Qatar - Ethical AI Guidelines

Principles and Guidelines for Ethical Development and Deployment of Artificial Intelligence (MCIT)

Qatar

RAI-QA-NA-PGEDDXX-2025
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

A voluntary, non-binding set of principles and practical guidelines published by Qatar’s Ministry of Communications and Information Technology (MCIT) to guide the ethical development and deployment of AI. The document emphasizes a human-centred approach, risk assessment, transparency, privacy, robustness, fairness, environmental considerations and accountability across the AI lifecycle.

Overview

The Principles and Guidelines for Ethical Development and Deployment of Artificial Intelligence, published and promoted by the Ministry of Communications and Information Technology (MCIT), set out non-binding but practical guidance for organisations and individuals involved in the creation, deployment and use of AI systems in Qatar. The guidance frames AI development within Qatar National Vision 2030 and the Digital Agenda 2030 and is intended to support social, economic and environmental objectives while protecting fundamental rights. The document defines eight core ethical principles ("Do no harm"; robustness, security and safety; fairness and anti-discrimination; environmental protection; privacy; transparency; human-centred development; and ultimate human accountability) and provides actionable measures, examples and rationales for each. The original guidance text and downloadable materials are available from MCIT and public portals; see the MCIT guidelines and the official PDF for the full text at Artificial Intelligence in Qatar – Principles and Guidelines for Ethical Development and Deployment (MCIT PDF) and further description on the MCIT site at MCIT Guidelines.

Definitions

Key terms used in the guidance include AI system (physical or virtual products or services using AI to serve end users), developer (the party responsible for creation and training of models), deployer (the organisation placing AI into operation), bias (systemic errors resulting in unfair outcomes), discrimination impact assessment (DIA) and data protection impact assessment (DPIA). The document clarifies that the guidance is legally non-binding and that existing laws such as Law No. 13 of 2016 on Personal Data Privacy Protection remain authoritative for legal compliance. It also references technical definitions used by international standards bodies, aligning local terminology with OECD and UNESCO frameworks.

Governance and Institutional Framework

The guidance recommends an institutional governance model that assigns clear roles and responsibilities across technical, legal and executive functions. It identifies MCIT as the policy lead and recommends coordination with the National Cyber Security Agency (NCSA) for system security guidance and with the competent authority overseeing the Personal Data Privacy Protection Law for privacy oversight. Organisations are advised to implement an internal AI governance board or designate an AI officer to oversee risk assessments, approval gates, procurement, and lifecycle monitoring. The guidance also suggests embedding ethical review into procurement and vendor management processes, instituting formal documentation and audit trails for model design choices, datasets, validation results, and change logs. For national coordination, it encourages cross-agency collaboration and references the MCIT AI Committee and the NCSA’s “Guidelines for Secure Adoption and Usage of Artificial Intelligence” for technical alignment; see MCIT AI Committee and NCSA guidance for programmatic details and implementation support.

Key Focus Areas

The Guidance focuses on several practical and thematic areas: risk assessment and mitigation, safety and robustness, bias and fairness, privacy and data governance, transparency and user communication, human oversight and accountability, environmental sustainability, and monitoring/post-deployment controls. For risk assessment it prescribes early-stage threat modelling, DPIAs and DIAs to evaluate possible harms and affected populations. For robustness and security it recommends verification/validation, adversarial testing, continuous monitoring and alignment with NCSA security standards. On bias, it requires representative datasets, fairness testing, and regular audits with feedback loops that allow remediation. On privacy it mandates minimization, pseudonymization/anonymization where possible, strong access controls and encryption for training and inference data. On transparency the guidance asks organisations to publish clear, accessible statements describing system purpose, capabilities, limitations and contact points for redress. Environmental sustainability guidance calls for measuring and optimising model training carbon footprint and prioritising efficient architectures. Finally, a human-centred approach emphasizes design for user dignity, inclusivity and usability; high-impact decisions should always include human oversight or appeal mechanisms.

Implementation Framework

The document offers a lifecycle-focused implementation framework: (1) Design & Procurement: require impact assessments, vendor due diligence and contractual clauses on transparency and security; (2) Development & Testing: apply secure coding, data quality controls, bias checks and robust test suites (including edge-case and adversarial tests); (3) Deployment & Monitoring: deploy with logging, performance and fairness monitoring, incident response plans, and explainability tools for affected users; (4) Maintenance & Retirement: require model retraining policies, decommissioning procedures and data retention controls. The guidance provides templated checklists and example governance artifacts to help organisations operationalize these phases and recommends periodic reviews and updates to keep pace with technological change.

Monitoring and Evaluation

MCIT’s Guidance proposes continuous monitoring using automated telemetry, periodic audits (internal and third-party), user feedback mechanisms and KPIs that track accuracy, performance drift, fairness metrics, and security incidents. Monitoring should include scheduled re-evaluation of training data representativeness, post-deployment bias scanning, and anomaly detection to identify degraded performance or malicious manipulation. The guidance also suggests establishing reporting channels for incidents and an escalation protocol to technical and legal leads; organisations are encouraged to record monitoring outputs and remediation actions in persistent evidence logs to support audits and accountability reviews.

Penalties, Liability, and Appeals

Because the document is presented as voluntary guidance, it does not itself create new statutory penalties. However, it explicitly notes that failure to follow its recommendations may increase legal and commercial risk and could lead to consequences under existing Qatari laws (for example, the Personal Data Privacy Protection Law and applicable cybersecurity regulations). Organisations are advised to maintain redress channels for affected individuals, retain records to support legal defence, and ensure procurement and contracting include clauses on liability allocation. The guidance also recommends clear internal appeals procedures for users affected by automated decisions and encourages organisations to document remediation outcomes publicly when appropriate.

Relationship to Other Instruments

The Guidance is designed to complement and reference existing national and international instruments rather than replace them. It cross-references Qatar’s Personal Data Privacy Protection Law (Law No. 13 of 2016), the NCSA’s secure AI adoption guidance, national cybersecurity standards, and Qatar’s National AI Strategy. Internationally it aligns with UNESCO’s Recommendation on the Ethics of Artificial Intelligence, the OECD AI Principles and other multilateral norms. The document recommends that organisations comply with binding law first and use the Guidelines to operationalise ethical best practices not yet codified in law.

International Alignment

MCIT frames the Guidelines to be consistent with leading international frameworks — citing UNESCO and OECD — and encourages interoperability with international standards and certifications. This alignment aims to facilitate responsible cross-border research, technology transfer and export of AI solutions from Qatar while meeting global expectations on human rights, privacy and safety. It further encourages participation in international standards development and recommends that national technical standards bodies consider adopting interoperable assessment and reporting templates to support international procurement and market access.

Implementation Timeline

MilestoneTarget Date
Guidelines first public posting (Sharek/MCIT asset)2024-05-16
MCIT publicity & conference highlights2025-05-08
Recommended organisational adoption window (initial)Within 12 months of guidance publication
Suggested review/update cadenceEvery 1–2 years

Compliance Checklist

RequirementYes/No
Conduct DPIA / DIA prior to deployment
Implement security controls per NCSA guidance
Perform bias and fairness testing
Publish user-facing transparency statement
Establish human oversight for high-impact uses
Maintain logs and documentation for audits

Sources and References

SourceType
Artificial Intelligence in Qatar – Principles and Guidelines for Ethical Development and Deployment (MCIT PDF)Primary Source
MCIT Guidelines (Guidelines overview page)Primary Source
Qatar News Agency: MCIT outlines efforts to establish regulatory, ethical frameworks for AI usePrimary Source (government press)
Plain English

Qatar's Ministry of Communications and Information Technology (MCIT) has issued voluntary guidelines to help organisations and individuals develop and deploy Artificial Intelligence (AI) systems ethically within the country. This guidance applies to anyone involved in the creation, deployment, or use of AI systems in Qatar, aiming to align with the nation's broader vision for social, economic, and environmental objectives while protecting fundamental rights.

The guidelines emphasize a human-centred approach and outline eight core ethical principles, including doing no harm, ensuring robustness and safety, fairness, environmental protection, privacy, transparency, and ultimate human accountability. To achieve these, organisations are encouraged to: - Conduct thorough risk assessments, including privacy and discrimination impact assessments, early in the AI lifecycle to identify potential harms. - Implement robust security measures, test for and mitigate bias in datasets and algorithms, and ensure continuous monitoring for fairness and performance. - Prioritize user privacy by minimizing data collection, using anonymization where possible, and applying strong access controls and encryption. - Maintain transparency by clearly communicating AI system purposes, capabilities, and limitations to users, and ensure human oversight for high-impact decisions.

MCIT recommends organisations establish internal AI governance boards or designate an AI officer to oversee these responsibilities, including procurement and lifecycle monitoring. While the guidelines were published in May 2024, organisations are encouraged to begin adopting them within 12 months of that date, with a suggested review and update cadence every one to two years.

It's important to note that these guidelines do not create new legal penalties, as they are voluntary. However, failing to follow their recommendations could significantly increase an organisation's legal and commercial risks under existing Qatari laws, such as the Personal Data Privacy Protection Law or cybersecurity regulations. A key practical takeaway is that despite their non-binding nature, these guidelines serve as a critical benchmark for responsible AI. Ignoring them could expose your organisation to legal challenges, reputational damage, or commercial setbacks, even if no specific "AI law" is directly broken. Organisations should also be prepared for extensive documentation and continuous monitoring throughout the AI system's lifespan to demonstrate adherence.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Qatar - Ethical AI Guidelines. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore processing personal data

    Applies to: Organisations developing and deploying AI systems in Qatar.

    On privacy it mandates minimization, pseudonymization/anonymization where possible, strong access controls and encryption for training and inference data.
  2. #2CriticalBefore placing on market or deploying

    Applies to: Organisations developing and deploying AI systems in Qatar.

    For robustness and security it recommends verification/validation, adversarial testing, continuous monitoring and alignment with NCSA security standards.
  3. #3ImportantEarly-stage, prior to deployment

    Applies to: Organisations developing and deploying AI systems in Qatar.

    For risk assessment it prescribes early-stage threat modelling, DPIAs and DIAs to evaluate possible harms and affected populations.
  4. #4ImportantDuring development and testing

    Applies to: Organisations developing and deploying AI systems in Qatar.

    On bias, it requires representative datasets, fairness testing, and regular audits with feedback loops that allow remediation.
  5. #5ImportantBefore deployment

    Applies to: Organisations deploying AI systems in Qatar.

    For transparency the guidance asks organisations to publish clear, accessible statements describing system purpose, capabilities, limitations and contact points for redress.
  6. #6ImportantBefore deployment

    Applies to: Organisations deploying AI systems in Qatar.

    high-impact decisions should always include human oversight or appeal mechanisms.
  7. #7ImportantContinuously throughout the AI lifecycle

    Applies to: Organisations developing and deploying AI systems in Qatar.

    instituting formal documentation and audit trails for model design choices, datasets, validation results, and change logs.
  8. #8ImportantUpon deployment

    Applies to: Organisations deploying AI systems in Qatar.

    MCIT’s Guidance proposes continuous monitoring using automated telemetry, periodic audits... and KPIs that track accuracy, performance drift, fairness metrics, and security incidents.
  9. #9ImportantBefore deployment

    Applies to: Organisations deploying AI systems in Qatar.

    Organisations are advised to maintain redress channels for affected individuals...
  10. #10RecommendedMay 16, 2025

    Applies to: Organisations involved with AI systems in Qatar.

    Organisations are advised to implement an internal AI governance board or designate an AI officer to oversee risk assessments, approval gates, procurement, and lifecycle monitoring.
  11. #11RecommendedBefore procurement

    Applies to: Organisations procuring AI systems or services in Qatar.

    The guidance also suggests embedding ethical review into procurement and vendor management processes...

© Regulations.AI — created on 13-Jun-2026