Profile
“Regulators don’t want documentation. They want to understand whether you know what you’re doing.”
Georges Haddad | GRC & AI Governance, board and advisoryDubai & London

The Work
For more than twenty years, Georges Haddad has advised governments, regulators and large enterprises across the Middle East and North Africa on cybersecurity strategy, regulatory compliance and the risk of moving critical workloads to cloud and, increasingly, to AI. His work tends to begin where the control frameworks stop being useful; in the rooms where an executive committee has to decide what it is willing to accept, and why.
That work has included contributions to national cloud and cybersecurity policy in the United Arab Emirates, Saudi Arabia, Oman and Kuwait: helping shape the conditions under which regulated data could leave a data centre, and translating between regulators who needed assurance and providers who needed to operate at scale. He has spent much of his career on both sides of that conversation, and treats it as one problem rather than two.
“Being compliant isn’t a finished state, just a snapshot of a moving system.”
His current focus is AI governance: building the operating models, accountability structures and evidence trails that make ISO/IEC 42001 something an organisation actually runs rather than something it merely certifies. He works in English, Arabic and French, and splits his time between Dubai and London, on a board and advisory track.
Credentials
- ISO/IEC 27001 Master
- ISO/IEC 42001 Lead Implementer
- ISO/IEC 22301 Lead Implementer
- CISA
- CISM
- CCSP
Experience
CloudCrest SecurityPrincipal Cybersecurity Consultant
Advises boards and executive teams on AI governance programmes, ISO/IEC 42001 readiness and the regulatory exposure that comes with deploying models into regulated processes.
Amazon Web ServicesSecurity Regulatory Program Lead
Led regulatory engagement across the Middle East, working with national regulators and financial supervisors to establish the conditions under which sensitive workloads could run in the cloud.
IBMPrincipal Cybersecurity Consultant
Designed and delivered enterprise security strategies and governance frameworks for government and financial-sector clients across the Gulf.
Deloitte Middle EastSenior Information Security Consultant
Ran information security assessments and compliance programmes for regional institutions navigating their first serious regulatory scrutiny.
Publications
- 2026.05
Identity Is the Perimeter. Governance Hasn't Caught Up.
Access decisions moved to identity years ago; most control frameworks still assume a network edge.
- 2026.04
The Board Asked About Cyber Risk. Nobody Had a Good Answer.
Why risk registers keep failing the one audience that actually decides what gets funded.
- 2026.03
The EU AI Act Will Fail Without Governance Operating Models
Obligations on paper mean little until someone owns them inside a working process.