Introduction Artificial intelligence (AI) has become an integral force in the evolution of cybersecurity. Governments, corporations and critical infrastructure sectors across the Gulf states have adopted AI-enabled technologies to detect cyber threats through anomaly detection, automated responses and the rapid processing of data volumes beyond human analytical capacity. Gulf countries are shifting from reactive cybersecurity models toward more adaptive and predictive approaches, recognising that malicious actors are increasingly employing sophisticated tools for intrusion, deception, reconnaissance, social engineering, cybercrime and information manipulation. Qatar, Saudi Arabia, the United Arab Emirates, Kuwait, Bahrain and Oman have accelerated their digital transformation agendas over the past decade through national visions centred on smart city projects, fintech ecosystems, cloud platforms and e-government services. (1) Within these strategies, AI has emerged as a key driver of modernisation due to the efficiency and productivity gains it is expected to generate for Gulf economies. (2) However, the growing integration of digital platforms, automated systems and digitally managed critical services has also introduced new vulnerabilities, increasing the potential for large-scale cyber disruption. Recent industry assessments indicate that cyberattacks across the Gulf countries have risen significantly in recent years. According to Cybersecurity Ventures, the projected global cost of cybercrime reached $8 trillion in 2023 and is expected to climb to $10.5 trillion annually by 2025. (3) This demonstrates that cybersecurity is no longer merely a technical issue, but also an economic and strategic concern with direct implications for resilience, investor confidence, public trust and national stability. In my research on cybersecurity developments in the Gulf, I observed that technological advancements and the adoption of cybersecurity applications have progressed more rapidly than institutional cyber governance frameworks. This gap matters because, while AI can significantly strengthen cyber defence capabilities, its effective deployment requires robust governance frameworks, clearly defined institutional responsibilities and sustained workforce