Gulf AI training needs a workplace test
Saudi and Dubai programmes show different training ambitions. Employers still need evidence that staff can use AI safely in their own workflows.

A training certificate tells an employer that someone completed a course. It does not, by itself, show whether that person will challenge a convincing but unsupported AI answer before sending it to a customer.
That distinction is the useful part of an October 5 interview with Cybergate CISO Srdjan Babic. He argues that Gulf organisations are buying AI capabilities faster than they can govern them, and criticises the assumption that course completion establishes workplace competence. These are a security supplier's observations, not a representative measurement of the GCC workforce.
For employers, the response should be specific: keep introductory training, but add an observed assessment of the work people will actually perform. Test whether staff can verify an output, protect information and stop a task that exceeds its approved purpose. A polished prompt is not the only skill worth measuring.
Cover: original SultanByte artwork showing the progression from course completion to an observed workplace assessment.
Saudi reach and Dubai role design answer different questions
Saudi Arabia's Ministry of Education reported in November 2025 that the Samai initiative had trained and certified more than one million citizens in AI. The programme involved the ministry, the Ministry of Human Resources and Social Development, and SDAIA. This is a reported participation achievement from 2025, not a newly achieved October 2026 milestone or proof of proficiency in a particular employer's systems.
Dubai's AI Workforce Transformation Program, AI+, announced on April 15, 2026, targets 50,000 Dubai Government employees. Its design separates leadership, Chief AI Officers, product and service owners, managers, and employees. The product-owner track explicitly includes impact measurement; the employee track includes practical tools and task automation. The announcement states a training target, not a verified completion total.
The two figures should not become a country ranking. Samai describes a national citizen programme; AI+ addresses a city government's workforce. Their populations, purposes and reporting states differ. Dubai's programme also cannot stand in for all UAE employers.
What an employer can borrow is the distinction between broad access and role-specific capability. National literacy programmes provide a starting point. The organisation still needs to establish what a person may do with its customer records, operational tools and decision processes.
Assess a task before buying another course
Choose one routine workflow, such as preparing a customer-response draft from an approved policy. Specify the allowed tool, permitted information and person accountable for the final response. Use synthetic records in the assessment rather than copying live customer material into a training environment.
The UK government's employer guide to AI upskilling, updated in July, provides a useful external reference. Its PRIMES framework recommends practical, accessible learning connected to real work, with opportunities for review as tools change. It draws on UK research; it is neither evidence of Gulf training outcomes nor a regional legal requirement.
Translate that guidance into a proposed assessment with a clear expected result. Give the learner the source policy, a customer request and an AI-generated draft containing one consequential error. Observe whether they find the error and correct it from the source. Then introduce a request outside the approved task and check whether they escalate instead of quietly broadening the tool's use.
For a bilingual service, run comparable Arabic and English cases. Have a competent reviewer check that both versions test the same policy and difficulty. Otherwise, a language or translation mismatch can be mistaken for a difference in AI competence.
Make the failure cases part of the exercise
A useful assessment includes a plausible answer that should not be accepted. A fabricated policy exception is more revealing than an obvious spelling mistake. Ask the learner to identify the supporting passage, explain what remains uncertain and decide whether the response is ready to send.
Also test the information boundary. Present a task that appears easier if the employee uploads a complete customer file to an unapproved tool. A passing response should follow the organisation's approved route, even when that means declining the shortcut. If staff cannot identify an approved alternative, the organisation has a process problem as well as a training need.
External documents deserve a separate exercise. OWASP's prompt-injection guidance explains how instructions in files or websites can influence a model's behaviour. Use a controlled example in which a supplied document tells the assistant to ignore the original task. Assess the employee's response to the suspicious output, but do not pretend human vigilance is a complete defence. OWASP also recommends controls such as least privilege and approval for high-risk actions. Application owners must implement those protections.
Original infographic: SultanByte. Proposed assessment framework informed by the UK employer guide, NIST AI RMF Playbook and OWASP guidance, reviewed October 2026. It describes a process, not measured training outcomes.
Keep evidence that explains the result
The NIST AI RMF Playbook's Govern function connects AI responsibilities with staff training, oversight and ongoing review. It is a voluntary risk-management reference, not a certification of either regional programme.
For this proposed assessment, retain the task version, tool configuration, expected response, observed result and reviewer's decision. Record why someone needed help. Was the problem source checking, unclear instructions, unfamiliar Arabic terminology or an unavailable escalation route? Those failures call for different remedies.
Keep access to assessment records proportionate. A manager needs enough evidence to assign work and support learning; that does not require putting unrestricted customer data or every employee prompt in a shared dashboard.
Separate completion, demonstrated performance and business outcomes in management reporting. Completion measures participation. The assessment measures performance on specified cases. Business outcomes need observation in the actual workflow, including review time and rework, rather than an assumption that a faster first draft saved time overall.
Make reassessment a condition of expanded use
An employee assessed on drafting an internal summary has not thereby demonstrated readiness to screen applicants or approve a payment. Those tasks need their own owners, boundaries and review criteria.
Treat a material change in the tool, data access or approved purpose as a reason to revisit the assessment. Give staff protected time to practise and a clear route to report confusing or unsafe behaviour. A test that exposes a broken process should lead to a process repair, not automatic blame for the learner.
The next training purchase should therefore include the assessment design and follow-up work, not just course seats. Start with one workflow, observe how staff handle its exceptions, and retain the reviewed evidence. Expand access when the organisation can explain what people have demonstrated and what remains outside their remit.




