The Strategy-vs-Law Gap: Why Most of Africa and the Middle East Don't Actually Have AI Regulation Yet
Eight governments across the Middle East and Africa have published national AI strategies, but none have actually enacted AI-specific statutes that create legal obligations or penalties. This critical distinction between policy guidance and enforceable law is reshaping how companies and researchers understand AI governance in these regions, even as global tracking systems often color these countries as "regulated".
The confusion stems from a fundamental mismatch in terminology. When Saudi Arabia, the United Arab Emirates, Egypt, Nigeria, Kenya, Rwanda, Morocco, and South Africa publish AI strategies, they are issuing executive policy documents that set direction and capacity-building goals. These frameworks carry no legal force. A strategy is guidance; a law creates obligations and specifies penalties for non-compliance.
This matters because compliance teams and AI developers often rely on governance trackers that list these countries as having AI regulation in place. The reality is more nuanced. Several of these nations do have binding, enforceable data-protection laws that reach AI systems when they process personal data, but data-protection statutes are not AI-specific legislation.
What's the Difference Between an AI Strategy and an AI Law?
A national AI strategy is a policy document issued by a ministry or authority under executive or administrative power. It names priority sectors, sometimes sets target dates or budgets, and provides direction for government investment and coordination. Critically, it creates no legal obligation for any company or researcher, and violating it carries no penalty because there is nothing to violate legally.
An AI law, by contrast, is a statute or act enacted through a jurisdiction's legislative or decree-issuing process. It creates enforceable obligations for the people and entities it covers, typically specifies an enforcement body, and outlines penalties for non-compliance. This is what exists in places like South Korea, which enacted the AI Basic Act, and the European Union, which implemented the EU AI Act.
- Saudi Arabia: The Saudi Data and Artificial Intelligence Authority (SDAIA) oversees AI strategy and the National Data Governance Interim Regulations, but the actual binding law is the Personal Data Protection Law (PDPL), issued by royal decree in 2021 and enforced from September 2024, which carries administrative penalties up to 5 million Saudi riyals per violation plus criminal penalties including imprisonment.
- United Arab Emirates: The UAE appointed the world's first cabinet-level AI minister in October 2017 and published a national AI strategy with a 2031 horizon, but this remains an executive and administrative instrument directing government investment, not a private-sector legal obligation.
- Egypt: Egypt's National Council for Artificial Intelligence issued a first national AI strategy in 2019 and a second edition covering 2025 to 2030, with implementation running through the Egyptian Center for Responsible AI, but no AI-specific statute has been enacted.
- Nigeria: Nigeria published its National AI Strategy in 2024 and is in an implementation phase, but the country's binding law is the Nigeria Data Protection Act 2023, which is general data-protection legislation, not AI-specific law.
- Kenya: Kenya's Ministry of Information, Communications and the Digital Economy published the Kenya National AI Strategy 2025 to 2030 Implementation Roadmap in December 2025, filed explicitly as policy rather than law.
Why Does This Matter for Companies Building AI Systems?
For organizations conducting compliance mapping, the distinction is crucial. If you are building an AI system and need to know whether anything in the Middle East or Africa actually binds you today, the honest answer is that no AI-specific statute creates obligations in these eight jurisdictions. However, several do have binding data-protection laws that reach AI systems handling personal data, and those carry real penalties.
This creates a compliance landscape that is far more fragmented than global governance trackers suggest. A company might see that Saudi Arabia is listed as an AI-regulated jurisdiction and assume comprehensive AI oversight exists. In reality, what binds the company is the PDPL's data-protection requirements, not an AI-specific framework. The distinction affects which teams own compliance, what audits are required, and what enforcement mechanisms apply.
How to Navigate AI Compliance in Regions Without AI-Specific Laws
- Verify the actual instrument: When a jurisdiction is listed as AI-regulated, confirm whether that refers to a strategy, a data-protection law, or an AI-specific statute by consulting local counsel or official government sources.
- Map data-protection obligations separately: Identify which countries have binding data-protection laws like South Africa's POPIA or Saudi Arabia's PDPL, and ensure AI systems comply with personal data handling requirements even if no AI-specific law exists.
- Monitor for legislative movement: Track announcements from government ministries and national AI councils, as strategies can evolve into proposed legislation; Morocco, for example, has a legislative proposal still pending that could change the landscape.
- Distinguish between sectors: Some regions may have binding rules in specific sectors (such as financial services or healthcare) through existing regulators, even if no cross-cutting AI law exists.
The gap between strategy and law is not unique to the Middle East and Africa. The United Kingdom is currently grappling with the same question. Following a wave of AI-agent related incidents and departures from AI safety teams in major AI labs, the UK government has acknowledged that voluntary commitments are insufficient to govern AI technologies. Parliament, industry, and government are now calling for binding AI legislation, with the Joint Committee on Human Rights recommending a dedicated AI bill and an independent regulator.
The UK's current approach relies on existing sector regulators to apply their powers to AI systems within their respective remits, similar to the business-as-usual model that many Middle Eastern and African countries are following. However, this approach has significant gaps. Frontier AI models in the UK are not subject to the kind of regulatory mechanisms that govern other high-risk sectors like aviation, financial services, pharmaceuticals, or food safety. There is no equivalent of independent standard-setting, pre-market authorization, mandatory safety testing, or enforcement and accountability mechanisms.
The UK government has begun to shift its position. In recent weeks, the UK AI Minister stated that the government was considering whether "further regulation, legislation, stronger protections or new powers" were needed for governing the most powerful AI models, noting that "nothing is off the table". This signals a potential move from strategy to statute, a path that Middle Eastern and African governments may eventually follow as their AI sectors mature.
For now, the reality remains clear: eight major jurisdictions in the Middle East and Africa have published direction-setting documents while their AI sectors grow ahead of any binding rulebook. Companies operating in these regions should verify what actually binds them legally, rather than relying on governance trackers that conflate strategy with law.