By Atlas Public Policy
Independent analysis by the Atlas Public Policy research team in Rabat.
Research area: Technology & AI
Executive Summary
Artificial intelligence has entered the Middle East and North Africa security debate through a different route than it has in Washington. In the United States, much of the policy discussion concerns frontier-model risk, institutional oversight, loss of control, and the governance of increasingly capable systems. In the Middle East, the more immediate concern is operational. AI systems, data centres, cyber infrastructure, and commercially supplied surveillance capabilities are already embedded in interstate competition and conflict.
The 2026 US-Israel-Iran war accelerated this shift. Gulf data centres became potential military targets, Iranian-linked cyber activity intensified, AI-generated information operations spread across regional media environments, and the physical security of digital infrastructure became inseparable from questions of technological sovereignty. At the same time, Gulf states continued to invest heavily in frontier-scale computing while developing only limited independent capacity to evaluate the models and systems operating on that infrastructure.
Three developments define the emerging regional landscape.
- First, Middle Eastern governments and companies increasingly treat AI and cyber security as interconnected national-security problems. Regional surveys suggest that cyber risk and AI now rank among senior leaders’ most important concerns, even as confidence in AI governance remains limited.
- Second, Gulf states are acquiring the physical infrastructure required for frontier AI faster than they are building institutions capable of independently evaluating the systems that infrastructure will host. The core regional question is therefore not only who develops advanced models, but who controls compute, model access, evaluation, and infrastructure security.
- Third, the Middle East already contains mature models of state-enabled private cyber operations. Israel has developed a commercial offensive-cyber export sector, Gulf states have employed foreign cyber operators and purchased surveillance capabilities, and Iran has relied extensively on state-linked and proxy cyber actors. These arrangements complicate emerging efforts elsewhere to formalise private-sector participation in offensive cyber operations.
The central policy challenge is therefore broader than AI governance narrowly understood. The region is constructing a security ecosystem in which frontier computing, military AI, commercial surveillance, cyber operations, cloud infrastructure, and geopolitical alignment increasingly reinforce one another. Yet the institutional mechanisms for evaluating, constraining, and deconflicting these capabilities remain underdeveloped.
A Different AI Security Debate
Much of the international debate over artificial intelligence and national security has been shaped by questions originating in the United States: how rapidly frontier capabilities may advance, whether increasingly autonomous systems can remain under meaningful human control, how governments should supervise private laboratories, and whether independent evaluators should verify corporate safety claims.
The Middle Eastern debate begins from a different premise. The central problem is not primarily the possibility of future capability. It is the rapid integration of existing AI systems into a region already characterised by interstate rivalry, offensive cyber activity, missile and drone warfare, extensive digital surveillance, and dependence on foreign technology providers.
This distinction matters because it changes the governance problem. In the United States, policymakers are debating how to regulate capabilities largely developed within their own jurisdiction. Gulf states, by contrast, are attempting to secure systems that are often developed abroad, hosted through international commercial partnerships, protected by foreign military relationships, and potentially targeted by regional adversaries.
The resulting security architecture combines considerable technological ambition with fragmented political control.
From AI Adoption to AI Security
There is no direct Middle Eastern equivalent of the large practitioner surveys that have shaped parts of the US national-security debate. Available evidence instead comes from business leaders, cyber-security professionals, and government statements.
Those sources nevertheless point in a consistent direction. A 2026 Heidrick & Struggles survey of 148 Middle Eastern board and C-suite leaders found that 49 percent identified cyber risk as a leading concern, while 47 percent identified AI. Only 36 percent expressed confidence in their organisations’ ability to manage AI. Other regional surveys found widespread concern about AI-enabled attacks, ungoverned use of AI systems within firms, and employees’ vulnerability to deepfake-enabled fraud.
These findings suggest that the regional governance problem is developing from the bottom up. AI systems are entering corporate workflows, government services, security institutions, and critical infrastructure faster than formal governance mechanisms are being built around them.
The Gulf states have simultaneously made artificial intelligence a central component of economic diversification. The UAE, Saudi Arabia, and Qatar have committed substantial capital to data centres, semiconductor access, cloud infrastructure, model development, and partnerships with major US technology companies. The scale of these investments has made computing infrastructure increasingly strategic.
That transformation is especially important because infrastructure built for economic development can acquire security relevance rapidly. Data centres may host commercial cloud workloads, government information, AI models, and services connected to military or intelligence operations. Once these functions coexist within the same infrastructure ecosystem, distinctions between civilian technology policy and national security become harder to maintain.
Israel represents a different part of the regional AI landscape. According to the research assembled for this paper, Israeli forces have deployed AI-enabled systems for target identification, individual tracking, and operational decision support. Systems including Lavender, The Gospel or Habsora, and Where’s Daddy? have become central to debates over the role of machine-supported analysis in targeting and military operations.
These systems have also generated substantial controversy. Critics have questioned the reliability of automated or semi-automated targeting processes and the degree of meaningful human review applied before strikes. Those claims remain contested, but the broader significance is clearer: AI-supported military decision-making is no longer a theoretical regional issue. It is already part of operational practice.
The informational domain is evolving in parallel. During the 2026 conflict, fabricated videos and other AI-generated material circulated widely, including false representations of attacks and military events. Gulf officials increasingly describe AI both as a defensive tool and as a threat multiplier for cyber and information operations.
Yet governments have provided little public guidance on the most consequential uses of these technologies. No Gulf state has published a detailed public doctrine governing AI use in missile defence, nuclear command systems, or other strategic military functions. Nor has the region produced a systematic practitioner survey capable of showing how military, intelligence, and civilian officials understand AI risk.
This absence is significant. The region is becoming an increasingly important user and host of advanced AI systems while producing relatively little public evidence about how security institutions intend to govern them.
Frontier Compute Without an Independent Evaluation Architecture
The second major challenge concerns frontier computing.
In the Gulf, debates over frontier AI are inseparable from semiconductor access, data-centre construction, US export controls, and technological sovereignty. The central question is less whether private laboratories should be audited and more who determines which countries and companies can obtain the hardware required to train and operate advanced systems.
US policy toward the Gulf changed significantly between 2025 and 2026. According to the source material underlying this paper, Washington expanded access to advanced computing infrastructure for the UAE while maintaining tighter restrictions elsewhere in the region. Earlier arrangements had attached security and reporting requirements to advanced-chip access. Later changes reduced some of those external constraints.
The consequences extend beyond semiconductor policy.
The UAE and Saudi Arabia have built national AI institutions, funded domestic model development, and established state-backed technology champions. Yet neither has developed a publicly documented equivalent to the independent frontier-model evaluation systems now being debated or constructed in parts of the United States. Public requirements for third-party model testing, incident reporting, or adversarial evaluation remain limited.
This creates an institutional asymmetry. Gulf states may possess the infrastructure necessary to host highly capable systems while remaining dependent on model developers and infrastructure partners for much of the expertise required to assess those systems.
The issue is not simply technical competence. Independent evaluation changes the distribution of authority. Without it, the entities developing or operating advanced models largely determine which risks are measured, which incidents are disclosed, and which safeguards are considered adequate.
That problem becomes more consequential when frontier models are hosted inside infrastructure with national-security significance.
The Physical Vulnerability of Digital Sovereignty
The 2026 war exposed another weakness in the Gulf technology strategy: digital infrastructure remains physical infrastructure.
Before the conflict, Gulf countries could frame domestic data centres as instruments of technological sovereignty. Locally hosted compute promised greater control over sensitive data, reduced dependence on overseas infrastructure, and the possibility of creating domestic AI ecosystems.
Conflict complicated that logic.
The source material for this paper reports that Iranian targeting included regional technology infrastructure and that AWS facilities in Bahrain and the UAE experienced disruption during the conflict. The economic case for locating large computing facilities in the Gulf consequently became more sensitive to physical-security costs, insurance, infrastructure resilience, and the possibility of military escalation.
The strategic implications are deeper than higher construction costs.
A state can control the legal jurisdiction in which a data centre operates without controlling the military systems required to protect it, the foreign companies operating its cloud infrastructure, or the geopolitical decisions that make the facility a target.
That tension complicates conventional understandings of digital sovereignty. Sovereignty over data does not necessarily produce sovereignty over infrastructure, hardware supply, model access, or physical protection.
The likely result is not technological disengagement from the United States or other major suppliers. The more plausible trajectory described in the source material is diversification. Gulf capital is increasingly distributed across different technology ecosystems, infrastructure locations, and international partnerships.
Such hedging may reduce dependence on individual suppliers or jurisdictions. It does not eliminate the underlying governance problem.
Offensive Cyber Power and the Private Sector
The region’s offensive-cyber ecosystem presents a third challenge.
Efforts in the United States to formalise private-sector participation in cyber operations are entering an international environment where similar relationships already exist in less formalised forms.
Israel has developed one of the world’s most significant commercial cyber and surveillance industries. Israeli export controls have historically regulated the sale of offensive cyber capabilities abroad, while companies associated with spyware, digital forensics, interception, and related capabilities have supplied governments across the Gulf and elsewhere.
Gulf governments have not only purchased commercial capabilities. The UAE’s experience with DarkMatter demonstrated another model: governments can employ foreign specialists, including former intelligence personnel, to conduct surveillance or cyber operations through ostensibly private organisations. Former US operatives involved in these activities later entered into agreements with US authorities concerning their work.
Iran employs a different architecture. State agencies have been repeatedly linked by private cyber-security researchers and Western governments to hacking groups, contractors, and hacktivist fronts that provide Tehran with deniable or semi-deniable operational capacity.
The 2026 conflict intensified this activity. The research compiled for this paper describes a sharp increase in pro-Iranian cyber operations following the opening strikes, with Israel and Gulf states becoming major targets. Iranian-linked groups reportedly conducted destructive attacks, data theft, phishing operations, intimidation campaigns, and attacks against infrastructure and commercial targets.
These examples illustrate a broader regional pattern. The boundary between state cyber operations and private activity is often porous.
Commercial vendors develop capabilities. Governments license or purchase them. Contractors supply specialised personnel. State-linked groups provide plausible deniability. Intelligence services may coordinate or sponsor activities that appear externally to be hacktivism or cybercrime.
This ecosystem matters because new legal frameworks for private-sector cyber operations may interact with existing Middle Eastern practices rather than replace them.
US-authorised firms, Israeli commercial operators, Gulf state contractors, and Iranian-linked groups could potentially operate against overlapping networks while being subject to very different legal standards and political authorities.
The resulting problem is not merely escalation. It is deconfliction.
There is currently no widely recognised regional framework for determining how state-authorised private cyber actors identify themselves, avoid interfering with allied operations, manage collateral effects, or distinguish between criminal infrastructure and infrastructure connected to foreign intelligence services.
AI may intensify these challenges. The source material indicates that regional organisations are already reporting AI-supported intrusion activity and substantially shorter timelines between network compromise and operational impact.
Faster operations leave governments with less time to attribute attacks, coordinate responses, or determine whether an apparent private actor is operating independently or under state direction.
Three Structural Differences Between the US and Middle Eastern Debates
The comparison with the United States reveals three important differences.
The first is ownership. US policymakers are largely attempting to govern technologies developed by domestic companies operating within US regulatory jurisdiction. Gulf states are more dependent on foreign laboratories, semiconductor suppliers, cloud providers, and defence relationships.
The second is threat proximity. Much of the US debate concerns the potential consequences of future AI capability. Middle Eastern governments are dealing simultaneously with cyberattacks, information operations, drone and missile threats, surveillance technology, and AI-supported military systems.
The third is institutional maturity. The region has invested rapidly in infrastructure and adoption, but equivalent institutions for independent model evaluation, public incident reporting, military AI governance, and private-cyber oversight remain much less developed.
These differences suggest that simply importing Western AI-governance frameworks will be insufficient.
The Middle Eastern policy problem is not only how to make models safer. It is how to govern an interconnected technological system whose critical components may be foreign-owned, commercially operated, militarily significant, and vulnerable to regional conflict.
A Regional Policy Agenda
Three areas deserve particular attention.
The first is independent technical evaluation. Gulf governments are becoming major hosts and purchasers of advanced AI systems. Their ability to assess those systems independently should grow alongside their computing capacity. That implies developing institutions capable of evaluating frontier models, conducting adversarial testing, investigating incidents, and assessing model deployment in critical sectors.
The second is infrastructure security. Data-centre strategy can no longer be treated solely as industrial policy. Governments need to examine physical protection, geographic concentration, energy resilience, network redundancy, cloud dependency, and the military consequences of hosting workloads used by foreign partners.
The third is the governance of private cyber operations. Regional governments have extensive experience buying cyber capabilities but comparatively little publicly articulated law governing when private entities may conduct operations on behalf of the state. Greater transparency around authorisation, targeting, accountability, and cross-border effects would reduce uncertainty as the private role in cyber conflict expands.
None of these challenges can be addressed exclusively at the national level. Gulf infrastructure is connected to US technology providers, Israeli security capabilities, European investment, Asian semiconductor supply chains, and regional military networks. Governance mechanisms will therefore need to cross institutional and national boundaries.
Filling the Evidence Gap
The greatest immediate limitation is not the absence of policy ideas. It is the absence of systematic evidence.
Three research projects would substantially improve understanding of the regional landscape.
A practitioner survey could establish how government officials, military officers, cyber-security professionals, and technology executives assess AI-related national-security risks. It would allow comparison between regional perceptions and the practitioner surveys now shaping US policy debates.
A public inventory of frontier-scale AI infrastructure could document which advanced models are hosted in Gulf data centres, which companies operate them, what evaluation procedures apply, and which incident-reporting mechanisms exist.
A comparative legal study of private-sector cyber operations could examine the authorities, export controls, contractor relationships, and accountability mechanisms used by Israel, the UAE, Saudi Arabia, the United States, and other relevant actors.
Together, these projects would move the regional debate beyond general discussions of AI strategy and toward the institutions that increasingly determine how technological power is exercised.
Conclusion
The Middle East is not simply importing the global AI-security debate. It is producing a distinct version of it.
The Gulf is becoming a major centre of advanced computing while remaining dependent on foreign technology providers and security relationships. Israel has integrated AI into military operations and developed a powerful commercial cyber ecosystem. Iran has demonstrated the strategic value of cyber proxies and asymmetric digital operations. Across the region, artificial intelligence is accelerating both defensive and offensive activity.
The resulting governance challenge is therefore not confined to algorithms.
It concerns the relationship between models and infrastructure, between cloud computing and military security, between commercial technology firms and intelligence services, and between technological sovereignty and geopolitical dependence.
The next phase of regional AI policy will be determined less by the number of data centres built or models deployed than by whether institutions capable of governing those relationships develop alongside them.
At present, they have not.
Sources
Internal only.