Three regimes, one record-keeping system
Most organisations do the same work three times: a separate file for the EU, another for the Gulf, another for national data law. Yet all three ask for the same core — which systems exist, what they do, where the data comes from, who owns them, how decisions are logged.
We build a single record-keeping regime and generate each regulator's required output from it. When a new regulation arrives, nobody starts from zero.
This is the largest single source of cost difference. An organisation running three separate files collects the same information three times and keeps none of them current.
The order of work
1. Inventory. Every AI system running in the organisation, including purchased tools. Most organisations find about twice what they expected.
2. Classification. Which risk tier does each system fall into? Done against the regulation's own criteria, not by intuition.
3. Gap analysis. Which obligation is unmet on each system, and by which date it must be met.
4. Build-out. Risk management regime, data governance records, technical documentation, automatic event logging, defined human oversight.
5. Ownership. Every file gets an owner by name. There is no such thing as an unowned compliance programme.
6. Refresh. When a system changes, the record changes. That gets a calendar and a responsible person.
If you are a supplier, this is a sales subject
European and Gulf buyers are pushing these obligations into supplier contracts. Tenders now ask bidders for technical documentation, data-governance records and a defined human-oversight arrangement.
In Saudi Arabia the SDAIA framework sets a mandatory governance baseline for public sector entities, and ISO 42001 is becoming central to procurement. If you intend to sell technology into government, governance is not a preference — it is the entry ticket.
A supplier holding these documents ready beats one that does not. Compliance stops being a cost line and becomes a point of differentiation.
Starting early changes the cost, not the calendar
The EU AI Act's high-risk obligations were postponed by the Digital Omnibus — 2 December 2027 for Annex III, 2 August 2028 for Annex I. That looks like relief. It is not.
As the date approaches, consultant and notified-body capacity becomes the scarcest resource in the market. Producing the same file in late 2027 costs several times what it costs today.
An organisation that starts early also does the work with its own people at its own pace; one that starts late buys it from outside, in a hurry.
What each regime asks for
| Regime | Core obligation | Critical date |
|---|---|---|
| EU AI Act — transparency | AI disclosure, machine-readable marking, deepfake disclosure | 2 August 2026 (in force) |
| EU AI Act — high risk | Risk management, data governance, technical documentation, human oversight | 2 December 2027 (Annex III) |
| SDAIA framework (Saudi Arabia) | Data governance, model accountability, transparency, human oversight, risk management | Mandatory baseline for public sector |
| Oman personal data law | Data protection officer appointment, documented consent trail | 5 February 2026 (fully in force) |
| National data protection law | Lawful basis, notice, retention periods, transfer rules | In force |