Skip to main content
v2026.11,858 entries · CC-BY 4.0

The Middle East and Africa: AI Strategies, Not AI Laws

Search “AI regulation in Saudi Arabia” or “AI law in Kenya” and you will find governance trackers that colour these countries in as regulated. What each government has actually published is a strategy — a policy document setting direction and capacity-building goals — not an enacted statute that creates obligations or penalties. This guide verifies the real instrument in each of eight Middle East and Africa jurisdictions, names the binding data-protection laws that do exist alongside them, and is explicit about the difference.

Written and maintained by CASRAI Editorial Board

Last updated

Short answer: every government covered in this guide — Saudi Arabia, the United Arab Emirates, Egypt, Nigeria, Kenya, Rwanda, Morocco and South Africa — has published a national AI strategy, framework, or (in Morocco’s case) a still-pending legislative proposal. None of them has an AI-specific statute in force that creates legal obligations or penalties for building or deploying AI systems. That is a different claim from “these countries have no relevant law at all”: several have binding, enforceable data-protection law that reaches AI systems when they process personal data — Saudi Arabia’s PDPL and South Africa’s POPIA carry real penalties. But a data-protection statute is not an AI statute, and conflating the two is exactly the error this guide exists to correct. If you are building a compliance map and need to know whether anything in this region actually binds you today, the honest answer, jurisdiction by jurisdiction, is below.

Strategy vs. law: the distinction that matters

A strategy is a policy document. It sets direction, names priority sectors, sometimes sets a target date or budget, and is issued by a ministry or authority under executive or administrative power. It creates no legal obligation for any company or researcher, and violating it carries no penalty, because there is nothing to violate — it is guidance, not law.

A law (a statute, act, or royal decree with force of law) is enacted through a jurisdiction’s legislative or decree-issuing process, creates obligations for the people and entities it covers, and typically specifies an enforcement body and penalties for non-compliance. CASRAI’s own jurisdiction map of AI regulation tracks this distinction across the EU, US states, and East Asia, where several binding, AI-specific statutes now exist — South Korea’s AI Basic Act and the EU AI Act among them. Nothing comparable exists yet in the Middle East or Africa. What exists instead is eight governments, at different stages of maturity, publishing direction-setting documents while their AI sectors grow ahead of any binding rulebook.

Saudi Arabia: SDAIA sets direction; the PDPL is the actual binding law

The Saudi Data and Artificial Intelligence Authority (SDAIA) was established by royal decree on 30 August 2019 as a government agency reporting directly to the Prime Minister, governed by a board chaired by the Deputy Prime Minister. SDAIA oversees three subordinate bodies: the National Center for Artificial Intelligence, the National Data Management Office (NDMO), and the National Information Center. Through the NDMO it administers the National Data Governance Interim Regulations and the Personal Data Protection Interim Regulations — data-governance rules, not an AI-specific statute.

The binding law that actually reaches AI in Saudi Arabia is the Personal Data Protection Law (PDPL), issued by Royal Decree No. M/19 on 16 September 2021 and amended by Royal Decree No. M/148 on 27 March 2023. It entered into force on 14 September 2023, with full compliance enforcement from 14 September 2024, and carries administrative penalties of up to SAR 5 million per violation plus criminal penalties, including imprisonment, for the most serious breaches. The PDPL is a general data-protection statute — it binds any AI system that processes personal data, the same way GDPR does in the EU — but it is not AI-specific legislation, and SDAIA’s own AI-strategy and AI-ethics work sits outside it as non-binding guidance. A compliance program that lists “Saudi Arabia” as an AI-regulated jurisdiction is really pointing at the PDPL, and should say so.

UAE: the world’s first AI minister, and a strategy horizon, not a statute

In October 2017 the UAE appointed Omar Sultan Al Olama as Minister of State for Artificial Intelligence — the first cabinet-level AI portfolio anywhere in the world, later expanded to Minister of State for Artificial Intelligence, Digital Economy and Remote Work Applications. The appointment was paired with a national strategy for artificial intelligence, setting the UAE’s ambition to be a global leader in the field with 2031 as its stated horizon. That strategy, and the ministerial portfolio built around it, are executive and administrative instruments — they direct government investment and coordination, not private-sector legal obligations. This guide did not locate an AI-specific UAE statute that creates obligations or penalties for AI developers or deployers; readers with a live compliance question for the UAE should verify current status directly with UAE federal or emirate-level counsel, since strategy documents of this kind are periodically updated and can be superseded by more specific rules issued through free-zone regulators such as DIFC or ADGM.

Egypt: a strategy now in its second edition, run by a body that keeps growing

Egypt’s National Council for Artificial Intelligence (NCAI), established in 2019 and chaired by the Minister of Communications and Information Technology, issued Egypt’s first National AI Strategy that year and has since issued a second edition covering 2025–2030. In January 2026 the Council’s mandate was expanded and it was renamed the National Council for Artificial Intelligence, Quantum Computing, and Emerging Technologies. Day-to-day implementation runs through the Egyptian Center for Responsible AI (ECRAI), the Council’s technical and executive arm, organized into a Planning and Policy department and a Training and Research department. All of this — the Council, the strategy, ECRAI’s departments — is administrative and policy machinery. Egypt has not enacted an AI-specific statute; the NCAI strategy functions as a guiding framework that the Council oversees, with no described enforcement mechanism or penalty regime of its own.

Nigeria: a National AI Strategy running alongside a binding data-protection act

Nigeria’s AI policy work sits under the Federal Ministry of Communications, Innovation and Digital Economy (FMCIDE), whose strategic blueprint is built around five pillars — Knowledge, Policy, Infrastructure, Innovation/Entrepreneurship/Capital, and Trade. Within that structure, the National Information Technology Development Agency (NITDA) coordinates Nigeria’s National AI Strategy, first published in 2024 and now in an implementation phase; NITDA’s own communications describe the country as having moved “from policy to progress” on AI adoption, language that itself signals a policy instrument rather than an enacted law. Nigeria does have a binding, general data-protection statute that reaches AI systems handling personal data: the Nigeria Data Protection Act 2023, which established the Nigeria Data Protection Commission (NDPC) as enforcement authority. As with Saudi Arabia and South Africa below, that is data-protection law, not AI-specific law — Nigeria has not enacted the latter.

Kenya: a strategy published this year, filed explicitly as policy

Kenya’s Ministry of Information, Communications and the Digital Economy (MICDE) published the Kenya National AI Strategy 2025–2030 Implementation Roadmap in December 2025. The ministry’s own website lists the document under “Policy and Strategy documents,” not under legislation, and it functions as an implementation roadmap — setting out how the strategy’s goals get executed — rather than a source of enforceable obligations. Kenya’s binding privacy statute is the Data Protection Act, 2019, administered by the Office of the Data Protection Commissioner; it is, again, a general data-protection law rather than an AI-specific one.

Rwanda: a Cabinet-level AI policy, now paired with a frontier-lab partnership

Rwanda’s AI governance work sits with the Ministry of ICT and Innovation (MINICT) and its implementing agency, the Rwanda Information Society Authority (RISA). The government has developed a National AI Policy through this structure to guide AI adoption across health, education and public-sector use cases — a policy instrument, not a statute. That the relationship remains at the policy-and-partnership stage rather than the legislative stage is visible in current activity: in February 2026, the Government of Rwanda and Anthropic announced a three-year memorandum of understanding to advance AI use in health, education and the public sector — a bilateral cooperation agreement, not a piece of domestic legislation, and consistent with a country still building AI capacity through policy and partnership rather than through binding rules.

Morocco: not yet even a settled strategy — a proposal still in Parliament

Morocco is the clearest case in this set of a country earlier in the process than the “strategy” label implies. Digital-transition policy generally runs through the Ministry of Digital Transition and Administrative Reform (MTNRA) and the Digital Development Agency (ADD), established in 2017 as the central coordinator of Morocco’s digital transition across the public and private sectors. But on AI specifically, what currently exists is a legislative proposal, put forward by a coalition of political parties in Parliament, to establish a National Agency for Artificial Intelligence — aimed at regulating AI technologies and increasing public awareness. That proposal has not been enacted. Morocco therefore sits a step behind Saudi Arabia, the UAE, Egypt, Nigeria and Kenya in this guide: those five have adopted strategy documents; Morocco, on the evidence available, has a pending parliamentary proposal for a coordinating body and no adopted national AI strategy or law of its own yet.

South Africa: a policy framework in development, with POPIA doing the binding work it touches

South Africa’s Department of Communications and Digital Technologies (DCDT) has been developing a National AI Policy Framework to guide the country’s approach to AI adoption and governance. As with the other policy documents in this guide, a framework of this kind is administrative guidance, not an enacted statute, and this guide did not verify a specific enactment date for it that would change that status. What is binding in South Africa, and does reach AI systems that process personal information, is the Protection of Personal Information Act (POPIA), in force since 1 July 2021 and enforced by the Information Regulator — South Africa’s equivalent of GDPR, and, again, a data-protection statute rather than an AI-specific one.

The pattern, and what it means if you have to build a compliance map

Read across all eight, the pattern is consistent rather than country-specific: every government here has stood up an AI authority, council, or ministerial portfolio, and every one of them has published (or, in Morocco’s case, proposed) a direction-setting policy document. None has followed the EU, South Korea, or the growing list of US states into AI-specific statute with obligations and penalties attached to building or deploying AI systems as such. Where binding law does reach AI in this region, it arrives sideways — through general data-protection statutes (Saudi Arabia’s PDPL, Nigeria’s Data Protection Act 2023, Kenya’s Data Protection Act 2019, South Africa’s POPIA) that apply to any system processing personal data, AI or not.

For a research-administration or compliance office, the practical takeaway is narrow but important: do not write a contract clause, a data-management plan, or an institutional AI-governance policy that cites “Saudi AI law,” “UAE AI law,” or “Nigeria’s AI Act” as if any of those exist as AI-specific statutes today — they do not. What you can cite, and what does create real obligations, are the data-protection statutes named above, for the specific case of AI systems that touch personal data. Everything else in this guide is a strategy: useful for understanding where a government is headed and what it is investing in, not a source of legal risk today.

Jurisdiction AI-specific instrument Issuing body Legal status Binding law that reaches AI (if any)
Saudi Arabia SDAIA strategy & ethics work SDAIA (est. 30 Aug 2019, royal decree) Non-binding PDPL (Royal Decree M/19, 2021; in force 14 Sep 2023)
UAE National AI strategy (2031 horizon) Ministry of State for AI, appt. Oct 2017 Non-binding None identified as AI-specific
Egypt National AI Strategy, 2nd ed. 2025–2030 NCAI (est. 2019) Non-binding None identified as AI-specific
Nigeria National AI Strategy (2024) NITDA / FMCIDE Non-binding Nigeria Data Protection Act 2023
Kenya Kenya National AI Strategy 2025–2030 Roadmap MICDE (Dec 2025) Non-binding (filed as policy) Data Protection Act, 2019
Rwanda National AI Policy MINICT / RISA Non-binding None identified as AI-specific
Morocco Proposal for a National AI Agency Parliamentary coalition (not enacted) Proposed, not adopted None identified as AI-specific
South Africa National AI Policy Framework DCDT Non-binding POPIA (in force 1 Jul 2021)

Frequently Asked Questions

Does any Middle East or Africa country have a binding AI law?

Not among the eight covered here. Each has an AI strategy, policy framework, or (in Morocco’s case) a pending legislative proposal, but none has enacted an AI-specific statute that creates obligations or penalties for building or deploying AI systems. Several — Saudi Arabia, Nigeria, Kenya, South Africa — do have binding general data-protection law that reaches AI systems processing personal data, which is a different and narrower thing.

Is Saudi Arabia’s SDAIA an AI law?

No. SDAIA is a government authority, established by royal decree in 2019, that issues AI strategy and ethics guidance and administers data-governance regulations. The actual binding statute that reaches AI activity in Saudi Arabia is the Personal Data Protection Law, a general data-protection statute, not an AI-specific one.

Does the UAE have an AI law?

The UAE appointed the world’s first AI minister in October 2017 and has a national AI strategy with 2031 as its stated horizon, but this guide did not identify an AI-specific UAE statute creating legal obligations or penalties. Free-zone regulators can move faster than federal law in the UAE, so a live compliance question should be checked against current DIFC or ADGM rules directly.

Which of these countries is furthest from having any AI governance instrument at all?

Morocco. Where the other seven have adopted strategy or policy documents, Morocco’s current AI-specific instrument is a legislative proposal — put forward by a coalition of parties in Parliament to create a National Agency for Artificial Intelligence — that has not been enacted.

If none of these are laws, why do compliance trackers list these countries as “regulated”?

Usually because a strategy document, a ministerial appointment, or a general data-protection law gets summarized as “AI regulation” without distinguishing which one it actually is. That collapse is the specific error this guide is written to prevent: a strategy, a ministry, and a statute are three different things, and only the last one creates legal obligations.

Related Reading

Sources

  • Egypt Ministry of Communications and Information Technology (mcit.gov.eg): National Council for Artificial Intelligence, National AI Strategy second edition (2025–2030), ECRAI structure, January 2026 Council mandate expansion.
  • Kenya Ministry of Information, Communications and the Digital Economy (ict.go.ke): Kenya National AI Strategy 2025–2030 Implementation Roadmap, filed under Policy and Strategy documents, December 2025.
  • Wikipedia, “SDAIA”: SDAIA’s 30 August 2019 establishment by royal decree, its subordinate bodies, the National Data Governance Interim Regulations and Personal Data Protection Interim Regulations, and the Personal Data Protection Law’s Royal Decree numbers, in-force and enforcement dates, and penalty structure.
  • Wikipedia, “Omar Sultan Al Olama”: October 2017 appointment as the UAE’s (and the world’s first) Minister of State for Artificial Intelligence.
  • Wikipedia, “Regulation of artificial intelligence”: Morocco’s parliamentary legislative proposal for a National Agency for Artificial Intelligence.
  • Wikipedia, “Digital Development Agency (Morocco)”: ADD’s 2017 establishment and coordinating role.
  • Nigeria Federal Ministry of Communications, Innovation and Digital Economy (fmcide.gov.ng) and NITDA (nitda.gov.ng): ministry structure and five-pillar blueprint; NITDA public communications referencing Nigeria’s National AI Strategy alongside “ongoing regulatory reforms” as a distinct item.
  • Rwanda Ministry of ICT and Innovation (minict.gov.rw): February 2026 announcement of a three-year Rwanda–Anthropic memorandum of understanding on AI for health, education and the public sector.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The Middle East and Africa: AI Strategies, Not AI Laws

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.