You’ve deployed AI. Governance came second.
That is not a failure. It is the order it happens in almost everywhere. The business moved first and governance is catching up. What changed is that somebody now has to answer for it to a regulator.
Solas is an AI-governance overlay for regulated operators. Built in Dubai, for the UAE first, then the wider Gulf and Southeast Asia. It sits on top of the security and GRC stack you already own. It does not replace any of it.
- UAE PDPL
- NESA/SIA
- ADHICS
- DIFC/ADGM Reg 10
- SAMA
- EU AI Act
- ISO 42001
- NIST AI RMF
- Singapore PDPA (roadmap)
- MAS (roadmap)
- The boardwhat AI are we running?
- The regulatorwho approved it, against which control?
- An enterprise customerthe security questionnaire
- Somebody senior has to answer
- Your AI estateAI deployed · governance catching up. The order it happens in almost everywhere.
Who this is for
Under real pressure, from a real regulator
Not “every enterprise.” The organisations where an AI system already has a named regime attached to it, and somebody senior has to sign that it is under control.
Financial services
DIFC / ADGM · SAMA (KSA) · central-bank model-risk expectations
Healthcare
ADHICS (Abu Dhabi) · UAE PDPL
Government & critical infrastructure
NESA / SIA · UAE PDPL
Maritime, logistics & industrial
Sector cyber requirements · UAE PDPL
If none of these describes you, we are probably not the right fit yet, and we would rather tell you that on a first call than on month three.
Regulatory coverage
The regimes you answer to, and how deep we actually go
Four stations, in the order they matter to us. Where our coverage is real, we say mapped. Where it is roadmap, we say roadmap. You should be able to hold us to the difference.
United Arab Emirates
Where we operateOur home jurisdiction. Engagements are mapped to these regimes directly.
- UAE PDPLFederal Decree-Law No. 45 of 2021: lawful basis, data-subject rights, breach duties.
- NESA / SIAInformation-assurance standard reaching government and critical-infrastructure entities.
- ADHICSAbu Dhabi healthcare information and cyber-security controls, layered on top of PDPL.
- DIFC / ADGM Reg 10Free-zone data-protection duties on high-risk automated processing.
Wider Gulf
MappedRegional regimes we map engagements against alongside the UAE stack.
- SAMA (KSA)Saudi Central Bank cyber-security and model-risk expectations for financial entities.
- Qatar, Oman & BahrainNational data-protection laws, scoped per entity and per deployment.
- UAE AI Charter & Council guidanceDirectional national AI policy we track and reflect in control mapping.
Reference standards
Mapped as referenceNot your regulator, but what your regulator, your auditor, and your enterprise customers keep pointing at.
- EU AI ActRegulation (EU) 2024/1689: the risk-tier vocabulary the region is converging on.
- ISO/IEC 42001AI management system structure, the shape most AI governance programmes end up taking.
- NIST AI RMFGOVERN · MAP · MEASURE · MANAGE: the function split we organise findings around.
Southeast Asia
Roadmap · not yet mappedWe serve customers with SEA exposure and we flag these regimes as applicable. We have not yet built depth mapping against them, and we will not pretend otherwise.
- Singapore PDPAFlagged as applicable in assessment. Depth mapping is roadmap. Verify with local counsel.
- MAS (Singapore)AI and model-risk guidance for financial entities. Roadmap.
- Malaysia PDPA · Bank Negara RMiTRoadmap.
- Indonesia PDP Law · OJKRoadmap.
Four questions · one chain
What your auditor actually asks
Four questions, in this order, every time. Each answer is only as good as the one before it, which is why we built four connected steps rather than four products.
“What AI are you actually running?”
Shadow AI, agents, third-party AI and OAuth grants, found through the identity provider you already run. Not a survey you send round, and not a spreadsheet somebody maintains. An inventory built from the sign-in and consent records your IdP already holds.
“Who approved it, and against which control?”
Every discovered system becomes a governed object with an owner, a risk finding, and a mapped control reference. A technical finding and a compliance gap stop being two records in two tools that nobody reconciles until the week before an audit.
“What stops the next one shipping ungoverned?”
A promotion gate at the release point that blocks on evidenced risk, with a named-human override that is logged rather than hidden. We decide and evidence; your existing controls enforce. For AI traffic routed through the gateway, enforcement is inline.
“Now prove that record was not edited.”
Discovery, risk, decision, and override all land on a continuous, tamper-evident audit trail. Each row links to the previous by SHA-256 and the head can be signed, so an auditor verifies after the fact that nothing was inserted, deleted, or quietly corrected.
Break the chain anywhere and the record at the end stops being evidence. Ask us what we deliberately do not do before the demo, not after.
Overlay, not replacement
No rip and replace. Ever.
You have an identity provider, a CASB or secure web gateway, an EDR, a SIEM, and probably a GRC platform. Every one of them is doing its job. None of them treats an AI system as a governed object with an owner, a risk finding, a mapped control, and a decision record you can prove was not edited.
That gap is the entire product. We read from the tools you already run, add the governance layer on top, and hand enforcement back to your controls.
- Entra ID
- Okta
- Cloudflare
- Netskope
- Defender
- CrowdStrike
- Splunk
- Vanta
- Drata
- GitHub Actions
Connector depth varies by tool. We scope which of these are in reach on the first call.
- Solas decides and evidences above itYour controls enforce below it.
- 01 DISCOVER · 02 POSTURE · 03 GATE · 04 PROVEThe four steps run across the overlay.
- IdentityEntra ID · Okta
- Network / CASBCloudflare · Netskope
- EndpointDefender · CrowdStrike
- Recordyour SIEM · GRC · CI/CD
Local presence
Dubai-based. Same time zone, same regulators.
We map engagements to UAE PDPL, NESA/SIA, ADHICS and the wider GCC regulatory landscape. Local presence, local accountability, and a working session inside your business hours, not eight hours after them.
Southeast Asia is where we are heading next. We will say that plainly on the call rather than list frameworks we have not mapped.
- 01Dubai
- A5, DIEZ, Dubai Silicon Oasis, Dubai, UAE
- UAE first · wider Gulf · Southeast Asia on the roadmap
- 02Engagement
- Led by named practitioners, not a rotating bench
- Evidence structured for local audit, not translated from a US template
same time zone, same regulators
Start here
Start with the inventory. Everything else follows it.
A free 30-day design-partner pilot: connect your identity provider on day one, see the AI actually in use, and leave with a record you can hand to an auditor. Read-only to start, no fee, no obligation at day thirty.
The calculator takes eight questions and no email address. It will tell you which regimes likely reach you before you ever speak to us.
- Day 1 · Connect + inventoryread-only · about fifteen minutes
- Mapsystems → the frameworks that reach you
- Gatelive in your pipeline, override logged
- Day 30 · Recordyours either way · no obligation
