






In this episode of GCC Tech Talks, Tom Stroud and Sye Rahman are joined by Don O’Shaughnessy to dive into the real-world world of governance, privacy, and security for AI and data in the GCC.
Don shares his journey from leading GDPR programmes in Ireland to building governance frameworks across the Middle East working with law firms, fintechs, government entities, and large enterprises.
We cover:
• The difference between automation vs “AI” (and why so many teams confuse them)
• Why data privacy sits awkwardly in org charts and where it should live
• How to set up a data governance committee/council that actually works (and why it can’t be “IT-only”)
• Personal data, sovereignty, and what “data residency” really means in practice
• The AI reality check: rubbish data = rubbish AI (and why quality takes time)
• Why AI laws are coming next and how they may follow the GDPR pattern
• How to innovate safely: sandboxing, aggregation, and starting small
Join us as we break down AI governance in the GCC: privacy, data quality, councils/committees, sovereignty, and why most “AI” programmes stall without foundations.