Skip to main content

Perspectives

The architecture gap in the GCC: three ways to join the 11% seeing an AI ROI

Taking a step back from the AI whirlwind, are GCC banks making any money from it?
Short answer, no. While 84% have adopted AI in at least one business function (opens in new tab) (up from 62% two years ago), only 31% have scaled past a pilot. And only 11% can point to real money on the bottom line.
That’s a 73-point gap between what banks say and what banks bank. Most companies already own the technology. What they’re missing is the architecture to use it.
I've spent 26 years watching Middle Eastern financial institutions buy technology, hire consultants, and announce transformation. What I haven't seen enough of is the unglamorous work underneath: fixing the plumbing before turning on the tap.
So why do pilots die before production? And what are the region’s better-run banks doing differently?
This guide answers those questions and puts forward three powerful principles to follow.

The pilot limbo

McKinsey, working with the GCC Board Directors Institute, surveyed 139 senior executives and board members across all six Gulf states in the second half of 2025 (opens in new tab). 84% said their organisation uses AI somewhere. Fine.
Then it gets harder. Only 31% have moved past piloting into actual scale. Only 11% qualify as what McKinsey calls “value realisers”, organisations attributing at least 5% of earnings to AI. That’s some gap.
"High usage of AI is out of sync with maturity or value." — McKinsey, The State of AI in GCC Countries, November 2025
None of this comes from a lack of ambition: 89% of GCC respondents plan to increase AI budgets this year. Nearly 9 out of 10. The money and the intent are there. What's missing is the understated middle part: getting from pilot to production without the whole thing falling apart.

Where AI is working and where it struggles

And to be fair, it isn't all pilot limbo. Roland Berger's December 2025 analysis (opens in new tab) found real production results in three narrow areas:
1. Fraud detection is the most mature. AI-driven models have cut false-positive rates by up to 90% at some GCC institutions.
2. Credit scoring has moved from pilot to live decisions in consumer and SME lending, compressing a multi-day process into seconds.
3. Conversational AI: Emirates NBD's Eva chatbot is the documented regional example, now resolving up to 80% of customer queries without a human.
Roland Berger's own regional survey (opens in new tab), published earlier this year, tells the same story from a different angle. Nearly 80% of GCC organisations now build AI into their strategic plans, and 90% trust AI-generated outputs enough to use them in decisions. Good news, on paper.
But the same report is blunt about where it breaks down: data quality issues, technology readiness gaps, weak cross-functional collaboration, resistance to change, and funding that quietly dries up after the pilot because nobody measured the impact properly.

The architecture gap: why plumbing is the problem

Every stalled pilot I've reviewed had a working model sitting on broken plumbing.
Walk into most GCC banks, and you'll find a polished mobile app sitting on top of a core banking platform that's been patched, extended, and held together for twenty years. Card processing on one system. CRM on another. None of it built to talk to the others in real time.
AI doesn't care about your org chart or your legacy vendor contracts. It wants clean, connected, real-time data. Feed it fragments, and you get a fragment of a result, an expensive one. Every new model starts from scratch, because nothing before it left behind usable infrastructure. That's not scaling. That's repeating the same mistake with better marketing behind it.
McKinsey's GCC data backs this up. The banks that count as value realisers are clearly stronger than everyone else on exactly three things:
1. Technology and data foundations,
2. Talent and operating model,
3. Change management.
Only 37% of the non-realisers say they have a well-established tech and data foundation. Most of the rest are, honestly, guessing.

The three traps

Three structural traps keep showing up, deal after deal, bank after bank. Here they are, without the consultancy jargon.
1. Data fragmentation
Customer data sits in five places at once, and none of them agrees with each other. Different formats. Different update schedules. Different owners.
The data exists somewhere. The question is whether anyone can pull it together fast enough, and trust it enough, for a model to act on without producing nonsense
2. Governance as an afterthought
Most governance frameworks in the region were built for quarterly reporting, not real-time decision-making.
Now banks are trying to attach automated decision-making onto processes designed for a compliance officer with a spreadsheet. It doesn't fit.
Projects stall right at the compliance checkpoint because governance was never designed into the system. Governance built for quarterly review cannot govern decisions made in milliseconds.
3. Weak change management
In the GCC survey, all but one value realiser had a defined change management strategy.
Deploying the model is the easy part. Getting three thousand employees to actually change how they work- that's where most transformation budgets go to die.

The regional context: sovereignty, security, diverging regulators

Three regulators, three timelines, one direction of travel: get your house in order before you scale.
What they share
The Central Bank of the UAE's February 2026 guidance note (opens in new tab) sets five principles for licensed institutions: governance and accountability, fairness and non-discrimination, transparency and explainability, human oversight, and data protection. The Qatar Central Bank's September 2024 guideline (opens in new tab) covers the same ground through transparency, ethical use and risk management. The CBUAE Governor described the aim as a framework that "enhances consumer protection, reinforces governance and transparency principles". In practice, banks across the region will be asked the same questions: who is accountable, how a decision was reached, and how customer data is protected.
Where they differ
UAE: certification. In May, the UAE Cyber Security Council, working with Cisco and Open Innovation AI, launched the National AI Test and Validation Lab (opens in new tab). The sovereign facility certifies AI models and agents against ISO 42001, NIST AI RMF, MITRE ATLAS and OWASP, and expects to assess tens to hundreds of thousands of agents a year.
Saudi Arabia: residency. There's no standalone AI cybersecurity standard yet. AI systems are assessed against the existing SAMA Cyber Security Framework, plus the Cloud Computing Regulatory Framework's requirement that core banking, CRM, and payment data stay inside the Kingdom, with limited exceptions for cross-border payments and correspondent banking.
The infrastructure is arriving too. In August, OpenAI switched on Inference Residency in the UAE (opens in new tab), the third location in the world after the United States and Europe. That means running the computation on GPUs inside the country, as well as storing the data there.
So the sovereign infrastructure exists, and the regulators have drawn clear lines. None of them is waiting for the banks to catch up. The open question is whether your bank's architecture is ready to use any of it.

The path forward: progressive modernisation

An overhaul sounds decisive. But it's also a multi-year, capital-eating exercise that kills careers and rarely finishes on schedule.
In my opinion, the better route is progressive modernisation: build an overlay that works with what you've got, while you fix the foundations underneath. You can stress-test any transformation plan against the three principles below before you fund it.
1) Overlay, don't replace. Put an API-led orchestration layer between the core and the AI. The model recommends and the human decides. You scale without touching the core, and without betting the bank on a rebuild.
2) Govern by design. Build CBUAE and SAMA expectations into the workflow from day one. Chase certification through the National AI Test and Validation Lab early. Don't wait for a post-build review to catch you out.
3) Start narrow. Pick the workflows where the win is obvious, and the risk is small: KYC, document processing, client servicing. Prove it there. Then move toward credit decisions and fraud, where the stakes are higher, and the tolerance for error is a lot lower.

Discipline beats capability

GCC banks have everything they need to be AI-native within two to three years. Modern front ends. Deep data. Regulators who are actually engaged, not just watching from the sidelines. Budgets still climbing. What separates the banks that make it from those stuck in pilot limbo is the rigour and discipline to make the right decisions in the right places.
Here are three things to do, starting next week:
  1. Commission an architecture readiness assessment before you approve the next pilot, not after it stalls, which is when most banks finally get around to asking the question.
  2. Put a board member's name against AI governance now, before the next CBUAE or SAMA review comes looking for one.
  3. Pick one workflow, KYC, onboarding, whatever's closest to completion, and prove the overlay model on it within two quarters. Then extend.
Do those three things and you're already in the 11%. Skip them, and you're another data point in the 73-point gap, wondering next year why nothing scaled.

This paper is the first in a GCC-specific series on AI implementation in GCC financial services.
Two more are coming:
  • The human-AI handoff: on governance, control, and regulatory readiness
  • Marketplace evolution: on the shift from product manufacturer to platform orchestrator.

Ahmed Kamel

Consultant, Softwire UAE

07 October 2026

Subscribe
to our monthly newsletter for our latest expert content.