Skip to content
Brocode SolutionsAI Software Development

UAE estate atlas

AI workloads across seven UAE estates. One control plane.

Hyperscaler, sovereign, carrier and on-premise — designed together. Six-week landing zone. Regulator-evidence pack pre-mapped to TDRA, CBUAE, FSRA and NCA.

Hyperscaler

AWS UAE North + Bahrain

me-central-1 / me-south-1

latency · 2.1ms

Microsoft

Azure UAE North + UAE Central

uaenorth / uaecentral

latency · 1.8ms

Oracle

OCI Abu Dhabi + Dubai

me-abudhabi-1 / me-dubai-1

latency · 2.4ms

Sovereign

G42 Cloud

Abu Dhabi sovereign

latency · 0.9ms

On-prem

Khazna data centres

Abu Dhabi + Dubai colocation

latency · 0.4ms

Carrier

du Cloud

Dubai South + Samacom

latency · 1.1ms

Carrier

e& enterprise / Etisalat

Abu Dhabi + Dubai

latency · 1.3ms

Seven estates. One control plane. One regulator-evidence pack.

The UAE cloud reality in 2026

Hyperscaler-only and G42-only are both wrong defaults.

A serious AI estate in the UAE in 2026 is not a single-cloud estate. The sovereign workload sits in G42 Cloud, the regulator-sensitive corpus sits in Khazna, the Azure OpenAI Service workload sits in Azure UAE North, the Bedrock-fronted GenAI workload sits in AWS UAE North, and the OCI-DB-heavy back-office sits in OCI Abu Dhabi — sometimes all five inside the same bank or federal entity.

The integrator who can deliver this estate is rare. Hyperscaler-only shops dodge the sovereignty conversation; G42-only integrators cannot deliver Azure OpenAI Service or Bedrock when the workload demands it. We run all seven estates inside the same control plane, with a single OpenTelemetry trail and a single regulator-evidence pack.

The seven estates

Where each shines, where each does not.

Partnership tier, BYOK story, regulator alignment, the workload class each is built for, and the honest caveats.

Hyperscaler

AWS UAE North + Bahrain

me-central-1 / me-south-1

2.1ms
Partnership
AWS Advanced Tier Services Partner
BYOK / HSM
KMS with external key store; AWS CloudHSM available
Regulator alignment
TDRA, CBUAE Outsourcing, ADGM DP
Where it shines
SageMaker / Bedrock-fronted GenAI; mature service breadth; cross-region resilience to Bahrain
Where it does not
GenAI model availability still trails US regions by one quarter; plan model rotations accordingly

Microsoft

Azure UAE North + UAE Central

uaenorth / uaecentral

1.8ms
Partnership
Microsoft AI Cloud Partner — Data & AI + Build & Modernize AI Apps
BYOK / HSM
Azure Key Vault HSM customer-managed keys; double encryption available
Regulator alignment
TDRA, CBUAE, FSRA-ADGM
Where it shines
Azure OpenAI Service joint deployments; deep Microsoft 365 integration; identity through Entra ID
Where it does not
Some Azure OpenAI models are gated on UAE North; capacity should be reserved upfront

Oracle

OCI Abu Dhabi + Dubai

me-abudhabi-1 / me-dubai-1

2.4ms
Partnership
Oracle Cloud partner — Dedicated Region @ Customer experience
BYOK / HSM
OCI Vault with external HSM integration; dedicated region option
Regulator alignment
TDRA, CBUAE, FSRA-ADGM, NCA-KSA
Where it shines
Oracle DB-heavy estates; dedicated region @ customer for entities that need OCI on their own floor
Where it does not
Smaller GenAI service catalogue; we typically pair OCI compute with externally-hosted model APIs

Sovereign

G42 Cloud

Abu Dhabi sovereign

0.9ms
Partnership
Core42 Compute partnership; G42 Inception-fronted
BYOK / HSM
Sovereign HSM; no foreign-operator access; metadata residency declared
Regulator alignment
TDRA, federal sovereign workloads, NESA
Where it shines
Arabic LLM training on G42 GPU pods; federal-grade residency; sovereign inference path
Where it does not
Service catalogue narrower than hyperscalers — pair with a hyperscaler estate for non-sovereign workloads

On-prem

Khazna data centres

Abu Dhabi + Dubai colocation

0.4ms
Partnership
Khazna colocation partner; NVIDIA DGX-ready halls
BYOK / HSM
Client-owned HSM; physical-security clearance regime
Regulator alignment
Federal sensitive; defence-adjacent allowed under clearance
Where it shines
Sensitive corpus training; dedicated GPU racks; OEM HGX H100 / H200 builds
Where it does not
Lead time on GPU procurement should be confirmed at landing-zone design

Carrier

du Cloud

Dubai South + Samacom

1.1ms
Partnership
du enterprise partnership for managed AI appliances
BYOK / HSM
Carrier-managed HSM; client-controlled key wrapping available
Regulator alignment
TDRA, DHA-aligned hosting
Where it shines
Telco-adjacent workloads; managed AI appliance with carrier-grade SLAs; competitive cross-connect fabric
Where it does not
GPU portfolio narrower than hyperscalers; works best as the residency tier next to a hyperscaler

Carrier

e& enterprise / Etisalat

Abu Dhabi + Dubai

1.3ms
Partnership
e& enterprise hosting partnership
BYOK / HSM
Carrier-managed HSM with client key escrow
Regulator alignment
TDRA, federal-aligned carrier hosting
Where it shines
National operator hosting for state-owned and federal-adjacent entities; long-standing carrier SLAs
Where it does not
Best paired with a hyperscaler estate where the workload needs hyperscaler-only AI services
  • 47

    Production AI landing zones since 2022

  • 42d

    Average time-to-first-workload

  • 7

    UAE cloud estates operated

  • 4

    Regulator overlays mapped at gate

Reference: a hybrid workload across three estates

UAE federal entity — Azure UAE North + G42 Cloud + Khazna on-prem.

One audit trail. One observability plane. Three estates, each chosen for the slice of the workload it is genuinely best for.

See the stack the workload runs on
  1. tier.1 — inference

    Azure UAE North

    Azure OpenAI Service for non-sovereign inference; customer-managed keys in Key Vault HSM; private endpoint into the workload VNet.

  2. tier.2 — training

    G42 Cloud

    Arabic LLM fine-tuning and RAG-index builds on G42 GPU pods; sovereign HSM; metadata residency declared with the regulator at gate.

  3. tier.3 — sensitive corpus

    Khazna on-premise appliance

    NVIDIA DGX appliance behind the client firewall for the most sensitive documents; client-owned control plane that we install and the client operates; client-owned HSM throughout.

  4. cross-cut — control plane

    Single OpenTelemetry plane + single FinOps view

    All three estates emit traces, metrics and logs to one observability plane; cross-cloud egress and capacity reservations modelled in a single FinOps dashboard.

The Six-Week Landing Zone

Week by week, deliverable by deliverable.

Each gate produces an artefact your second line of defence and internal audit can attach directly to the next regulator submission.

  1. Week 1

    Residency workshop and target architecture

    Workload-by-workload residency classification, regulator overlay map, target architecture across the chosen estates, and the cross-cloud network fabric (Megaport, Equinix Fabric, G42 cross-connect).

    Deliverables signed by client architect

  2. Week 2

    Terraform module skeleton and identity baseline

    Module skeleton committed to your repo; identity baseline (Entra ID / IAM Identity Center / OCI IAM / G42 IDP) federated; first key-management proof on customer-managed keys.

    IaC merged to main

  3. Weeks 3–4

    Landing zones provisioned

    Per-cloud landing zones built from the skeleton: VPC / VNet topology, encryption-at-rest baselines, audit log routing, OpenTelemetry collector pattern, KServe / SageMaker / Azure ML / OCI Data Science target setup.

    4 cloud accounts hardened

  4. Week 5

    First workload deployed end-to-end

    One end-to-end AI workload (typically a RAG service or a model-serving endpoint) deployed against the live landing zone with full observability and key-management proofs.

    First workload live

  5. Week 6

    Regulator-evidence pack handed over

    TDRA / CBUAE / FSRA / NCA control-mapping pack handed to the second line of defence. Gate review with internal audit. Hyper-care plan signed.

    Evidence pack signed off

Regulator-evidence pack

Mapped to TDRA, CBUAE, FSRA-ADGM and NCA.

Each control-mapping section ships in the Cloud Atlas with an editable annex per regulator.

TDRA

Telecommunications and Digital Government Regulatory Authority

Hosting, residency, telecom infrastructure controls

CBUAE

Central Bank Outsourcing Regulation

Outsourcing notification, exit clauses, third-party risk

FSRA-ADGM

Financial Services Regulatory Authority — ADGM

Principles for Adoption of AI; data protection regulations

NCA-KSA

National Cybersecurity Authority — KSA

ECC, CCC and DCC control catalogues

Versus the alternatives

Hyperscaler-only, G42-only, legacy on-prem — and what we do instead.

CapabilityBrocodeHyperscaler-only SIG42-only integratorLegacy on-prem world
AI workloads on hyperscaler + G42 + on-prem on one control plane
Six-week landing zone with regulator-evidence packYes — Terraform skeleton per cloud, pre-mapped controls12–20 weeks16–26 weeksSovereign-only, longer for hyperscaler
TDRA / CBUAE / FSRA / NCA control mapping shipped at gateYes — sample available pre-engagementOn request, post-engagementBuilt per engagementTDRA only
Sovereign HSM and external key store options documented per cloudGeneric guidance only
Production AI landing zones since 202247 across seven UAE estates<10 in-cloud12–18 mainly hyperscaler15–20 G42-only
Cross-cloud observability and FinOps from day oneSingle OpenTelemetry plane, single FinOps viewPer-cloud silosSpreadsheet-drivenG42-only view

Free download

UAE Sovereign & Hybrid Cloud Atlas

The 56-page PDF, the Terraform landing-zone starter pack, and a CSV of measured cross-cloud latencies between UAE estates.

  • AWS UAE North landing-zone Terraform skeleton
  • Azure UAE North landing-zone Terraform skeleton
  • OCI Abu Dhabi landing-zone Terraform skeleton
  • G42 Cloud sovereign landing-zone pattern
  • Khazna on-prem appliance reference design
  • du Cloud + e& enterprise hosting patterns
  • Per-estate BYOK and HSM playbook
  • TDRA / CBUAE / FSRA / NCA control mapping annex

Instant download. No spam. Unsubscribe any time.

Architecture questions

What infrastructure leads ask before the design session.

  • Yes — each estate is configured with a customer-managed key strategy. On AWS we use KMS with an external key store backed by your CloudHSM or on-premise HSM. On Azure we use Key Vault HSM with customer-managed keys and optional double encryption. On OCI we use OCI Vault with external HSM integration. On G42 Cloud we use the sovereign HSM. On Khazna we work directly with your owned HSM. The landing-zone Terraform sets all of this up by variable; no manual ClickOps.

Book the design session

A principal cloud architect, your estates, your regulator.

A senior Brocode architect responds within one business day. If your landing-zone gate is inside two weeks, we will work in parallel with your account teams at AWS, Microsoft, OCI or G42.

Prefer chat? Message us on WhatsApp.

Quote request

Book a 60-minute landing-zone design session

A principal cloud architect walks the regulator overlay, residency story and Terraform module skeleton for your UAE estates.

Prefer chat? Message us on WhatsApp — we'll see it within working hours.

Book a design sessionWhatsApp