Guide
Bahrain’s General Policy for the Use of AI: what government suppliers align to
Bahrain’s General Policy for the Use of Artificial Intelligence, version 1.0, was approved by the Ministerial Committee for Information and Communication Technology on 20 May 2025 and launched by the Information & eGovernment Authority (iGA) on 27 July 2025. It applies to all government entities in the Kingdom, which have had to comply with its rules and principles since 20 May 2025. It sets eleven principles, led by human decision-making: the final decision in important matters, especially those touching individual and societal rights, stays under human control. Its four pillars are compliance with named laws and policies (among them the Personal Data Protection Law, Law No. 16 of 2014 on state information and documents and the GCC’s AI ethics manual), adoption of AI in coordination with iGA, awareness and education, and local and international cooperation. It is a government policy, not a law, and it places no duty directly on companies. A supplier meets it through the entity it sells to, which will ask for evidence against each principle.
Bahrain General Policy for the Use of AI. The General Policy for the Use of Artificial Intelligence, version 1.0 of 20 May 2025, issued by Bahrain’s Information & eGovernment Authority (iGA) and approved by the Ministerial Committee for Information and Communication Technology (MCICT), which applies to all government entities in the Kingdom of Bahrain.
Checked . The General Policy for the Use of AI in English and Arabic (version 1.0, 20 May 2025), iGA’s launch notice of 27 July 2025 and its directorate notice of 2 October 2025, the GCC Guiding Manual on the Ethics of AI Use (version 1.0, November 2023), the Cloud First Policy (version 1.0, 24 April 2017), iGA’s AI readiness report of 12 November 2025 and the National Enterprise Architecture list of policies and standards were read on iga.gov.bh, bahrain.bh and nea.gov.bh on this date. iGA may amend the policy and announces changes on those sites, so check the current text before you rely on it. This page is not legal advice.
What the policy is, and who it binds
Bahrain’s General Policy for the Use of Artificial Intelligence runs to thirteen pages in English, and it is easy to underestimate. Version 1.0 is dated 20 May 2025, the day the Ministerial Committee for Information and Communication Technology (MCICT) approved it, and iGA launched it publicly on 27 July 2025, together with Bahrain’s adoption of the GCC’s AI ethics manual [1, 3]. iGA publishes it in English and in Arabic, both as version 1.0 of the same date [1, 2].
Its scope is one sentence: it applies to all government entities in the Kingdom of Bahrain [1]. From 20 May 2025, the activation clause says, every government entity must comply with its rules, requirements and guiding principles [1]. The roles split three ways. MCICT sets the strategic direction and approved the policy; the ICT Governance Committee (ICTGC) approves updates and decides requests for exemptions or exceptions; iGA manages and promotes the policy and supervises its implementation [1]. In October 2025 iGA said a new Innovation and Advanced Technologies Directorate now develops its emerging technology policy and supports entities adopting AI [8].
What it is not matters as much. It is a government policy, not a law, and nothing in it places a duty directly on a company. A supplier meets it second-hand, through the entity it sells to, and that entity has signed up to principles it can only show it meets with the supplier’s help. That is the practical reason to read it: every principle turns into a question in a tender, a pilot review or an audit.
A binding AI law may follow. The AI readiness report iGA published on 12 November 2025 describes a draft AI law under parliamentary review, with a dedicated AI unit, licensing for developing and deploying AI, prohibited uses and penalties [7]. I have not treated it as law on this page. Check where it stands before you plan around it.
The eleven principles, and the question each one becomes
The policy lists eleven principles [1]. Read from the supplier’s side of the table, each one is a question the buying entity needs answered, and the answer that holds up in a review is an artefact rather than an assurance.
| Dimension | What the policy says | What the buyer will ask | Evidence that answers it |
|---|---|---|---|
| Human decision-making | AI assists people; the final decision in important matters stays under human control, especially where individual and societal rights are involved | Which decisions does the system make, and where does a person decide? | A decision map with a named approver for each rights-affecting step, and a log of the approvals |
| Safety and prevention of harm | Applications are safe and prevent physical or psychological harm; safety comes first in design | What can go wrong, and how do you stop it? | A risk assessment and a tested way to stop or roll back the system |
| Fairness, equity and non-discrimination | No discrimination by race, religion, gender or any other non-objective factor, and no unjust bias in outcomes | How do you know outcomes are fair across groups? | Bias tests on the data and on the outputs, with the results kept |
| Transparency and explainability | Processes are clear, and explainable and understandable to users and specialists | Can you explain this output to the person affected and to our specialists? | A record of inputs, sources and reasons for each decision, and a plain description of the system |
| Responsibility, accountability and awareness | Responsibilities are clearly defined, with accountability mechanisms for errors | Who answers when it is wrong? | A written allocation of who owns what, and an incident route with a named owner |
| Integrity and non-fabrication | Data and information used and provided by AI systems are accurate and not falsified | How do you stop it inventing facts? | Answers grounded in cited sources, and factual accuracy tested before release |
| Privacy and data protection | Personal data is preserved and secure, under the applicable laws and standards | What personal data does it touch, where, and under which law? | A data map, processing records and the terms for any transfer |
| Reliability and safety | Accurate, consistent results, with the system protected from manipulation and breaches | Will it give the same answer tomorrow, and can it be attacked? | Regression tests, security testing that includes prompt injection, and access logs |
| Investment in advanced technology | Continuous investment in the latest AI to improve performance and capability | Will this still be current in two years? | A plan for swapping the model, and a test suite that can re-test its replacement |
| Promoting technological innovation | New ideas and the latest AI, in support of digital transformation | What does this do that the current process cannot? | A baseline and a measured result from a pilot |
| Protection of intellectual property rights | Clear frameworks and controls that protect innovations and intellectual output in AI projects | Who owns what you build, and what did it learn from? | Contract terms on ownership, and a record of the training and reference data |
The first column paraphrases the policy [1]. The second and third are my reading of what a buyer will do with it, and this page is not legal advice.
Two rows carry most of the weight. Human decision-making is the first principle, and the second pillar repeats it: responsibility rests with people, not machines, and a negative outcome is a human decision [1]. That rules out a design where the model acts on a citizen’s case and a person reviews a sample afterwards. What fits is a set of gates that stop the model acting alone on anything that touches someone’s rights. Transparency is the other. A system that cannot say which document and which rule produced an answer will struggle in a government review, however accurate it is.
The laws and policies the first pillar names
The first pillar, commitment to policies and legislation, is where a supplier’s legal exposure sits. It names seven instruments and asks government entities to comply and align with each one [1].
- Personal Data Protection Law
- Law No. 30 of 2018. The policy points to its provisions on processing by automated means, on transferring personal data out of the Kingdom, and on the Data Protection Authority that enforces it.
- State information and documents
- Law No. 16 of 2014 gives criminal protection to state information and documents, and the policy says it expects private companies involved with that information to meet the security standards too. It sorts information into three levels, top secret, secret and restricted, and each entity decides which topics fall into each.
- Cybercrime
- Law No. 60 of 2014 makes unauthorised access to systems, damage to data and electronic fraud, among other acts, criminal offences.
- Cloud services to foreign parties
- Decree-Law No. 56 of 2018 governs cloud services provided to foreign parties and, in the policy’s summary, sets requirements for protecting data stored in cloud data centres in the Kingdom.
- Electronic transactions
- Decree-Law No. 54 of 2018 covers electronic communications and transactions, including electronic signatures, seals and records.
- Open Data Policy
- Bahrain’s open data policy, which the AI policy treats as a source of machine-readable data for training and analysis, with personal information still protected.
- GCC AI ethics manual
- The Guiding Manual on the Ethics of AI Use in GCC Member States, which Bahrain has adopted. It has its own section below.
Each item is as the policy describes it [1], and the manual is in the launch notice too [3]. The one I would put first for any AI project is Law No. 16 of 2014, because it is the one a technical team is least likely to have read. An AI assistant that indexes a ministry’s shared drive will meet classified documents sooner or later. The classification of every source has to travel with it into the index, and the system must never show a user a passage from a document they could not open themselves.
The Personal Data Protection Law needs its own reading for any system that makes or supports decisions about people. Its transfer provisions also decide whether a model hosted outside Bahrain may see personal data at all, which is a question for your counsel before it is a question for your architects.
The second pillar: adopt with iGA, audit, and keep responsibility human
The second pillar, on using and adopting AI, sets five rules for government entities [1].
- Consider AI
- Entities should study where AI could serve their initiatives, projects and procurements.
- Adopt with iGA
- Entities must adopt AI in cooperation with iGA and coordinate with it on developing AI initiatives.
- Follow iGA’s standards
- Entities must follow any relevant standard iGA issues, and the policy gives the criteria and procedure for launching and adopting AI initiatives as its example.
- Audit regularly
- Entities should run regular audits and reviews to check that AI is used to good practice and improves efficiency.
- Own the outcome
- Entities bear the responsibility for applying AI, and any negative effects are attributed to the responsible individuals, not to the machine.
For a supplier, the second rule is the one that changes a timeline. A government entity cannot adopt an AI solution on its own; coordination with iGA is written in as a must [1]. Put that step in the plan, and expect iGA’s questions to follow the principles above.
The third rule points to a document I could not find. The National Enterprise Architecture site, where Bahrain publishes its government ICT policies and standards, listed two AI documents when I checked, the policy and the GCC ethics manual, and no AI standard [6]. Ask the entity for iGA’s current criteria and procedure for AI initiatives before you write a proposal, because that is the checklist the project will be read against.
The pillar’s objectives also ask for specific criteria to evaluate and identify which projects can benefit from AI [1]. Scoring every candidate the same way, with a risk rating for each proposed use case, is a reasonable way to show that before iGA asks. The third and fourth pillars ask entities to train their staff and to cooperate, including exchanging experiences, algorithms, infrastructure and security standards between entities where possible [1]. Expect training in the scope, and settle who owns what early, because the work may be shared.
What the GCC ethics manual adds
The policy adopts the Guiding Manual on the Ethics of Artificial Intelligence Use in GCC Member States, version 1.0 of November 2023, issued by the GCC Ministerial Committee for eGovernment [3, 4]. The manual sets four values and seven principles, and where the Bahraini policy states a principle, the manual often says what putting it into practice looks like [4]. The overlap is close: the policy’s principles on human decision-making, safety, fairness, privacy, transparency, accountability and integrity track the manual’s seven, and the policy adds reliability, investment, innovation and intellectual property [1, 4].
These are the manual’s recommendations a supplier can build to [4].
- Rights impact assessment
- Where a system puts fundamental rights at risk, assess that before it is developed, including the level of harm and risk to every part of society.
- No solely automated decisions
- Give users the right not to be subject to decisions made solely by automated processing where those decisions have legal effects or affect them significantly.
- Rollback
- Include a rollback mechanism for high-risk harms, developed and tested in advance where the risk is particularly high.
- Error rates
- Where inaccurate predictions cannot be avoided, estimate the error rate so decision-makers can choose whether to deploy.
- Dataset audits
- Check training and operating data for unintended bias, and document testing at every stage, including for systems sourced from outside.
- Access control and audit trails
- Limit access to personal data to authorised people with a legitimate need, and keep and monitor audit trails of access and use.
- Disclosure and a human option
- Tell users when they are dealing with AI, let them choose a person where needed, and send appeals to a designated official who can correct the decision.
- Traceability and audit
- Document datasets and decision processes so a wrong decision can be traced, and keep systems open to internal and independent external auditors.
The manual is guidance. Its final provisions say it replaces none of a state’s duties or rights, and it asks member states to give its values effect through their own legislation, regulations and guidelines [4]. Bahrain has done that through the policy. My reading is that the list above is the most practical definition either document gives of what the principles mean once a system ships, and I would build to it rather than to the principles alone.
Cloud First, classification and where the model runs
Bahrain’s Cloud First Policy, version 1.0 of 24 April 2017, predates the AI policy by eight years and still frames how government systems are hosted [5]. Government entities are required to use cloud services for new ICT services and when replacing existing ones, unless another approach meets a special requirement, costs less over its lifetime and gives at least the same security assurance [5].
Its position on residency is the reverse of what many Gulf buyers assume. The policy says the benefits of cloud are best realised when no data residency restrictions are placed on data, and that entities concerned about foreign access to government data should choose vendors with the right security standards and controls [5]. That is not a licence to send anything anywhere. The same policy ties protection to data classification, and the AI policy adds the state information law, the personal data law’s transfer provisions and the decree on cloud services [1, 5]. My summary is that Bahrain decides location by classification and by law, data class by data class, rather than by one residency rule.
Cloud providers serving government are expected to meet international security standards and hold the certifications that go with them, and each entity needs a backup plan, which should keep a copy of its data in a second location across two regions [5]. For an AI system the region question has a second half, because a cloud region in Bahrain does not mean the model runs there. What each vendor runs in its Gulf regions is covered model by model in the residency guide, and it is the question to put to any vendor before a proposal promises processing in the Kingdom.
A supplier evidence pack
This is the pack I would have ready before a first meeting with a Bahraini government entity. It is built from the policy and the manual [1, 4]; it is not a list iGA publishes.
- Decision map
- Every decision the system makes or supports, whether it touches someone’s rights, and the named person who takes the final decision on each one that does.
- System description
- What the system does and does not do, its data sources and its known limits, written for users and for specialists.
- Risk and rights assessment
- The rights impact assessment the manual asks for, with a risk rating and the controls that answer each risk.
- Evaluation results
- Accuracy, consistency and error rates on the entity’s own documents and questions, and bias tests across the groups the policy names.
- Classification handling
- How each document’s classification under Law No. 16 of 2014 is carried into the system, and proof that a user never sees content they could not open themselves.
- Data and hosting map
- Where personal and classified data is stored and processed, which model endpoints see it, and the legal basis for anything that leaves Bahrain.
- Rollback and incident route
- How the system is stopped or rolled back, who is called, and a record of having tested it.
- Audit access
- Logs and records an internal or external auditor can read without the supplier in the room, and the written allocation of who owns what.
- Ownership terms
- Who owns the code, the prompts, the test sets and any fine-tuned model, and how sharing between government entities is handled.
The strongest version of each item comes out of the system itself, as logs, test runs and configuration. A document describing controls the system does not enforce is the first thing an audit under the second pillar will find. An entity that wants its own internal rules under the national policy can start from an AI policy written as clauses a system can enforce, so each principle maps to a control someone can test.
Where 1AYM fits
The evidence pack above is what we build as AI governance implementation: the decision gates, the logs, the evaluation and bias tests and the audit trail sit inside the system, so a government entity can show iGA and its auditors what the system does rather than what a document says it does. Where an entity is still at the second pillar’s first step, deciding which initiatives are worth doing, the AI Opportunity & Feasibility Sprint scores and sizes the candidates before anything is procured. 1AYM has built Arabic-language AI, including bilingual Arabic and English search and Arabic document OCR, which matters when an entity’s records and forms are in Arabic.
We work with clients across the UK, the US and the Gulf, and we have an entity in the UAE. Our closest published work in the region is the production estate of a government-accredited EdTech in the Middle East, whose database we replatformed into Google Cloud’s Doha region, me-central1, to meet Gulf data-residency requirements. Once a scope is signed, a fixed-scope build can start within a day, and if you already have a scoped job, we can resource it on contract from the collective of associates who work with us, held to the same standard. If you are preparing a bid or a pilot for a Bahraini government entity, book a call from the end of this page or email us.
For engineers: human gates, classification-aware retrieval, rollback and audit logs
The policy’s principles and the manual’s recommendations in engineering terms. Each item is something an auditor can check in configuration, code or logs rather than by asking someone.
- Decision gates
- Classify every action the system can take by whether it affects a person’s rights. Anything that does goes through an approval step recorded with the approver’s identity, and the model cannot call it directly (policy principle one; manual principle one).
- Classification-aware retrieval
- Carry each document’s classification level and access list into the index as metadata, filter at query time on the user’s own entitlements, and test that a restricted passage never reaches the prompt for a user who could not open its source.
- Endpoint inventory
- Generate the list of model endpoints, their regions and the data classes each one receives from infrastructure code, and fail the deployment if personal or classified data is routed to an endpoint outside the approved list.
- Evaluation in CI
- Keep a test set built from the entity’s own documents and questions, in Arabic and English, and run accuracy, consistency and error-rate checks on every change and every model swap.
- Bias tests
- Where the system’s outputs could differ by religion, gender or another non-objective factor the policy names, test for it and keep the results with the release.
- Traceable answers
- Return the sources behind each answer, and log the input, the retrieved passages, the model version and the outcome for each decision, so a wrong answer can be traced to its cause.
- Rollback and a manual route
- Version prompts, retrieval configuration and model choice together so a release rolls back in one step, and keep a switch that sends all work to people.
- Disclosure and handoff
- Say in the interface that the user is dealing with AI, offer a route to a person, and log each appeal to the designated official with its outcome.
- Access audit trail
- Log every read of personal or classified data by a person or by the system, and review the log on a schedule the entity sets.
Sources
- [1]Information & eGovernment Authority, General Policy for the Use of Artificial Intelligence, version 1.0 (20 May 2025), English, read 30 September 2026
- [2]Information & eGovernment Authority, General Policy for the Use of Artificial Intelligence, version 1.0 (20 May 2025), Arabic text, read 30 September 2026
- [3]Information & eGovernment Authority, “Bahrain Launches National AI Policy and Adopts GCC Ethics Manual” (27 July 2025), read 30 September 2026
- [4]GCC Ministerial Committee for eGovernment, The Guiding Manual on the Ethics of Artificial Intelligence Use in Member States of the GCC, version 1.0 (November 2023), on Bahrain’s national portal, read 30 September 2026
- [5]Information & eGovernment Authority, Cloud First Policy, version 1.0 (24 April 2017), read 30 September 2026
- [6]National Enterprise Architecture Framework, policies and standards list, read 30 September 2026
- [7]Kingdom of Bahrain, UNESCO Artificial Intelligence Readiness Assessment Methodology (RAM) report (12 November 2025), published by iGA, read 30 September 2026
- [8]Information & eGovernment Authority, notice on six National Digital Economy Strategy initiatives and the Innovation and Advanced Technologies Directorate (2 October 2025), read 30 September 2026
Questions suppliers and government teams ask
What is Bahrain’s AI policy?
The General Policy for the Use of Artificial Intelligence, version 1.0, approved by the Ministerial Committee for Information and Communication Technology on 20 May 2025 and launched by the Information & eGovernment Authority (iGA) on 27 July 2025. It applies to all government entities in Bahrain and sets eleven principles and four pillars: compliance with named laws and policies, adoption of AI in coordination with iGA, awareness and education, and local and international cooperation.
Does Bahrain’s AI policy apply to private companies?
Not directly: its scope is government entities. A company selling AI to a government entity meets it through that entity, which has to show the system follows the policy’s principles. Some of the laws the policy names reach further, and the policy says Law No. 16 of 2014 expects private companies involved with state information to meet its security standards.
Does Bahrain have an AI law?
The sources read for this page show a draft, not an enacted law. The AI readiness report iGA published on 12 November 2025 described a draft AI law under parliamentary review, with a dedicated AI unit, licensing for developing and deploying AI, prohibited uses and penalties. Government use of AI is governed meanwhile by the policy and by existing laws on personal data, state information, cybercrime, cloud services and electronic transactions. Check the draft’s status before relying on this.
Who oversees Bahrain’s AI policy?
iGA manages, updates and promotes the policy and supervises its implementation. The ICT Governance Committee approves updates and decides requests for exemptions and exceptions, and the Ministerial Committee for Information and Communication Technology sets the strategic direction and approved the policy.
What is the GCC AI ethics manual?
The Guiding Manual on the Ethics of Artificial Intelligence Use in GCC Member States, version 1.0 of November 2023, issued by the GCC Ministerial Committee for eGovernment. It sets four values and seven principles, from human decision-making to integrity, with practical recommendations such as rights impact assessments, rollback mechanisms and audit trails. Bahrain adopted it alongside the national policy in July 2025.
Does government data have to stay in Bahrain?
No single rule in the sources read for this page says so for AI. Bahrain’s Cloud First Policy of 2017 says cloud works best without data residency restrictions, but location still depends on the data: information classified under Law No. 16 of 2014 and transfers of personal data under the Personal Data Protection Law carry their own conditions. Ask the entity how each kind of data is classified before choosing where a model runs. This is not legal advice.
What should a supplier bring to a Bahraini government AI pilot?
A decision map with a named person on every decision that affects someone’s rights, a plain description of the system, a risk and rights assessment, evaluation and bias results on the entity’s own data, proof that classified documents reach only the people entitled to them, a map of where data is hosted, a tested rollback and access for auditors.
More in this topic
Where OCR and document AI fail on the Arabic forms and stamped documents government services run on.
Why search tuned for English misses Arabic policies and reports, and how to test a bilingual system before a ministry relies on it.
- Saudi PDPL and AIGuide
The duties Saudi Arabia’s data law puts on public bodies and companies that run AI on personal data.
Further
- AI governance implementation · The engagement that builds the decision gates, logs and tests a government review asks about into the system itself.
- Engagement file D-02 · A government-accredited EdTech in the Middle East, replatformed into Google Cloud’s Doha region for residency.
- AI Opportunity & Feasibility Sprint · Scoring and sizing candidate AI initiatives before an entity procures one.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM