Business 10 mins read

Why the Middle East Will Lead the Sovereign AI Era

Updated:

How Nikola Kočić Built Growww AI Engine for Markets Where Data Never Leaves the Building.

Two years ago, the question of where your data lives when you use an AI tool was a footnote in a terms-of-service page. Today it is the first question a board asks before signing a contract. Companies have become acutely aware that they cannot freely share data with large language models hosted on someone else’s servers. What started as a technical concern has become a commercial reality that is reshaping which AI platforms survive and which get disqualified before the conversation even begins.

Nowhere is this shift more visible than in the Middle East. The region has built one of the most stringent regulatory frameworks for data protection in the world, and that framework is not a paper barrier. It is an architecture that defines which data may leave the jurisdiction, under what conditions, and who bears responsibility when the line is crossed. For any company selling AI into this market, sovereignty is not a feature. It is the price of entry.

Nikola Kočić recognized this earlier than most

His company, Growww AI, did not build another cloud-hosted AI application. It built an engine that installs inside the client’s own infrastructure, runs behind their firewall, and keeps every byte of data exactly where it has always been. The model that powers the intelligence can be OpenAI, Claude, Grok, or whatever the client prefers. Growww AI does not sell intelligence. It sells the architecture that makes that intelligence sovereign.

“Data sovereignty is not a limitation. It is the condition under which AI becomes possible at all for organizations operating under regulatory frameworks.” – Nikola Kočić

PaaS, Not an SaaS

Growww AI, available at growww.ai, is a PaaS platform that deploys directly onto a client’s local infrastructure. For organizations operating under strict regulatory frameworks, banks, public institutions, government agencies, the entire platform is installed within their environment. The model runs inside the firewall. Compute, storage, network, every byte that flows through the system stays where it has always been.

The business model is fundamentally different from what the SaaS industry offers. Growww AI charges a monthly license for access to its engineering core. Setup, agent training, and customization are part of the delivery. The client uses their own models in the background, whether that is OpenAI, Claude, Grok, or any other LLM that suits them. The platform is a vessel. The content is what the client puts into it.

Most AI platforms today charge by token consumption or by user count, and in that model the client implicitly pays to have their data pass through someone else’s infrastructure. Growww AI charges a license for the framework. Which model the client uses, how much they use it, how they configure it, that is their decision. The distinction matters because it inverts the power dynamic. The client owns the infrastructure, the data, the model, and the output. Growww AI provides the engineering layer that makes all of those work together securely.

“We did not build another product for the shelf. We built infrastructure for organizations that SaaS cannot serve.” – Nikola Kočić

Why the Middle East Is the Defining Market

The market that most clearly demonstrates why sovereign AI is not a niche but a necessity is the Middle East, and the United Arab Emirates in particular. The UAE has constructed one of the most rigorous regulatory frameworks for data protection anywhere in the world, and that framework is enforced with penalties that make non-compliance commercially fatal.

Federal Decree-Law No. 45 of 2021, known as the PDPL, is the foundational data protection law of the United Arab Emirates. Its key provision is unambiguous: personal data and confidential business data may not be transferred outside the jurisdiction without explicit approval from the regulator. Violators face fines of up to five million dirhams. This is not a recommendation. It is law that is enforced.

The Central Bank of the UAE has gone further. In its guidelines for financial institutions adopting emerging technologies, it explicitly requires that AI models be reliable, transparent, explainable, and subject to audit, with data retention of at least five years. All records pertaining to customers must be stored locally. In February 2026, the Central Bank launched a sovereign financial cloud, a dedicated infrastructure ensuring that data from financial institutions never leaves UAE territory.

The Dubai Data Law moves in the same direction. It mandates that all data generated by government bodies and regulated entities within the Emirate must be classified, managed, and shared exclusively within the framework defined by the Dubai Data Establishment. Classification covers four tiers: open, confidential, secret, and restricted. Each tier has its own regime for access, storage, and transfer. For confidential and secret data, cross-border transfer is possible only with prior approval and under strict conditions.

The National Electronic Security Authority, NESA, operates a sovereign cloud environment for classified workloads. The health sector, regulated by the Dubai Health Authority and the Department of Health Abu Dhabi, requires local storage of patient data. The Dubai International Financial Centre amended its data protection law in July 2025, expanding its territorial reach and enabling direct court actions. The Abu Dhabi Global Market adopted more precise data protection regulations in September 2025. Both financial centres introduced definitions for providers, operators, and users of AI systems, aligned with European standards but under local jurisdiction.

In June 2026, Sheikh Mohammed bin Rashid Al Maktoum established the Federal Authority for Artificial Intelligence and Data. This body coordinates AI strategy at the federal level, defines standards for AI implementation in the public sector, and oversees compliance with data law. It is not a research lab. It is a regulator with the authority to halt implementations that fail to meet sovereignty standards.

The UAE AI Strategy 2031 sets the goal of making the Emirates a global leader in artificial intelligence by the end of the decade. But that ambition is explicitly conditioned on data sovereignty. The strategy does not say “adopt AI.” It says “adopt AI in a manner that is controlled, transparent, and sovereign.” For companies selling AI solutions into this market, that is not a marketing message. It is a condition of entry.

The Evidence Is Already Here

Research conducted by McKinsey in its report on AI adoption in the Middle East shows that 73 percent of organizations in the region cite data security as the primary barrier to AI implementation, ahead of talent shortages and cost. Gartner, in its 2026 report on AI trends, identifies sovereign AI as one of ten strategic technologies, predicting that by 2028 more than 50 percent of government AI implementations will require local infrastructure. Deloitte, in its report on digital transformation across the GCC, concludes that data sovereignty is not merely a regulatory requirement but a competitive advantage for companies that can guarantee it.

The conclusion is straightforward. The Middle East will not adopt AI despite data sovereignty. It will adopt AI because data sovereignty exists. Every platform that cannot guarantee data stays within the borders of the Emirates, inside the institution’s firewall, under the client’s control, is disqualified before it enters the conversation. That is why Growww AI engine, with its architecture that installs into the client’s infrastructure, is the ideal solution for this market. Not because it is cheaper. Not because it is faster. Because it is the only approach that functions within the framework this market has defined.

“The Middle East does not adopt AI despite data sovereignty. It adopts AI because data sovereignty exists. That is the difference that defines who even enters the conversation in this market.” – Nikola Kočić

The Philosophy Behind the Architecture

Nikola Kočić did not arrive at this approach overnight

He has spent more than a decade building companies and driving sales across markets in Europe, the Middle East, and North America. Multiple successful businesses, several startup ventures, and deep operational experience in sectors where data confidentiality is not something discussed in marketing materials but a condition under which a system can be installed at all.

His approach to technology has always been pragmatic. You use what improves the result. But through all those years, every conversation about AI with a serious client ended at the same point. The technology was ready. The budget was there. The data could not leave the building.

The decision to build an engine that installs into the client, rather than another platform sold off the shelf, grew out of that frustration. Every organization he worked with wanted AI. Had budget for AI. But could not send data to a third-party cloud. Regulatory frameworks, audit requirements, internal security policies, all of it made the SaaS model impossible. It was not a matter of preference. It was a matter of permission.

“We did not build another product for the shelf,” Kočić explains. “We built infrastructure for organizations that SaaS cannot serve. Banks, public institutions, government agencies, enterprises operating under regulatory frameworks that make processing data at a third party impossible. Those are the organizations that will define the next phase of AI adoption. They do not need a finished product. They need a system that adapts to them, enters their infrastructure, and stays there.”

“The platform is a vessel

The content is what the client puts into it. We do not sell intelligence. We sell the architecture that makes that intelligence sovereign.” – Nikola Kočić

Why This Moment Is Different

The AI industry has exited the experimentation phase. Companies no longer want pilots. They do not want proof of concept. They want AI in production, integrated into operations, with a measurable result at the end of the month.

The barrier to that transition is not in the intelligence of the models. It is in the infrastructure. The organizations that will lead the next phase are not the ones with the most advanced models. They are the ones that can deploy those models securely, locally, and under their own control.

Sovereign AI is ceasing to be a niche and becoming the standard for every implementation where data confidentiality is not negotiable. The question is not whether this category will exist. It already does. The question is who will lead it and who will be first to build the verticals that solve concrete problems within it.

On a market that is increasingly defined by regulation rather than preference, Growww AI engine does not offer an option. It offers a condition. And that is the difference between a product that is sold and infrastructure that is installed.

“Dubai has built the regulatory framework that creates demand for sovereign AI. We built the engine that answers it.” “We did not build another product for the shelf. We built infrastructure for organizations that SaaS cannot serve.” – Nikola Kočić

Find out more:

Visit Growww AI engine: growww

ai

Contact Nikola Kočić, Founder, Growww AI on LinkedIn: linkedin.com/in/nikola-kocic-growww

Photography: Predrag Despotović

Related Stories