compliance framework.1 The site’s pages did not render for automated retrieval, so the content of the NIA material, including any cryptography domain, and the question of who must comply could not be checked against the primary text. The Qatar Central Bank’s general cyber and technology risk rules were not reviewed for this article; its AI guideline is covered below.

For Bahrain, the Central Bank of Bahrain Rulebook could not be retrieved during research, and its rules were not reviewed for this article.2 For Oman and Kuwait, no central bank or national cyber agency framework text could be located as a primary document during research. The specific wording of any framework has to be read before anyone relies on it.

What Still Applies

A firm in Doha, Manama, Muscat or Kuwait City is not outside cryptography rules simply because its national regulator has not published post-quantum text. Three kinds of obligation reach across borders.

Payment card rules. PCI DSS is a contractual standard that applies wherever card data is stored, processed or transmitted. Since 31 March 2025, requirement 12.3.3 has required a current list of the cipher suites and protocols in use, an active watch on whether each stays safe and a written plan for reacting to foreseeable cryptographic weaknesses, all revisited at least every 12 months.3 Status: Binding (contractual). Cryptography Compliance covers it in depth.

Group and cross-border rules. A Gulf banking group with a Saudi subsidiary falls under SAMA’s quantum circular for that subsidiary, which requires cryptographic asset classification procedures by the end of 2026 and a quantum risk assessment by the end of March 2027.4 Status: Binding for SAMA-supervised institutions. A firm that operates UAE critical information infrastructure falls under the UAE National Encryption Policy, whose post-quantum section asks for a public-key cryptography inventory and a transition plan.5 Status: Binding for UAE federal and emirate government entities and non-government CII operators. See the Saudi Arabia and UAE articles.

Parent and partner expectations. Groups headquartered in the EU, UK or US bring their home regulators’ expectations with them, and international partners may ask about cryptographic inventories in due diligence. The overview of post-quantum and cyber regulation in 2026 shows which of those expectations are binding and which are guidance.

AI Rules In The Four States

As of October 2026, no binding AI law was found in Qatar, Bahrain, Oman or Kuwait. What exists is narrower: a central bank guideline in Qatar, government policies in Bahrain and Oman, and national strategies.

StateMain AI InstrumentWho It Applies ToStatus
QatarQatar Central Bank Artificial Intelligence Guideline, in force 4 September 2024Firms licensed by the Qatar Central BankSupervisory, with approvals and reporting to the bank
QatarNational AI Strategy, adopted October 2019National goalsStrategy
BahrainGeneral Policy for the Use of AI, version 1.0, 20 May 2025Government entitiesBinding on government entities (policy, not law)
BahrainStandalone AI lawUnder parliamentary review in November 2025, per UNESCO; no enacted law found as of October 2026Draft
OmanGeneral Policy for the Safe and Ethical Use of AI Systems, first version, April 2025Government units, and regulated private institutions that build or use AIMinistry policy requiring compliance (not a law)
KuwaitNo government AI instrument retrievedNot applicableNo binding AI law found
Main AI instruments in four GCC states, as of October 2026. A policy that requires compliance is still not a law, so the status column says whom it binds.

Qatar. The central bank’s guideline is the most detailed of these instruments. It covers a licensed firm that builds AI, buys it or outsources work that depends on it. Firms must keep a register of their AI systems and send it to the bank every year, obtain the bank’s approval before launching an AI system they provide or signing a high-risk AI purchase or outsourcing deal, give every system a human oversight protocol, and defend models against prompt injection and query attacks. Customers must be told when they deal with AI and can ask a qualified person to review a negative AI decision.6 The bank calls it a guideline, but most of it is written as duties. Separately, the transport and communications ministry adopted a blueprint from the Qatar Computing Research Institute as the national AI strategy in October 2019,7 the NCSA released guidelines on secure AI use in February 2024,8 and the Ministry of Communications and Information Technology (MCIT) described two AI ethics guidance documents in May 2025.9 The NCSA and MCIT texts were not retrieved for this article.

Bahrain. The Information and eGovernment Authority’s AI policy was approved by a ministerial committee on 20 May 2025, and government entities have had to comply since that date. They must adopt AI in cooperation with the authority and follow its standards, should audit their AI use regularly, and remain responsible for any harm, which is attributed to people rather than the machine.10 The policy does not cover private companies. A UNESCO readiness assessment dated November 2025 describes a standalone AI law, with licensing and penalties, still under parliamentary review.11 The assessment is not a rule, and no enacted AI law was found as of October 2026.

Oman. The transport, communications and IT ministry published its AI policy, in Arabic, in April 2025. It covers government units and regulated private institutions that build or use AI, which must comply in full and assess their systems regularly for accuracy, bias and harmful content. Developers must assess ethical, social and environmental impact before release and mark generated content. The ministry monitors government units and reports to the Council of Ministers, while sector regulators monitor the firms they supervise.12

Kuwait. No AI law, AI policy or published government AI strategy was found. The one strategy document reviewed is a May 2024 Microsoft whitepaper, prepared in cooperation with the Central Agency for Information Technology, which proposes a national AI strategy framework. It is a vendor’s proposal, not government policy.13

None of the AI documents whose full texts were reviewed mentions quantum computing. On cryptography, Oman’s policy asks for classified data used in AI to be protected with measures such as encryption, multi-factor authentication and anonymisation,12 and the Qatar Central Bank guideline applies the bank’s sector information security regulation to every AI deployment.6

  1. In effect

    Qatar · Qatar Central Bank Supervisory

    The guideline enters into force, including the AI register disclosed to QCB annually, QCB approval before launching a new AI system as provider or signing a high-risk AI purchase, licensing or outsourcing agreement, human oversight protocols and customer notification.

    Artificial Intelligence Guideline (Regulating the Use of Artificial Intelligence by QCB Licensed Entities). Applies to entities regulated by the Qatar Central Bank that develop, buy or outsource AI. Source · Explainer · Verified 7 Oct 2026

  2. In effect

    Bahrain · Information and eGovernment Authority (approved by the Ministerial Committee for Information and Communication Technology) Binding

    Government entities must comply with the rules, requirements and guiding principles of the policy from the date of its approval.

    General Policy for the Use of Artificial Intelligence, version 1.0. Applies to government entities in Bahrain only (a government policy, not a law). Source · Explainer · Verified 7 Oct 2026

AI dates in the four states. Both have passed and the duties apply now.

What To Watch

The one regional example of a dated instrument so far, SAMA’s August 2026 circular, focuses on inventory, risk assessment and governance. If the four states act, a first step of that kind seems more plausible than a full migration mandate. That is an inference from a single example, not a forecast from any official source.

There is one early signal from Qatar. At its fifth National Cyber Governance and Assurance Affairs Conference, reported by the Qatar News Agency on 5 October 2026, the NCSA set out initiatives that include planning for the post-quantum era.14 Status: Announcement. No instrument or published text has followed so far.

Practical signals worth tracking are updates to the four central banks’ cyber or technology risk rules, new versions of Qatar’s national information assurance material, and any regional statements through GCC bodies. A firm that has already built a cryptographic inventory with classification by sensitivity and migration priority will be well placed whichever form these take. Which Regulators Require A Cryptographic Inventory? explains the fields that the existing regimes ask for.

For AI, watch Bahrain’s draft law. AI Regulation At A Glance compares these states with other regions.

Footnotes

  1. National Cyber Security Agency of Qatar, “National Information Assurance (NIA) Certification”, accessed October 2026. ncsa.gov.qa ↩

  2. Central Bank of Bahrain, “CBB Rulebook”, accessed October 2026. cbben.thomsonreuters.com ↩

  3. PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirement 12.3.3. pcisecuritystandards.org ↩

  4. Saudi Central Bank (SAMA), Circular 482021280, “Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩

  5. UAE Cyber Security Council, “National Encryption Policy”, version 1.0, September 2025. csc.gov.ae ↩

  6. Qatar Central Bank, “Artificial Intelligence Guideline (Regulating the Use of Artificial Intelligence by QCB Licensed Entities)”, in force 4 September 2024, sections 1, 5, 10.1, 10.6, 11.1, 11.2, 13.1, 17.1, 17.6, 17.7, 20.1 and 21.2. qcb.gov.qa ↩ ↩2

  7. Hamad Bin Khalifa University, “Minister of Transport and Communications Announces Qatar’s National Artificial Intelligence Strategy Developed by HBKU’s Qatar Computing Research Institute”, 29 October 2019. hbku.edu.qa ↩

  8. Qatar News Agency, “NCSA Organizes Conference on Secure Usage of Artificial Intelligence”, 19 February 2024. qna.org.qa ↩

  9. Qatar News Agency, “MCIT Outlines Efforts to Establish Regulatory, Ethical Frameworks for AI Use at Doha Conference”, 25 May 2025. qna.org.qa ↩

  10. Information and eGovernment Authority, Kingdom of Bahrain, “General Policy for the Use of Artificial Intelligence”, version 1.0, 20 May 2025, sections 3, 6.2.2 and 8. iga.gov.bh ↩

  11. UNESCO, “Kingdom of Bahrain: UNESCO’s Artificial Intelligence Readiness Assessment Methodology Report (RAM)”, 12 November 2025, Part III, p. 21. iga.gov.bh ↩

  12. Ministry of Transport, Communications and Information Technology, Oman, “General Policy for the Safe and Ethical Use of Artificial Intelligence Systems” (Arabic), first version, April 2025, printed pp. 11, 14, 17, 20 and 26. mtcit.gov.om ↩ ↩2

  13. Microsoft, “Kuwait National AI Strategy Framework: Empowering Kuwait through AI”, whitepaper, May 2024, pp. 1, 4 and 5. info.microsoft.com ↩

  14. Qatar News Agency, “NCSA Organizes Fifth National Cyber Governance and Assurance Affairs Conference”, 5 October 2026. qna.org.qa ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.