AI’s cloud challenge

The region’s AI ambitions face a security reality check, according to Dario Perfettibile, VP, Kiteworks.

As the UAE pours billions into becoming a top 10 AI nation by 2031 and Saudi Arabia anchors its Vision 2030 on artificial intelligence, a dangerous gap has emerged. The region’s organisations have achieved an impressive 85% AI adoption rate, according to new research from Wiz. But here’s the catch: 86% of these same organisations can’t see where their data goes once it enters AI systems.

The race to lead in AI has created a paradox: the faster organisations deploy AI, the larger their security blind spots become. In a region where business runs on relationships and trust, these vulnerabilities threaten the entire digital transformation agenda.

Racing towards an AI future

The Middle East’s AI adoption isn’t following the typical technology curve. Where cloud computing took years to gain trust, AI went from experiment to essential in just 18 months. Saudi Arabia’s NEOM project integrates AI into its foundational infrastructure. Qatar’s financial sector uses AI for everything from fraud detection to customer service. Kuwait and Bahrain have launched national AI strategies that touch every sector from healthcare to logistics.

The numbers tell the acceleration story. Self-hosted AI adoption in the region jumped from 42% to 75% in a single year. Organisations aren’t just using pre-built AI services — they’re running sophisticated models within their own cloud environments. Meanwhile, 67% of regional cloud environments now use OpenAI or Azure OpenAI SDKs, up from 53% last year.

Competition demands innovation. Digital transformation initiatives that once focused on moving to the cloud now centre entirely on AI capabilities.

But speed has a price. A Kiteworks report reveals that only 17% of organisations can automatically prevent confidential data from flowing into AI systems. The other 83% rely on employee training, warning messages – or nothing at all. When humans are the only barrier between sensitive data and AI platforms, breaches become inevitable.

DeepSeek incident: a regional wake-up call

January 2025 should have been a celebration for DeepSeek adopters. Usage of the AI platform more than doubled across Middle Eastern organisations, with companies integrating it into everything from customer service to data analysis. Then Wiz researchers made a discovery that changed everything.

DeepSeek’s infrastructure leaked over one million lines of log streams containing confidential information from organisations worldwide. The exposed database didn’t just reveal usage patterns — it provided complete database control access to potential attackers. Any organisation that had connected DeepSeek to their systems had potentially exposed sensitive data.

Think about what this means practically. A government agency in Riyadh using DeepSeek for citizen services. A Kuwaiti bank analysing transaction patterns. A healthcare provider in Abu Dhabi processing patient records. All of them potentially exposed through a single vulnerability in a platform they trusted.

The timing makes it worse. Organisations were rapidly onboarding DeepSeek precisely when it had fundamental security flaws. They were essentially inviting a compromised system into their most sensitive operations. And because most organisations can’t track their AI data flows, many still don’t know what they exposed.

This isn’t a story about one bad platform. It’s a preview of what happens when AI adoption outpaces security implementation. Today it’s DeepSeek. Tomorrow it could be any of the dozens of AI platforms that regional organisations are rushing to adopt.

Understanding where security breaks

Traditional security tools excel at monitoring networks, tracking file access, and watching application behaviour. But AI operates differently. When an employee copies a financial report into ChatGPT to summarise it, no file transfer occurs. When a developer pastes code into an AI assistant, no network anomaly appears. The most sensitive data movements have become invisible.

The problem compounds through what researchers call “permission cascade”. Here’s how it typically unfolds: An employee in a Dubai financial firm connects an AI tool to their Google Workspace account. The AI needs broad permissions to function effectively, so the employee grants access to their drives, calendars and emails. But corporate Google accounts include access to shared drives, archived projects, and organisational resources that the employee rarely touches.

Suddenly, an AI platform has access to years of accumulated corporate data. Market research. Strategic plans. Customer databases. The permissions persist even after the employee stops using the AI tool. Multiply this by hundreds of employees across an organisation, and the exposure becomes staggering.

Infrastructure vulnerabilities add another layer of risk. The CVE-2024-0132 vulnerability affected NVIDIA GPU containers across 35% of cloud environments. For a region betting heavily on AI infrastructure, this means a single vulnerability can compromise a significant portion of national AI capabilities. GPU-based processing isn’t optional for serious AI workloads — it’s essential. When the foundation cracks, everything built on top becomes unstable.

Counting costs beyond the breach

The immediate financial impact is sobering. AI-related breaches cost 28% more than conventional incidents, according to industry analysis. But the true cost for Middle Eastern organisations extends far beyond immediate damages.

Consider competitive intelligence risks. When a Saudi petrochemical company’s proprietary process data gets analysed by a shared AI model, that information doesn’t disappear. It potentially influences the model’s training, making traces of that intelligence available to competitors using the same platform. In industries where competitive advantage depends on closely guarded expertise, this invisible leakage can destroy market positions.

A recent report by Varonis found over 225,000 compromised AI credentials available on dark web marketplaces. For a region where business relationships build on decades of trust, a single leaked credential can unravel partnerships, damage reputations and close doors that took years to open.

Then there’s the compliance time bomb. US agencies issued 59 new AI regulations in 2024. The EU AI Act adds another layer of requirements. Middle Eastern organisations with international operations face a maze of overlapping regulations. AI systems deployed hastily last year must now meet standards that didn’t exist when they were implemented. The resulting compliance debt threatens to derail digital transformation initiatives before they deliver value.

Regional talent sees these vulnerabilities too. The best AI engineers and data scientists want to work for organisations that take security seriously. When breaches make headlines, recruitment becomes harder – and retention becomes expensive.

Solutions that actually work

Forward-thinking organisations across the region are proving that secure AI deployment is possible without sacrificing innovation. Their approaches share common elements that any organization can implement.

Zero-trust AI architectures lead the way. A major UAE bank routes all AI interactions through controlled gateways in their cloud infrastructure. Employees get the productivity benefits of AI tools, but data never leaves the bank’s security perimeter. Every query is logged, monitored and analyzed for potential exposure.

Integration beats isolation. Rather than treating AI security as a new challenge requiring new tools, successful organisations incorporate AI controls into existing security frameworks. They extend their cloud access policies to cover AI platforms, include AI data flows in their compliance monitoring, and train their incident response teams on AI-specific threats.

Automation scales where human oversight fails. With AI adoption at 85% and growing, manual reviews and approval processes can’t keep pace. Leading organisations implement automated controls that detect new AI integrations, assess permission requests in real-time and flag suspicious data movements before they become breaches.

Looking ahead

Middle Eastern organisations don’t need to choose between innovation and security. The same engineering excellence that builds skyscrapers in the desert and creates cities from sand can build AI systems that are both powerful and protected. The question isn’t whether AI will transform business in the region — that’s already happening. The question is whether organisations will take control of that transformation or let it control them.

Smart organisations are doing three things. They’re mapping every AI tool their employees use, implementing automated AI data gateways to control on data flows, and treating AI security as part of their existing cloud infrastructure rather than a separate problem. These aren’t complex solutions. They’re practical steps that recognise a simple truth: in the race to AI leadership, the winners won’t be those who move fastest, but those who move wisely.

The opportunity remains enormous. The Middle East stands poised to demonstrate that rapid AI adoption and robust security aren’t opposing forces — they’re complementary requirements for sustainable success. In a region that has always understood the value of strong foundations, it’s time to apply that wisdom to our digital future.

Tags:
, ,
No Comments

Sorry, the comment form is closed at this time.

1