Semi-government entities — the GREs that actually deliver national AI strategy — combine commercial competitive pressure with sovereign oversight expectations. This benchmark — measured against ISO 42001 — reveals where GREs stand and why they are the natural first movers for AI governance certification in the GCC.
Four major regulatory and strategic drivers are converging on semi-government entities simultaneously — creating the most compelling AI governance window in the GCC. Every day without a structured governance framework widens the gap between sovereign expectations and operational reality.
—
Days Until EU AI Act
High-risk obligations · Aug 2, 2026
LIVE
DORA
Fully applicable since Jan 2025
—
KSA PDPL
Full enforcement · Sep 2025
ACTIVE
UAE AI Strategy 2031
GREs are primary execution vehicles
01 — EXECUTIVE SUMMARY
The Semi-Government AI Governance Gap
Semi-government entities are, on average, 44% ready for ISO 42001 certification — making them the second-most-prepared sector after financial services, and notably ahead of both pure government (41%) and commercial energy (40%). This reflects their unique position: they combine the commercial competitive pressure that drives AI adoption with the governance expectations that come from sovereign ownership.
Semi-government entities — government-related entities (GREs) — are the organisations that actually deliver national AI strategy. When the UAE National AI Strategy 2031 calls for AI-powered services, it is entities like e&, DEWA, Emirates Group, and Mubadala that build and operate them. When Saudi Vision 2030 embeds AI across the economy, it is Saudi Aramco, stc, NEOM, and the Public Investment Fund portfolio that execute.
Large GREs at 55% readiness represent the most certification-ready segment across all industries we assess. The gap from 55% to certification-ready (~70%) is achievable in 4–6 months of focused governance work. This makes semi-government entities the natural first movers for ISO 42001 certification in the GCC — they have the commercial incentive, the governance infrastructure, and the national mandate.
€35M
Max EU AI Act Penalty
Or 7% of global turnover
80%
Lack Mature AI Governance
Deloitte State of AI, 2026
55%
Large GRE Readiness
Highest of any sector segment
4-6mo
Path to Certification
For large GREs from current baseline
Benchmark scores are directional estimates derived from regulatory analysis, ISO adoption research, and industry governance maturity patterns. They reflect expected readiness levels based on published data and are updated periodically as the market matures.
02 — AI GOVERNANCE LANDSCAPE
Approaches to AI Governance
AI governance is not a single framework — it's a discipline with multiple approaches, each with distinct strengths and limitations. Understanding the full landscape is essential before choosing a path, and helps explain why ISO 42001 has emerged as the leading certifiable option for organizations serious about structured AI governance.
Approach
What It Is
Strengths
Limitations
Internal AI Policies
Self-defined governance frameworks developed in-house
Flexible, quick to implement, tailored to organization
No external validation, inconsistent across teams, not recognized by regulators or clients as proof of governance
EU AI Act Compliance
Meeting requirements of Regulation 2024/1689
Mandatory in EU, clear penalties create urgency, detailed requirements for high-risk AI
Jurisdiction-specific, not certifiable, reactive (compliance ≠ governance), doesn't cover full management lifecycle
NIST AI RMF 1.0
Voluntary US framework: GOVERN, MAP, MEASURE, MANAGE functions Source: NIST AI 100-1, January 2023
Well-structured, free, aligns with ISO 42001 concepts
Voluntary only — no certification, no audit mechanism, US-centric, no enforcement
IEEE Ethically Aligned Design
Ethics-focused standards for autonomous systems Source: IEEE P7000 series
Strong on fairness, transparency, and human rights
Narrow scope (ethics, not full governance), not widely adopted, not a management system
Industry-Specific Frameworks
Basel Committee (banking), FDA (medical AI), EBA Guidelines (EU banking) Source: BCBS d/575 (May 2024), EBA GL on ML for IRB
Deep domain expertise, regulatory weight in specific sectors
Siloed — doesn't transfer across industries, can't certify against them, doesn't cover full AI governance
ISO/IEC 42001:2023
International standard for AI Management Systems (AIMS) Source: ISO/IEC 42001:2023, published December 2023
Certifiable by accredited bodies worldwide. Covers full lifecycle (Clauses 4–10 + 39 Annex A controls). Compatible with ISO 27001/9001. Satisfies multiple regulations simultaneously. Continuous improvement built in.
Relatively new (27 months old). Certification body capacity still scaling. Requires genuine organizational commitment.
03 — WHY ISO 42001
The Case for ISO 42001
ISO 42001 is not the only approach to AI governance — but for organizations seeking a structured, certifiable, and internationally recognized framework that covers the full AI lifecycle from leadership accountability through operational controls to continuous improvement, it is the strongest available option. Here's why it stands apart from other approaches.
The Only Certifiable AI Framework
You cannot get a certificate for NIST AI RMF compliance. You cannot certify against the EU AI Act. ISO 42001 is the only AI governance framework where an accredited third-party auditor can verify your implementation and issue an internationally recognized certificate. For GREs reporting to sovereign boards, certificates are proof — and proof is what boards demand.
ISO 42001 follows the Annex SL management system structure used by ISO 27001, ISO 9001, and ISO 14001. GREs already certified to these standards can integrate ISO 42001 into their existing management system — extending governance infrastructure rather than building from scratch. ISO estimates 30–40% reduction in implementation effort.
Source: ISO/IEC 42001:2023 follows the ISO Harmonized Structure (Annex SL) for management system standards.
The Regulatory Multiplier
A single ISO 42001 implementation addresses requirements across the EU AI Act, DORA, PDPL, DIFC DPL, ADGM Responsible AI Guidance, and ESG disclosure frameworks. For GREs operating across multiple jurisdictions and regulatory regimes, one governance system replaces five separate compliance projects.
Source: EU AI Act Recital 40 references harmonized standards; ISO 42001 submitted for harmonization under the EU AI Act framework.
Compatible with Existing ISO Systems
Many GREs hold multiple ISO certifications (27001, 9001, 14001, 45001, 55001). This means they already have auditable management system infrastructure — document control, internal audit, management review, continual improvement — that can be extended to ISO 42001 rather than built from scratch. This is the GRE sector's single greatest structural advantage.
Source: ISO Annex SL harmonized structure; ISO/IEC 42001:2023 Annex D (informative) on relationship to other standards.
39 Controls Across the Full AI Lifecycle
Annex A provides 39 specific controls covering data governance (A.4), transparency (A.5), accountability (A.6), bias and fairness (A.7), reliability (A.8), security (A.9), privacy (A.10), human oversight (A.11), documentation (A.12), and third-party AI management (A.13). No other framework provides this breadth of AI-specific controls in a single, auditable structure.
Source: ISO/IEC 42001:2023, Annex A — Reference control objectives and controls.
What ISO 42001 Does Not Cover
Jurisdiction-specific compliance. ISO 42001 is a governance framework, not a legal compliance tool. GREs must still address EU AI Act conformity assessments, PDPL requirements, DIFC DPL provisions, and sector-specific regulatory filings separately — though ISO 42001 provides the foundation.
Technical AI safety. The standard covers governance and management of AI risks, but does not prescribe specific technical solutions for model testing, adversarial robustness, or algorithmic fairness. Organizations must select appropriate technical approaches within the governance framework.
Our position: ISO 42001 is not a silver bullet — no single framework can solve AI governance in isolation. But for GREs seeking to demonstrate governance that satisfies both sovereign oversight and commercial expectations simultaneously, it is the strongest available option. The benchmarks in this report measure readiness against this standard specifically.
The Benchmark
Semi-government entities average 44% readiness. The certification threshold is 75%.
Here's the clause-by-clause breakdown of where that gap lives.
04 — CLAUSE ANALYSIS
Clause-by-Clause Benchmark
How semi-government and government-related entities score across each of the 7 mandatory ISO 42001 management system clauses — from context and leadership through planning, support, and operations to performance evaluation and improvement. Scores reflect the degree to which current industry practices align with each clause's specific requirements. Click any clause to see the detailed analysis, key gaps, and recommendations.
Estimated readiness based on regulatory analysis, ISO Survey certification adoption data (2019–2024), published AI governance maturity research, and industry-specific compliance infrastructure patterns across semi-government and government-related entities.
Large semi-government entities at 55% readiness represent the most certification-ready segment across all industries.
05 — ANNEX A CONTROLS
Control Maturity by Domain
ISO 42001 Annex A defines 39 controls across 12 groups, which we organize into 5 operational domains for clarity. Each domain is scored on a 1–5 maturity scale based on typical implementation patterns observed across semi-government entities and GREs. Documentation maturity at 2.5/5.0 — the highest of any sector — reflects the direct benefit of existing ISO certifications. Third-party management at 1.6/5.0 remains the most urgent remediation priority.
Maturity scores estimated from regulatory compliance patterns, published AI governance research, and industry-specific control implementation analysis across semi-government and government-related entities.
The first GCC semi-government entity to achieve ISO 42001 certification sets the benchmark for the entire GRE ecosystem.
06 — CRITICAL GAPS
Top 5 Gaps in Semi-Government Entities
The most significant AI governance gaps we consistently identify across semi-government entities and GREs — ranked by severity, with ISO 42001 clause references and estimated remediation timelines for each.
GREs combine the commercial incentive, the governance infrastructure, and the national mandate — the question is not whether, but how quickly.
07 — REGULATORY LANDSCAPE
Semi-Government AI Regulations
A comprehensive reference of every regulation affecting AI governance in semi-government entities — current status, enforcement dates, penalty structures, and the specific impact on GRE operations across the GCC and international markets.
Regulation
Jurisdiction
Status
Penalties
Impact on GREs
ISO 42001 Alignment
EU AI Act
EU/EEA
High-risk: Aug 2026
€35M / 7%
GREs with EU operations: credit scoring (§5b), critical infrastructure (§2), chatbots (Art.50). Obligations Aug 2, 2026.
Cl.6 · Cl.8 · A.5 · A.7 · A.11
UAE AI Strategy 2031
UAE
Active
National directive
GREs are primary execution vehicles. AI governance expected as national exemplars.
Cl.4 · Cl.5 · Cl.6 · A.5
UAE Data Protection
UAE
In force
AED 5M (~$1.36M)
Personal data processing for customer and employee data in AI systems.
A.4 · A.10
KSA PDPL
Saudi Arabia
Full: Sep 2025
SAR 5M
Data localisation. Consent and purpose limitation for AI processing.
A.4 · A.9 · A.10
ADGM AI Guidance
Abu Dhabi
Active
FSRA action
Responsible AI for ADGM-licensed financial services GREs.
A.5 · A.6 · A.7
DIFC DPL
Dubai
In force
$100K/violation
UK Data Bridge partner. Automated decision-making provisions.
A.4 · A.10
SDAIA Framework
Saudi Arabia
Active
Governance mandate
14 principles. All GRE entities must comply.
Cl.5 · Cl.6 · A.5 · A.6 · A.7
DORA
EU/EEA
Live since Jan 2025
€10M / 5%
ICT risk including AI. Third-party AI provider oversight for GREs with EU operations.
The regulatory multiplier: For GREs operating across multiple jurisdictions — UAE, KSA, EU, and global markets — ISO 42001 serves as a single governance framework that addresses the overlapping requirements of all applicable regulatory regimes simultaneously. The first GRE to certify demonstrates compliance readiness across all of these frameworks with one implementation.
08 — METHODOLOGY
How This Benchmark Was Built
Scores were derived by mapping each ISO 42001 clause requirement against known industry practices, regulatory compliance maturity data from ISO Survey certifications, and published AI governance maturity research. Each clause score reflects the estimated degree to which GREs of that size typically demonstrate alignment with the clause's specific requirements, adjusted for industry-specific factors such as existing ISO certifications, board governance maturity, and AI deployment breadth across subsidiaries.
Data Sources
› ISO Survey of Management System Certifications (2019–2024)
› EU AI Act (Regulation 2024/1689) — Articles 6–72, Annex III
› Deloitte State of AI in the Enterprise 2026 (3,235 leaders)
› PwC Global AI Jobs Barometer 2025
› OECD AI Policy Observatory (80+ jurisdictions)
› Regional frameworks: ADGM, DIFC, SDAIA, SAMA
› NIST AI RMF 1.0 (January 2023)
Important Caveats
› ISO 42001 published December 2023 — no GRE globally has certified yet
› GREs are heterogeneous — a tech-forward GRE may score 65%+ while a traditional one scores 35%
› Existing ISO certifications are the biggest advantage (30-40% infrastructure already built)
› First-mover advantage is significant — the first GRE sets the regional benchmark
› Certification typically requires 70–75% readiness to engage and 80–85% to certify
› These benchmarks will be updated as the market matures
09 — ABOUT THE AUTHOR
Mike Merdinian
Founder · Digital North Associates
Mike Merdinian works at the intersection of governance and AI, helping organizations scale decision-making at machine speed without losing control.
He is a transformation leader specializing in governance, large-scale change, and AI-driven operating models, with over 20 years of experience across North America, Europe, and the GCC. He has led complex transformation and M&A initiatives across banking, supply chain, retail, and the public sector — working both as a strategic advisor and as an internal transformation leader.
He has advised members of parliament from more than 20 Commonwealth countries on technology and governance strategy, and teaches emerging technologies at leading international universities. He holds an AI Strategy and Leadership certification from MIT and is currently pursuing Applied Agentic AI for Organizational Transformation (MIT, expected May 2026).
He is the founder of Digital North Associates, an AI governance and transformation firm focused on enabling organizations to operate at machine speed while maintaining control through policy-driven governance. The firm transitioned to an AI-first model in March 2026, with a clear principle: keep humans at the core, using AI to amplify expertise rather than replace it.
Under his leadership, DNA is on track to become a fully AI-augmented organization by May 2026, with intelligent systems embedded across sales, marketing, advisory, operations, delivery, and finance.
Mike Merdinian
Founder · March 2026
Digital North Associates
AI Governance & Digital Transformation · Strategic Advisory & Purpose-Built Technology