The compliance library
Field guides for CTOs and compliance leads who run AI on regulated data. Each guide takes one framework and turns it into a deadline, a checklist, and an architecture decision.
Egypt PDPL: the 31 October 2026 compliance countdown
The executive regulations (Decree 816/2025) are out and the grace period is running. Registration tiers, DPO classes, 72-hour breach reporting, and cross-border licences.
Read the guide →DIFC · AIDIFC Regulation 10: what the Gulf’s first AI data rule actually requires
Enacted September 2023 — not 2026 — and now being revised through the June 2026 public consultation. The obligations, the July 2025 amendments, and a living tracker.
Read the guide →Saudi Arabia · PDPL × AISaudi PDPL × AI: running AI on company data without breaking the law
Fully enforceable since September 2024, with 48 SDAIA violation decisions in 2025. What the transfer rules actually say — and the architecture that keeps AI compliant.
Read the guide →Saudi Arabia · NPHIESNPHIES claim denials: reading the data before the rejection
Denials are a data problem before they are a billing problem. The defect classes behind rejections — and how to catch them before submission.
Read the guide →Oman · AI Special ZoneOman’s AI Special Zone: what the Seeb decree created and who it’s for
Established by royal decree on 30 April 2026, under OPAZ. What is confirmed, what has not been published yet, and the data rules already in force. A living tracker.
Read the guide →UAE · Health dataMalaffi, NABIDH, Riayati: what vendors must actually do
Three exchanges, one federal map. The facility-connection mandate, the conformance testing behind “certification”, and the residency rules that decide where systems live.
Read the guide →