Why Enterprise AI in the GCC Needs a Better Data Foundation

Ahmed Hafez, Director, Solution Engineering for the Middle East, Turkey and Africa at Snowflake, believes the next phase of enterprise AI adoption in the GCC will depend less on the power of individual AI models and more on whether organisations have built the data foundations needed to use them effectively.
The Gulf’s AI ambitions are moving rapidly from experimentation to execution. Governments and enterprises across the region are investing in generative and agentic AI, while organisations are simultaneously modernising legacy infrastructure and expanding their use of cloud and data platforms.
Yet one of the biggest barriers to turning those investments into measurable business outcomes may have little to do with the sophistication of the AI model. It is the data underneath it.
PwC research suggests that only 16% of GCC CEOs believe their AI systems have access to all relevant data. For Ahmed Hafez, Director, Solution Engineering for the Middle East, Turkey and Africa at Snowflake, the finding reflects a problem that has existed long before generative AI arrived: enterprise information has been built up across disconnected applications, databases, documents and legacy systems, each with its own permissions, definitions and processes.
The arrival of AI has simply made the consequences of those silos more visible. “The question is whether they are building a data foundation that is truly AI-ready, or simply adding AI on top of the same fragmented environment,” Hafez says. That distinction is becoming increasingly important as organisations attempt to move AI beyond individual pilots and departmental applications and into core business processes.
The Data Problem Behind the AI Problem
Enterprise data rarely exists in one convenient location or format. Structured information may sit inside platforms such as SAP, Salesforce and Workday, while IoT devices, sensors and machine logs generate semi-structured data. Documents, contracts, emails, images and video add another layer of unstructured information.
Then there is data generated outside the organisation, including information from partners and third parties. Bringing these sources together is therefore more complicated than simply connecting another database to an AI application. Organisations need to make information available within a governed environment while ensuring that it can be accessed at the appropriate latency, whether in real time or through batch processing.
This matters because AI has the potential to work across information that conventional analytics has traditionally struggled to analyse at scale. Instead of requiring every relationship between different data sources to be documented manually, AI can help identify patterns and connections across the enterprise. But that only works if the underlying data can be accessed, trusted and governed.
This is where the architecture of the data platform becomes critical. Snowflake’s proposition is centred on providing a governed environment in which organisations can consolidate, connect and use their data for analytics and AI. But the challenge extends beyond simply making more information available to a model. AI also needs to understand what that information actually means.
Context Could Become the Next AI Battleground
Giving an AI system access to enterprise data does not necessarily mean it understands the business. Consider the word “revenue”. Finance, sales and operations may use the same term while applying different definitions or calculations. The same problem can arise with customer value, inventory, risk and churn.
For a human employee who has spent years inside an organisation, much of this context may be obvious. For an AI system, it needs to be established and governed. Hafez believes AI itself can increasingly help organisations build this understanding by analysing query histories, transformation logic, BI metrics and existing definitions to identify relationships and patterns in how data is actually being used.
Importantly, conflicting definitions should not simply be resolved by an AI system making an assumption. Governed definitions need to remain authoritative, while discrepancies can be surfaced for human resolution. Snowflake’s Cortex Sense is designed to bring this semantic context together, enabling AI applications and agents to work with the meaning behind enterprise data.
That becomes particularly important as AI systems evolve from tools that retrieve information to systems that can make decisions and take action.
When AI Starts Taking Action
The shift towards agentic AI changes the governance equation. An AI assistant that produces a summary is fundamentally different from an AI agent capable of accessing several enterprise systems, modifying records or initiating a business workflow.
Once AI can act, organisations need to establish not just what an agent knows, but what it is allowed to do. Hafez argues that agents should be treated much like other identities operating within an enterprise. They need verified identities, permissions appropriate to the tasks they perform and an auditable record of what they accessed and what they did.
The principle is relatively simple: permissions should correspond to consequences. An agent that retrieves a sales report does not require the same level of authority as one capable of modifying financial forecasts, changing customer records or initiating transactions.
High-consequence actions may therefore require human approval, while agent activity needs to remain observable and, where appropriate, reversible. The challenge is magnified when an organisation begins deploying dozens or hundreds of agents across different applications, models and tools.
Creating individual governance mechanisms for each agent will quickly become difficult to manage. This is where the concept of an agentic control plane becomes relevant — a central layer through which authentication, permissions, monitoring and activity records can be managed consistently across an organisation’s AI environment. The objective is not necessarily to restrict autonomous AI. It is to make autonomy manageable.
Data Residency Becomes an AI Architecture Issue
For organisations in the UAE, governance also intersects with data residency. As AI workloads become more complex, information can potentially move between storage environments, applications, processing services and models. Organisations therefore need to understand where data is stored and processed, what services interact with it and which controls remain in place when that information is consumed by AI.
Data residency consequently needs to be considered at the architecture stage rather than bolted on after an AI application has already been deployed. Snowflake’s presence in the UAE allows organisations to keep data and compute within national boundaries, while its cloud-agnostic architecture is designed to support different cloud environments.
For enterprises, however, the larger issue is maintaining governance throughout the AI lifecycle. Permissions, classification and access controls should continue to apply when information moves into an AI application or agent. Keeping data and AI workloads within a governed environment can reduce unnecessary movement of sensitive information while providing security and compliance teams with greater visibility. This will become increasingly important as AI adoption expands from isolated experiments into production environments.
Measuring AI Beyond Tokens and Models
There is another challenge that enterprises will have to confront: proving that AI investment is actually delivering business value. The number of models deployed or tokens consumed can tell an organisation how much AI infrastructure it is using. It does not necessarily tell it whether the technology is improving the business.
The appropriate metrics depend on the problem being addressed. For some organisations, AI may be expected to increase revenue. For others, the objective could be reducing operating costs, improving customer outcomes, reducing errors or accelerating product development.
Hafez describes this broader principle as intelligence efficiency — measuring how effectively an organisation converts compute, models, data and context into measurable business impact. The distinction is significant.
A retailer deploying AI for personalised recommendations, for example, should ultimately be looking at conversion rates, customer retention and repeat purchases rather than simply counting how many recommendation models it operates.
As AI workloads grow, organisations will increasingly need to ask not just Can we deploy this? but Is the outcome worth the resources required to run it?
Avoiding the Next Generation of Lock-In
The rapid development of AI models creates another strategic consideration. Enterprises investing in an AI architecture today cannot necessarily assume that the model or provider they select will remain the most appropriate choice several years from now.
Different models may be better suited to different workloads, with organisations weighing quality, performance, latency, cost and availability. Open-source models are also becoming an increasingly important part of the enterprise AI landscape.
This makes interoperability and architectural flexibility important considerations. Snowflake has extended its cloud-agnostic approach to AI by supporting access to different models rather than requiring customers to build around a single provider. Dynamic model routing can further allow organisations to select approved models according to factors such as quality, cost, latency and availability.
For enterprises, the broader lesson is that the data foundation should not have to be rebuilt every time the AI model landscape changes. That flexibility could prove particularly valuable in the GCC, where organisations are making substantial investments in AI while also developing sovereign and locally governed digital infrastructure.
From AI Ambition to AI Readiness
The conversation around enterprise AI is gradually changing. The first phase was largely about experimentation: which models could generate content, summarise information, write code or answer questions? The next phase is considerably more consequential.
AI is being connected to enterprise data, embedded into workflows and increasingly given the ability to make decisions and perform actions. That makes the foundations beneath the AI more important than ever.
For GCC organisations, becoming genuinely AI-ready means more than selecting a powerful model. It requires breaking down data silos, establishing consistent business context, controlling agent permissions, maintaining data residency and governance, measuring tangible business outcomes and keeping the underlying architecture flexible enough to accommodate the next generation of AI.
The region has demonstrated considerable appetite for AI. The next test will be whether enterprises can build the data and governance foundations required to turn that appetite into sustainable business value. The AI model may attract the headlines, but the quality, context and governance of the data underneath it could ultimately determine how much value organisations extract from AI.



