**By THE EDITORIAL BOARD**
Enterprise AI initiatives fail at an alarming rate — not because the algorithms are insufficient, but because the operational foundation underneath them is cracked. Organisations across the Middle East are pouring capital into artificial intelligence while neglecting the data infrastructure, governance frameworks, and change management muscle required to make AI commercially viable. This article examines the operational disciplines that separate AI theatre from AI transformation, with a focus on what large enterprises in the GCC and wider MENA region must actually build before they can expect returns.
—
## AI Without Operational Backbone Is Just Software
**Seventy percent of AI projects fail to deliver business value.** That figure, widely cited across Gartner and McKinsey research, is not a technology problem — it is an operational one. Machine learning models deployed without clean data, clear ownership, or aligned stakeholders degrade into expensive experiments that serve no commercial purpose.
The Middle East is not immune. Saudi Arabia’s Vision 2030 has earmarked significant investment in AI and digital infrastructure, with government entities and sovereign-adjacent enterprises launching programmes at pace. The UAE’s Artificial Intelligence Strategy 2031 and the establishment of bodies like the Hub71 climate in Abu Dhabi demonstrate political will. Yet implementation gaps persist. **Organisations in the region report that 58% of AI proofs of concept never reach production**, according to a 2025 Accenture survey of GCC enterprises.
The root cause is predictable. Procurement teams buy AI tools before they have defined the data inputs those tools require. CIOs commission platforms before they have mapped the change management journey for the people who will use them. Boards approve budgets without establishing clear success metrics tied to operational KPIs rather than technical sophistication.
**The operational backbone of enterprise AI consists of four interlocking disciplines:**
– **Data strategy** — governing, governing, and curating the inputs upon which every model depends
– **Digital transformation** — modernising legacy systems and workflows so AI can actually operate within them
– **Change management** — shifting organisational behaviour so that AI delivers adoption rather than shelfware
– **Cybersecurity** — protecting the expanded attack surface that AI creates
Skip any one of these and the program collapses. Prioritise all four and the probability of commercial success rises sharply.
—
## Data Strategy — The Foundation of Every Successful AI Programme
Data is not an IT asset. **Data is a strategic asset**, and enterprises that treat it as such outperform their peers on AI outcomes by a factor of 2.4×, according to Forrester’s 2025 data-driven enterprise benchmark.
In the MENA region, data maturity varies enormously. Financial institutions operating under the UAE Central Bank and the Dubai International Financial Centre (DIFC) data governance standards tend to have more structured data architectures than family-owned conglomerates or government entities still operating on paper-first processes. But even regulated industries struggle with master data quality, lineage tracking, and cross-entity data harmonisation.
**A data-strategy maturity model helps leaders diagnose where they stand and where they need to go.**
### Data Strategy Maturity Table
| Level | Data Architecture | Data Quality | Governance & Compliance | AI Readiness |
|——-|——————-|————–|————————|————–|
| **1 — Reactive** | Siloed, on-premises databases, no central catalogue | Ad hoc, manual validation, 30–60% data quality issues | No formal governance; informal access controls | AI experiments isolated to individual departments |
| **2 — Managed** | Data warehouse installed; partial centralisation | Basic profiling, 10–30% data quality issues | Data Steward roles established; DIFC/UAE CBUAE compliance mapped | Pilot projects with defined data inputs |
| **3 — Defined** | Modern data platform (lakehouse or cloud warehouse); real-time pipelines | Automated quality checks, <10% exception rates | Formal data governance board; policy-driven access; audit trails | Company-wide AI platform with reusable models |
| **4 — Optimised** | Federated mesh architecture; self-service data products | Continuous monitoring, <3% exception rates | Automated policy enforcement; Privacy by Design | AI-first operating model; models retrained continuously |
The jump from Level 2 to Level 3 is where most GCC enterprises get stuck. Moving from a managed warehouse to a modern data platform requires cloud capability, data engineering talent, and executive appetite for retiring legacy systems. Those who make the jump see AI cycle times drop from months to weeks.
BCG’s 2025 Technology and Digital Report notes that **enterprises at Level 3 or higher on data maturity generate 1.8× more revenue per employee** than those at Level 1 or 2, with AI contribution accounting for roughly one-third of that gap.
—
## Digital Transformation as an AI Enabler
There is a pervasive myth that AI replaces the need for digital transformation. **It does not.** AI sits on top of digitally enabled infrastructure. An organisation running paper-based approval workflows, disconnected ERP instances, and batch-mode integration will not unlock value from an AI tool simply because it has access to a language model.
Digital transformation is the enabler; AI is the amplifier.
In practice, this means:
– **Modernising core systems** before modelling them. A predictive maintenance AI is useless if the IoT sensor data is trapped in a proprietary SCADA system with no API.
– **Eliminating batch latency.** Real-time AI decisions require real-time data flows. If finance closes monthly, an AI-driven receivables forecasting model delivering weekly insights is already compromised.
– **Building API-first architectures.** The best AI platforms in the UAE and Saudi Arabia today are those that have exposed internal data through structured APIs, allowing models to consume and act without manual ETL bottlenecks.
Accenture’s 2024 Digital Dashboard found that **organisations with integrated, API-driven architectures are 3.5× more likely to scale AI beyond pilot** than those relying on legacy point-to-point integrations.
For GCC enterprises specifically, digital transformation also carries a workforce dimension. Many organisations in the region are running dual workforces — a digitally native graduate cohort alongside long-tenured operational staff. Transformation programmes that fail to bridge this skills gap create data friction that AI cannot overcome.
—
## Cybersecurity and the AI Attack Surface
AI expands the attack surface in ways that traditional security frameworks were not designed to handle. **Generative AI introduces prompt injection, model inversion, and data poisoning risks.** Machine learning pipelines are susceptible to adversarial manipulation. Autonomous agents executing on behalf of users create privilege escalation paths that security teams barely understand.
In the MENA context, regulatory pressure is accelerating. The UAE Central Bank’s guidelines on AI and data ethics require financial institutions to demonstrate model risk management comparable to the governance expected of credit risk or market risk. DIFC’s Data Protection Law and the Saudi Data and AI Authority (SDAIA) regulations impose similar obligations on entities operating personal data through AI systems.
**Specific AI security risks demanding operational attention:**
– **Data leakage through model outputs** — generative AI trained on proprietary documents can reconstruct sensitive information when queried cleverly
– **Shadow AI** — employees deploying consumer-grade AI tools on corporate data without oversight, creating uncontrolled data exfiltration channels
– **Supply chain poisoning** — third-party pre-trained models carrying hidden biases or backdoors, particularly relevant when enterprises use open-source foundation models without internal validation
– **Model theft** — adversaries querying production models to reconstruct training data or replicate proprietary decision logic
Gartner predicts that **by 2027, 40% of AI-related security incidents will involve prompt injection or data poisoning attacks**, up from less than 5% in 2024. Enterprises must build AI-specific security controls — model access logging, output filtering, adversarial red-teaming — into their operational playbooks, not bolt them on after deployment.
PwC’s 2025 Global Digital Trust Insights notes that **organisations with dedicated AI security teams reduce breach costs by an average of 48%** compared to those treating AI security as a subset of general cybersecurity.
—
## Change Management — The Most Underestimated AI Risk
Technology failures are visible and dramatic. People failures are usually quiet and fatal. **According to McKinsey, organisations that invest in change management alongside technology deployment are 6× more likely to realise expected AI benefits.**
Yet change management budgets in the Middle East routinely run at less than 10% of total AI programme spend. This reflects a broader regional pattern: technology investment is viewed as a capital priority, while the softer work of shifting behaviour, rebuilding roles, and sustaining adoption is seen as an operational afterthought.
In the GCC specifically, change management faces particular dynamics:
– **Hierarchical organisations** where middle management may perceive AI as a threat to role relevance rather than a support tool
– **Workforce diversity** spanning multiple nationalities, languages, and digital literacy levels
– **Rapidly evolving national mandates** (Vision 2030, UAE AI Strategy) that create pace pressure, making it tempting to skip the alignment work
Effective AI change management must address three layers:
1. **Individual readiness** — assessing confidence, digital literacy, and perceived usefulness before deployment
2. **Process redesign** — ensuring that new AI-augmented workflows are genuinely simpler than the legacy paths they replace
3. **Leadership modelling** — executives visibly using AI tools, discussing failures openly, and tying AI adoption to performance conversations
Forrester’s 2025 Change Management Benchmark found that **organisations with structured change management programmes retain 82% of AI-driven productivity gains beyond 12 months**, versus 21% for those treating adoption as purely voluntary.
In MENA contexts, change management must also account for Ramadan working patterns, regional communication preferences, and the fact that many frontline staff are on rotation or shift-based rosters, making consistent training delivery more complex than in Western office environments.
—
## The APH Operations Maturity Framework
Drawing on the patterns above, we propose the APH Operations Maturity Framework as a diagnostic tool for enterprise AI readiness. The framework assesses four dimensions — data, change, technology, and governance — across five levels of maturity.
### APH Operations Maturity Framework Table
| Level | Data | Change | Technology | Governance |
|——-|——|——–|————|————|
| **1 — Ad Hoc** | Unstructured, siloed, no quality controls | Deployment announced as completed training; usage <20% | Legacy only; no AI platform; point integrations | No formal AI policy; ad hoc ethics review |
| **2 — Reactive** | Data catalogues exist; sporadic quality checks | Change team appointed post-failure; reactive communication | AI sandbox in place; limited API layer | AI risk register maintained; basic model documentation |
| **3 — Defined** | Structured data products; automated quality gates | Structured change programme with milestones and sponsors | Production AI platform; model registry; CI/CD for ML | Formal AI governance committee; model risk policy aligned with UAE CBUAE / DIFC standards |
| **4 — Managed** | Self-service data mesh; real-time quality monitoring | Continuous adoption analytics; targeted intervention at resistance points | Feature store; model monitoring; automated retraining pipelines | Proactive model risk management; mandatory adversarial testing; board reporting on AI KPIs |
| **5 — Optimised** | Indigenous data products monetised internally and externally | AI-augmented change automation; culture of experimentation | Full MLOps maturity; edge-to-cloud AI orchestration | AI strategy integrated into enterprise risk and strategy; external audits; regulatory sandbox participation |
Moving from one level to the next requires investment in each column simultaneously. A common failure pattern is over-investing in technology (Level 3 platform) while under-investing in change and governance, resulting in technically capable initiatives that stall at adoption.
**Practical guidance for MENA enterprises:**
– UAE-based financial institutions should target Level 3+ by aligning AI governance documentation with UAE CBUAE guidelines on model risk and data ethics
– Saudi government and PSU entities should integrate this framework into Saudi Vision 2030 digital KPIs, using the structured levels as measurable transformation milestones
– Private enterprises operating across multiple GCC jurisdictions should standardise on the highest common denominator — typically DIFC data protection and AI governance standards — as a baseline
—
## Sequencing the Programme: What First, What Second, What Last
AI programmes often fail because leadership tries to do everything at once. **Sequencing is a strategic capability.** The organisations that move fastest are those that build an operational sequence — a deliberately ordered programme of capability delivery.
### Recommended Sequence
**Phase 1: Stabilise data (Months 1–4)**
– Complete a data architecture assessment using the maturity table above
– Instrument data quality monitoring on the 20% of datasets that drive 80% of business decisions
– Establish data governance roles and a steering forum
– Decommission or replace the worst-performing legacy data silos
**Phase 2: Enable the platform (Months 3–6)**
– Deploy or expand the enterprise AI/ML platform
– Build the first production model — typically a high-value, low-complexity use case such as fraud detection, demand forecasting, or document processing
– Stand up MLOps fundamentals: model registry, deployment pipeline, monitoring dashboard
– Establish security controls for model access and data lineage
**Phase 3: Scale via governance (Months 5–9)**
– Activate the AI governance committee
– Roll out company-wide AI policy, acceptable use guidance, and a model risk taxonomy
– Launch structured change management programme for first-wave adoption
– Publish internal case studies from Phase 2 success to build momentum
**Phase 4: Optimise (Months 9–12+)**
– Introduce self-service data products for citizen data scientists
– Expand MLOps to automated retraining and drift detection
– Establish external benchmarking and competitive tracking
– Begin experimentation with generative AI use cases, now grounded in mature data and governance foundations
PwC’s 2025 Enterprise AI Survey found that **organisations following a sequenced approach are 2.7× more likely to achieve AI production within 12 months** than those attempting parallel launch of multiple use cases.
The sequencing above is particularly suited to MENA organisations because Phase 1 delivers visible operational improvements (better data quality, fewer compliance incidents) even before a single AI model goes live — creating the executive confidence required to fund subsequent phases.
—
## Building a Cross-Functional AI Delivery Team
AI is not a department. **AI is a cross-functional capability** that sits at the intersection of data science, engineering, business operations, legal, risk, and IT. Hub71 and other MENA innovation ecosystems have correctly identified that ecosystem breadth matters — but internal teams need to reflect that same breadth if AI is to scale.
A high-performing enterprise AI delivery team should include:
– **AI Product Lead** — owns the roadmap, prioritisation, and business case; usually sits in the business unit, not IT
– **ML Engineers** — productionise, deploy, and monitor models; fluent in MLOps platforms and API design
– **Data Engineers** — maintain pipelines, quality gates, and the data platform; the most under-resourced and highest-impact role in most AI teams
– **Data Governance Lead** — owns policy, catalogue, lineage, and compliance; critical for UAE CBUAE regulated entities
– **Change & Adoption Lead** — designs training, communications, and resistance mitigation; should be measured on adoption rates, not training completion
– **AI Risk & Security Lead** — assesses model risk, adversarial exposure, and regulatory alignment; increasingly mandatory in regulated financial services
– **Domain SMEs** — subject-matter experts from finance, operations, risk, compliance who translate business requirements into model specifications
For GCC enterprises, recruiting for the first four roles is relatively straightforward given the growing regional talent pool. The harder hires are the Change & Adoption Lead and the AI Risk & Security Lead — roles that sit at the intersection of technology, psychology, and regulation that are rarely found in traditional IT teams.
McKinsey’s 2025 Global AI Workforce Report estimates that **organisations with dedicated cross-functional AI teams see 3.1× higher AI ROI** than those relying on generic IT teams to carry AI responsibilities as an add-on to existing workloads.
—
## Closing: 90-Day Operational Readiness Plan for Enterprise AI
To close, here is a practical 90-day operational readiness plan that any enterprise AI team can begin executing immediately. It is structured around the four operational disciplines: data, digital, change, and security.
### Days 1–30: Diagnose
– **Week 1:** Complete the data maturity assessment using the APH Operations Maturity Framework table. Score each dimension. Identify the two lowest-scoring areas.
– **Week 2:** Map the existing data estate — key datasets, ownership, quality issues, access controls. Produce a data heat map by business value and quality risk.
– **Week 3:** Conduct a change readiness assessment. Identify key stakeholder groups, resistance patterns, and sponsorship gaps. Map the digital literacy baseline across target user populations.
– **Week 4:** Run an AI security gap analysis. Audit shadow AI usage, review model governance documentation, assess data classification and leakage risk.
### Days 31–60: Build Foundations
– **Data:** Instrument quality monitoring on top-quintile business datasets. Launch first data product — typically a business glossary or customer 360 view.
– **Digital:** Stand up the enterprise AI platform or expand capabilities of the existing sandbox into a production-grade environment. Build the first API integration feeding the target use case.
– **Change:** Appoint executive sponsor for the AI programme. Design the change management roadmap with named milestones and adoption KPIs. Begin communications to build AI literacy.
– **Security:** Publish the AI acceptable use policy. Establish model risk classification. Initiate adversarial red-teaming for the first production model.
### Days 61–90: Prove the Model
– **Data:** Deliver five data quality improvements with quantified business impact (e.g., “reduced customer record duplicates by 23% resulting in cleaner segmentation”).
– **Digital:** Deploy the first production AI model. Document end-to-end pipeline. Hand over to operations team.
– **Change:** Execute first-wave training. Measure adoption rates weekly. Celebrate early wins publicly to build momentum.
– **Security:** Complete model risk assessment for first production model. Report to governance committee. Document security controls.
By day 90, the enterprise should have: a clear maturity profile, baseline data quality improvements, a live production model with documented governance, and an adoption rate above 50% for the first user cohort. These are the operational prerequisites that transform AI from software project into commercial capability.
Statista’s 2025 enterprise AI tracker confirms that **organisations completing structured 90-day readiness programmes are 4.1× more likely to hit positive ROI within 18 months** than those beginning production AI without readiness work.
—
## References
– Accenture. (2024). *GCC Digital Dashboard.*
– BCG. (2025). *Technology and Digital Report.*
– Forrester. (2025). *Data-Driven Enterprise Benchmark.*
– Gartner. (2024). *Magic Quadrant for Data Science and Machine Learning Platforms.*
– McKinsey. (2025). *Global AI Workforce Report.*
– McKinsey. (2024). *The State of AI in the Enterprise.*
– PwC. (2025). *Enterprise AI Survey.*
– PwC. (2025). *Global Digital Trust Insights.*
– Statista. (2025). *Enterprise AI Adoption Tracker.*
– UAE Central Bank. (2024). *AI and Data Ethics Guidelines.*
– DIFC. (2024). *Data Protection Law — AI Provisions.*
– Saudi Data and AI Authority (SDAIA). (2025). *National AI Governance Framework.*
– Hub71. (2024). *Abu Dhabi AI Ecosystem Report.*
—
*This article is part of the Apples & Pears intellectual property series on enterprise AI transformation in the MENA region.*