01The reality

    Someone on your team is pasting client data into ChatGPT.

    No rules. No oversight. It is not a hypothesis - it is what we find in every organization we audit.

    02The exposure

    You are using AI. The law says you are exposed.

    One breach, one inspection, one complaint - up to QAR 5,000,000 under applicable GCC law · up to 3 years imprisonment under the Cybercrime Law. Most teams cannot answer the question a regulator will eventually ask.

    03The aegis

    Arcus turns invisible AI risk into a defensible shield.

    Every tool mapped against your applicable laws. Every gap documented. A governance framework you can show any client, regulator, or auditor - your Risk Report in 48 hours, your full audit in 3 to 5 business days.

    04The move

    Know exactly where you stand. In 48 hours.

    A 15-minute questionnaire. Your free Risk Report back within 48 hours. No credit card, no commitment - real value before any decision.

    Your data never leaves Doha. Processed locally on our own infrastructure. We do not use OpenAI, Google, or any external AI provider to analyse your questionnaire.

    Governance coverage for the AI tools your team already uses

    Delivered in 48 hours

    Your Risk Report lands in two days - prioritised and ready to implement Monday morning. Most advisory firms take weeks.

    01/The Risk Reality

    Using AI in your business today means this is your legal exposure - right now.

    These are not edge cases. These are the three situations we find in almost every business we audit - each one active today, each one mapped to a specific law and a specific penalty.

    You do not need a breach for this to cost you everything. You need an inspection, a disgruntled employee, or a client who asks the wrong question.

    ChatGPT + client data

    Data protection law - GCC jurisdictions

    Personal data processed with no lawful basis.

    Penalty

    up to QAR / SAR 5,000,000 · UAE: up to AED 20,000,000

    Critical exposure0%

    AI images of real people

    Cybercrime legislation - GCC jurisdictions

    Publishing or editing identifiable individuals without consent.

    Penalty

    up to 1 year imprisonment + QAR 100,000 fine + deportation · equivalent criminal penalties across GCC

    High exposure0%

    No DPA with your AI vendor

    Data protection regulations - GCC jurisdictions

    No vendor agreement = you carry the full liability.

    Penalty

    up to QAR / SAR 5,000,000 · UAE: up to AED 20,000,000

    High exposure0%

    Laws shown reflect Qatar's framework. Every GCC jurisdiction has equivalent obligations - Saudi PDPL, UAE Federal PDPL, Bahrain PDPL, Kuwait Cybercrime Law, Oman PDPL - with comparable or higher penalties. Your audit maps the laws that apply to you.

    Quick Check

    How exposed are you right now?

    Six questions. No email required. Toggle what’s true for your organisation and watch your exposure profile build in real time.

    Estimated exposure

    0/ 100

    MINIMAL

    Nothing toggled - but the exposure you can't see is the kind that costs the most. A 48-hour audit confirms you're actually clean.

    02/Who This Is For

    Find your business. See your top AI risks.

    Every sector uses AI differently - and carries different legal exposure as a result. Here are the industries where we find the highest concentration of unaddressed risk today.

    Marketing Agency

    • Client data pasted into ChatGPT, Jasper or Copilot without a DPA - PDPPL Art. 7
    • AI-generated or edited images of real, identifiable people - Law No.11/2025 Art.8(bis)

    Restaurant & F&B

    • Customer contact lists loaded into AI marketing tools - PDPPL Art. 7
    • Loyalty and reservation data shared with un-vetted vendors - PDPPL / Consumer Protection Law

    Medical Clinic

    • Patient health data in AI = maximum PDPPL exposure + DPIA strongly recommended - PDPPL (special-nature data)
    • AI transcription or scribe tools with no Data Processing Agreement - QFC DPR Art.12 / PDPPL

    Real Estate

    • Buyer and tenant IDs and financial data entered into AI tools - PDPPL Art. 7
    • AI-staged or AI-edited listing images featuring real, identifiable people - Law No.11/2025 Art.8(bis) / IP Law No.7/2021

    Professional Services

    • Confidential client files pasted into public AI models - PDPPL / professional duty of confidentiality
    • No AI usage policy - undocumented, ungoverned decisions - PDPPL / NCSA

    Hotel & Hospitality

    • Guest passport and payment data processed through AI systems - high PDPPL exposure - PDPPL (special-nature data)
    • Cross-border data transfers to AI vendors without documented safeguards - PDPPL transfer rules

    IT Consulting

    • Confidential client data pasted into ChatGPT or Copilot without a DPA - PDPPL Art. 7
    • No AI usage policy across development and delivery teams - PDPPL / NCSA
    03/The Audit, Simplified

    From questionnaire to governance - in four steps.

    A structured, repeatable methodology - not ad-hoc consulting. You always know exactly what happens next.

    Step 1 of 4

    15 minutes

    Fill the online questionnaire

    No technical knowledge required. You describe the AI tools your team uses, how data is handled, and your main priorities. Everything we need to map your exposure accurately.

    Step 2 of 4

    Behind the scenes · 48 hours

    Arcus analyses your tools against your applicable laws

    Your questionnaire is mapped against every regulation that applies to your business - PDPPL, Cybercrime Law, QFC DPR, NCSA Framework, QCB AI Directives, Consumer Protection Law, and any cross-border frameworks including GDPR where relevant.

    Every AI tool identified. Every data flow examined. Every gap documented with the specific article, the specific penalty, and the specific action required.

    Your free Risk Report includes:

    • Your company's current AI compliance status
    • Your identified risk exposure - by tool, by law, by severity
    • Your estimated financial exposure under applicable law
    • A sector-specific risk profile for your industry
    • A personal recommendation on whether you need our services
    • Your AI Risk Score - 0 to 100

    Delivered within 48 hours.

    Step 3 of 4

    Free · Your strategy session

    We sit down. Together.

    Your Risk Report is not a document we send and disappear. It is the starting point of a conversation.

    In a 30-minute call, we walk through your findings together - what the exposure means for your specific business, your clients, and your team. We answer your questions, challenge your assumptions, and give you a clear picture of what happens next.

    No pressure. No sales script - a frank conversation between two people who now understand your situation.

    Step 4 of 4

    Your call

    You implement - or we support you further

    Act on the report yourself using the findings as your roadmap. Or move to the Standard or Advanced audit - a complete governance framework, operational documents, and structured checkpoints over 3 or 6 months.

    The decision is yours. The exposure is not.

    The Deliverable

    Review your Risk Roadmap.

    Every Arcus engagement plots your risks by likelihood and impact - so leadership sees what to fix first, not just what’s wrong. This is a live sample.

    Click any highlighted point to explore.

    Business impact ↑
    LowHigh
    Likelihood →
    High priority

    Confidential data in public AI tools

    Likelihood

    88%

    Impact

    86%

    Recommended action

    Deploy an AI usage policy and an approved-tool list; block or wrap high-risk inputs.

    Illustrative data shown for demonstration. Your real map is built from your environment, then re-scored after mitigation to show progress.

    How we handle your data

    Everything you share is strictly confidential and used solely to deliver your audit, aligned with Qatar's PDPPL and the GDPR. Read our Privacy Policy.

    04/Services & Pricing

    Two audits. Both priced at a fraction of a single fine.

    Standard maps your exposure and gives you the tools to act. Advanced builds the complete governance framework and proves you solved it.

    Standard

    Standard Audit

    Know where you stand. Act today.

    QAR 8,000≈ EUR 2,020

    Delivered in 3 business days.

    Risk Report · 5 Priority Actions · Approved Tool List.

    You will know exactly where your team is exposed, what to fix first, and how to talk about your AI practices to any client or regulator.

    • A concise, decision-focused executive risk report, written for business leaders
    • Visual AI risk heat map
    • Key risk identification across legal, financial, and reputational dimensions
    • Immediate action checklist with justification for each item
    • Escalation recommendations
    • Monthly progress checkpoints for 3 months

    → Not subject to VAT, no hidden fees, follow-up included.

    Recommended

    Advanced

    Advanced Audit

    From exposure to defensible governance.

    QAR 15,000≈ EUR 3,800

    Delivered in 5 business days.

    Risk Report · 16 Operational Documents · 6-month checkpoint · full compliance toolkit.

    A documented, auditable governance framework you can show to any client, regulator, or auditor - with confidence.

    Everything in Standard, plus:

    • Arcus Risk Mapping Framework - full architecture of your AI risk landscape
    • Structured risk register with severity, impact, and assigned ownership
    • Control gap analysis - exactly what is missing and why it matters
    • Three AI misuse scenarios with financial, legal, and reputational impact analysis
    • Employee AI Responsibility Agreement - signed by every team member
    • Data Handling Guidelines distributed to your full team
    • 6-month implementation roadmap
    • Monthly progress checkpoints for 6 months
    • Client-Facing AI Data Statement - ready to send to your clients
    • Vendor Risk Assessment - DPA gap check for every AI tool your team uses
    • 11 additional operational documents covering every governance dimension

    → Not subject to VAT, no hidden fees, follow-up included.

    QAR 5,000,000

    Maximum PDPPL fine

    0.00%

    The Standard Audit, as a share of your maximum exposure

    < 1 hour

    with a QFC law firm - for less than that, you get the full audit

    You are here
    QAR 8,000-15,000 · your auditQAR 5,000,000 · maximum regulatory fine

    Already audited? Annual Refresh - QAR 4,000 keeps your governance current as the law evolves.

    05/FAQ

    Questions? Answered.

    Everything you need to know before reaching out.

    One framework. Six jurisdictions.

    GCC-first. Built on international standards.

    Our methodology is built on the data protection and AI governance frameworks of Qatar, Saudi Arabia, UAE, Bahrain, Kuwait and Oman - cross-referenced with EU standards where relevant. Wherever you operate in the GCC, Arcus maps your AI use to the laws that apply to you - specifically, accurately, and without generic checklists.

    Qatar & GCC
    European Union
    United Kingdom
    Americas
    Asia-Pacific
    Africa
    Primary market - Qatar & GCC Served worldwide
    The next move is yours

    Most businesses using AI are not compliant. Most never know until it's too late.

    Free - receive your personalised risk feedback in under 48 hours. The cost of finding out later: everything.

    Not sure which you need?