Any ERPRegionMiddle East

Gulf defence + sovereign AI

AI for ERP in the UAE and Saudi Arabia: Sovereign, On-Prem Design for Defence Manufacturing

Short answer

UAE and Saudi defence and aerospace manufacturers running SAP, Oracle Fusion Cloud ERP, IFS Cloud, or Infor LN can add AI to their ERP through a sovereign, in-country deployment rather than a public cloud API, keeping data inside UAE PDPL or Saudi PDPL boundaries and within reach of NCA Essential Cybersecurity Controls. The design also has to speak to GAMI localisation evidence requirements, which is a documentation problem an AI layer can genuinely help with.

ERP
SAP S/4HANA, Oracle Fusion Cloud ERP, IFS Cloud, Infor LN
Industries
Defense, Aerospace, Electronics
Written for
CIO

Both the UAE and Saudi Arabia have spent the past several years building a domestic defence and aerospace manufacturing base as part of broader economic diversification programmes, and the supplier ecosystem around that push has grown quickly. Many of these suppliers are running modern ERPs, SAP S/4HANA, Oracle Fusion Cloud ERP, IFS Cloud, Infor LN, but their AI options have lagged their ERP maturity, largely because the compliance bar for anything touching defence-adjacent data is higher here than for a typical mid-market manufacturer.

In Saudi Arabia, GAMI, the General Authority for Military Industries, sets local content and technology transfer expectations that suppliers need to evidence, and that evidence today is largely compiled by hand from procurement, BOM, and vendor master data already sitting in the ERP. NCA's Essential Cybersecurity Controls add a further layer of technical and governance requirements for critical infrastructure and government-adjacent systems, requirements that most off-the-shelf SaaS AI copilots simply cannot demonstrate compliance against.

In the UAE, the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data sets the baseline privacy regime, and Saudi Arabia's own PDPL, enforced by SDAIA, does the same for Saudi operations. Both regimes push toward in-country data handling for anything sensitive, which rules out routing ERP queries through a public LLM API hosted outside the Kingdom or the Emirates, regardless of how convenient that API might otherwise be.

For a CIO in this position, the practical starting point is the same one that works elsewhere: a bilingual, Arabic and English, natural-language query layer over the ERP, deployed on infrastructure that never leaves the country, answering the questions planners, buyers, and quality engineers already ask every day, before extending into the GAMI evidence and export tracking use cases that carry more compliance weight.

What usually gets in the way

The problems we hear most from cio teams running SAP S/4HANA.

GAMI local content evidence is compiled by hand

Demonstrating local content percentages and technology transfer progress against GAMI requirements today means pulling procurement, BOM origin, and vendor data into spreadsheets manually, on a cycle that rarely matches how fast the underlying ERP data actually changes.

Public cloud AI routes through infrastructure outside the country

Most SaaS AI products, including many marketed as enterprise-ready, process data on infrastructure outside the UAE or the Kingdom, which is a non-starter for classified or sensitive defence-adjacent work regardless of contractual assurances.

NCA ECC controls are hard to evidence with off-the-shelf AI

Essential Cybersecurity Controls require specific technical and governance evidence, access logging, data classification, incident response integration, that most consumer-grade or lightly adapted enterprise AI tools were never built to produce.

Arabic and English data live side by side, most tools handle only one

ERP master data, documentation, and day-to-day queries mix Arabic and English, and a copilot built and tested primarily in English produces noticeably weaker results on the Arabic half of the business.

Local AI and ERP skills are both in short supply

The talent pool that understands both the ERP platform and modern AI deployment is thin locally, so an engagement that does not deliberately transfer capability leaves the customer dependent on the vendor indefinitely.

Where AI earns its place in SAP S/4HANA

Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.

GAMI local content and evidence assistant

Aggregates procurement, BOM origin, and vendor master data into a continuously updated local content and technology transfer evidence base.

Touches: Vendor master, purchase order lines, BOM origin fields, technology transfer milestone tracking

Outcome: turns an annual scramble to compile evidence into a query the procurement or compliance team can run at any time

Bilingual natural-language query over ERP

Planners and buyers ask questions in Arabic or English and get answers grounded in live SAP, Oracle Fusion, IFS, or LN data.

Touches: Sales order headers and lines, inventory balances, MRP action messages

Outcome: closes the gap between Arabic-speaking shop floor and procurement staff and an ERP interface that often defaults to English

MRP and PO exception triage

Groups and prioritises reschedule, expedite, and cancel messages for planner review.

Touches: MRP action messages, purchase order lines, supplier confirmations

Outcome: cuts routine exception triage time for the majority of low-risk lines, freeing planners for the exceptions that need judgement

Export licence and end-use tracking assistant

Flags a sales order or shipment against outstanding export licence or end-user certificate requirements before release.

Touches: Customer master, sales order headers, export licence and end-use certificate fields

Outcome: catches a missing or expired licence reference before the shipment releases rather than after

Quality NCR and CAPA drafting

Drafts a first-pass root cause and containment narrative from a quality notification, formatted for AS9100.

Touches: Quality notifications, NCR records, 8D worksheets

Outcome: gives quality engineers a reviewable draft in minutes rather than a blank template

Maintenance and EAM work order triage

Prioritises open maintenance work orders and drafts a summary for the maintenance planning meeting.

Touches: IFS Cloud maintenance projections, work order records, equipment master

Outcome: gives the maintenance planner a grounded starting point instead of reviewing every open work order manually

RFQ-to-quote drafting from historical costs

Pulls comparable historical job costs and routing data to give estimators a grounded starting draft for a new quote.

Touches: Job costing history, routing data, quote header and line records

Outcome: shortens the time from RFQ receipt to a defensible first quote draft

Reference architecture

The architecture is built for in-country, sovereign operation from the start, with bilingual Arabic and English support and classification tagging that mirrors the customer's own security controls.

  1. 1

    ERP connectors

    Read-only connectors into SAP (OData/BAPI), Oracle Fusion Cloud ERP (REST APIs, Oracle Integration Cloud), IFS Cloud (projections, Aurena), and Infor LN (BODs, ION).

  2. 2

    Data and semantic layer

    A permissioned index with Arabic-aware tokenisation and right-to-left rendering, tagged for GAMI evidence relevance and export licence status alongside standard role-based access.

  3. 3

    Model serving

    Open-weight models served on infrastructure physically located inside the UAE or the Kingdom, sized to the deployment's actual query volume.

  4. 4

    Retrieval and agents

    Bilingual retrieval-augmented generation grounded in connected ERP data, with any write-back action gated behind explicit human approval.

  5. 5

    Governance and audit

    Access and query logging structured to produce NCA ECC evidence artefacts directly, rather than requiring a separate compliance reporting exercise.

Integration notes for your ERP team

  • SAP connections use OData services and BAPI/RFC calls scoped to read-only roles.
  • Oracle Fusion Cloud ERP integration uses REST APIs and Oracle Integration Cloud rather than direct database access.
  • IFS Cloud integration uses projections and Aurena-compatible interfaces to stay upgrade-safe.
  • Infor LN integration goes through BODs and ION.
  • The UI and retrieval layer support Arabic and English by default, including right-to-left rendering where needed.
  • Every deployment starts read-only, with write-back actions gated behind explicit human approval.
  • GPU hardware sizing accounts for in-country import lead times, so capacity is planned ahead rather than added reactively.

Deployment options

Air-gapped on-prem

classified or ITAR-adjacent defence programmes

Model serving and retrieval run entirely inside the facility network with no outbound path, matching the physical and personnel security controls already applied to classified programme data.

Sovereign in-country cloud

companies that want managed infrastructure but must keep data inside UAE or KSA borders

A licensed UAE or Saudi cloud region hosted by an in-country provider, giving managed infrastructure without moving data outside national boundaries, suited to non-classified but still sensitive workloads.

Hybrid

groups with both classified programmes and commercial manufacturing divisions

Classified programme deployments stay fully air-gapped while commercial divisions run on a shared sovereign cloud instance, with programme-level data segregation enforced at the retrieval layer.

Compliance and data control

How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.

UAE PDPL (Federal Decree-Law No. 45 of 2021)

Personal data used in AI features is scoped to a documented business purpose, with data residency kept inside the UAE for any deployment covered by the law.

Saudi PDPL (enforced by SDAIA)

The same purpose-limitation and residency discipline applies for Saudi operations, with SDAIA's registration and cross-border transfer rules factored into any deployment that spans both countries.

NCA Essential Cybersecurity Controls (ECC-1:2018)

Access logging, data classification, and governance in the AI layer are structured to produce the technical evidence NCA ECC audits expect, rather than being bolted on afterwards.

GAMI localisation and technology transfer requirements

Local content and technology transfer evidence is assembled continuously from ERP procurement and BOM data, with a documented, auditable trail rather than a point-in-time spreadsheet exercise.

In-country data residency for government and defence contracts

Deployment options are scoped from the start to keep data inside national borders, whether that means fully air-gapped on-prem or a licensed sovereign cloud region.

How an engagement runs

Phase 1 . 2-3 weeks

Discovery

  • -Data classification review across ERP, procurement, and export licence records
  • -Security clearance and personnel access requirements for implementation staff confirmed
  • -Deployment option recommendation with an in-country network and residency diagram

Phase 2 . 6-8 weeks

Pilot

  • -Working bilingual query pilot for one department (procurement, quality, or planning)
  • -Read-only connector to the primary ERP with role-mirrored access controls
  • -Arabic-language accuracy validated with real users, not just English-first testing

Phase 3 . 8-12 weeks after pilot sign-off

Production

  • -Hardened deployment on the agreed air-gapped or sovereign cloud environment
  • -Audit logging aligned to NCA ECC evidence requirements
  • -GAMI evidence assistant tied to live procurement and BOM data

Phase 4 . ongoing

Scale

  • -Additional use cases (export licence tracking, maintenance triage) added incrementally
  • -Rollout to sister sites with shared governance and programme-level data segregation
  • -Quarterly review of access logs, model performance, and new GAMI or NCA guidance

Questions to ask any vendor, including us

A short list that separates real SAP S/4HANA AI work from a chatbot demo.

  1. Where does the model physically run, and can that be confirmed with a network diagram rather than a policy statement?
  2. How does the deployment handle security clearance requirements for the implementation team itself?
  3. What evidence does the system produce for NCA ECC or GAMI audits, and in what format?
  4. Has Arabic-language accuracy actually been validated with our own procurement and quality staff?
  5. How is data segregated between classified and non-classified programmes within the same company?
  6. What is the process if we need to add capacity, and how long does GPU procurement take given local import timelines?
  7. What does an exit or in-sourcing path look like if we want to take this over ourselves later?

Frequently asked questions

Can we deploy AI on our ERP if some of our programmes are classified?

Yes, but the classified and non-classified portions need separate deployment boundaries. A common pattern is a fully air-gapped instance for classified programme data and a sovereign in-country cloud instance for the rest of the business, with clear rules about which ERP data feeds which deployment and no shared retrieval index between the two.

Does UAE PDPL or Saudi PDPL actually block using AI on ERP data?

No, but both laws push toward in-country data residency and purpose-limited processing, which rules out routing ERP queries through a public LLM API hosted abroad. A sovereign or on-prem deployment that keeps data inside national borders and scopes access to a documented business purpose satisfies the intent of both regimes.

How does the GAMI evidence assistant actually reduce audit work?

Instead of compiling local content and technology transfer figures from scratch when GAMI asks for them, the assistant maintains a continuously updated view sourced from the same procurement and BOM data already in the ERP. The compliance team reviews and finalises the figures rather than assembling them from spreadsheets under deadline pressure.

Is Arabic support genuinely native, or is it translated English?

It should be native, meaning the retrieval and generation layer is built and tested on Arabic queries directly, with right-to-left rendering and Arabic-aware indexing, not a translation layer bolted onto an English-first system. That distinction matters most for technical terminology, where translation tends to lose precision.

What does NCA ECC compliance mean for the AI layer specifically?

It means the AI deployment needs to produce the same categories of evidence NCA ECC expects from any system touching sensitive data: access logging, data classification, defined incident response integration, and governance sign-off. Building that logging in from the start is considerably cheaper than retrofitting it after a first audit finding.

How long does a typical engagement take from discovery to production?

Discovery and pilot together usually run eight to eleven weeks, and production hardening adds another two to three months, longer than a comparable engagement in a less regulated market because of the additional security clearance and evidence-logging work. Most of that time goes into getting the governance right, not into the AI itself.

Can a single deployment serve both our UAE and Saudi operations?

It can, but the two operations need separate data residency boundaries because UAE PDPL and Saudi PDPL are enforced by different regulators with different registration and transfer rules. A shared governance framework with country-specific deployment instances tends to work better than either a single undifferentiated system or two fully disconnected ones.

Talk it through with an engineer who knows SAP S/4HANA

Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.