Qatar - Ethical AI Guidelines
Principles and Guidelines for Ethical Development and Deployment of Artificial Intelligence (MCIT)
Qatar
RAI-QA-NA-PGEDDXX-2025Qatar - Ethical AI Guidelines is In Force in Qatar as of 9 Sep 2026, according to mcit.gov.qa.
GuidelineGovernance and OversightRisk ManagementData Protection and PrivacyThe Principles and Guidelines for Ethical AI guides developers and organizations in Qatar on responsible AI use, issued by the Ministry of Communications and Information Technology in 2024. It sets out eight core principles and recommends risk impact assessments. The non-binding guidance took effect on May 8, 2025, and is currently in force.
Summary
The “Principles and Guidelines for Ethical Development and Deployment of Artificial Intelligence” is a national guidance document issued and promoted by the Ministry of Communications and Information Technology (MCIT) of the State of Qatar. It is non-binding guidance aimed at developers, deployers, public sector entities, private organisations, academic institutions and the general public. The Guidance sets out eight core principles (including “Do no harm”; robustness, security and safety; prevention of bias and discrimination; environmental protection; privacy safeguards; transparency; human-centred development; and assigning ultimate accountability to humans). Each principle is accompanied by rationale, practical guidelines, and examples. The guidance encourages comprehensive risk and impact assessment at the design and deployment phases, continuous monitoring, documentation, testing and validation, and transparent disclosures to users and affected stakeholders. It references national strategy goals (Qatar National Vision 2030 and Digital Agenda 2030) and aligns with international frameworks such as UNESCO and OECD AI principles. The document also cross-references national cybersecurity guidance by the National Cyber Security Agency (NCSA) and Qatar’s Personal Data Privacy Protection Law (Law No. 13 of 2016), recommending adherence to applicable legal requirements (for example on data protection) even though the guidance itself remains voluntary.
Operationally, the guidelines recommend procedural measures: perform discrimination and data protection impact assessments, ensure representative training data, maintain secure data handling and encryption, adopt logging and explainability practices, introduce human oversight mechanisms for high-impact decisions, and minimize environmental footprint during model training and deployment. The Guidance promotes internal and external auditing, user feedback mechanisms and redress channels. While it does not create new statutory penalties, it warns that failure to follow its recommendations may expose organisations to existing legal obligations under Qatar’s data protection and cybersecurity regimes and could negatively affect procurement eligibility or certification opportunities. The document is intended to be updated periodically (every 1–2 years) as technologies and risks evolve. Key stakeholders identified include MCIT (policy lead), the National Cyber Security Agency (technical and security guidance), the Ministry/department responsible for personal data protection (oversight on privacy compliance), and other government and industry actors in the AI ecosystem.
The Guidance is positioned as a practical first-tier governance instrument to promote responsible AI across sectors including healthcare and finance, and to provide a foundation for future rule-making and standards development. It combines high-level ethical principles with actionable practices for engineers, managers, and public officials, and it strongly emphasizes transparency, fairness, security, and the primacy of human accountability in AI systems.
Full article
Read full text ↗Overview
The Principles and Guidelines for Ethical Development and Deployment of Artificial Intelligence, published and promoted by the Ministry of Communications and Information Technology (MCIT), set out non-binding but practical guidance for organisations and individuals involved in the creation, deployment and use of AI systems in Qatar. The guidance frames AI development within Qatar National Vision 2030 and the Digital Agenda 2030 and is intended to support social, economic and environmental objectives while protecting fundamental rights. The document defines eight core ethical principles ("Do no harm"; robustness, security and safety; fairness and anti-discrimination; environmental protection; privacy; transparency; human-centred development; and ultimate human accountability) and provides actionable measures, examples and rationales for each. The original guidance text and downloadable materials are available from MCIT and public portals; see the MCIT guidelines and the official PDF for the full text at Artificial Intelligence in Qatar – Principles and Guidelines for Ethical Development and Deployment (MCIT PDF) and further description on the MCIT site at MCIT Guidelines.
Definitions
Key terms used in the guidance include AI system (physical or virtual products or services using AI to serve end users), developer (the party responsible for creation and training of models), deployer (the organisation placing AI into operation), bias (systemic errors resulting in unfair outcomes), discrimination impact assessment (DIA) and data protection impact assessment (DPIA). The document clarifies that the guidance is legally non-binding and that existing laws such as Law No. 13 of 2016 on Personal Data Privacy Protection remain authoritative for legal compliance. It also references technical definitions used by international standards bodies, aligning local terminology with OECD and UNESCO frameworks.
Governance and Institutional Framework
The guidance recommends an institutional governance model that assigns clear roles and responsibilities across technical, legal and executive functions. It identifies MCIT as the policy lead and recommends coordination with the National Cyber Security Agency (NCSA) for system security guidance and with the competent authority overseeing the Personal Data Privacy Protection Law for privacy oversight. Organisations are advised to implement an internal AI governance board or designate an AI officer to oversee risk assessments, approval gates, procurement, and lifecycle monitoring. The guidance also suggests embedding ethical review into procurement and vendor management processes, instituting formal documentation and audit trails for model design choices, datasets, validation results, and change logs. For national coordination, it encourages cross-agency collaboration and references the MCIT AI Committee and the NCSA’s “Guidelines for Secure Adoption and Usage of Artificial Intelligence” for technical alignment; see MCIT AI Committee and NCSA guidance for programmatic details and implementation support.
Key Focus Areas
The Guidance focuses on several practical and thematic areas: risk assessment and mitigation, safety and robustness, bias and fairness, privacy and data governance, transparency and user communication, human oversight and accountability, environmental sustainability, and monitoring/post-deployment controls. For risk assessment it prescribes early-stage threat modelling, DPIAs and DIAs to evaluate possible harms and affected populations. For robustness and security it recommends verification/validation, adversarial testing, continuous monitoring and alignment with NCSA security standards. On bias, it requires representative datasets, fairness testing, and regular audits with feedback loops that allow remediation. On privacy it mandates minimization, pseudonymization/anonymization where possible, strong access controls and encryption for training and inference data. On transparency the guidance asks organisations to publish clear, accessible statements describing system purpose, capabilities, limitations and contact points for redress. Environmental sustainability guidance calls for measuring and optimising model training carbon footprint and prioritising efficient architectures. Finally, a human-centred approach emphasizes design for user dignity, inclusivity and usability; high-impact decisions should always include human oversight or appeal mechanisms.
Implementation Framework
The document offers a lifecycle-focused implementation framework: (1) Design & Procurement: require impact assessments, vendor due diligence and contractual clauses on transparency and security; (2) Development & Testing: apply secure coding, data quality controls, bias checks and robust test suites (including edge-case and adversarial tests); (3) Deployment & Monitoring: deploy with logging, performance and fairness monitoring, incident response plans, and explainability tools for affected users; (4) Maintenance & Retirement: require model retraining policies, decommissioning procedures and data retention controls. The guidance provides templated checklists and example governance artifacts to help organisations operationalize these phases and recommends periodic reviews and updates to keep pace with technological change.
Monitoring and Evaluation
MCIT’s Guidance proposes continuous monitoring using automated telemetry, periodic audits (internal and third-party), user feedback mechanisms and KPIs that track accuracy, performance drift, fairness metrics, and security incidents. Monitoring should include scheduled re-evaluation of training data representativeness, post-deployment bias scanning, and anomaly detection to identify degraded performance or malicious manipulation. The guidance also suggests establishing reporting channels for incidents and an escalation protocol to technical and legal leads; organisations are encouraged to record monitoring outputs and remediation actions in persistent evidence logs to support audits and accountability reviews.
Penalties, Liability, and Appeals
Because the document is presented as voluntary guidance, it does not itself create new statutory penalties. However, it explicitly notes that failure to follow its recommendations may increase legal and commercial risk and could lead to consequences under existing Qatari laws (for example, the Personal Data Privacy Protection Law and applicable cybersecurity regulations). Organisations are advised to maintain redress channels for affected individuals, retain records to support legal defence, and ensure procurement and contracting include clauses on liability allocation. The guidance also recommends clear internal appeals procedures for users affected by automated decisions and encourages organisations to document remediation outcomes publicly when appropriate.
Relationship to Other Instruments
The Guidance is designed to complement and reference existing national and international instruments rather than replace them. It cross-references Qatar’s Personal Data Privacy Protection Law (Law No. 13 of 2016), the NCSA’s secure AI adoption guidance, national cybersecurity standards, and Qatar’s National AI Strategy. Internationally it aligns with UNESCO’s Recommendation on the Ethics of Artificial Intelligence, the OECD AI Principles and other multilateral norms. The document recommends that organisations comply with binding law first and use the Guidelines to operationalise ethical best practices not yet codified in law.
International Alignment
MCIT frames the Guidelines to be consistent with leading international frameworks — citing UNESCO and OECD — and encourages interoperability with international standards and certifications. This alignment aims to facilitate responsible cross-border research, technology transfer and export of AI solutions from Qatar while meeting global expectations on human rights, privacy and safety. It further encourages participation in international standards development and recommends that national technical standards bodies consider adopting interoperable assessment and reporting templates to support international procurement and market access.
Implementation Timeline
| Milestone | Target Date |
|---|---|
| Guidelines first public posting (Sharek/MCIT asset) | 2024-05-16 |
| MCIT publicity & conference highlights | 2025-05-08 |
| Recommended organisational adoption window (initial) | Within 12 months of guidance publication |
| Suggested review/update cadence | Every 1–2 years |
Sources and References
| Source | Type |
|---|---|
| Artificial Intelligence in Qatar – Principles and Guidelines for Ethical Development and Deployment (MCIT PDF) | Primary Source |
| MCIT Guidelines (Guidelines overview page) | Primary Source |
| Qatar News Agency: MCIT outlines efforts to establish regulatory, ethical frameworks for AI use | Primary Source (government press) |
Requirements for a company
What an organisation has to do under Qatar - Ethical AI Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
10- Designate an AI officer or establish an internal AI governance board to oversee risk assessments, approval gates, and lifecycle monitoring.Organisations developing or deploying AI systems in Qatar
- Perform data protection impact assessments and discrimination impact assessments to evaluate potential harms during early design stages.AI developers and deployers in Qatar
- Publish clear, accessible statements outlining system purpose, capabilities, limitations, and contact points for user redress.AI deployers in Qatar
- Incorporate human oversight and appeal mechanisms for AI systems that make high-impact decisions.Deployers of high-impact AI systems in Qatar
- Execute robust test suites, including edge-case and adversarial testing, prior to deploying AI systems.AI developers in Qatar
- Use representative datasets and conduct regular post-deployment fairness testing and bias scanning.AI developers and deployers in Qatar
- +4 more in the table below
Should not do
0Nothing in this category.
Who must do what
The obligations under Qatar - Ethical AI Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Organisations developing or deploying AI systems in Qatar | Designate an AI officer or establish an internal AI governance board to oversee risk assessments, approval gates, and lifecycle monitoring. “Organisations are advised to implement an internal AI governance board or designate an AI officer to oversee risk assessments, approval gates, procurement, and lifecycle monitoring.” | — | — | Recommended |
| 2 | AI developers and deployers in Qatar | Perform data protection impact assessments and discrimination impact assessments to evaluate potential harms during early design stages. “For risk assessment it prescribes early-stage threat modelling, DPIAs and DIAs to evaluate possible harms and affected populations.” | Before deployment | — | Recommended |
| 3 | AI deployers in Qatar | Publish clear, accessible statements outlining system purpose, capabilities, limitations, and contact points for user redress. “publish clear, accessible statements describing system purpose, capabilities, limitations and contact points for redress.” | — | — | Recommended |
| 4 | Deployers of high-impact AI systems in Qatar | Incorporate human oversight and appeal mechanisms for AI systems that make high-impact decisions. “high-impact decisions should always include human oversight or appeal mechanisms.” | — | — | Recommended |
| 5 | AI developers in Qatar | Execute robust test suites, including edge-case and adversarial testing, prior to deploying AI systems. “apply secure coding, data quality controls, bias checks and robust test suites (including edge-case and adversarial tests)” | Before deployment | — | Recommended |
| 6 | AI developers and deployers in Qatar | Use representative datasets and conduct regular post-deployment fairness testing and bias scanning. “On bias, it requires representative datasets, fairness testing, and regular audits with feedback loops that allow remediation.” | — | — | Recommended |
| 7 | AI developers and deployers in Qatar | Implement data minimization, pseudonymization, robust access controls, and encryption for training and inference data. “On privacy it mandates minimization, pseudonymization/anonymization where possible, strong access controls and encryption for training and inference data.” | — | — | Recommended |
| 8 | AI developers and deployers in Qatar | Maintain persistent evidence logs for model design choices, datasets, validation results, and change logs. “instituting formal documentation and audit trails for model design choices, datasets, validation results, and change logs.” | — | — | Recommended |
| 9 | Organisations procuring AI systems in Qatar | Include contractual clauses on transparency, security, and liability allocation in vendor and procurement agreements. “require impact assessments, vendor due diligence and contractual clauses on transparency and security” | During procurement | — | Recommended |
| 10 | AI developers in Qatar | Measure and optimize the carbon footprint generated during AI model training while prioritizing efficient architectures. “Environmental sustainability guidance calls for measuring and optimising model training carbon footprint and prioritising efficient architectures.” | — | — | Recommended |
Related Regulations
More AI regulation in Qatar
© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash