We use privacy-friendly, cookieless analytics to understand how this site is used and improve it - handled in line with Qatar's PDPPL and the GDPR. No personal profiles, no ad tracking. Privacy Policy
No rules. No oversight. It is not a hypothesis - it is what we find in every organization we audit.
One breach, one inspection, one complaint - up to QAR 5,000,000 under applicable GCC law · up to 3 years imprisonment under the Cybercrime Law. Most teams cannot answer the question a regulator will eventually ask.
Every tool mapped against your applicable laws. Every gap documented. A governance framework you can show any client, regulator, or auditor - your Risk Report in 48 hours, your full audit in 3 to 5 business days.
A 15-minute questionnaire. Your free Risk Report back within 48 hours. No credit card, no commitment - real value before any decision.
Your data never leaves Doha. Processed locally on our own infrastructure. We do not use OpenAI, Google, or any external AI provider to analyse your questionnaire.
Governance coverage for the AI tools your team already uses
Your Risk Report lands in two days - prioritised and ready to implement Monday morning. Most advisory firms take weeks.
These are not edge cases. These are the three situations we find in almost every business we audit - each one active today, each one mapped to a specific law and a specific penalty.
You do not need a breach for this to cost you everything. You need an inspection, a disgruntled employee, or a client who asks the wrong question.
Data protection law - GCC jurisdictions
Personal data processed with no lawful basis.
Penalty
up to QAR / SAR 5,000,000 · UAE: up to AED 20,000,000
Cybercrime legislation - GCC jurisdictions
Publishing or editing identifiable individuals without consent.
Penalty
up to 1 year imprisonment + QAR 100,000 fine + deportation · equivalent criminal penalties across GCC
Data protection regulations - GCC jurisdictions
No vendor agreement = you carry the full liability.
Penalty
up to QAR / SAR 5,000,000 · UAE: up to AED 20,000,000
Laws shown reflect Qatar's framework. Every GCC jurisdiction has equivalent obligations - Saudi PDPL, UAE Federal PDPL, Bahrain PDPL, Kuwait Cybercrime Law, Oman PDPL - with comparable or higher penalties. Your audit maps the laws that apply to you.
Six questions. No email required. Toggle what’s true for your organisation and watch your exposure profile build in real time.
Estimated exposure
MINIMAL
Nothing toggled - but the exposure you can't see is the kind that costs the most. A 48-hour audit confirms you're actually clean.
Every sector uses AI differently - and carries different legal exposure as a result. Here are the industries where we find the highest concentration of unaddressed risk today.
A structured, repeatable methodology - not ad-hoc consulting. You always know exactly what happens next.
Step 1 of 4
15 minutes
No technical knowledge required. You describe the AI tools your team uses, how data is handled, and your main priorities. Everything we need to map your exposure accurately.
Step 2 of 4
Behind the scenes · 48 hours
Your questionnaire is mapped against every regulation that applies to your business - PDPPL, Cybercrime Law, QFC DPR, NCSA Framework, QCB AI Directives, Consumer Protection Law, and any cross-border frameworks including GDPR where relevant.
Every AI tool identified. Every data flow examined. Every gap documented with the specific article, the specific penalty, and the specific action required.
Your free Risk Report includes:
Delivered within 48 hours.
Step 3 of 4
Free · Your strategy session
Your Risk Report is not a document we send and disappear. It is the starting point of a conversation.
In a 30-minute call, we walk through your findings together - what the exposure means for your specific business, your clients, and your team. We answer your questions, challenge your assumptions, and give you a clear picture of what happens next.
No pressure. No sales script - a frank conversation between two people who now understand your situation.
Step 4 of 4
Your call
Act on the report yourself using the findings as your roadmap. Or move to the Standard or Advanced audit - a complete governance framework, operational documents, and structured checkpoints over 3 or 6 months.
The decision is yours. The exposure is not.
Every Arcus engagement plots your risks by likelihood and impact - so leadership sees what to fix first, not just what’s wrong. This is a live sample.
Click any highlighted point to explore.
Likelihood
88%
Impact
86%
Recommended action
Deploy an AI usage policy and an approved-tool list; block or wrap high-risk inputs.
Illustrative data shown for demonstration. Your real map is built from your environment, then re-scored after mitigation to show progress.
How we handle your data
Everything you share is strictly confidential and used solely to deliver your audit, aligned with Qatar's PDPPL and the GDPR. Read our Privacy Policy.
Standard maps your exposure and gives you the tools to act. Advanced builds the complete governance framework and proves you solved it.
Standard
Know where you stand. Act today.
Delivered in 3 business days.
Risk Report · 5 Priority Actions · Approved Tool List.
You will know exactly where your team is exposed, what to fix first, and how to talk about your AI practices to any client or regulator.
→ Not subject to VAT, no hidden fees, follow-up included.
Advanced
From exposure to defensible governance.
Delivered in 5 business days.
Risk Report · 16 Operational Documents · 6-month checkpoint · full compliance toolkit.
A documented, auditable governance framework you can show to any client, regulator, or auditor - with confidence.
Everything in Standard, plus:
→ Not subject to VAT, no hidden fees, follow-up included.
QAR 5,000,000
Maximum PDPPL fine
0.00%
The Standard Audit, as a share of your maximum exposure
< 1 hour
with a QFC law firm - for less than that, you get the full audit
Already audited? Annual Refresh - QAR 4,000 keeps your governance current as the law evolves.
Everything you need to know before reaching out.
Our methodology is built on the data protection and AI governance frameworks of Qatar, Saudi Arabia, UAE, Bahrain, Kuwait and Oman - cross-referenced with EU standards where relevant. Wherever you operate in the GCC, Arcus maps your AI use to the laws that apply to you - specifically, accurately, and without generic checklists.
Free - receive your personalised risk feedback in under 48 hours. The cost of finding out later: everything.
Not sure which you need?