top of page

Unveiling Seven Continents Yearbook Journal U7Y

ISSN 3042-4399

Author declarations (funding, conflicts of interest, AI use, data availability, and ethics) are located below the main paper.

Authorising the Algorithm: Ex Ante Supervisory Clearance and the Limits of Human Oversight in Qatari Banking

2 hours ago
76 min read

Author: Her Excellency Sheikha Mashael bint Hamad Al Thani

Affiliation: Swiss International University (SIU)

ORCID ID: 0009-0008-0720-3456

Doi: https://doi.org/10.65326/u7y10031


Submitted 29 May 2026; Revised 28 June 2026; Revised 18 July 2026; Revised 21 August 2026; Accepted 7 September 2026; Available online 14 September 2026; Version of Record 14 September 2026.


Volume 3, December 2026, (10031)


Abstract

Oversight requirements for artificial intelligence usually take one shape: a deployer must ensure a natural person can understand, monitor and override the system at the point of decision, and arranges the rest itself. Qatar took a different route. The Artificial Intelligence Guideline issued by the Qatar Central Bank in September 2024 conditions high-risk AI use on prior supervisory approval, a register of AI systems, board accountability and annual disclosure of that register to the supervisor. The European Union's AI Act also acts before deployment; what separates them is who must be satisfied, since the Act leaves most high-risk systems to the provider's internal control while Qatar requires permission from a public supervisor. This paper develops a typology of three loci at which oversight can sit, with a second axis, who must be satisfied, that applies to the ex ante case, and argues that moving the obligation to a supervisor exchanges the overseer's cognitive failure for means-ends decoupling, since a register, a committee and a policy are easier to verify than the outcomes they exist to produce. Supervisory evidence on approved internal models, spanning the two decades the form has operated, shows that pattern already. Four design conditions are specified that separate an authorisation regime producing supervisory information from one producing reassurance, and four testable statements are set out, only one of which external evidence can reach in full. That distribution is itself the finding: a regime whose record only its supervisor can read leaves the outside world able to study what banks say and not what they do.

Keywords: algorithmic governance, human oversight, banking supervision, ex ante regulation, decoupling, Qatar, Islamic banking


1. Introduction

Banking supervisors have required their own permission before a bank may use an internal model for two decades. Articles 143 and 283 of the Capital Requirements Regulation require prior permission from the competent authority, which for significant institutions under the Single Supervisory Mechanism is the European Central Bank, before an internal model is used for credit or counterparty credit risk, and the market risk framework carries an equivalent permission for the internal model approach (European Central Bank, 2025), the Basel framework sets minimum requirements for entry to and continued use of the internal ratings-based approach (Basel Committee on Banking Supervision, 2023), and the United States has operated interagency model risk management guidance since 2011 (Board of Governors of the Federal Reserve System, 2011). Nor have supervisors confined that scrutiny to regulatory capital. United States model risk management guidance has never been limited to capital models (Board of Governors of the Federal Reserve System, 2011), the Equal Credit Opportunity Act and its implementing Regulation B have governed credit decisions and adverse action notices for decades (Equal Credit Opportunity Act, 2011), and the European Banking Authority's loan origination guidelines require institutions using automated models in creditworthiness assessment to understand those models, detect bias and document overrides (European Banking Authority, 2020b). What the Qatar Central Bank did in September 2024 was different in form rather than in subject. Its Artificial Intelligence Guideline conditions deployment of a high-risk AI system on a centralised administrative clearance dedicated to the risks of the system itself, rather than on internal validation checked afterwards, and reaches the purchase, licensing and outsourcing agreements through which most banks acquire such systems (Qatar Central Bank, 2024a). Seventeen months later the Central Bank of the United Arab Emirates issued guidance built on model inventories, board accountability and annual bias testing, without an approval requirement (Central Bank of the United Arab Emirates, 2026).

The literature on algorithmic oversight has reached an unusually firm conclusion. Human oversight, as currently mandated, does not work. Green (2022) surveyed forty-one policies requiring a human in the loop and found that none established that the people concerned could perform the task assigned to them. Wagner (2019) named the resulting arrangement quasi-automation: a person formally inserted into a process that is otherwise fully automated, whose presence satisfies the rule without changing the decision. Laux (2024) puts the objection in its sharpest form. Article 14 of the European Union's Artificial Intelligence Act rests its protection on a capacity the empirical record does not establish. Binns (2022) locates the normative case for the human in the loop in individual justice rather than in accuracy.

The critique is persuasive and narrower than it appears. Article 14 of the AI Act (Regulation (EU) 2024/1689, 2024), Article 22 of the General Data Protection Regulation (Regulation (EU) 2016/679, 2016) and the adverse action notice requirements of United States consumer credit law (Barocas et al., 2020) impose duties attaching at or near the moment of decision, on the deploying party, and leave the arrangement of oversight to that party. The AI Act is not confined to that duty. Built on the European Union's New Legislative Framework for product safety (Veale & Zuiderveen Borgesius, 2021), it imposes substantial pre-market obligations on providers of high-risk systems: a risk management system under Article 9, data governance under Article 10, technical documentation under Article 11, conformity assessment under Article 43, registration under Article 49, post-market monitoring under Article 72. Its ex ante tier is considerable. What distinguishes the Qatari instrument is not that it acts before deployment but who decides. Under Annex VI most high-risk systems are assessed by the provider's own internal control with no notified body involved, making conformity a matter of documented self-assessment against harmonised standards (Mokander et al., 2021). Under the Qatari Guideline a public supervisor grants or withholds permission.

Several things about AI in banking are no longer in dispute. Supervisory stocktakes find that AI in credit, risk and fraud functions operates as decision support rather than autonomous decision-making, generating scores, flags and recommendations that staff then review (Financial Stability Board, 2017; Organisation for Economic Co-operation and Development, 2021; European Banking Authority, 2020). The fairness consequences are equally well established and are not a matter of removing protected attributes. Machine learning credit models redistribute rather than eliminate disparity (Fuster et al., 2022), algorithmic mortgage pricing narrows but does not close discriminatory gaps (Bartlett et al., 2022), the mechanisms by which data mining reproduces discrimination without discriminatory intent were mapped a decade ago (Barocas & Selbst, 2016), and digital footprint variables now match credit bureau scores in predictive power, which multiplies the proxy problem (Berg et al., 2020). None of this settles the normative question. Kleinberg et al. (2018) argue that a properly regulated algorithm makes discrimination easier to detect than the human judgement it replaces, because its inputs, objective and records can be inspected. The disagreement is about what regulation must require, not about whether the technology is inherently worse.


1.1 What the Oversight Debate Has Not Examined

Where the literature stops is at who authorises. Green's (2022) forty-one policies are decision-level duties. Specification work on Article 14 concerns what the overseer must be able to do, when, and with what information (Enqvist, 2023; Sterz et al., 2024), and Malgieri's (2019) survey of national implementations of Article 22 catalogues divergent safeguards, all attached to the decision. Lazcoz and De Hert (2023) treat Article 22 as an unenforceable second-class right and argue that human intervention should be engineered by the controller rather than invoked by the data subject, which relocates the duty without leaving the decision. Cobbe et al. (2021) push furthest toward an institutional account, and even there the unit is the decision-making process rather than the permission to operate. Where the AI Act's ex ante tier is examined, it is examined as product-safety self-certification: Veale and Zuiderveen Borgesius (2021) read the Act through the New Legislative Framework, Almada and Radu (2024) argue that the product-safety architecture limits the protection it affords to fundamental rights, and Mokander et al. (2021) treat conformity assessment and post-market monitoring as its two enforcement mechanisms. None of this work concerns administrative permission granted by a sector supervisor.

A second literature concerns exactly that, and the two have not been connected. Prudential supervisors have approved internal models for years, and the record on what approval produces is not encouraging: Behn et al. (2022) find that approval allows banks to underreport risk systematically, and Mariathasan and Merrouche (2014) find risk-weight density falling after approval for the internal ratings-based approach, most sharply at weakly capitalised banks and where supervision is weaker. That evidence bears directly on what a supervisor learns by approving a model, and it has never entered the debate about human oversight of AI.

The separation has a cause. European instruments set the research agenda for AI oversight, and the European Union chose provider self-assessment over supervisory authorisation, so administrative pre-clearance of an AI system had no case to study. The qualification worth stating is that European law is not silent before deployment: Article 35(3)(a) of the General Data Protection Regulation requires an impact assessment for systematic automated evaluation producing legal or similarly significant effects, and Article 36(1) obliges the controller to consult the supervisory authority before processing where that assessment shows unmitigated high risk (Regulation (EU) 2016/679, 2016). That is a pre-deployment step facing a public authority, and it is not an authorisation gate: the controller decides whether the trigger is met, consultation follows only from its own finding of residual high risk, and the authority advises rather than permits. The distinction between conditional prior consultation and permission to operate is what the Qatari instrument makes visible; model risk management, meanwhile, is read by prudential scholars and its scholarship concentrates on capital models even though the supervisory instruments do not. Qatar's Guideline sits across that divide, applying the approval machinery to a class of systems defined by their effect on customers. Leaving this unexamined has a cost. Supervisors across the Gulf are writing AI rules now, mostly through national strategies that Albous et al. (2025) characterise as soft regulation, and they are choosing a regulatory form with no analysis of how it performs.

A further reason to doubt that decision-level duties can carry the weight placed on them comes from the evidence base rather than from the law. The over-reliance findings are real: automation bias produces omission and commission errors across domains (Parasuraman & Manzey, 2010; Skitka et al., 1999) and appears in three quarters of the clinical decision support studies reviewed by Goddard et al. (2012). Alon-Barkat and Busuioc (2023) then ran three experiments, including with serving civil servants, and found no general bias toward algorithmic advice, while Dietvorst et al. (2015) document the opposite tendency. The largest synthesis available finds human-AI combinations performing on average worse than the better component alone (Vaccaro et al., 2024). This is not a simple story of rubber-stamping. It is something more awkward for regulators: overseer performance varies with task, expertise and framing in ways a general duty cannot anticipate.

This paper takes that variance as its starting point. If the protective effect of an individual overseer cannot be relied on in either direction, the case for relocating the obligation to a level where it can be inspected grows stronger, and relocation is what Qatar has done. This paper argues that relocation solves less than it appears to. The paper develops a typology of three loci at which algorithmic oversight can be placed and a second axis concerning who must be satisfied, shows that each position carries a distinct failure mode, and argues that moving the obligation to the supervisor exchanges the cognitive failure of the overseer for the institutional failure that organisational theory calls decoupling. No legal responsibility moves with it, as Section 4.4 sets out; what the approving authority takes on is a reputational and political constraint on acting against what it has permitted. Two decades of evidence on internal model approval already show that pattern in prudential supervision. What follows is a framework, four design conditions, and a set of hypotheses divided by who is able to test them; Section 1.2 sets out the evidence the paper rests on and Section 5.4 the boundaries of that evidence.


1.2 Sources and Analytical Procedure

The analysis proceeds by document comparison and theoretical reconstruction. Regulatory instruments, comprising the Qatar Central Bank's Guideline and 2024-2030 strategy, the 2011 circular on Islamic windows, Qatar's national AI strategy, the Emirati guidance note, the AI Act, the Capital Requirements Regulation as applied through the European Central Bank's guide to internal models, the Basel framework and the General Data Protection Regulation, are read for what they require of whom and at what point in the deployment cycle. The European, Basel and United States instruments were read in their authentic published texts. The Qatari Guideline was not: its complete text could not be retrieved, so it is described from official announcements, regulatory commentary and an independent regulatory tracking record, only where those sources agree, and no clause of it is quoted or cited by article number anywhere in this paper. Section 5.4 states what that constrains. Official publications supply factual context and are cited for that alone, and peer-reviewed literature supplies the theoretical apparatus and the empirical claims, attributed to the studies that produced them rather than aggregated into consensus. Sources were located through searches of OpenAlex and Semantic Scholar coverage, semantic search of peer-reviewed work, and targeted retrieval from issuing bodies, conducted between January and May 2026 across nine thematic lanes corresponding to the paper's sections. Every reference was confirmed against a database record carrying full metadata, a resolving digital object identifier, or a fetched publisher or official page before being cited.

The framework in Section 3 was derived by taking the regulatory design distinction between ex ante and ex post intervention, asking where each instrument in the comparison set places its oversight obligation, and then matching each resulting position to the failure mechanism the relevant literature documents for that position. The argument connecting evidence to claims runs in one direction only: from what an instrument requires, to what a supervisor can verify from the resulting record, to what organisational research predicts firms will do with the difference. No claim is made about what Qatari banks have in fact done.

Because the account of the Qatari instrument rests on secondary description, two checks were run on it for this study rather than left to later work. The first produced corroboration. The Digital Policy Alert database, maintained by the St Gallen Endowment and citing the official Qatar Central Bank document, records the instrument as issued and in force on 4 September 2024 and classifies its policy area as authorisation, registration and licensing (Digital Policy Alert, 2024). That corroborates the two features the argument depends on, the date and the presence of an authorisation requirement, from a source independent of both the announcement and the practitioner commentary, and it establishes that the authentic text has been available to at least one party outside the supervisory perimeter. The individual requirements described in Section 2 are separately reported in agreement by an international law firm, a Qatari firm and a United States national law library, which is not the same as reading the instrument but is more than a single-source reconstruction.

The second check returned nothing, and what it was and was not is set out in Appendix E. A scan of publicly indexed reporting by the eight Qatari-owned commercial and Islamic banks the supervisor licenses, covering material published after the Guideline's issue in September 2024 and run in May 2026, located no disclosure describing AI governance arrangements against the Guideline's requirements, no reference to an AI register, and no statement that approval had been sought or obtained for any system. This was a scan of indexed material rather than a hand-collected corpus of every published report, so it establishes that no such disclosure was locatable by these means and nothing more. It is not a finding about compliance, and no result is claimed for it beyond the bearing it has on the coding, which runs in one direction. Requirements generating visible public artefacts would be the easiest to corroborate from outside, and none was corroborated, which leaves the strong-verification column resting on what the supervisor receives rather than on anything a reader can inspect. The result is consistent with this paper's own argument that the record goes to the supervisor and stops there, and that agreement is a reason for caution rather than for confidence: an argument and a limitation that point the same way can be mutually reinforcing without either being tested. Two further routes, the authentic text and the International Monetary Fund's periodic assessments of Qatar's financial sector, were not available here and are named in Section 5.4, which sets out what all of this does to the argument.


2. Qatar's Supervisory Architecture and the 2024 Guideline

Qatar's banking sector is small, concentrated and unusually legible. Sixteen banks operate in the country, nine of them domestic: five conventional and four Shariah-compliant, with seven foreign branches alongside. That structure is itself a product of supervisory intervention. In February 2011 the Qatar Central Bank required conventional banks to stop opening Islamic branches, cease accepting Islamic deposits and wind down their Islamic operations by the end of that year (Elgammal et al., 2021). The decree eliminated the Islamic window, the hybrid form in which a conventional bank offers Shariah-compliant products through a segregated unit. Across six Gulf states over the preceding decade, window-operating conventional banks had been the region's least stable category of institution (Abedifar et al., 2017), which gives the intervention a prudential rationale and left a cleanly separated sector in which no institution straddles the two models (Péran & Sdiri, 2024). Section 4.3 sets out why that separation does not support a comparison of algorithmic oversight between them.

The AI Guideline sits inside a broader programme. Qatar's national artificial intelligence strategy dates from 2019 (State of Qatar, 2019), the Third Financial Sector Strategy was launched in November 2023 (International Monetary Fund, 2025), and the Qatar Central Bank's 2024-2030 strategy spans financial resilience, market development, digitalisation and workforce capability (Qatar Central Bank, 2024b). Ibrahim and Truby (2022) read the earlier fintech strategy as enthusiastic about the technology and cautious about the regulatory perimeter, which describes the Guideline as well. The sector is not marginal: global Islamic financial services assets reached USD 3.88 trillion in 2024, growing at 14.9% year on year (Islamic Financial Services Board, 2025).

What the Guideline requires can be grouped into four layers. The first is organisational: a documented AI strategy subject to periodic review, an AI governance policy covering audits, documentation, roles, training and controls, and a dedicated oversight function with committees that assess proposed use cases. The second is accountability: the board and senior management are accountable for the outcomes and decisions of the firm's AI systems, and the board approves the firm's AI risk appetite. The third is classification and control: risk and criticality assessments integrated into enterprise risk management, identification of high-risk systems as those affecting access to financial services, employment decisions or sensitive personal data, prior Qatar Central Bank approval before a new or materially modified high-risk system is deployed and before purchase, licensing or outsourcing agreements are signed, with the supervisor able to require sandbox testing. The fourth is record and disclosure: a register recording classification, providers, risks, impact assessments, oversight protocols and third-party assessments, disclosed to the supervisor annually and on request; oversight protocols distinguishing AI-assisted, human-exception and fully autonomous modes, with stop controls for the autonomous case; and plain-language notification to customers that AI is in use and involved in a decision, with a right to request review and correction (Qatar Central Bank, 2024a).

Almost none of this is unfamiliar. Documented strategies, oversight functions, board accountability, risk assessment, inventories and periodic review are the standard furniture of prudential model risk management, and a European bank using an internal model for credit risk meets comparable demands (European Central Bank, 2025). Two features are less familiar, and neither is the subject matter. Supervisors have long examined underwriting and creditworthiness for conduct reasons, most recently in the European Banking Authority's requirement that institutions using automated models in credit decisions understand them, test for bias and document overrides (European Banking Authority, 2020b), and consumer credit statutes have regulated access for far longer (Equal Credit Opportunity Act, 2011; Consumer Financial Protection Bureau, 2022, 2023). What is unfamiliar is the gate. Scrutiny of this kind is normally decentralised, conducted by the institution's own validation function and tested by the supervisor afterwards through examination; here it is centralised in an administrative clearance granted before use, on a risk classification defined by effect on customers rather than on capital.

That classification deserves unpacking, since it carries the regime's scope. Access, in this context, means the set of decisions determining whether a person obtains a banking service at all, on what terms, and whether an existing relationship is maintained: approval or refusal of retail credit and card limits, account opening and onboarding, the pricing attached to a risk score, and the decision to exit or restrict a customer. Each is a candidate for algorithmic determination and each has a documented failure mode. Applicants without conventional financial history are credit invisible to standard scoring, a population concentrated in developing economies while the alternative models built to score them are trained largely on developed-economy data (Njuguna & Sowon, 2021; Costa et al., 2015). Relationship termination has its own literature: de-risking, in the Financial Action Task Force's definition, is the termination or restriction of relationships with categories of client to avoid rather than manage risk, and it has fallen heavily on money transfer operators and the remittance corridors they serve (Financial Action Task Force, 2021; World Bank Group, 2015; de Koker & Casanovas, 2024). Qatar makes these questions unusually live. International migrant stock stood at 76.7 per cent of the population in 2024 (World Bank, 2025), and migrant workers in Gulf states face documented bureaucratic, documentary and language barriers in reaching formal services (Lowe et al., 2023), with informal lending filling the gap where formal credit does not reach (Alowais & Suliman, 2025). No Qatar-specific measure of any of this is public, which is itself relevant to what follows. And prior approval extends to purchase, licensing and outsourcing agreements, placing the supervisor inside the procurement decision. A European provider of a high-risk AI system may self-assess under Annex VI; a Qatari bank acquiring one must obtain permission first.


3. Three Loci of Algorithmic Oversight

Regulatory theory has long treated the timing of intervention as a design variable rather than a detail. Shavell (1984) set out when a regulator should act before harm occurs rather than assign liability afterwards: where private parties lack information the regulator holds, where harm is diffuse and hard to attribute, and where those causing it may be unable to pay. Algorithmic harm in retail credit satisfies all three. A rejected applicant rarely knows the model existed, the injury is spread across many small decisions, and no single decision generates a claim worth bringing. Ayres and Braithwaite (1992) and Parker (2002) supply the complementary move, in which the regulator works on the firm's internal control capacity rather than its outputs, while Black (2008) and Baldwin and Black (2008) show how principles-based and risk-based supervision distribute discretion between the two. The oversight literature has not brought this apparatus to bear on AI mandates.

Two questions organise the design space. The first is where the obligation attaches: at the decision, at the institution, or before deployment. The second is who must be satisfied, which cuts across the first, because an ex ante obligation can be discharged by the provider's own internal control, by an accredited third party, or by a public supervisor. The AI Act and the Qatari Guideline both act before deployment and differ on the second question entirely. Each of the three loci carries its own characteristic failure.

Decision-level oversight places the obligation on a person reviewing a particular output. This is Article 14 of the AI Act, Article 22 of the GDPR, and the human-exception mode in Qatar's own Guideline. Its failure mode is cognitive and well documented. The information the overseer receives is part of the problem: opacity arises from corporate secrecy, from technical illiteracy and from the mismatch between how models operate and how people reason about them (Burrell, 2016), and experiments on automated loan approval show that explanation changes perceived fairness through what people believe they understand rather than what they do (Schoeffer et al., 2022). Green and Chen (2019) tested this directly in pretrial release and lending, and found participants unable to evaluate the risk assessments they were formally overseeing. Sterz et al. (2024) specify four conditions for effective oversight, causal power, epistemic access, self-control and fitting intentions, and the record suggests the second and fourth are rarely satisfied in practice.

Institution-level oversight places the obligation on an internal body: a model risk function, a committee, a board with an approved risk appetite. Its failure mode is organisational rather than cognitive. Mikes (2009) showed that formally identical enterprise risk management systems are enacted in fundamentally different ways inside different banks, Power (2009) argued that risk management degenerated into auditable process compliance detached from the risks it addressed, and Palermo et al. (2017) found competing logics rather than a single risk culture across UK financial institutions. The structure exists, is inspectable, and does not determine what it produces.

Pre-deployment authorisation conditions use on a decision by the supervisor rather than by the deployer. This is not new in banking, where permission to use an internal model has been required for years (European Central Bank, 2025; Basel Committee on Banking Supervision, 2023), but it is new for systems defined as high risk by their effect on customers. Its failure mode has a name in organisational theory that the regulatory literature on AI has not applied to it. Meyer and Rowan (1977) described how organisations adopt rationalised rules as legitimating myths and decouple formal structure from operating practice, and Bromley and Powell (2012) identified the more corrosive variant: means-ends decoupling, in which policies are genuinely implemented but stay disconnected from the outcomes they were adopted to secure. Wijen (2014) specified when this occurs. In opaque fields, where the causal link between prescribed practices and desired outcomes is unclear, standard-setters can secure compliance or outcomes, and the instruments delivering the first tend to undermine the second.

Decoupling is not the only thing that can go wrong with an ex ante regime, and the regulatory economics literature identifies two other failure modes that any account of pre-deployment authorisation should acknowledge before settling on one. The first is drag. An approval requirement inserts delay between a model improvement and its use, and delay has a measured social cost: Grennan and Town (2020) exploit differences between European and United States pre-market testing requirements for medical devices to show stricter ex ante testing reducing the rate at which improvements reach the market, and Frakes and Wasserman (2023) set out the full ledger, in which the litigation savings from stricter scrutiny are offset by suppressed innovation. Henry et al. (2022) model the choice among liability, withdrawal and authorisation regimes on exactly this trade-off, and the regulatory sandbox exists as a response to it, with Cornelli et al. (2024) finding that the United Kingdom's sandbox increased the capital raised by entrants by around fifteen per cent. The second is perimeter arbitrage. Strict requirements inside the regulated perimeter push activity outside it: Buchak et al. (2018) attribute a substantial share of the rise of shadow bank mortgage lending to regulatory burden on banks, Irani et al. (2021) find less capitalised banks shedding loans to non-banks under Basel III, and Plantin (2015) models the conditions under which tightening bank capital requirements makes the shadow sector larger rather than the system safer. Algorithmic credit scoring is in principle the kind of activity that can migrate, since it requires no deposit base. The channel is narrower in Qatar than in the markets those studies examine, and the difference is legal rather than incidental. Consumer credit provision is not open to unlicensed firms. The Central Bank Law of 2012 requires any company carrying on credit activity to hold a licence before it begins and makes the Qatar Central Bank the authority for licensing and supervising financial services conducted in or through the country (Law No. 13 of 2012; Clifford Chance, 2013), so there is no large unregulated lending sector for scoring to move into, and the informal lending noted in Section 2 substitutes for credit rather than for the capacity to score it. What Qatar does have is a second licensing perimeter, since business authorised by the Qatar Financial Centre Regulatory Authority falls outside the Qatar Central Bank's jurisdiction while the Guideline binds the entities the Qatar Central Bank licenses. The arbitrage question here is therefore which authority's rules apply rather than regulated against unregulated, a narrower problem than the shadow banking literature describes.

Both are real, and neither is this paper's subject. Drag and arbitrage are failure modes of stringency, and they bite hardest where an approval requirement is demanding and enforced. The failure this paper examines is different in kind and arises where an approval requirement is satisfiable: the regime obtains everything it asks for and learns little from it. The three are not mutually exclusive, and a regime could exhibit drag at the perimeter and decoupling within it at the same time. Decoupling is the relevant failure for this instrument because of the character of the field it governs.

Algorithmic fairness in credit is exactly such a field, and the reason can be stated as a property of the record a regime collects. A requirement is verifiable in a strong sense when a supervisor can establish from the file itself whether the claim is true, and in a weak sense when the file records an assertion whose truth lies outside it. A supervisor can confirm that a register exists, that a committee met, that an impact assessment was filed. Whether the resulting model treats a thin-file applicant fairly depends on training data, proxy structure, threshold selection and the conduct of the officers who read its output, none of which the approval file settles. Pre-deployment regimes concentrate strong verification on structure and weak verification on outcome. The regime is most auditable where it is least informative. This asymmetry carries the rest of the argument, and Section 4.3 applies it requirement by requirement.

Table 1 sets the three loci against the instruments that use them.


Table 1: Where Four Instruments Place the Oversight Obligation, and Who Must Be Satisfied

Design dimension

AI Act (2024)

GDPR, Art. 22

QCB Guideline (2024a)

CBUAE Guidance (2026)

Primary locus of obligation

Pre-deployment and decision

Decision

Pre-deployment and decision

Institution and decision

Acts before deployment

Yes, Arts. 9-15, 43, 49

No

Yes

No

Who must be satisfied ex ante

The provider itself, by internal control under Annex VI for most high-risk systems

Not applicable

The supervisor

The firm, subject to inspection

Third party involved

A notified body only for Annex III point 1 systems

No

No, the supervisor decides directly

No

Standard applied

Harmonised standards, with presumption of conformity

Suitable safeguards, set nationally

Supervisory judgement

Supervisory expectations

Decision-level oversight duty

Yes, Art. 14

Yes, human intervention

Yes, three oversight modes

Yes, three oversight modes

Covers acquisition and outsourcing

Duties fall on provider and deployer separately

No

Yes, prior approval required

Yes, third-party due diligence

Inventory or registration

EU database registration, Arts. 49 and 71

No

Register of AI systems, held by supervisor

Model inventory

Recurring quantitative testing

No

No

No

Yes, annual bias testing

Record routinely seen by supervisor

Registration entry, plus post-market monitoring under Art. 72

No

Yes, annual disclosure of the register

Yes

Customer notified of AI involvement

Transparency duties, Art. 13 and Art. 50

Yes, with safeguards

Yes, with consent and review right

Yes, bilingual disclosure

Note. Compiled from Regulation (EU) 2024/1689 (2024), Regulation (EU) 2016/679 (2016), Qatar Central Bank (2024a) and Central Bank of the United Arab Emirates (2026), with the AI Act rows read alongside Veale and Zuiderveen Borgesius (2021) and Mokander et al. (2021), and the Article 22 rows alongside Malgieri (2019). Three of the four instruments impose duties at more than one locus, which is why the first row records each as a combination; the dimension on which they genuinely diverge is who must be satisfied before deployment, not whether anything happens then. The General Data Protection Regulation row records the absence of an authorisation gate, not the absence of any pre-deployment duty: Article 35(3)(a) requires an impact assessment for systematic automated evaluation producing legal or similarly significant effects, and Article 36(1) requires prior consultation with the supervisory authority where that assessment shows unmitigated high risk, but the trigger is the controller's own and the authority advises rather than permits, as Section 1.1 sets out. Entries describe published requirements, not supervisory practice. The Emirati entry in the second row records only the absence of an ex ante requirement; that regime's inventory and annual bias testing duties are post-deployment and appear in the eighth and ninth rows. The Qatari entries are reconstructed from secondary descriptions, for the reason given in Section 5.4.


The framework's central claim follows from the comparison rather than from any single row. Placing the obligation on a public supervisor before deployment buys three things a deployer-facing duty cannot: the supervisor sees the system before it operates, the obligation attaches to an entity it can inspect and sanction, and the vendor relationship is captured, which matters because opacity in third-party models is a recurring supervisory complaint (European Banking Authority, 2020a). It does not buy verification of outcomes. Decision-level oversight at least sits adjacent to the outcome, even where the overseer cannot act on it. Pre-deployment authorisation is structurally distant from it. Figure 1 sets out the relationship.


Figure 1: Three Loci of Algorithmic Oversight and Their Characteristic Failure Modes

Note. Moving the oversight obligation from the decision toward pre-deployment authorisation raises how much of the arrangement a supervisor can verify and lowers how close that verification sits to the outcome experienced by the customer.


4. Analysis

4.1 What Approval Already Produces: The Model-Risk Record

Before asking what the Qatari instrument will produce, it is worth asking what the same mechanism has produced where it has operated longest. Supervisory permission to use an internal model is not a novel regulatory technology. It is the basis of the internal ratings-based approach to credit risk, and it has been administered at scale by the European Central Bank, which conducted 200 on-site internal model investigations at 65 institutions between 2016 and 2021 and issued 253 supervisory decisions on the back of them (European Central Bank, 2021). Table 2 sets the Qatari Guideline against that lineage.

Table 2: Supervisory Permission to Use a Model: The Qatari Guideline Against Its Prudential Lineage

Regime

What requires permission

What triggers re-examination

How outcomes are observed

IRB approach, Basel framework

Use of internal ratings for regulatory capital, against minimum requirements for adoption and continued use

Material model change; ongoing validation and use test

Realised losses against risk weights

ECB internal model permission

Use of internal models for credit and counterparty credit risk under Arts. 143 and 283 CRR, and for market risk under the internal model approach

Model changes and extensions; on-site investigation

Supervisory findings and decisions; 253 issued after TRIM

US model risk guidance, 2011

No permission; supervisory expectations for development, validation and governance

Supervisory examination

Examination findings

QCB Guideline, 2024

Deployment of high-risk AI systems, and the agreements through which they are acquired

Material modification, as judged by the firm in the first instance

Not specified; access outcomes yield no realised benchmark, and none is publicly observable

Note. Compiled from Basel Committee on Banking Supervision (2023), European Central Bank (2025), European Central Bank (2021), Board of Governors of the Federal Reserve System (2011) and Qatar Central Bank (2024a). The 2011 United States guidance was replaced in April 2026 by revised interagency guidance that excludes generative and agentic AI (Office of the Comptroller of the Currency, 2026).


The empirical record on internal model approval is the part most relevant here, and it is unflattering. Mariathasan and Merrouche (2014) found risk-weight density falling after banks received supervisory approval for the internal ratings-based approach, with the effect strongest among weakly capitalised banks and in jurisdictions with weaker supervision. Behn et al. (2022) found that model-based regulation approved ex ante allowed banks to underreport risk systematically, with approved models producing lower capital requirements than the outcomes subsequently justified. Neither study concerns AI. Both concern the same regulatory form, and both find the approved record diverging from the behaviour it was meant to represent.

That is the decoupling argument of Section 3 with supervisory evidence behind it, produced by supervisors with more resources and more settled validation methods than any AI oversight regime currently commands. The incumbent regimes have not absorbed AI either: the United States guidance of 2011 was replaced on 17 April 2026 by revised guidance that expressly excludes generative and agentic systems (Office of the Comptroller of the Currency, 2026). The credit scoring, onboarding and pricing models at issue here are discriminative rather than generative, so they remain inside that perimeter; what falls outside it is the generative and agentic tier the Qatari Guideline's high-risk class would also capture, which is where the incumbent model-risk framework now has nothing to say. The Qatari Guideline should therefore be read as an extension rather than an innovation, and the question it raises is not whether supervisory approval is a coherent regulatory form but whether extending it from regulatory capital to customer access changes what approval can establish. Two things about the extension cut in opposite directions. Capital models have an observable outcome against which approval can eventually be judged, since losses realise, enter published accounts and can be set against the risk weights that were approved. Fairness in credit access has no equivalent, and the reason is worth stating precisely, because a supervisor does hold figures. Rejection and pricing dispersion by customer segment are distributional statistics rather than realisations. The repayment behaviour of applicants who were refused is never observed, so there is no outcome against which the approved model's treatment of them can be scored, and what counts as a disparity requiring correction has to be settled normatively before the figures carry any implication at all. Nor does any of this reach the public record, where realised losses eventually appear whatever a supervisor does. The correction mechanism that made prudential model approval self-correcting therefore fails twice, once for want of a realised benchmark and once for want of an external audience that could see one. Against that, the Guideline reaches procurement, which prudential model approval does not, and the vendor channel is where most banks now acquire the systems in question.


4.2 From the Officer's Desk to the Authorisation File

The Guideline's approval requirement changes who bears the burden of proof. Under Article 14, a deployer decides for itself whether its oversight arrangements meet the standard, and the question is tested, if at all, after something has gone wrong. Under the Qatari instrument the bank must persuade the supervisor in advance, and the supervisor may require sandbox testing before agreeing. Enforced self-regulation in the sense of Ayres and Braithwaite (1992) becomes something closer to authorisation.

That shift has an underrated consequence for the vendor problem. Banks increasingly acquire rather than build the models in question, and international supervisory work treats third-party provision as the normal channel rather than the exception (Financial Stability Board, 2017, 2023). Acquisition is where opacity enters, because a purchased model arrives with contractual limits on inspection and a supplier incentive to disclose as little as possible. Extending prior approval to purchase, licensing and outsourcing agreements places the supervisor inside the procurement decision rather than downstream of it. Neither Article 14 nor Article 22 reaches that point, and the reviewability framework of Cobbe et al. (2021) assumes access a deployer may be contractually unable to grant.

Whether that reach converts into anything depends on a bargaining relationship the instrument cannot alter. Credit scoring, fraud detection and enterprise AI in banking are supplied by a small number of global providers, and the Financial Stability Board has documented both the concentration and the difficulty supervisors face in obtaining assurance about providers they do not authorise (Financial Stability Board, 2019, 2023). Those providers contract on standard cross-jurisdictional terms over proprietary architectures. A supervisor can require that an outsourcing agreement secure audit and access rights, as the European Banking Authority's outsourcing guidelines do (European Banking Authority, 2019), and the European Union has concluded that contractual requirements alone were insufficient, establishing direct oversight of designated critical providers under the Digital Operational Resilience Act (Regulation (EU) 2022/2554, 2022). Anderson-Princen (2022) examined an actual bank-to-cloud outsourcing transaction and found substantial misalignment between what the regulatory framework assumed the bank could negotiate and what it could.

There is a prudential dimension to this that the access framing can obscure, and it follows from the same market structure. Where the banks in a market of this size acquire high-risk models from the same small pool of global providers, they do not hold nine independent model risks. They hold one risk, held nine times. Whether Qatari banks do so is not established here, and the argument is conditional on it. A flaw in a widely licensed scoring model, a drift left uncorrected at the provider, a change in a vendor's training data, or a disruption at the provider itself propagates across the sector at once, and correlated failure of that kind is a different object from the idiosyncratic model failure that internal validation was built to catch. The Financial Stability Board has made this point about third-party dependencies directly, finding that reliance by many institutions on a limited number of providers reduces the ability of both institutions and authorities to assess whether services are being delivered as expected (Financial Stability Board, 2019, 2023), and the European Union's answer under the digital operational resilience regime is to designate critical providers and supervise them directly rather than to leave the problem to each firm's contract (Regulation (EU) 2022/2554, 2022).

Prior authorisation does not reach that risk, and the reason is structural rather than a matter of effort. Approval examines one bank's file for one system at a time, and concentration is invisible in any single file: every submission can be complete and accurate while the whole portfolio of approvals a supervisor has granted rests on three vendors. The supervisor is nonetheless better placed to see it than anyone else, because the register names providers and provider identity is one of the four elements Section 4.3 codes as strongly verifiable. Read across firms rather than one at a time, the approval archive becomes a concentration map, and that is an unusual case in this analysis of a weakly verified instrument yielding something strong, obtainable from records the supervisor already holds. Nothing in the published requirements indicates that the register is read this way or structured to permit it. The consequence for access follows from the same fact and compounds the asymmetry described in Section 4.3. Where one model scores applicants at most banks in a market, an applicant the model treats badly is not refused by one lender and accepted by another. Refusal replicates, and the competitive process that would otherwise correct a single bank's error does not operate at all.

Bargaining power is not the only obstacle, and the second one is jurisdictional. The constraint runs through the provider's home law rather than the bank's, and the direction is worth stating because it is easy to reverse. A Qatari bank processing Qatari customer data is not itself governed by foreign data protection law. Its vendor is governed by the law of the place the vendor is established, and the vendor is what a supervisory audit right has to reach. Several major jurisdictions deny effect to a foreign authority's demand for disclosure unless an international agreement supplies the channel. In the European Union, Article 48 of the General Data Protection Regulation withholds recognition from a third-country authority's decision requiring disclosure absent such an agreement, and Chapter V conditions transfers on adequacy or appropriate safeguards, which after Schrems II require a case-by-case assessment of equivalence (Regulation (EU) 2016/679, 2016; Court of Justice of the European Union, 2020). In the United States, where most of the providers at issue are established, disclosure to a foreign authority is constrained rather than free: the Stored Communications Act restricts a provider of communications services to the public from divulging the contents of communications, and the CLOUD Act opens a route for foreign orders only where an executive agreement is in place, of which there were two by mid-2025, with the United Kingdom and Australia (Congressional Research Service, 2018; Daskal & Salgado, 2025). The reach of that example should be stated rather than assumed, because it is easy to overdraw. Both instruments were written for criminal process and for personal data, and a vendor's model documentation, validation reports and audit access are neither. What they bear on is the customer data a supervisor would need in order to test a model against live records rather than against the file describing it, which is the step that would convert a weakly verified assertion into something stronger and is also the step most exposed to a restriction in the provider's home state. Narrowing the example does not dissolve the problem. A supervisor's access to a foreign provider runs through that provider's home law and through cooperation between authorities, not through the bank's contract, and where no such channel exists an audit right is worth what the provider chooses to honour. Data localisation compounds the problem, with roughly 100 measures in force across 40 countries by early 2023, two thirds of them pairing local storage with a prohibition on outward flow (Del Giovane et al., 2023). The European Banking Authority's outsourcing guidelines require that third-country arrangements not impair a competent authority's ability to supervise, and route access through cooperation agreements rather than through the contract alone (European Banking Authority, 2019), and the European Union went further still, concluding that contractual rights were not enough: under the Digital Operational Resilience Act a third-country provider designated as critical must establish a subsidiary in the Union within twelve months, and the Lead Overseer inspects it there (Regulation (EU) 2022/2554, 2022). That is a territorial solution available to a market of the European Union's size. It is not available to a supervisor whose entire banking system is a rounding error in a hyperscaler's revenue.

Two outcomes are then available to such a supervisor, and the second is likelier. It can hold up approvals until a global vendor accepts bespoke inspection terms, which asks a bank holding a fraction of a per cent of that vendor's revenue to win a concession the vendor has refused elsewhere, and to win it against a legal position the vendor may not be free to concede. Or it can accept vendor attestations and third-party assurance reports as evidence the conditions are met. The second path reproduces the problem the approval gate was built to solve, one step earlier: an assurance report is a documentary artefact whose existence is strongly verifiable and whose substance is not, and the compliance-audit literature finds such reports functioning as legitimacy rituals rather than inspection (Islam et al., 2018; Power, 2021). Procurement approval widens the supervisor's formal reach without widening what it can see.

The shift also moves the oversight obligation to a party that can actually discharge it. An officer reviewing a credit score has minutes, one case and no counterfactual. A supervisor reviewing a model has documentation, comparison across institutions and the option of testing. The oversight literature's core objection, that we are asking the wrong person to do something they cannot do, does not apply in the same way to a prudential supervisor with a model risk function behind it.

What the shift cannot do is follow the model into operation. Approval is granted once, on the basis of a file. Model behaviour drifts, populations change, and the officers reading the output develop habits no approval file anticipates. Fritz-Morgenthal et al. (2022) treat continuous validation as the substantive control for this reason. The Guideline requires periodic review of the strategy, integration of AI risk into enterprise risk management, and re-approval for materially modified systems. Whether a drifted model counts as materially modified is the question on which the regime's effectiveness turns, and the instrument leaves it to the firm's judgement in the first instance.


4.3 What Prior Authorisation Can Verify

The register is the Guideline's central artefact. It records classification, providers, risks, impact assessments, oversight protocols and third-party assessments, and goes to the supervisor annually. It is worth being clear about what kind of instrument that is, because the disclosure literature would mislead here. Legitimacy and signalling accounts explain voluntary public disclosure, where a firm chooses what to say to an audience whose approval it needs. The register is none of those things: it is mandatory, confidential, and submitted to an authority that can withhold permission to operate. It belongs with supervisory returns rather than with annual reports, and the relevant literature treats such returns as monitoring and enforcement instruments. Costello et al. (2019) show regulators using mandatory bank call reports as an enforcement input, with strict supervisors acting on what the returns reveal, and Li (2023) finds mandatory reporting by regulated facilities causing regulators to increase inspections of those facilities. That evidence transfers with one qualification, and the qualification is this paper's own argument applied to its own comparison. Call reports and emissions returns carry realised quantities, which is what lets a supervisor read an anomaly off the return and act on it directly. The register carries structural metadata: an inventory, classifications, named providers, the existence of assessments and protocols. Nothing in it can be out of line with a measured outcome, so it cannot trigger enforcement the way a capital ratio or a pollutant reading can. What it can do is tell a supervisor where to look, which is the weaker of the two functions those studies document and is still a real one. The register's purpose is to direct supervisory attention rather than to supply grounds for action, and it should be evaluated on whether it does that.

What it shares with a disclosure instrument is narrower and still decisive: it measures what a firm states, not what a firm does. That limitation belongs to compiled records as such, not to any theory of why firms compile them. Barakat and Hussainey (2013) found the quality of operational risk disclosure by European banks responding to board and supervisory characteristics rather than to the risk being disclosed, which is the same gap appearing in a mandatory banking context.

Four elements of the Qatari register are strongly verifiable in the sense set out in Section 3: the existence and composition of the AI inventory as submitted, the identity of the providers named in it, the existence of an impact assessment for each system that was submitted, and the existence of documented oversight protocols. Four further elements are only weakly verifiable: that the high-risk classification is correct, that the impact assessment identified the material risks, that the oversight protocol is followed in practice, and that every system requiring approval was in fact submitted.

The last of these deserves separating out, because it is easy to miscount as strong. A supervisor can confirm with certainty that it approved the systems it approved. It cannot confirm from the same record that nothing was withheld, and the gap is not hypothetical: the classification that determines whether a system needs approval is made by the firm, and so is the judgement that a model has drifted far enough to count as materially modified. Approval of what is submitted is strongly verifiable; completeness of submission is not.

The obvious objection is that prudential supervisors do not rely on the record alone. Ex ante approval is paired with on-site examination precisely to test what the file asserts, and the pairing works: the European Central Bank's targeted review conducted 200 on-site internal model investigations at 65 institutions and produced more than 5,800 findings and 253 supervisory decisions (European Central Bank, 2021). That is a supervisory toolkit operating at a scale and intensity no AI oversight regime currently approaches. It does not dispose of the problem, for reasons that are structural rather than matters of effort.

The first is that examination is far better at testing a submitted model than at discovering an unsubmitted one. To find a system that was never registered, an examiner must first suspect it exists, and the inventory that would reveal it is the artefact the firm compiles. Detection therefore depends on the very record whose completeness is in question. The second is frequency. Models are retrained and repointed on a cadence measured in weeks; on-site examinations arrive on a cadence measured in years, and a system can enter service, drift and be replaced between visits. The third is that what an examiner can see on site has changed. Models increasingly run in distributed cloud environments the bank does not control and cannot fully expose, and the Financial Stability Board has recorded that such arrangements may reduce the ability of institutions and of authorities to assess whether a service is being delivered in line with regulatory obligations (Financial Stability Board, 2019). Auditing an enterprise architecture against a submitted register presupposes that the architecture is legible to the auditor, which a managed service consumed through an interface is not. To this is added the capacity question. Detecting an unregistered model requires examiners able to read data pipelines and model artefacts rather than documentation, a skill set supervisors are acquiring rather than holding, and one the Gulf's regulators are building against policy readiness that already lags technological readiness (Albous et al., 2025). Examination is also subject to the variation the supervision literature documents, with Agarwal et al. (2014) using an exogenous examiner rotation to identify systematic leniency and link it to subsequent failures. The decisive evidence is that examination has not cured the problem where it is most developed: the ECB conducts those investigations in the same regime in which Mariathasan and Merrouche (2014) and Behn et al. (2022) find approved models continuing to underreport risk. Examination mitigates weak verifiability. It does not convert it into strong verifiability, and the design conditions in Section 5.1 are aimed at the residue it leaves. Everything the supervisor can establish concerns the apparatus; everything it cannot concerns the decision the apparatus was built to govern. That asymmetry is the decoupling risk, stated precisely, and it follows from placing the obligation before deployment rather than from any defect of drafting.

The evidence for what firms do with that asymmetry should come from supervisory reporting rather than from market signalling, and in this field it does. Mariathasan and Merrouche (2014) find risk-weight density falling after banks obtain supervisory permission for the internal ratings-based approach, most sharply where supervision is weaker, and Behn et al. (2022) find approved models permitting systematic underreporting of risk. Those are mandatory returns to a supervisor with inspection powers, not announcements to a market, and they show the reported position drifting from the underlying one under precisely the institutional conditions this instrument creates. The organisational literature supplies the mechanism rather than the evidence: Edelman (1992) showed ambiguous mandates being mediated by the organisations subject to them, which construct visible structures whose sufficiency is established by their existence, and Krawiec (2003) named the result cosmetic compliance. Both concern internal compliance programmes, which is what the Guideline's first three layers require a bank to build.

One body of evidence on layered institutional oversight bears on the mechanism, and what it is and is not should be stated before it is used. Islamic banks operate Shariah supervisory boards, internal bodies holding independent authority and a review mandate, and Qatari banks have operated them under this supervisor since 2008. The interview evidence, however, is Malaysian. Karbhari et al. (2024) applied Goffman's frame analysis across forty-six interviews in the Malaysian Islamic banking sector to show managers deploying passing and covering strategies toward those boards, managing the appearance of compliance rather than submitting to scrutiny, and Mohd Haridan et al. (2018), interviewing in two Malaysian Islamic banks, find the same bodies constrained by limited technical competence and by dependence on management for information. That is the mechanism the Guideline relies on when it requires an oversight function and a committee assessing use cases, observed in a setting where the reviewer has clearer standards and a longer history than any AI oversight function will have for years. It carries no further than that, and the limit is jurisdictional before it is anything else: the evidence establishes a pattern in layered oversight, not a fact about Qatari institutions, about which this paper makes no empirical claim. A Shariah board is not an oversight body for credit models: IFSB-10 confines it to pronouncements, dissemination, internal Shariah review and audit, and annual verification, with intervention not to exceed that mandate (Islamic Financial Services Board, 2009), while credit risk measurement sits with the board and senior management (Islamic Financial Services Board, 2005) and the risk framework, risk committee and chief risk officer report to the board (Islamic Financial Services Board, 2023). No comparison between Islamic and conventional banks can therefore speak to algorithmic oversight, and none is offered here.

The weakness is not distributed evenly across customers, and that is where the population described in Section 2 re-enters the argument. The elements a register verifies strongly concern the existence of artefacts. The elements it verifies weakly concern whether a system performs as claimed for the people it decides about. Those two classes fall differently on different applicants. A borrower with a long domestic credit history is scored on the data the model was built for, and an error in that case is the ordinary kind a bank has every incentive to find, because it costs the bank money. A credit invisible applicant is scored by inference from proxies, in a market where migrant stock exceeds three quarters of the population, and an error there costs the bank a customer it never acquired and a loss it never books. Nothing in the register separates the two cases. An impact assessment records that fairness was considered; it does not record performance by segment, and the segments where performance is weakest are the segments whose exclusion leaves no trace in any figure the bank reports or the supervisor receives. The asymmetry therefore compounds: weak verification is least consequential where a commercial incentive already corrects the error, and most consequential where none does. That is why the outcome-linked condition in Section 5.1 is not one design condition among four. The contestability and override conditions record what customers and officers do, so they reach a population that appears somewhere in the process. The outcome-linked condition is the only one that reaches the population a model silently excludes, applicants who never generate a review request because they never contested and never appear in an override because no officer saw them, and the applicants most exposed to the decisions the Guideline classifies as high risk are precisely those an artefact-based record cannot see.

None of this makes the register worthless. It makes it a starting point that requires a second instrument to become informative, which is the substance of the design conditions in Section 5. A register that recorded override rates, appeal volumes and outcomes by segment would not convert weak verification into strong verification, and the earlier formulation of this paper's own construct has to be applied against it. A number a firm reports about itself is still an assertion whose truth lies outside the file. What changes is narrower and still worth having. An assertion of quantity can be contradicted, by the firm's own transaction records, by its other returns, and by the distribution of the same quantity across the sector; an assertion that an impact assessment was adequate can be contradicted by nothing, because no evidence bears on it. The design conditions in Section 5.1 therefore do not remove weak verification from the regime. They move claims from a class that cannot be falsified at all into a class that can be falsified by evidence held elsewhere, and they make misstatement detectable rather than merely unattractive. That gain is real and it is conditional, since it depends on an examination capability the file cannot supply, which is why this section treats approval and examination as a pair rather than as alternatives.


4.4 What the Supervisor Acquires by Approving

Prior authorisation changes the supervisor's position, and it is worth being precise about how, because the change is not the one the phrase first suggests. Nothing in supervisory approval shifts legal responsibility from the bank to the supervisor. The Basel corporate governance principles and the Core Principles for effective banking supervision both place ultimate responsibility for a bank's risk management with its board and senior management (Basel Committee on Banking Supervision, 2015, 2024), and that allocation is unaffected by a supervisory permission or non-objection. Nor does approval immunise the firm. The European Central Bank's targeted review of internal models produced more than 5,800 findings and 253 supervisory decisions against models it had previously permitted, imposing remediation deadlines and limits on model use (European Central Bank, 2021). A bank whose approved system produces disparate outcomes remains exposed to supervisory enforcement, to conduct redress and to its own board's liability.

The contrast with pharmaceutical and device regulation is instructive precisely because that field does sometimes do what prudential supervision does not. Premarket approval of a medical device under the Medical Device Amendments preempts state common-law claims challenging the device's safety or effectiveness (Riegel v. Medtronic, Inc., 2008), while approval of a prescription drug label carries no equivalent protection against failure-to-warn claims (Wyeth v. Levine, 2009). Approval can confer a legal shield, and whether it does is a question of the statute rather than of the act of approving. No banking statute makes supervisory model permission a defence. Carpenter's (2004) account of approval conferring durable advantage, and Sharkey's (2024) reading of premarket approval as a feedback loop between regulation and liability, therefore transfer to banking only as descriptions of institutional behaviour, not as claims about legal exposure.

What does transfer is reputational and political. An agency that has examined a model and permitted its use has made a public commitment, and enforcing against that model later means conceding that its own examination missed something. Maor et al. (2013) show a banking regulator managing exactly this kind of exposure after its own decisions, treating reputational threat as a variable to be governed rather than an incidental cost, and Herder (2019) documents approving agencies being institutionally and politically constrained in acting after approval. Shavell's (1984) treatment of ex ante and ex post instruments as substitutes anticipates the same result at the level of design: assurance given before deployment is paid for in willingness to act afterwards.

Qatar's instrument intensifies this. Authorisation extends to purchase, licensing and outsourcing agreements, so the supervisor has passed on the vendor as well as the model; the register goes to the supervisor rather than the public, so any later failure is one it was uniquely placed to catch; and the high-risk classification on which approval turns is made by the firm in the first instance, so the supervisor may find itself defending a decision resting on a judgement it did not make. Ayres and Braithwaite's (1992) enforcement pyramid assumes a regulator able to escalate from a low rung, and prior authorisation raises that rung, because the first step now carries an admission. The implication is not that the form should be avoided but that escalation becomes costlier under it, which is the argument for the recurring obligations in Section 5.1: they generate evidence of changed behaviour after approval, letting the supervisor act on new facts rather than on a revised view of its own earlier decision.


4.5 The Emirati Comparison: Diffusion Without Evaluation

The Emirati guidance of February 2026 requires documented AI governance frameworks, board accountability, model inventories, annual bias testing, third-party due diligence and bilingual customer disclosure (Central Bank of the United Arab Emirates, 2026). Those duties divide across two of the three loci, and it is worth saying which, because the instrument is easy to read as covering all three. Documented frameworks, board accountability and the model inventory attach to the institution in the sense Section 3 gives that term: they oblige an internal body to hold a standard, not a person to review an output. The oversight modes and the customer disclosure attach to the decision. Nothing attaches before deployment. No supervisory permission conditions use, and the inventory and the annual test report on systems already running, which is a duty to account for what was deployed rather than a gate in front of deploying it. The two Gulf instruments sit on opposite sides of the distinction this paper draws, seventeen months apart, in neighbouring markets of similar structure.

One element of the UAE instrument is worth isolating because it addresses the weak-verification problem directly. Annual bias testing is an outcome-adjacent requirement: it obliges the firm to generate evidence about what the model does, not merely about what governance surrounds it. Qatar's Guideline requires impact assessments but does not, on its published terms, require recurring quantitative testing of model behaviour by segment. That is the single largest difference between the two in terms of what a supervisor will learn.

Albous et al. (2025) characterise the six GCC national AI strategies published between 2018 and 2024 as a shared soft-regulation posture. Qatar and the UAE have moved past it in the financial sector; Saudi Arabia, Bahrain, Kuwait and Oman operate through strategies and draft legislation rather than binding supervisory instruments. The comparative work that exists classifies regimes as types (García-Llorente & Olmeda, 2026), which maps the field of rules but does not tell a supervisor choosing between forms what each form will fail to catch.


5. Discussion

5.1 Four Design Conditions

The argument to this point is that pre-deployment authorisation is better positioned than decision-level oversight and worse protected against decoupling. Whether a given instrument escapes that trade-off depends on how much of what it collects is verifiable in the strong sense. Four conditions follow from the analysis, set out in Table 3.

Table 3: Four Design Conditions for a Pre-Deployment Authorisation Regime

Condition

What the instrument would have to require

What it converts

Present in the Qatari Guideline

C1. Outcome-linked registration

Model behaviour by borrower segment recorded in the register alongside governance artefacts

Classification from assertion to testable statement

No

C2. Contestability reporting

Volumes of review requests, reversal rates, and their distribution across segments

A granted right into an observed one

No

C3. Operational override data

Override rates by system and by officer grade, reported to the supervisor

An approved protocol into observed behaviour

No

C4. Drift-triggered re-approval

Re-approval triggered by measured performance change and validated independently of the unit that sought approval

Materiality, and with it completeness of submission, from firm discretion to measurement

Partly, re-approval is required for material modification but the trigger is left to the firm

Note. Derived by the authors from the analysis in Sections 3 and 4. The final column records whether the condition appears in the published descriptions of the Qatar Central Bank (2024a) Guideline, not whether Qatari banks satisfy it.


The first condition concerns the register's content. As specified, Qatar's register documents governance around the model. A register that also recorded model behaviour by borrower segment would convert the classification claim from an assertion into a testable statement, and the approval decision would rest on evidence rather than on a firm's characterisation of its own system. The UAE's annual bias testing does part of this work, the clearest instance of one Gulf instrument compensating for a weakness in the other.

The second concerns contestability. The Guideline grants customers a right to request review and correction, and the data showing whether that right functions already exists inside banks: how often reviews are requested, how often they reverse the outcome, and how those rates differ across segments. Citron and Pasquale (2014) argued a decade ago that opaque scoring demands due-process safeguards, and reversal rates are the closest available measure of whether such a safeguard is live. None of this appears in the published requirements.

The third concerns what happens after approval. Protocols are approved as documents; overrides happen as events. A supervisor receiving override rates by system and officer grade can observe whether the human-exception mode is used at all, the most informative signal available about whether decision-level oversight functions underneath the pre-deployment regime. Wagner's (2019) quasi-automation is visible in override data and invisible in a protocol.

The fourth concerns drift. Leaving the firm to judge when a system has been materially modified puts the trigger for re-approval inside the party with the weakest incentive to pull it. Tying re-approval to measured performance change, validated independently of the unit that sought approval, removes that discretion; model risk practice already supplies the machinery (Fritz-Morgenthal et al., 2022).


5.2 Hypotheses, and Who Can Test Them

The statements below divide on a line worth drawing openly, because it determines who could ever settle them. A statement no external researcher can test is not a falsifiable hypothesis, whatever its plausibility. The constraint is the paper's own argument applied to itself: the register goes to the supervisor and is not published, and no loan-level or supervisory microdata reaches third-party researchers in Qatar or the region, where scholarship on bank risk is built from hand-collected annual reports and aggregate series (Elamer et al., 2019; Elsamadisy et al., 2014). One statement follows that external evidence can refute, and three that only a supervisor's own records can evaluate.

The first proposition needs its mechanism stated, because the obvious one does not work. A confidential filing cannot by itself cause convergence in voluntary public reporting. The mechanism is indirect: the regime obliges every firm in scope to build the same documentary apparatus, in the same categories, on the same timetable, after which firms hold low-cost material for external communication in a form the regime has standardised. What converges is the vocabulary and structure of what banks say, through mimetic and normative pressure on a common template, not their compliance, which stays unobserved. A finding of high uniform disclosure would be consistent both with substantive compliance and with its absence.

P1. The rate at which cross-firm variance in the structure and vocabulary of public AI governance disclosure falls among firms in scope increases after a supervisory authorisation regime takes effect, and that increase exceeds any contemporaneous change in a matched panel of banks operating under no ex ante authorisation requirement. The prediction is a divergence in slopes at the instrument's boundary rather than a difference in levels, and it is confined to disclosure categories specific to the regime rather than to the generic governance vocabulary available to every large bank. Refutable by content analysis of published reporting across the years spanning the instrument's introduction. Persistent dispersion among firms in scope, or the same slope change appearing in the control panel, would count against it.

The measurement needs specifying at two levels, because the construct and the estimator do not sit at the same one. Isomorphism is a statement about dispersion, and dispersion is one number per market-year, which with nine domestic banks leaves too few effective observations for asymptotic inference. The workable design is therefore paired. At the firm-year level, a disclosure index built from the regime-specific categories supports an ordinary difference-in-differences estimate of adoption density, with each bank-year an observation and standard errors clustered by bank. At the market-year level, the dispersion measure that actually tests convergence is estimated on the same index, with inference by permutation across the panel rather than by asymptotic standard errors, which is what a panel of this size permits. The first is the tractable test and the second is the theoretically faithful one, and they answer different questions: density alone would rise under voluntary standard adoption, which is why the restriction to jurisdiction-specific categories does the identifying work for both.

The comparison has to be specified that tightly, because convergence in a Gulf banking market is overdetermined. ISO/IEC 42001 was published in December 2023 and the United States National Institute of Standards and Technology released its AI risk management framework in January 2023 (International Organization for Standardization, 2023; National Institute of Standards and Technology, 2023), and international banking groups operating in the region import governance templates drafted at group level for reasons unconnected to any local supervisor. Uniformity observed after 2024 is therefore consistent with a supervisory cause and with mimetic and normative isomorphism on a global template at once (DiMaggio & Powell, 1983), and a test that cannot separate them establishes nothing. Three features of the specification do the separating. The control panel holds the voluntary standards, the vendor population and much of the regional supervisory culture constant while varying the ex ante regime, for which the other Gulf Cooperation Council markets are the natural comparison. The slope specification discards level differences, which group templates and voluntary standard adoption produce on their own. The restriction to jurisdiction-specific categories discards the vocabulary the international standards distribute freely: a bank reporting that it maintains a risk taxonomy evidences nothing, whereas a bank describing a register in the form a supervisory submission requires, a pre-deployment approval file or an annual return to its supervisor evidences the regime that demands them. A researcher without the authentic instrument text can still build that coding frame, since the three categories appear in the official announcement and in practitioner commentary, which is why P1 remains testable under the access constraint recorded in Section 5.4. What P1 measures should be named rather than left to be inferred. It tests the public discursive spillover of a confidential mandate, not the operation of the gate. The register is a supervisory return and is not published, so no external instrument can reach the approval decision itself, and P1 stands as a secondary proxy whose result in either direction constrains what the regime does to firms' external accounts rather than what it does inside them. A reader who took convergence in disclosure as evidence that the gate works would be making exactly the inference Section 4.3 says the record cannot support.

Only one proposition survives that test, and the reason the second does not is worth stating rather than hiding. The claim that procurement authorisation reduces third-party opacity less than its formal reach implies looked externally testable, through vendor identity in published reporting and through bespoke contractual terms where disclosed. Neither proxy holds. Banks do not publish inspection clauses, audit rights or service-level terms from vendor contracts, and a vendor's corporate identity measures institutional transparency rather than the technical opacity of the model it supplies. For the reason given three paragraphs below, it is therefore not carried as a hypothesis at all.

The remaining two are hypotheses of the same logical form as P1, separated from it not by their form but by who holds the evidence, which in each case is the supervisor. The paper does not claim the academic community can falsify them as things stand.

One claim that might have been listed is deliberately not. The conclusion that procurement authorisation reduces third-party opacity less than its formal reach implies does not await evidence: the concentration of provision among a few global vendors is documented (Financial Stability Board, 2019, 2023), the contractual misalignment between what a regulatory framework assumes a bank can negotiate and what it can has been observed in an actual transaction (Anderson-Princen, 2022), and the European Union's move to direct oversight of designated critical providers is itself a supervisory judgement that contractual rights were insufficient. Section 4.2 therefore states it as an analytical conclusion drawn from established market structure rather than as an open question, and it is not carried here as a hypothesis.

S1. The greater the share of a regime's mandated record that is only weakly verifiable, the greater the divergence between documented governance and realised outcomes. Testing it relies on internal evaluative measures and nothing else. The variables that would settle it are aggregate rejection and pricing dispersion by customer segment, volumes and reversal rates of customer review requests, and the supervisor's own findings on inspection, all of which sit inside the supervisor or behind banking secrecy. No external proxy is proposed, because none can be identified in the target jurisdiction's public record, and offering one that may not exist would be worse than offering none.

S2. Regimes requiring recurring quantitative testing by segment generate supervisory information that prior authorisation alone does not, and the difference is largest where populations change fastest. Evaluable by supervisors in comparison with one another, and by researchers only where testing results are published.

S3. Where the supervisor's principal holds equity in the firms it authorises, the authorisation record grows in length, formality and apparatus across successive cycles while approval remains near-universal, refusals stay rare, and the conditions attached to approvals remain procedural rather than substantive. This is the co-ownership mechanism of Section 5.3 stated as a claim rather than as an observation about incentives, and it is joint by construction: elaboration alone is consistent with an ordinary compliance burden, and a low refusal rate alone is consistent with well-prepared applicants, so neither half counts as evidence without the other. Approval and refusal rates, the character of the conditions imposed, and the growth of filings measured against them would settle it, and all three sit with the supervisor. A rising refusal rate alongside thickening files would refute it. Who can settle it needs splitting, because detection and attribution are not the same task. A single supervisor can detect the pattern in its own archive, since filing volume, approval and refusal rates and the character of conditions all sit in records it already holds. Attributing the pattern to co-ownership needs variation in ownership, and one archive supplies that only partially: state equity is not uniform across the licensed population, so a supervisor can compare its own treatment of more and less state-owned licensees, and that within-jurisdiction contrast is the first-line design. The cross-jurisdictional comparison is stronger and no single supervisor can run it, since the approval archives of other authorities are closed to it. That test would require collection coordinated across supervisors, of the kind international bodies undertake, and it is named here as what the claim would need rather than as something this paper can ask of anyone.

The division is itself a finding, and the proportions are the sharpest form of it. Of the four statements the analysis generates, exactly one can be refuted from outside, and it concerns what banks say rather than what they do. A regulatory form that produces a record only its supervisor can read confines external scholarship to the study of disclosure. That is why Section 5.1 treats what the supervisor collects, and what of it becomes public, as the design variable that matters most: it determines what the supervisor learns, and whether anyone else can ever check.


5.3 Whether the Form Travels

Qatar approved a form of oversight that its own market makes practicable. Nine domestic banks, a single supervisor already holding approval powers over licensing and outsourcing, and a population of high-risk systems small enough for an approval queue to clear. The last of these is an assumption this paper makes rather than a figure it establishes, since no count of deployed high-risk systems is public. Under those conditions the supervisor can read what it authorises. None of these conditions holds in a large fragmented market.

Scale bites in a specific way, and the way it bites is this paper's argument turned back on the regulator. A supervisor overseeing several thousand institutions cannot examine every high-risk system before deployment. It can lengthen the queue, which suppresses deployment. It can raise the classification threshold, which returns most decisions to the deployer. Or it can approve on the documentation submitted, which is quasi-automation in Wagner's (2019) sense relocated one level upward: a formally required reviewer, inserted into a process they cannot evaluate, whose approval satisfies the rule without changing the outcome. The failure modes in Figure 1 are not confined to the regulated firm. A supervisor is an institution too.

This supplies a reading of the European choice that the critical literature has not offered. Provider self-assessment under Annex VI, with market surveillance afterwards, is what a regulator adopts when administrative permission is arithmetically unavailable to it, and the AI Act governs a market with no single sector supervisor and no common approval channel. The choice looks less like a failure of ambition than like an accommodation to scale.

Concentration is more than an arithmetic advantage, and treating it as one misses the condition running the other way. The same features that make authorisation administrable make the authorising relationship dense: few firms, repeated interaction, a supervisor dependent on those firms for the information on which it decides, and in many concentrated markets substantial state ownership on both sides of the relationship. That is the standard setting for the concerns the capture literature has described since Stigler (1971), formalised by Laffont and Tirole (1991) as collusion arising from informational asymmetry between regulator and regulated firm, surveyed by Dal Bo (2006), and identified empirically in banking supervision by Agarwal et al. (2014), who exploit an exogenous examiner rotation to show systematic supervisory leniency and link it to subsequent failures. Quintyn and Taylor (2003) set out what mitigates it, in the four dimensions of supervisory independence, and Das et al. (2004) find across Financial Sector Assessment Program data that the quality of regulatory governance tracks system soundness.

One feature of Gulf banking sits outside that literature and deserves stating, because the classical model does not describe it. Capture theory assumes a private firm and a public regulator with distinct principals. In several Gulf markets the state is on both sides: the Government of Qatar holds a 50 per cent stake in Qatar National Bank through the Qatar Investment Authority (Moody's Ratings, 2025), and Qatari banks' holdings of public sector assets run at roughly 30 per cent of total assets (International Monetary Fund, 2025). Where the state is simultaneously owner, supervisor and policymaker, the governance distortion is structural rather than behavioural (Cuervo-Cazurra et al., 2014), and the empirical literature on state-owned banks documents lending patterns that follow political rather than commercial cycles (La Porta et al., 2002; Dinc, 2005).

Sovereign co-ownership does not simply raise or lower the capture risk; it changes the mechanism, and three consequences follow for an authorisation regime specifically. The first concerns the cost of refusal. In the principal-agent model the loss a firm suffers when permission is withheld is external to the regulator, which is what allows refusal to function as a credible threat. Where the state holds the equity, that loss lands on the same balance sheet the supervisor's principal owns, so the threat is internalised and its credibility depends on an institutional separation the classical account does not have to assume. The second concerns information. An owning state is not informationally dependent in the way Laffont and Tirole's regulator is, since it sees inside the firm through the board it appoints. That substitutes proprietorial knowledge for supervisory knowledge, and proprietorial knowledge does not produce a documentary record. The pressure to build a rigorous file is weakest precisely where the state already believes it knows what the file would say. The third concerns reputation. Maor et al. (2013) show a banking regulator managing reputational exposure after its own decisions; under co-ownership a failure is a failure of the state in two capacities at once, which raises the cost of acknowledging one and so sharpens the constraint identified in Section 4.4.

The second consequence raises a question the argument should answer rather than leave standing. If proprietorial visibility is as good as described, a formal clearance regime that imposes documentary friction on banks the state part-owns is hard to explain on monitoring grounds alone. Three readings reduce the tension, and all three are theoretical. Board-level visibility is firm-specific and does not aggregate; a supervisor comparing nine institutions needs records in a common form, which a seat in each boardroom cannot produce, so the register's value may lie in comparability rather than in revealing anything the state does not already know somewhere. Ownership is also partial and uneven across the sector, and an instrument written for the whole licensed population cannot be calibrated to what the state happens to see inside the institutions it part-owns. And a documentary regime does external work that internal knowledge cannot: it is legible to assessors, correspondent banks and rating agencies, the audiences that read a jurisdiction's regulatory maturity from its published architecture, and financial sector assessment methodology evaluates supervisory frameworks on exactly that kind of evidence (Das et al., 2004). On the third reading the register is in part a boundary artefact addressed outward rather than a monitoring device addressed inward, which follows the decoupling argument of Section 3 rather than contradicting it. The readings are not mutually exclusive, and none is tested here.

The three consequences point the same way. Each weakens the external observability on which an authorisation regime depends for correction, and they do so at exactly the moment the regime concentrates decision-making in a single public authority holding an unpublished record. An authorisation regime operating under sovereign co-ownership therefore has more need of the independence safeguards Quintyn and Taylor describe, and far more need of publication, than the same regime would in a dispersed private market.

Put as a prediction rather than as a description, the mechanism runs as follows. Where the cost of refusal is internalised, the approval decision loses the property that makes it informative. A gate that is not expected to close invites a file compiled to be accepted rather than to be read, and a supervisor whose refusal is not credible has little reason to demand more than the file already contains. Approval under those conditions becomes ceremonial in a specific sense, and the sense matters, because the obvious prediction is the wrong one. A gate that does not bind produces an elaborate file rather than a thin one. The two pressures described above act on different properties of the same record. The external audience rewards volume, formality and visible apparatus, while the internalised cost of refusal removes what would otherwise make the standard discriminating. That is ceremonial conformity in Meyer and Rowan's sense, elaboration without consequence, and Power (2021) models the organisational logic by which an auditable trail proliferates independently of what it establishes. The prediction is therefore joint, and being joint it is harder to satisfy by accident: filings growing in length, formality and apparatus across successive cycles while approval stays near-universal, refusals stay rare, and conditions attached to approvals stay procedural rather than substantive. Thick files with a flat approval rate exhibit the pattern; thick files with a rising refusal rate do not. Volume and selectivity rise together where a gate binds and separate where it does not, which is what makes the pair observable at all. That is the means-ends decoupling of Section 3 arriving through the supervisor instead of through the firm, and it predicts that regimes operating under co-ownership decouple further than the ownership-neutral version of the argument implies. Approval and refusal rates, the character of the conditions imposed, and the growth of what is filed measured against them would settle it. All three sit with the supervisor, which is why the claim is carried in Section 5.2 as S3 rather than among the statements external evidence can reach. None of it is a claim about what any supervisor has done. This framework models structural incentives, not observed supervisory conduct, and the analysis that follows should be read on those terms throughout. What the argument establishes is that an authorisation regime's resistance to capture is a design question of the same order as its arithmetic feasibility, and that a regime combining approval powers with an unpublished record removes the external observers who would otherwise notice a lenient decision. Risk-based supervision offers the standard response, since regulators have long allocated scrutiny by expected harm rather than uniformly (Baldwin & Black, 2008), and an approval regime calibrated to a narrow class of the highest-impact systems could travel further than a universal one. Whether the resulting threshold captures the systems that matter is then the design question, and it is the same weak-verification problem in a new position: the supervisor must rely on the firm's own classification to decide what it will examine.

The framework therefore carries a scope condition. Pre-deployment authorisation is available where a supervisor has approval powers, a countable population of regulated systems and the capacity to use both. Where any is missing, the locus cannot move upstream however attractive the theory, and the design conditions in Table 3 become the more important instrument, since they attach to a reporting duty without an approval gate.

For a supervisor designing an AI instrument, the choice of locus determines what will be missed rather than how much. A decision-level regime misses systematic problems because the overseer sees one case; a pre-deployment regime misses operational problems because the approval file predates operation. The two are complements, and Qatar's Guideline contains both. Its weakness is not that it chose the wrong locus, but that the pre-deployment layer collects governance evidence while the decision-level layer collects nothing the supervisor sees.

Lee (2020) argues that AI regulation in financial services should carry access to finance as an explicit objective rather than as a by-product of consumer protection, and the Guideline's own definition of a high-risk system, one affecting access to financial services, points the same way without committing the supervisor to measuring it. On whether human oversight requirements should exist at all, the question has been posed at the wrong level. Green (2022) and Laux (2024) are right that an individual overseer is a weak guarantee, but it does not follow that oversight mandates should be abandoned; what follows is that their protective work cannot be done by the individual. Shifting the obligation upward is the available answer. The cost is a governance record that is easy to satisfy and hard to read.


5.4 Limitations

The verifiability coding in the supplementary material inherits that constraint and needs a stated error margin. Each requirement is classified as strongly or weakly verifiable on the basis of secondary descriptions, and a summary that omits a statutory audit right, an inspection power or a reporting obligation would place a requirement in the wrong column. The direction of that error is not neutral. Practitioner summaries written for compliance audiences tend to report duties that generate work and to pass over powers reserved to the supervisor, which biases the coding toward understating strong verifiability rather than overstating it, so the individual classifications are more likely to be too pessimistic than too generous.

Three things limit what the error can do to the argument. The distinction between strong and weak verification is a property of documentary records in general rather than of this instrument, since no file can establish whether the assertion it records is true, so the asymmetry survives intact even if several rows move; the argument rests on the shape of the distribution, not on any single classification; and the requirements coded weak are weak for reasons internal to their own logic, a classification made by the firm being unverifiable from a record the firm compiles whatever the instrument says about audit rights. A reader should nonetheless treat the row-level coding as provisional. Four routes would triangulate it, and two of them were run for this study, with the results reported in Section 1.2: independent regulatory tracking, which corroborated the instrument's date and its authorisation requirement, and the disclosures of QCB-licensed banks, which returned nothing bearing on the coding either way. The two that remain are the ones that would settle it. The authentic instrument text answers the question directly. The International Monetary Fund's periodic assessments of Qatar's financial sector report on supervisory powers from a position of access this study did not have. One further calibration is available to any researcher and was not attempted here: the Emirati guidance is public, and coding its comparable requirements from authentic text would show how far a coding frame built on secondary description departs from one built on an instrument.

The most consequential limitation concerns the primary text, which was not obtained. Appendix E records what was searched, where, and which sources the account rests on instead. What could not be established is which of two situations obtains. The instrument may be published and simply not have been reachable by the means available here, in which case the gap is an artefact of this study and a reader with institutional access can close it. It may instead be distributed through supervisory channels to licensed entities and their compliance functions rather than to the public, which would make the gap a feature of the jurisdiction and a finding in its own right. The regulatory tracking record reported in Section 1.2 shows the authentic text reaching a party outside the supervisory perimeter, which is consistent with either. The evidence does not distinguish them, and the paper asserts neither.

A related and more consequential unknown is the instrument's legal standing, and it is worth theorising rather than merely conceding, because the two possibilities generate different predictions. If the Guideline is a binding instrument carrying sanctions, compliance runs on deterrence, and the decoupling it invites takes a particular form: filings that are complete, uniform and technically accurate, and thin in the places no rule specifies. If it is a supervisory expectation enforced relationally, compliance runs on the standing of each firm with its supervisor, and decoupling takes the opposite form: variance across firms tracking the closeness of that relationship rather than the character of their systems. The two are separable in the disclosure record, which makes the question a discriminator for P1 rather than only a gap.

The ambiguity has an effect of its own, and it runs in the same direction as both branches. A firm that cannot tell which regime it is in faces an asymmetric payoff: visible satisfaction of the formal requirements is cheap and protects against either enforcement posture, while substantive investment in fairness testing protects against neither more than the formal compliance already does. The dominant response to genuine uncertainty about legal standing is therefore to build the apparatus and defer the substance, which is the decoupling prediction of Section 3 arrived at by a second route. The argument advanced here does not depend on resolving the instrument's status, and a reader who resolves it gains a sharper test rather than a different conclusion. The paper therefore describes requirements at the level of substance and reports only what its sources agree on; it advances no reading of a specific clause, quotes no provision, and cites no article number of the Guideline, and any of its characterisations could be revised by the authentic text. Readers should treat the description in Section 2 as a reconstruction from secondary sources rather than as a textual analysis, and a subsequent study with access to the instrument in Arabic and English should verify it. The AI register, the artefact on which most of the argument turns, goes to the supervisor and is not published, so the extent to which registers contain outcome information cannot be established from outside. The regime had been in force for twenty months when this analysis closed, which spans at most two annual cycles and is too short a period for any claim about its effects. One further qualification attaches to P1 specifically. A matched regional control panel isolates the regulatory effect from the global one only if the control jurisdictions are not themselves moving; banks that expect a comparable instrument in their own market may adjust in advance of it, which would compress the measured difference and bias the test toward rejection. That is a conservative bias rather than a spurious one, and it is a reason to read a null result cautiously rather than a reason to distrust a positive one.

The framework is derived from regulatory design theory, organisational research and document analysis. It has not been tested. The hypotheses in Section 5.2 are the means of testing it, not findings, and that section states which of them external evidence can reach. The Shariah governance evidence used in Section 4.3 is Malaysian and concerns religious compliance review rather than algorithmic governance, of which there is very little in any Islamic banking setting, so it establishes a pattern in layered oversight generally and not a prediction specific to AI or to Qatar. The scope condition in Section 5.3 is a limitation as well as a finding. The framework was built from an instrument operating in a concentrated market with a single supervisor, and the claim that it generalises beyond such markets is argued rather than demonstrated. The capture argument in Section 5.3 models incentives rather than conduct, and no empirical claim about any supervisor or bank is made or implied anywhere in this paper. Finally, the analysis is confined to two Gulf instruments and the European ones they are read against; the classification of the four remaining GCC states as operating through soft regulation follows Albous et al. (2025) and published regulatory surveys, and would need verification against each supervisor's own rulebook before being relied upon. Literature searches were conducted between January and May 2026, and no source published after 31 May 2026 is cited.


5.5 Future Research

Three lines follow. The first is a content analysis of algorithmic governance disclosure by Qatari and GCC banks across the reporting years spanning the Guideline's introduction, scored against an index derived from the instrument's own requirements, which would give P1 its first test. The second is a comparison of Qatari and Emirati banks after February 2026, the two regimes now differing on exactly one design condition of interest in markets similar enough to make the comparison informative. The third is supervisory rather than academic: override rates, review requests and reversal outcomes exist inside banks and inside the Qatar Central Bank, and a supervisor willing to publish them in aggregate would settle questions no document analysis can reach.

What remains open is the question the paper could not address. Whether prior approval improves outcomes for the customers the Guideline names, those whose access to financial services depends on a high-risk system, is unanswerable from the public record as it stands, and will stay unanswerable until the regime requires the generation of the evidence that would answer it.


6. Conclusion

Qatar's Artificial Intelligence Guideline did something the academic literature on algorithmic oversight had not yet had a case to examine. It anchored the oversight obligation at pre-deployment authorisation, made a banking supervisor the party that must be satisfied, and captured the procurement channel through which most high-risk models actually arrive in a bank. The decision-level duty was not abandoned: the Guideline retains human oversight protocols alongside the approval gate, and the two operate as complements. The critique that has accumulated against decision-level mandates, that they place an unperformable task on an individual, does not transfer to this form.

A different problem does. Prior approval generates a record that is auditable in inverse proportion to its informativeness. The existence of a register, a committee and an impact assessment can be confirmed from a file; the correctness of a classification, the adequacy of an assessment and the observance of a protocol cannot. Organisational research has documented what firms do with that asymmetry for fifty years, and interview evidence from Islamic banks operating a second institutional oversight layer shows the pattern where it could be observed directly, though in another jurisdiction.

The finding generalises past this jurisdiction, and it does so in a direction that is uncomfortable for the regime usually treated as the benchmark. If decoupling arises from the character of a documentary record rather than from the identity of whoever reads it, moving the reader does not repair it. Qatar and the European Union sit at opposite ends of the axis of who must be satisfied before a high-risk system is deployed, a public supervisor at one end and, under Annex VI, the provider's own internal control at the other. What the analysis here says is that the Qatari end buys three real things, an entity that can be inspected and sanctioned, sight of the system before it operates, and reach into procurement, and that it does not buy verification of what the file asserts. The European end forgoes the first three and inherits the fourth unchanged, because a conformity assessment conducted by the provider produces the same class of record and is read by the party with the strongest interest in its conclusion. That comparison should be stated as a hypothesis about a design axis rather than as a verdict on either instrument, and the European regime carries compensating machinery the Qatari one lacks, in post-market monitoring, market surveillance and a public database of registered systems, all of which operate after deployment where the evidence of performance actually exists. The general lesson runs against the framing of the debate rather than against either party to it. The question worth asking of an ex ante regime is not who signs off, which is what the comparative literature has mostly examined, but whether the record the regime creates contains anything that could turn out to be false. On that test the two regimes fail in the same place, and so would a third built anywhere else on the same documentary logic.

The four design conditions set out here separate a pre-deployment regime that produces supervisory information from one that produces supervisory reassurance, and none requires new legal powers in Qatar's case. The form also has limits that are not about design at all: it depends on a supervisor able to examine what it authorises. The Guideline's effect on the customers it names remains unknown, and the current design does not require the generation of the evidence that would make it knowable.


Declarations

Dedication. I dedicate this research to the pure soul of my late father, His Highness the Father Amir Sheikh Hamad bin Khalifa Al Thani. May his soul find eternal rest, mercy, and serenity in Paradise.

Funding. This research received no external funding.

Conflicts of interest. The authors declare no conflicts of interest.

Ethics. This study involved no human participants and no personal data. It analyses publicly available regulatory instruments, official publications and published scholarly literature, and therefore did not require ethical approval.

Data availability. No dataset was constructed and no statistical analysis was performed. All regulatory instruments, official publications and scholarly sources examined are cited in the reference list and are publicly available from the issuing bodies and publishers. One source check reported in Section 1.2 and specified in Appendix E scanned publicly indexed reporting by the eight Qatari-owned banks named there; that material is publicly available through the institutions' own investor relations pages and returned no qualifying disclosure, so no corpus was assembled or retained.


References

 

Appendices (available in the pdf file)

Appendix A. Search and Discovery Record

Appendix B. Reference Verification Record

Appendix C. The Guideline Mapped onto the Framework

Appendix D. Hypotheses and How They Could Be Tested

Appendix E. Note on Primary Source Access

 

Hashtags:

Comments


Declaration on the Use of Artificial Intelligence
Artificial intelligence–assisted tools were utilized solely to support language refinement and editorial improvement. All conceptual development, theoretical framing, analytical interpretation, and final editorial decisions were undertaken independently by the authors. The authors assume full responsibility for the content and integrity of the manuscript.

Data Availability Statement
This study is based on a review and conceptual analysis of existing literature. No new datasets were generated or analyzed during the course of this research. Consequently, data sharing is not applicable to this article.

Conflict of Interest Statement
The authors declare that they have no known competing financial interests or personal relationships that could have influenced, or appeared to influence, the work reported in this paper.

Funding Statement
This research did not receive any specific grant from funding agencies in the public, commercial, or not-for-profit sectors.

​​

Ethics Approval
This study did not involve human participants, animal subjects, or identifiable personal data. Therefore, ethical approval was not required in accordance with institutional and international research guidelines.

This article is licensed under  CC BY 4.0

61e24181-42b7-4628-90bc-e271007e454d.jpeg
feb06611-ad56-49a5-970f-5109b1605966.jpeg

Open Access License Statement

© The Author(s). Published by U7Y Journal under CC BY 4.0.

How to Cite and Reference U7Y Journal Articles

To ensure consistency and proper academic recognition, all articles published in the U7Y Journal – The Seven Continents Yearbook of Research should be cited following internationally recognized bibliographic standards. The journal supports multiple citation styles to accommodate diverse academic disciplines and indexing systems.
Here are standard reference formats for citing articles published in the U7Y Journal – The Seven Continents Yearbook of Research (ISSN 3042-4399). Authors, readers, and indexing services may use any of the following styles according to their institutional or publisher requirements.
bottom of page