The procurement of AI infrastructure by a governmental body is generally a different process than that of a private firm. In this case, the government does not simply procure computing power, data storage, and connectivity but decides where citizen data resides, who has access to it, and what the country’s dependencies will be once the provider has won the procurement. The reasons why stakes like citizen data, national security, and dependencies make the question about whether to choose sovereign cloud or a foreign cloud service provider one of the central questions of this piece.
The UAE has been one step ahead of other governments in the region in doing so – the UAE has its own compute capacity, national network connections, and one of the more advanced governance structures for artificial intelligence in the Gulf. What follows looks at how that approach actually works in practice, from the sovereign-versus-public-cloud tradeoff to the physical constraints, GPU access, and network capacity among them that shape what any government buyer can realistically procure, inside the UAE or elsewhere in the GCC.
What is the UAE government’s approach to AI?
The United Arab Emirates is the first country in the world to establish a Minister of State for Artificial Intelligence by naming Omar Sultan Al Olama in 2017. In addition, the government established the UAE Strategy for Artificial Intelligence, with the aim of making Artificial Intelligence one of the strategic priorities of the government services, economy, and infrastructure. This has developed into the wider framework of the National Artificial Intelligence Strategy 2031, which outlines how the country will govern and develop its economy.
That strategy has translated into operational systems rather than staying at the policy level. The UAE Ministry of Justice, for example, runs its Virtual Legal Advisor, also referred to as the Virtual Legal Consultant, directly inside its public services, using natural language processing to answer legal queries against federal law databases. A tool like this runs on infrastructure that had to be procured, secured, and governed before it went live, not just written into a policy document.
However, the more general trend within UAE federal bodies relates to digital transformation being treated as an integral part of government infrastructure. Such an approach is significant for procurement processes since it takes the issue of infrastructure involving artificial intelligence out of the scope of ordinary IT budgeting to the scope of strategic planning, reviewed at a senior-level position with the consideration of data governance and national resilience alongside cost and performance.
Sovereign cloud vs. public cloud: the procurement decision
Many government AI deployments in the region face a version of the same choice at some point: use public cloud infrastructure from an international provider, or build and use sovereign cloud infrastructure that stays within the country and under national jurisdiction.
Public cloud from providers like AWS, Microsoft Azure, or Google Cloud offers speed and elasticity, and a government entity can provision compute quickly without building physical infrastructure. The main providers are now operating data centers within the UAE borders, and data residency is an option available to them. This significantly reduces the sovereignty problem as compared to what it was just a few years ago. The only thing that will remain with the international company will be the corporate ownership behind the infrastructure and jurisdiction, and this is what brings up problems to any organization dealing with citizens’ data or national security data.
The UAE has made a deliberate choice to build sovereign infrastructure alongside its public cloud relationships rather than defaulting to one or the other. Core42, operating under the G42 Group, is built around the Condor Galaxy supercomputer, developed with Cerebras Systems on Cerebras’ wafer-scale CS chips rather than conventional GPUs, and physically hosted in Santa Clara, California and other US data centers, not inside the UAE. That location matters for a government buyer: a workload sent to Condor Galaxy generally travels to US-based infrastructure, though the specifics depend on how a given engagement is set up. For entities that need strict in-country data residency, the more relevant option is Core42/G42’s own sovereign data centers located within the UAE, or Microsoft Azure’s UAE regions, rather than Condor Galaxy itself.
Microsoft’s relationship with G42, which began with a 1.5 billion US dollar investment announced in 2024, opened the door to this kind of hybrid layer, but the clearer example of what it looks like in practice came later. In March 2025, Abu Dhabi’s Department of Government Enablement announced that the Abu Dhabi Government, Microsoft, and Core42 had signed an agreement to roll out a Sovereign Public Cloud powered by Azure, giving government entities Azure-based services with sovereign controls built in, as part of Abu Dhabi’s push to automate its government processes. A sovereign infrastructure for highly sensitive data workloads, combined with a data-resident hybrid approach to all other data, is the way forward suggested by this sort of agreement in the region.
Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) would be one component of the legislative landscape pertinent to the discussion, but it needs to be emphasized clearly that this is a personal data protection law on data processing, data subject rights, and data transfer rules, not any sort of absolute mandate of national sovereignty or in-country data residency in and of itself. However, Article 2 of the PDPL excludes government data, public bodies, health data, credit data, and free zone data with their own data protection laws. A federal or local government body procuring AI infrastructure is therefore governed by a separate track, chiefly the UAE Information Assurance Regulation overseen by the Signals Intelligence Agency for federal and critical-infrastructure entities, with the Dubai Electronic Security Center’s own Information Security Regulation covering Dubai government bodies specifically.
Data sovereignty in an AI context is a broader question than either regime answers on its own. A government buyer weighing sovereign versus public cloud is really asking a longer set of questions: who trains the models running on this infrastructure, who has the ability to audit them, what happens when the system makes a mistake, and can the entity move its data and workloads to a different provider without losing access or incurring prohibitive cost. That last point, data portability, is worth treating as a practical test of genuine sovereignty rather than an established procurement standard: an entity that cannot leave a provider without losing its own data has less real control than the location of the servers alone would suggest.
GPU capacity and connectivity: the physical requirements behind the strategy
Behind every AI strategy document is a physical constraint: AI models, particularly the large language models increasingly used in government services, need specialised hardware to train and run. GPUs, or graphics processing units, are that hardware, and high-end supply is tight globally. Paul Dawalibi, CEO of Innovation City, in comments to Data Center Magazine, has described Nvidia’s B200 GPUs as sold out worldwide with waitlists stretching into 2027, calling compute access an existential bottleneck for AI builders today. That kind of scarcity means capital and tax incentives alone no longer decide who gets to build an AI hub; hardware access matters just as much, and governments that treat compute capacity as strategic infrastructure, comparable to energy or telecommunications rather than a routine IT purchase, are better placed to secure it.
The UAE’s response to this scarcity operates at more than one scale. At the immediate level, Core42 operates the Condor Galaxy supercomputer, built on Cerebras’ wafer-scale chip systems rather than GPUs, which gives it a form of compute capacity that does not compete for the same GPU supply chain everyone else is chasing. Since that hardware sits in US data centers rather than inside the UAE, it addresses compute scarcity rather than data residency; entities that need in-country processing still route those specific workloads to Core42’s local UAE facilities or Azure’s UAE regions instead. At a much larger scale, the country is also building toward the Abu Dhabi and US agreement for an AI campus planned at 5 gigawatts, with Stargate UAE, a 1 gigawatt cluster built by G42 with OpenAI, as its first phase, a bet that enough capacity solves the scarcity problem rather than just managing around it.
Newer sovereign facilities built from scratch in the region take a different approach again. Innovation City, for instance, describes its Siada data centre as built for single-jurisdiction control and hardware-isolated tenancy, with workloads processed under UAE jurisdiction from day one, the kind of advantage a purpose-built sovereign facility has over older infrastructure adapted after the fact.
Power is the third constraint that gets less attention than GPUs or bandwidth but matters just as much. High-density AI racks draw far more electricity per square metre than conventional IT equipment, and securing enough substation capacity and grid allocation for a facility of real scale is often a longer lead-time item in the Gulf than the compute contract or the building itself. A procurement that locks in GPU access and network capacity but has not confirmed power availability at the specific site has secured the easier two-thirds of the problem, not the whole thing.
Compute is only half of the physical picture. AI services depend on fast, reliable connectivity to move data between storage, compute clusters, and the end users or government systems consuming the output. The UAE has built out substantial 5G and fixed-line network infrastructure under TDRA’s regulatory oversight, and that groundwork, built for digital government generally rather than AI specifically, is part of what large-scale AI deployment now runs on. This is not a background utility sitting off to the side of the AI conversation. Connectivity quality is one of the factors that shapes how well an AI service performs in practice, particularly for real-time applications like the legal chatbots and diagnostic tools UAE entities are already running.
For a government buyer, this means GPU capacity, connectivity, and power all have to be evaluated together rather than as separate line items. A provider with strong compute but weak regional connectivity, or plenty of both but no confirmed power allocation at the site, creates a bottleneck somewhere in the pipeline regardless of how the contract is structured.
What should government buyers evaluate before selecting an AI infrastructure provider?
One useful assessment framework for structuring this evaluation comes from a 2026 working paper on UAE AI infrastructure readiness by Ahmed Mubarak Al Mansoori, Director of AI & Telecom Business Development at Core42, G42 Group. Its four-layer model works well as a procurement checklist regardless of the specific government context it was written for.
Talent and leadership. This is less about the provider’s own staff and more about whether the government entity itself has people who understand what the AI system can and cannot do, and leadership that will support the training and change management the rollout needs. A provider that offers onboarding support and staff training as part of the engagement, rather than assuming the buyer’s team is already fluent, closes a gap the working paper flags as a common reason government AI projects stall.
Cloud and compute infrastructure. Genuine GPU availability, a sovereign or data-resident option for sensitive workloads, and a connectivity backbone strong enough to support the intended use case. This is the layer covered above, and it is worth verifying with specifics rather than taking on marketing claims alone.
Data and sovereignty. Buyers should ask where data is stored, who can access it and under what legal framework, whether the provider supports data classification and cross-entity sharing standards, and critically, whether data can be moved to another provider without loss or excessive cost if the relationship ends. Vendor lock-in disguised as sovereignty is a real risk in this market, and data portability terms are worth scrutinising in the contract itself, not only in the sales conversation.
Governance and policy. Whether the provider supports the impact assessments, explainability requirements, and audit trails that government AI use increasingly calls for, even ahead of formal regulation catching up. A provider that can point to a named point of contact for AI accountability, and a process for testing systems before deployment, is operating at a level of maturity the market has not fully standardised yet.
Running a structured assessment against these four layers before selecting a provider, rather than relying on a procurement scorecard built for conventional IT purchases, tends to surface gaps that only become visible once a project is already underway.
AI Infrastructure Readiness in UAE Government, unpublished corporate working paper (not peer-reviewed), Core42 / G42 Group, April 2026.
Should Middle East governments build their own data centers or use cloud services?
There is no single correct answer to this question, and governments across the Middle East are taking genuinely different paths depending on their starting point, budget structure, and risk tolerance.
A handful of factors tend to drive the decision in practice. Data residency and sovereignty are a live consideration for entities handling citizen data, health records, or financial systems, and that alone can push the decision toward owned or dedicated infrastructure over shared public cloud. GPU availability is another factor: governments that secure dedicated compute capacity, whether through owned infrastructure or a long-term sovereign cloud agreement, avoid competing for scarce GPU allocation on the open market during periods of high demand. Capital versus operational expenditure profiles matter too, since building owned infrastructure requires significant upfront capital that not every entity has budget flexibility for, while cloud services convert that into an ongoing operating cost. Speed to deployment is a further consideration, and this is where modular and phased construction approaches have changed the calculus for some entities, since a modular build can generally reduce deployment timelines compared with a traditional hyperscale facility, without requiring the entity to commit to public cloud dependency in the meantime.
In practice, a hybrid approach lets government entities match different infrastructure models to different workloads instead of defaulting to one path across the board. The UAE illustrates this well, though it is not one standardised architecture: different entities and emirates run sovereign infrastructure, public cloud, and dedicated facilities side by side, generally pairing tighter controls for the most sensitive workloads with more elastic public cloud arrangements for everything else.
FAQs
Does regulation slow down AI infrastructure deployment?
Not necessarily. Data Center Magazine‘s reporting on the region’s sovereign AI build-out makes the case that uncertainty, rather than regulation itself, is what actually slows innovation down, and that businesses adapt readily once rules are clear. The countries pulling ahead on AI infrastructure are the ones regulating with greater clarity, not regulating less, and treating compute capacity as strategic national infrastructure rather than a routine procurement category.
What is the difference between AI adoption and AI ownership?
AI adoption is the fast deployment of existing AI tools and platforms to cut costs or improve efficiency, while AI ownership goes further and means controlling the full value chain behind those tools: where the underlying data is stored, who has access to it, and who ultimately benefits from the insights the AI system generates. He calls the difference return on intelligence, a measure of who ultimately owns the value AI creates rather than efficiency gains alone. It is a useful lens for a government buyer to weigh alongside the sovereignty questions covered in Khaleej Times.
How do connectivity and network infrastructure factor into AI procurement decisions?
Connectivity is a core input to AI infrastructure procurement, not a background utility. AI services depend on fast, low-latency networks to move data between storage, compute clusters, and end users, and the UAE’s build-out of digital infrastructure under TDRA’s regulatory oversight is part of the groundwork that makes large-scale AI deployment feasible in the country, even though that build-out was for digital government generally rather than AI specifically. The scale the UAE is now attracting, as Tech Policy Press has documented, shows up in projects like the Abu Dhabi and US agreement for an AI campus planned at 5 gigawatts, with Stargate UAE, a 1 gigawatt cluster built by G42 with OpenAI, as its first phase.
What makes a sustainable data center for government AI deployments?
According to Crowe UAE‘s analysis of AI’s role in sustainability and ESG, three practices show up consistently in sustainable AI infrastructure design. The three key practices are as follows: liquid cooling for efficient thermal management of high-density racks; renewable energy generation for powering the facilities; and smaller and more efficient AI models that can offer performance comparable to large AI models while using less energy. The principle here is to reduce unnecessary processing capacity as compared to maximizing computational capacity, so that the infrastructure for AI helps instead of hindering the ESG commitment of an organization.
What kind of cooling does an AI data center need to handle the UAE climate?
The need for liquid cooling comes primarily from rack density and heat load, not from the UAE’s climate as such. High-density AI racks, especially for training and inference at scale, generate more heat per square meter than air handling can efficiently remove once density climbs high enough, and that is true in any climate. What the UAE’s heat adds on top is a harder ambient design problem: summer temperatures that regularly climb into the mid-40s Celsius reduce how much cooling a facility can draw from outside air, narrowing the margin available to whatever system, air or liquid, is handling the load. Liquid cooling, which removes heat directly at the chip rather than relying on room-level air handling, is increasingly used for the highest-density AI workloads. Equipment rated for genuine high-ambient conditions, rather than the standard test conditions used in cooler markets, and a water strategy that accounts for the UAE’s water scarcity are the other two variables that most affect whether an AI facility performs as designed once summer temperatures peak.