Skip to main content
Who It’s For

You’ve deployed AI. Governance came second.

That is not a failure. It is the order it happens in almost everywhere. The business moved first and governance is catching up. What changed is that somebody now has to answer for it to a regulator.

Solas is an AI-governance overlay for regulated operators. Built in Dubai, for the UAE first, then the wider Gulf and Southeast Asia. It sits on top of the security and GRC stack you already own. It does not replace any of it.

  • UAE PDPL
  • NESA/SIA
  • ADHICS
  • DIFC/ADGM Reg 10
  • SAMA
  • EU AI Act
  • ISO 42001
  • NIST AI RMF
  • Singapore PDPA (roadmap)
  • MAS (roadmap)
Where the question comes from· usually all three, in the same quarter
Who is asking
  • The board
    what AI are we running?
  • The regulator
    who approved it, against which control?
  • An enterprise customer
    the security questionnaire
Where it lands
  • Somebody senior has to answer
  • Your AI estate
    AI deployed · governance catching up. The order it happens in almost everywhere.

Who this is for

Under real pressure, from a real regulator

Not “every enterprise.” The organisations where an AI system already has a named regime attached to it, and somebody senior has to sign that it is under control.

Financial services

DIFC / ADGM · SAMA (KSA) · central-bank model-risk expectations

You already run model risk for credit and pricing.
Then a team stood up a GenAI assistant on a business card, and it sits outside every register you maintain.
Your regulator is asking the question you already answer for models. It just now covers systems nobody registered.

Healthcare

ADHICS (Abu Dhabi) · UAE PDPL

Clinical and administrative AI touch patient data, and ADHICS adds specific controls on top of PDPL.
The exposure is rarely the flagship diagnostic tool you scoped carefully.
It is the transcription add-on somebody enabled inside an app you already licensed.

Government & critical infrastructure

NESA / SIA · UAE PDPL

Entity classification decides how hard NESA/SIA reaches you, and AI is not carved out of it.
If your assurance evidence for AI systems is a spreadsheet somebody updates the week before an audit, that is the gap, not the AI itself.

Maritime, logistics & industrial

Sector cyber requirements · UAE PDPL

AI is entering routing, scheduling, and inspection decisions where the output has physical consequence.
Our maritime heritage is why we understand the difference between an office system and one that moves things.

If none of these describes you, we are probably not the right fit yet, and we would rather tell you that on a first call than on month three.

Regulatory coverage

The regimes you answer to, and how deep we actually go

Four stations, in the order they matter to us. Where our coverage is real, we say mapped. Where it is roadmap, we say roadmap. You should be able to hold us to the difference.

01

United Arab Emirates

Where we operate

Our home jurisdiction. Engagements are mapped to these regimes directly.

  1. UAE PDPLFederal Decree-Law No. 45 of 2021: lawful basis, data-subject rights, breach duties.
  2. NESA / SIAInformation-assurance standard reaching government and critical-infrastructure entities.
  3. ADHICSAbu Dhabi healthcare information and cyber-security controls, layered on top of PDPL.
  4. DIFC / ADGM Reg 10Free-zone data-protection duties on high-risk automated processing.
02

Wider Gulf

Mapped

Regional regimes we map engagements against alongside the UAE stack.

  1. SAMA (KSA)Saudi Central Bank cyber-security and model-risk expectations for financial entities.
  2. Qatar, Oman & BahrainNational data-protection laws, scoped per entity and per deployment.
  3. UAE AI Charter & Council guidanceDirectional national AI policy we track and reflect in control mapping.
03

Reference standards

Mapped as reference

Not your regulator, but what your regulator, your auditor, and your enterprise customers keep pointing at.

  1. EU AI ActRegulation (EU) 2024/1689: the risk-tier vocabulary the region is converging on.
  2. ISO/IEC 42001AI management system structure, the shape most AI governance programmes end up taking.
  3. NIST AI RMFGOVERN · MAP · MEASURE · MANAGE: the function split we organise findings around.
04

Southeast Asia

Roadmap · not yet mapped

We serve customers with SEA exposure and we flag these regimes as applicable. We have not yet built depth mapping against them, and we will not pretend otherwise.

  1. Singapore PDPAFlagged as applicable in assessment. Depth mapping is roadmap. Verify with local counsel.
  2. MAS (Singapore)AI and model-risk guidance for financial entities. Roadmap.
  3. Malaysia PDPA · Bank Negara RMiTRoadmap.
  4. Indonesia PDP Law · OJKRoadmap.

Four questions · one chain

What your auditor actually asks

Four questions, in this order, every time. Each answer is only as good as the one before it, which is why we built four connected steps rather than four products.

01Discover

“What AI are you actually running?”

Shadow AI, agents, third-party AI and OAuth grants, found through the identity provider you already run. Not a survey you send round, and not a spreadsheet somebody maintains. An inventory built from the sign-in and consent records your IdP already holds.

02Posture

“Who approved it, and against which control?”

Every discovered system becomes a governed object with an owner, a risk finding, and a mapped control reference. A technical finding and a compliance gap stop being two records in two tools that nobody reconciles until the week before an audit.

03Gate

“What stops the next one shipping ungoverned?”

A promotion gate at the release point that blocks on evidenced risk, with a named-human override that is logged rather than hidden. We decide and evidence; your existing controls enforce. For AI traffic routed through the gateway, enforcement is inline.

04Prove

“Now prove that record was not edited.”

Discovery, risk, decision, and override all land on a continuous, tamper-evident audit trail. Each row links to the previous by SHA-256 and the head can be signed, so an auditor verifies after the fact that nothing was inserted, deleted, or quietly corrected.

Break the chain anywhere and the record at the end stops being evidence. Ask us what we deliberately do not do before the demo, not after.

Overlay, not replacement

No rip and replace. Ever.

You have an identity provider, a CASB or secure web gateway, an EDR, a SIEM, and probably a GRC platform. Every one of them is doing its job. None of them treats an AI system as a governed object with an owner, a risk finding, a mapped control, and a decision record you can prove was not edited.

That gap is the entire product. We read from the tools you already run, add the governance layer on top, and hand enforcement back to your controls.

  • Entra ID
  • Okta
  • Cloudflare
  • Netskope
  • Defender
  • CrowdStrike
  • Splunk
  • Vanta
  • Drata
  • GitHub Actions

Connector depth varies by tool. We scope which of these are in reach on the first call.

One layer · on the stack you already own
One line
  • Solas decides and evidences above it
    Your controls enforce below it.
  • 01 DISCOVER · 02 POSTURE · 03 GATE · 04 PROVE
    The four steps run across the overlay.
What it reads from
  • Identity
    Entra ID · Okta
  • Network / CASB
    Cloudflare · Netskope
  • Endpoint
    Defender · CrowdStrike
  • Record
    your SIEM · GRC · CI/CD

Local presence

Dubai-based. Same time zone, same regulators.

We map engagements to UAE PDPL, NESA/SIA, ADHICS and the wider GCC regulatory landscape. Local presence, local accountability, and a working session inside your business hours, not eight hours after them.

Southeast Asia is where we are heading next. We will say that plainly on the call rather than list frameworks we have not mapped.

Local presence · local accountability
  1. 01Dubai
    • A5, DIEZ, Dubai Silicon Oasis, Dubai, UAE
    • UAE first · wider Gulf · Southeast Asia on the roadmap
  2. 02Engagement
    • Led by named practitioners, not a rotating bench
    • Evidence structured for local audit, not translated from a US template

same time zone, same regulators

Start here

Start with the inventory. Everything else follows it.

A free 30-day design-partner pilot: connect your identity provider on day one, see the AI actually in use, and leave with a record you can hand to an auditor. Read-only to start, no fee, no obligation at day thirty.

The calculator takes eight questions and no email address. It will tell you which regimes likely reach you before you ever speak to us.

The thirty days· read-only to start
Thirty days · no fee
  • Day 1 · Connect + inventory
    read-only · about fifteen minutes
  • Map
    systems → the frameworks that reach you
  • Gate
    live in your pipeline, override logged
  • Day 30 · Record
    yours either way · no obligation