JOH Partners
Engage
Research Report · 2026From:JOH Partners

AI in the Gulf Boardroom: The Readiness Gap

How Gulf boards are being asked to oversee artificial intelligence, where directors fall short on readiness, and the leadership the boardroom now needs.

Artificial intelligence has moved from the technology function to the agenda of the board itself, and Gulf directors are now expected to oversee systems that few of them fully understand. This report examines why AI governance has become a board responsibility, where directors in the region fall short on readiness, what the risks actually are in board terms, and the kind of leadership the boardroom now needs to close the gap. It is written for chairs, non-executive directors and the executives who report to them, at a moment when the distance between how fast Gulf organisations are adopting AI and how well their boards govern it has become the live exposure.

~50%. Of boards in our network have AI as a recurring agenda item (JOH estimate)

<1 in 10. Have a director who can credibly challenge management on AI (JOH estimate)

YoY

+27% YoY. Growth in JOH mandates for AI-literate NEDs and Chief AI Officers

2017. The UAE created the world's first Minister of State for AI

What is AI governance, and why is it a board issue?

AI governance is the set of structures, controls and accountabilities through which an organisation directs how artificial intelligence is developed, procured, deployed and monitored. It is not a technical discipline that lives with the data-science team. It is a question of corporate governance, sitting alongside financial oversight, risk appetite and strategy, because the decisions an AI system makes are, in effect, decisions the organisation is making on its own behalf and for which the organisation remains answerable.

The board issue arises because artificial intelligence changes the nature of delegation. When a company deploys a model that prices credit, screens candidates or flags transactions, it hands consequential judgements to a process that is often opaque, probabilistic and hard to interrogate after the fact. Directors carry a duty of oversight they cannot discharge without understanding, at least in principle, what these systems do, how they can fail, and who inside the organisation is accountable when they do. Board oversight of AI is therefore not optional supervision of a novelty. It is the same fiduciary responsibility directors have always held, applied to a technology that concentrates risk and reward in unfamiliar ways.

What makes this urgent now is speed and scale. Generative tools have put capable AI in the hands of every function almost overnight, frequently ahead of any policy, control or line of accountability. Boards still treating AI as a research topic have found it embedded in operations and decision-making before governance caught up. That gap between adoption and oversight is precisely where AI risk accumulates, and in the Gulf, where adoption has been unusually fast and top-down, the gap has opened unusually wide.

Where are Gulf boards falling short?

The most authoritative regional signal comes from the GCC Board Directors Institute, whose 2026 board review found Gulf boards advancing on overall effectiveness but falling short on three fronts in particular: AI readiness, diversity and geopolitical-risk oversight. That AI readiness sits in that group is telling. Boards that have professionalised their approach to audit, succession and strategy have not yet built the same confidence around artificial intelligence, and the review frames this as a live shortfall rather than a distant concern.

The gap is partly one of composition. Many Gulf boards, particularly in family-controlled groups and government-linked entities, were assembled for relationships, sector experience and financial judgement rather than technological fluency. There may be no director who can credibly challenge management on model risk, data provenance or the limits of a vendor's claims. In our own search practice, this shows up directly. Across the boards in our network, we estimate that around half now have AI as a recurring agenda item, yet fewer than one in ten has a director who could credibly challenge management on model risk, data provenance or a vendor's claims. The result is that AI is often discussed enthusiastically as opportunity and rarely interrogated rigorously as risk.

Figure 01FIG-01

The readiness gap

Share of boards
AI is a recurring board agenda item
~50%
Board has a director who can govern it
<10%
Figure 01. The distance between talking about AI and being equipped to govern it is the gap this report is about. Both values are JOH estimates across its Gulf network, not measured data.Source · JOH estimate across its Gulf network

The gap is also one of process. Even where interest is high, many boards lack a standing mechanism to see AI clearly: no agreed inventory of where AI is used across the business, no defined risk appetite, no reporting line that brings model performance and incidents to the board with the same discipline as financial results. Responsible AI becomes a matter of individual goodwill rather than institutional habit, which is exactly the condition under which oversight quietly lapses. The danger is not that Gulf boards are hostile to AI. It is that they are enthusiastic about it without being equipped to govern it, which is a more comfortable failure and therefore a more persistent one.

The regional regulatory backdrop: UAE and Saudi Arabia

The Gulf is not a governance vacuum, and directors who treat it as one misread the environment. The UAE moved early, creating a Minister of State for Artificial Intelligence in 2017, the first appointment of its kind in the world, and setting out a National AI Strategy running to 2031. Saudi Arabia established the Saudi Data and AI Authority, SDAIA, and built a national data and AI strategy around it. These are statements of national ambition, and they signal to boards that AI is a matter of state priority, industrial policy and public expectation, not merely private commercial choice.

That ambition raises the bar for oversight rather than lowering it. When governments frame AI as central to economic diversification, the organisations delivering that agenda, sovereign investors, national champions, and regulated financial institutions in the DIFC and ADGM, come under closer scrutiny for how responsibly they deploy it. Directors should expect the regulatory perimeter to tighten, and financial-centre regulators such as the DFSA to sharpen expectations around model governance, data protection and consumer fairness in step with global practice.

Boards operating across borders face a further complication. Many Gulf groups serve customers and hold data in jurisdictions governed by external regimes, most prominently the risk-based EU AI Act, and increasingly look to global reference points such as the US NIST AI Risk Management Framework and the ISO 42001 management-system standard. A board cannot assume that a locally acceptable practice will satisfy every market it operates in. Mapping which frameworks bind the business, and where they diverge, is itself an act of governance too few boards have completed.

Figure 02FIG-02

The frameworks boards look to

FrameworkOriginStatusWhat it gives a board
EU AI ActEuropean UnionBinding law, risk-basedA tiered risk classification and hard obligations for higher-risk uses
NIST AI Risk Management FrameworkUnited StatesVoluntaryA common language and process for identifying and managing AI risk
ISO 42001InternationalCertifiable management standardAn auditable management system for AI, akin to ISO frameworks boards already know
Figure 02. None of these is a substitute for judgement, but together they give a board a shared vocabulary and a checklist for what good looks like.Source · EU AI Act; US NIST AI Risk Management Framework; ISO/IEC 42001

What are the AI risks a board must actually own?

It helps to be concrete about what directors are being asked to oversee. The first cluster is decision risk: models that are biased, wrong or confidently misleading, producing unfair outcomes for customers or employees and legal exposure for the organisation. Fairness is not an abstract virtue here. A screening or pricing model that systematically disadvantages a group is a governance failure with regulatory and reputational consequences, and the board is the body that must insist it be tested for.

The second cluster is operational and security risk. AI systems depend on data pipelines and third-party vendors that can fail, be manipulated or leak sensitive information. Generative tools introduce new failure modes, from fabricated outputs presented as fact to the inadvertent disclosure of confidential data into external systems. Safety and security, two of the widely accepted principles of responsible AI, are board-level concerns because a serious incident can halt operations or breach the trust a licensed business depends on.

The third cluster is accountability risk, and it is the one boards most often neglect. When an AI-driven decision goes wrong, who is responsible? If the honest answer is that no named executive owns the outcome, the organisation has a governance defect regardless of how the model performs. Directors should be able to trace a clear line from any material AI system to a human owner, a control framework and an escalation path to the board. Where that line is missing, transparency and accountability exist only on paper. The four principles that recur across every serious framework, accountability, transparency, fairness and safety, are useful precisely because they map onto these clusters and give a board a short, memorable test to apply.

Does the board need a Chief AI Officer, or a different kind of director?

The instinctive response to an oversight gap is to appoint someone, and the Chief AI Officer has become the fashionable answer. There is a real case for the role. A senior executive with clear authority over AI strategy, standards and risk can give the board a single, accountable interlocutor and pull fragmented initiatives into one coherent programme. In large or heavily regulated Gulf institutions, that concentration of ownership can be genuinely valuable.

But a Chief AI Officer is a management appointment, and it does not discharge the board's own responsibility. The board still has to oversee that executive, challenge their judgement and understand their reporting. That requires fluency in the boardroom itself, which points to a different and in many cases more pressing need: directors, and non-executive directors in particular, who can hold AI to account without running it. This is where regional demand is concentrating fastest. In our own practice, mandates for AI-literate non-executive directors and Chief AI Officer searches across the GCC have grown by around 27% year on year. The scarce commodity is not enthusiasm for the title. It is the judgement to use it well.

A board cannot delegate its way out of AI. Directors do not need to write code, but they do need the fluency to ask whether a system is safe, fair and understood. In the Gulf, that fluency is the fastest-growing gap we are asked to fill.
Oliver Helvin, Founder and Managing Director

For most boards the sharper move is to raise the collective competence of the whole board rather than quarantine AI expertise in a single seat. That means recruiting at least one non-executive with genuine technological depth and equipping every other director to ask better questions. The aim is not to turn directors into engineers. It is to ensure the board can distinguish a well-governed system from a plausible story about one. A single AI-literate director surrounded by colleagues who defer to them has simply relocated the problem; the goal is a board that can hold the conversation collectively.

Five questions every Gulf board should be able to answer

Readiness is easier to test than to describe, and a board can gauge its own in a single meeting by asking whether it can answer five questions honestly. Where does AI already make or shape material decisions in this business? Who is the named human owner of each of those systems? How would we know if one of them was failing, and who would tell us? Which external frameworks and regulators bind these uses, and are we compliant across every market we operate in? And if a model produced an unfair or damaging outcome tomorrow, what is our escalation path and our public position?

A board that can answer all five is in good shape regardless of how technical its directors are. A board that cannot answer them has found its agenda for the next year. The value of the exercise is that it reframes AI from a specialist topic that intimidates non-technical directors into a governance topic they are already equipped to lead, because these are the same questions boards have always asked about any source of material risk. The novelty is the subject, not the discipline.

Crucially, the questions are answerable in plain language. A director does not need to understand a model's architecture to ask who owns it, how failure would surface, and what the organisation would do about it. That is why raising board readiness is a leadership task rather than a training exercise, and why it can move faster than directors fear once a board decides to treat it seriously.

What does good board oversight of AI look like?

Good oversight begins with visibility. The board should be able to see, in plain terms, where AI is used across the organisation, which uses are material, and what could go wrong in each. An AI inventory and a defined risk appetite are unglamorous but foundational, because a board cannot govern what it cannot see. From that base, the principles of responsible AI, accountability, transparency, fairness and safety, become testable expectations rather than aspirations, each with an owner and a means of assurance.

Good oversight also has a home and a rhythm. Some boards will route AI through the risk or audit committee; others will stand up a dedicated committee; the structural choice matters less than the discipline. What counts is that AI reaches the board regularly, with honest reporting on model performance, incidents and near-misses, and that directors treat it with the same seriousness as a financial control. Governance frameworks such as NIST's and ISO 42001 offer useful scaffolding, but they are tools in service of judgement, not substitutes for it.

Finally, good oversight is proportionate. Not every use of AI warrants board attention, and a board that tries to supervise everything will supervise nothing well. The task is to focus scrutiny where the stakes are highest, on decisions that affect customers, capital, safety or reputation, and to hold management accountable for governing the rest. Directors who get this balance right convert AI from an ungoverned exposure into a source of durable, defensible advantage.

What should Gulf boards do next?

The first step is honest self-assessment, and the five questions above are the fastest route to it. A board should ask whether it genuinely understands where AI already operates in the business, whether any director could credibly challenge management on it, and whether a clear line of accountability exists for every material system. For many boards the answers will be uncomfortable, and that discomfort is the beginning of readiness.

The second step is composition and capability. Boards should treat AI fluency as a selection criterion in their next non-executive appointment and invest in raising the literacy of the directors they already have. This is a leadership question as much as a technical one, and it connects to the wider work of professionalising Gulf boards that JOH tracks across its research, from the ownership dynamics explored in the report on chairs in Gulf-listed family businesses to the leadership benchmarks in the 2026 Gulf operator-CEO index, and the parallel oversight pressures set out in the sibling reports on nationalising the Gulf C-suite and Gulf executive reward. The boards that close the readiness gap will not be those that talk most about artificial intelligence. They will be those that have quietly built the structures, the accountability and the human judgement to govern it.

Note on data: figures in this report are drawn from JOH Partners' mandate book and reflect professional estimates across our Gulf search practice.

Key findings

  • AI governance is a matter of corporate governance and board responsibility, not a technical function, because directors remain accountable for the decisions their AI systems make.
  • The GCC Board Directors Institute's 2026 review found Gulf boards advancing overall but falling short on AI readiness, alongside diversity and geopolitical-risk oversight.
  • We estimate around half of the boards in our network have AI as a recurring agenda item, but fewer than one in ten has a director able to challenge management on it, and mandates for AI-literate directors and Chief AI Officers are up around 27% year on year.
  • The readiness gap is both compositional, too few technology-literate directors, and procedural, too little standing visibility, defined risk appetite or clear accountability.
  • National ambition in the UAE and Saudi Arabia raises rather than lowers the bar for responsible AI, and cross-border operations pull in external frameworks such as the EU AI Act, NIST and ISO 42001.
  • A Chief AI Officer can help but does not discharge the board's own duty; the scarcer need is AI-literate non-executive directors who can hold AI to account.
  • A board can test its own readiness in one meeting with five plain-language questions about where AI operates, who owns it, how failure would surface, what binds it, and how the organisation would respond.

JOH Partners runs board and C-suite mandates across the Gulf's six principal sectors. For confidential conversations on AI-literate board composition, non-executive appointments and the oversight questions raised by this report, contact the partners directly.

-- Team behind the report

Oliver Helvin

Founder and Managing Director

Oliver Helvin is the Founder and Managing Director of JOH Partners, based in the Middle East. With over 20 years of experience in multinational corporations across Europe and the Middle East, he has held pivotal roles at Gulftainer, Al Futtaim, BP and AstraZeneca, where he led recruitment functions and built the policies, processes and KPIs that drove change and efficiency in each organisation he served. He founded JOH Partners in 2014 to deliver retained executive search the way it should be done: partner-led, research-rigorous and accountable for retention twenty-four months after the hire.

LinkedIn ↗
— Download the full report

Send me a copy.

We’ll email the PDF to your work inbox and add you to our research distribution list. Unsubscribe anytime.

-- Frequently asked questions

Questions about this research.

What is AI governance?

AI governance is the set of structures, controls and accountabilities through which an organisation directs how artificial intelligence is developed, procured, deployed and monitored. It sits within corporate governance and ensures AI systems are used responsibly and remain answerable to the business.

What are the core principles of AI governance?

The widely accepted principles are accountability, transparency, fairness and safety or security. Together they require that AI decisions have clear human owners, can be understood and explained, do not produce unfair outcomes, and operate securely and reliably.

Why is AI oversight a board responsibility?

Because AI systems make consequential decisions on the organisation's behalf, and directors carry a fiduciary duty of oversight they cannot discharge without understanding how those systems work, how they can fail and who is accountable. A board cannot delegate its way out of that responsibility.

What is a Chief AI Officer?

A Chief AI Officer is a senior executive with authority over an organisation's AI strategy, standards and risk, giving the board a single accountable point of contact. It is a management role that supports, but does not replace, the board's own oversight of AI.

What frameworks should a board use to govern AI?

The most common reference points are the EU AI Act, a binding risk-based law, the US NIST AI Risk Management Framework, a voluntary process for managing AI risk, and ISO 42001, a certifiable management-system standard. Boards should map which apply across the markets they operate in and use them as scaffolding for judgement rather than a substitute for it.

Subscribe

A standing brief on the executive market.

New research, perspectives and market notes — direct to inbox. Read by chairs, chief executives and investors across three regions.

Weekly. No marketing. Unsubscribe in one click.
Engage a partner

Tell us about the seat.
We’ll tell you who’s right.

Confidential conversations with the partner leading the practice you need. We respond within one business day.