Gulf defence + sovereign AI
AI for ERP in the UAE and Saudi Arabia: Sovereign, On-Prem Design for Defence Manufacturing
Short answer
UAE and Saudi defence and aerospace manufacturers running SAP, Oracle Fusion Cloud ERP, IFS Cloud, or Infor LN can add AI to their ERP through a sovereign, in-country deployment rather than a public cloud API, keeping data inside UAE PDPL or Saudi PDPL boundaries and within reach of NCA Essential Cybersecurity Controls. The design also has to speak to GAMI localisation evidence requirements, which is a documentation problem an AI layer can genuinely help with.
- ERP
- SAP S/4HANA, Oracle Fusion Cloud ERP, IFS Cloud, Infor LN
- Industries
- Defense, Aerospace, Electronics
- Written for
- CIO
Both the UAE and Saudi Arabia have spent the past several years building a domestic defence and aerospace manufacturing base as part of broader economic diversification programmes, and the supplier ecosystem around that push has grown quickly. Many of these suppliers are running modern ERPs, SAP S/4HANA, Oracle Fusion Cloud ERP, IFS Cloud, Infor LN, but their AI options have lagged their ERP maturity, largely because the compliance bar for anything touching defence-adjacent data is higher here than for a typical mid-market manufacturer.
In Saudi Arabia, GAMI, the General Authority for Military Industries, sets local content and technology transfer expectations that suppliers need to evidence, and that evidence today is largely compiled by hand from procurement, BOM, and vendor master data already sitting in the ERP. NCA's Essential Cybersecurity Controls add a further layer of technical and governance requirements for critical infrastructure and government-adjacent systems, requirements that most off-the-shelf SaaS AI copilots simply cannot demonstrate compliance against.
In the UAE, the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data sets the baseline privacy regime, and Saudi Arabia's own PDPL, enforced by SDAIA, does the same for Saudi operations. Both regimes push toward in-country data handling for anything sensitive, which rules out routing ERP queries through a public LLM API hosted outside the Kingdom or the Emirates, regardless of how convenient that API might otherwise be.
For a CIO in this position, the practical starting point is the same one that works elsewhere: a bilingual, Arabic and English, natural-language query layer over the ERP, deployed on infrastructure that never leaves the country, answering the questions planners, buyers, and quality engineers already ask every day, before extending into the GAMI evidence and export tracking use cases that carry more compliance weight.
What usually gets in the way
The problems we hear most from cio teams running SAP S/4HANA.
GAMI local content evidence is compiled by hand
Demonstrating local content percentages and technology transfer progress against GAMI requirements today means pulling procurement, BOM origin, and vendor data into spreadsheets manually, on a cycle that rarely matches how fast the underlying ERP data actually changes.
Public cloud AI routes through infrastructure outside the country
Most SaaS AI products, including many marketed as enterprise-ready, process data on infrastructure outside the UAE or the Kingdom, which is a non-starter for classified or sensitive defence-adjacent work regardless of contractual assurances.
NCA ECC controls are hard to evidence with off-the-shelf AI
Essential Cybersecurity Controls require specific technical and governance evidence, access logging, data classification, incident response integration, that most consumer-grade or lightly adapted enterprise AI tools were never built to produce.
Arabic and English data live side by side, most tools handle only one
ERP master data, documentation, and day-to-day queries mix Arabic and English, and a copilot built and tested primarily in English produces noticeably weaker results on the Arabic half of the business.
Local AI and ERP skills are both in short supply
The talent pool that understands both the ERP platform and modern AI deployment is thin locally, so an engagement that does not deliberately transfer capability leaves the customer dependent on the vendor indefinitely.
Where AI earns its place in SAP S/4HANA
Each use case names the ERP objects it reads or writes, so your ERP team can judge the integration effort before anyone commits budget.
GAMI local content and evidence assistant
Aggregates procurement, BOM origin, and vendor master data into a continuously updated local content and technology transfer evidence base.
Touches: Vendor master, purchase order lines, BOM origin fields, technology transfer milestone tracking
Outcome: turns an annual scramble to compile evidence into a query the procurement or compliance team can run at any time
Bilingual natural-language query over ERP
Planners and buyers ask questions in Arabic or English and get answers grounded in live SAP, Oracle Fusion, IFS, or LN data.
Touches: Sales order headers and lines, inventory balances, MRP action messages
Outcome: closes the gap between Arabic-speaking shop floor and procurement staff and an ERP interface that often defaults to English
MRP and PO exception triage
Groups and prioritises reschedule, expedite, and cancel messages for planner review.
Touches: MRP action messages, purchase order lines, supplier confirmations
Outcome: cuts routine exception triage time for the majority of low-risk lines, freeing planners for the exceptions that need judgement
Export licence and end-use tracking assistant
Flags a sales order or shipment against outstanding export licence or end-user certificate requirements before release.
Touches: Customer master, sales order headers, export licence and end-use certificate fields
Outcome: catches a missing or expired licence reference before the shipment releases rather than after
Quality NCR and CAPA drafting
Drafts a first-pass root cause and containment narrative from a quality notification, formatted for AS9100.
Touches: Quality notifications, NCR records, 8D worksheets
Outcome: gives quality engineers a reviewable draft in minutes rather than a blank template
Maintenance and EAM work order triage
Prioritises open maintenance work orders and drafts a summary for the maintenance planning meeting.
Touches: IFS Cloud maintenance projections, work order records, equipment master
Outcome: gives the maintenance planner a grounded starting point instead of reviewing every open work order manually
RFQ-to-quote drafting from historical costs
Pulls comparable historical job costs and routing data to give estimators a grounded starting draft for a new quote.
Touches: Job costing history, routing data, quote header and line records
Outcome: shortens the time from RFQ receipt to a defensible first quote draft
Reference architecture
The architecture is built for in-country, sovereign operation from the start, with bilingual Arabic and English support and classification tagging that mirrors the customer's own security controls.
- 1
ERP connectors
Read-only connectors into SAP (OData/BAPI), Oracle Fusion Cloud ERP (REST APIs, Oracle Integration Cloud), IFS Cloud (projections, Aurena), and Infor LN (BODs, ION).
- 2
Data and semantic layer
A permissioned index with Arabic-aware tokenisation and right-to-left rendering, tagged for GAMI evidence relevance and export licence status alongside standard role-based access.
- 3
Model serving
Open-weight models served on infrastructure physically located inside the UAE or the Kingdom, sized to the deployment's actual query volume.
- 4
Retrieval and agents
Bilingual retrieval-augmented generation grounded in connected ERP data, with any write-back action gated behind explicit human approval.
- 5
Governance and audit
Access and query logging structured to produce NCA ECC evidence artefacts directly, rather than requiring a separate compliance reporting exercise.
Integration notes for your ERP team
- SAP connections use OData services and BAPI/RFC calls scoped to read-only roles.
- Oracle Fusion Cloud ERP integration uses REST APIs and Oracle Integration Cloud rather than direct database access.
- IFS Cloud integration uses projections and Aurena-compatible interfaces to stay upgrade-safe.
- Infor LN integration goes through BODs and ION.
- The UI and retrieval layer support Arabic and English by default, including right-to-left rendering where needed.
- Every deployment starts read-only, with write-back actions gated behind explicit human approval.
- GPU hardware sizing accounts for in-country import lead times, so capacity is planned ahead rather than added reactively.
Deployment options
Air-gapped on-prem
classified or ITAR-adjacent defence programmes
Model serving and retrieval run entirely inside the facility network with no outbound path, matching the physical and personnel security controls already applied to classified programme data.
Sovereign in-country cloud
companies that want managed infrastructure but must keep data inside UAE or KSA borders
A licensed UAE or Saudi cloud region hosted by an in-country provider, giving managed infrastructure without moving data outside national boundaries, suited to non-classified but still sensitive workloads.
Hybrid
groups with both classified programmes and commercial manufacturing divisions
Classified programme deployments stay fully air-gapped while commercial divisions run on a shared sovereign cloud instance, with programme-level data segregation enforced at the retrieval layer.
Compliance and data control
How the architecture supports your obligations. Certification and accountability stay with your organisation; the design keeps the evidence straightforward.
UAE PDPL (Federal Decree-Law No. 45 of 2021)
Personal data used in AI features is scoped to a documented business purpose, with data residency kept inside the UAE for any deployment covered by the law.
Saudi PDPL (enforced by SDAIA)
The same purpose-limitation and residency discipline applies for Saudi operations, with SDAIA's registration and cross-border transfer rules factored into any deployment that spans both countries.
NCA Essential Cybersecurity Controls (ECC-1:2018)
Access logging, data classification, and governance in the AI layer are structured to produce the technical evidence NCA ECC audits expect, rather than being bolted on afterwards.
GAMI localisation and technology transfer requirements
Local content and technology transfer evidence is assembled continuously from ERP procurement and BOM data, with a documented, auditable trail rather than a point-in-time spreadsheet exercise.
In-country data residency for government and defence contracts
Deployment options are scoped from the start to keep data inside national borders, whether that means fully air-gapped on-prem or a licensed sovereign cloud region.
Where Netray fits
ERPray
Bilingual question answering and dashboards across SAP, Oracle Fusion, IFS Cloud, or Infor LN data, respecting existing role-based access and export licence controls.
Custom build
The GAMI local content evidence assistant and export licence tracking are specific enough to a customer's procurement and compliance setup to warrant a scoped custom build.
How an engagement runs
Phase 1 . 2-3 weeks
Discovery
- -Data classification review across ERP, procurement, and export licence records
- -Security clearance and personnel access requirements for implementation staff confirmed
- -Deployment option recommendation with an in-country network and residency diagram
Phase 2 . 6-8 weeks
Pilot
- -Working bilingual query pilot for one department (procurement, quality, or planning)
- -Read-only connector to the primary ERP with role-mirrored access controls
- -Arabic-language accuracy validated with real users, not just English-first testing
Phase 3 . 8-12 weeks after pilot sign-off
Production
- -Hardened deployment on the agreed air-gapped or sovereign cloud environment
- -Audit logging aligned to NCA ECC evidence requirements
- -GAMI evidence assistant tied to live procurement and BOM data
Phase 4 . ongoing
Scale
- -Additional use cases (export licence tracking, maintenance triage) added incrementally
- -Rollout to sister sites with shared governance and programme-level data segregation
- -Quarterly review of access logs, model performance, and new GAMI or NCA guidance
Questions to ask any vendor, including us
A short list that separates real SAP S/4HANA AI work from a chatbot demo.
- Where does the model physically run, and can that be confirmed with a network diagram rather than a policy statement?
- How does the deployment handle security clearance requirements for the implementation team itself?
- What evidence does the system produce for NCA ECC or GAMI audits, and in what format?
- Has Arabic-language accuracy actually been validated with our own procurement and quality staff?
- How is data segregated between classified and non-classified programmes within the same company?
- What is the process if we need to add capacity, and how long does GPU procurement take given local import timelines?
- What does an exit or in-sourcing path look like if we want to take this over ourselves later?
Frequently asked questions
Can we deploy AI on our ERP if some of our programmes are classified?
Yes, but the classified and non-classified portions need separate deployment boundaries. A common pattern is a fully air-gapped instance for classified programme data and a sovereign in-country cloud instance for the rest of the business, with clear rules about which ERP data feeds which deployment and no shared retrieval index between the two.
Does UAE PDPL or Saudi PDPL actually block using AI on ERP data?
No, but both laws push toward in-country data residency and purpose-limited processing, which rules out routing ERP queries through a public LLM API hosted abroad. A sovereign or on-prem deployment that keeps data inside national borders and scopes access to a documented business purpose satisfies the intent of both regimes.
How does the GAMI evidence assistant actually reduce audit work?
Instead of compiling local content and technology transfer figures from scratch when GAMI asks for them, the assistant maintains a continuously updated view sourced from the same procurement and BOM data already in the ERP. The compliance team reviews and finalises the figures rather than assembling them from spreadsheets under deadline pressure.
Is Arabic support genuinely native, or is it translated English?
It should be native, meaning the retrieval and generation layer is built and tested on Arabic queries directly, with right-to-left rendering and Arabic-aware indexing, not a translation layer bolted onto an English-first system. That distinction matters most for technical terminology, where translation tends to lose precision.
What does NCA ECC compliance mean for the AI layer specifically?
It means the AI deployment needs to produce the same categories of evidence NCA ECC expects from any system touching sensitive data: access logging, data classification, defined incident response integration, and governance sign-off. Building that logging in from the start is considerably cheaper than retrofitting it after a first audit finding.
How long does a typical engagement take from discovery to production?
Discovery and pilot together usually run eight to eleven weeks, and production hardening adds another two to three months, longer than a comparable engagement in a less regulated market because of the additional security clearance and evidence-logging work. Most of that time goes into getting the governance right, not into the AI itself.
Can a single deployment serve both our UAE and Saudi operations?
It can, but the two operations need separate data residency boundaries because UAE PDPL and Saudi PDPL are enforced by different regulators with different registration and transfer rules. A shared governance framework with country-specific deployment instances tends to work better than either a single undifferentiated system or two fully disconnected ones.
Related guides
On-Prem AI for ERP in Aerospace, Defense, and Electronics Manufacturing
A hub guide to on-prem AI across SAP, Infor LN, Costpoint, IFS, and Oracle EBS for aerospace, defense, and electronics manufacturers under ITAR, CMMC, and AS9100.
ITAR + on-prem AIITAR-Compliant AI for ERP Technical Data
How to add generative AI to your ERP without creating a deemed export under ITAR. On-prem architecture patterns an Empowered Official can sign off on.
ERP AI for DISP membersAI for ERP in the Australian Defence Industry: DISP-Aligned and On-Prem
On-prem AI for SAP, IFS Cloud, and Infor LN built for DISP members: aligned to the ISM, Essential Eight, and AUKUS Pillar II export control realities.
European defence supply chain AIOn-Prem AI for European Defence and NATO Supply Chain Manufacturers
AI grounded on SAP, IFS, or Infor LN for NATO and EDF supply chain manufacturers, kept inside the accredited network boundary your ERP already sits in.
Israel defense + air-gapped AIAI for ERP in Israel: Defense Export Controls and Air-Gapped Deployment
AI for SAP, Oracle, Infor LN and Priority ERP in Israeli defense and electronics manufacturing: DECA export control, closed-network AI, and air-gapped deployment.
Agents + approval gatesAI Agents for ERP, Running On-Prem
A practical guide to on-prem AI agents for ERP: what they can safely automate, where human approval belongs, and how to design the guardrails.
Plan it with numbers
Sovereign AI Readiness Assessment
Score your organization across eleven dimensions of sovereign AI readiness, from data residency and model provenance to cleared personnel and air-gapped operations.
Free ToolAir-Gapped AI Readiness Assessment
A 10-question assessment that scores how prepared your organization is to deploy and operate LLMs inside an air-gapped or classified enclave.
Free ToolAI Data Sovereignty Risk Assessment
Score your organization across eight dimensions of AI data sovereignty risk, from inference location and encryption key custody to subprocessor visibility and audit readiness.
GuideAI Governance for Export-Controlled Data (ITAR/EAR)
AI governance for export-controlled data: policies, access controls, and audit trails that keep ITAR and EAR data out of public LLMs and off foreign servers.
GuideOn-Prem AI for Defense Contractors: The Complete Guide
On-prem AI for defense contractors: deploy LLMs and AI agents inside your CMMC and ITAR boundary. Architecture, hardware costs, timelines, and vendor options.
GuideAI-Driven Defense Supply Chain Visibility
AI-driven defense supply chain visibility: track DPAS-rated orders, predict supplier delays, and meet DFARS flow-downs with AI agents tied to your ERP data.
Talk it through with an engineer who knows SAP S/4HANA
Bring one real question your team cannot answer from the ERP today. We will map the data path, the model, and where it runs, and tell you honestly if AI is the wrong tool for it.