What We Do

Nuhaa AI engages across three layers — Advisory, Delivery, and Products and Enablement — designed to move with a client from first strategic conversation to sustained production capability. Each layer is designed to compound the value of the one that came before it.

Every engagement is scoped, priced on a fixed-fee basis, and structured with named deliverables and measurable outcomes. We do not sell billable hours. We do not engage in open-ended retainers without defined scope. And we do not start with implementation before we have done the diagnostic work that earns the right to implement.

Layer 01

Land — Advisory

AI creates enterprise value only when it is deployed with the clarity of strategic intent, the discipline of governance, and the accuracy of regulatory awareness. The Land layer is where that clarity is built. We work at board and C-suite level, combining structured diagnostic methodology with deep familiarity with the Kingdom's regulatory landscape, to produce an honest, evidence-based picture of where the organisation stands — and a roadmap that is credible enough to act on.

The Nuhaa AI Readiness Diagnostic

Our primary entry point. A structured five-dimensional assessment — covering Strategic Vision, Value Logic, Architecture and Scaling Capacity, Governance and Sovereignty, and Capability and Talent — conducted through leadership interviews, document review, and targeted technical inspection. Delivered as a signed Readiness Report with dimensional scoring, regulatory posture analysis, and an eighteen-month prioritised roadmap.

Typical engagement: six to eight weeks. Fixed fee. Available in Express (three weeks) and Full formats. Delivered bilingually on request.

Governance Architecture

For organisations that have a clear AI strategic direction but lack the governance infrastructure to execute it safely. We design the AI governance framework, risk taxonomy, decision-rights model, and board reporting structure — mapped specifically to the client's regulatory obligations and sector context (SAMA for financial services, NCA ECC for critical entities, PDPL for all).

Typical engagement: four to six weeks. Fixed fee. Delivered as a governance charter and operating model, ready for board approval.

Regulatory Posture Review

A focused diagnostic for organisations preparing for or responding to regulatory scrutiny of their AI activities. Maps existing and planned AI workloads against PDPL, applicable sector regulation, and data-residency requirements. Produces a gap analysis and remediation sequence.

Typical engagement: two to four weeks. Fixed fee.

Layer 02

Build and Run — Delivery

The Advisory layer surfaces what to build. The Delivery layer builds it — and then operates it. These are not separate engagements grafted together; they are a single continuous service designed so that what we build, we can run, and what we run, we can govern. The result is AI that stays in production, stays compliant, and stays under management.

Build — AI Engineering and Implementation

We build production-grade AI systems using sovereign-capable architecture. Our engineering work is organised around named, reusable delivery systems — Deployment Kits — that encode the lessons of prior engagements into a repeatable methodology. This is not bespoke development from a blank canvas; it is disciplined engineering with named patterns, tested security architecture, and documented governance integration.

Core Build capabilities: — Sovereign RAG systems: retrieval-augmented generation over internal enterprise knowledge, deployed within the client's data-residency boundary. — Agentic workflow development: custom AI agents for defined operational workflows, with human-in-the-loop oversight architecture. — Data pipeline engineering: structured data flows with lineage, quality control, and governance integration. — Model fine-tuning and evaluation: adaptation of foundation models to client-specific domains, with documented performance baselines. — Enterprise system integration: AI layer connected to core systems through documented, auditable API architecture.

Typical engagement: twelve to twenty weeks. Fixed-price, milestone-based.

Run — Managed AI Operations

Production AI is not a project. It is an ongoing operational responsibility. Models drift. Prompts degrade. Regulatory environments change. An AI system that was performing correctly when deployed may not be performing correctly six months later — and in a regulated enterprise, the organisation is accountable for that difference.

Nuhaa's Managed AI Operations service provides ongoing, structured oversight of production AI workloads. A retainer engagement with defined SLAs, monthly reporting, and a named Nuhaa operations lead.

MAOps coverage includes: — 24/7 system monitoring and incident response for production AI workloads. — Model performance tracking, drift detection, and remediation. — Prompt governance: version control, change management, and regression testing. — Red-teaming and adversarial testing on a defined periodic schedule. — PDPL and sector-specific compliance monitoring, with documented audit trails. — Monthly performance report delivered to the client's AI governance owner.

Minimum engagement: twelve months.

Layer 03

Scale — Products and Enablement

The third layer converts delivery into enterprise capital. It is the difference between an organisation that has implemented AI and an organisation that has become AI-native. The products and programmes in this layer are designed to compound the value of what the first two layers built — and to ensure that capability is owned by the organisation, not dependent on a consulting relationship.

Nuhaa Sovereign Intelligence Platform

A managed, multi-tenant AI environment designed for regulated enterprises operating within Saudi Arabia's data-residency boundaries. The Platform provides a governed infrastructure layer for AI workloads — so that organisations can deploy, monitor, and scale AI capabilities without building and maintaining the entire infrastructure themselves.

The Platform is in active development. Design partners — organisations participating in the early-access programme — receive preferred commercial terms, direct input into the product roadmap, and a reference partnership with Nuhaa AI. Organisations interested in the design partnership programme should note this in their executive briefing request.

Executive Education and Saudi AI Talent

The organisations that sustain AI capability over years are the ones that build it internally. Nuhaa's executive education programmes develop the AI fluency and strategic judgment of leadership teams — to produce executives who can evaluate AI proposals, govern AI systems, and lead AI-enabled organisations with confidence.

We also work with organisations on their Saudi AI talent strategy: Saudization targets for AI roles, graduate pipeline development, and partnerships with SDAIA, HRSD, and Kingdom universities.

The engagement model

Every Nuhaa engagement follows a consistent four-step structure. Steps may be compressed or expanded depending on context, but the sequence is never skipped.

Step 01

Meeting

A 45-minute conversation, complimentary, with Nuhaa's founding team. Tailored to the client's sector, regulatory context, and immediate priorities. No slide decks. No sales material. A conversation.

Step 02

Readiness Diagnostic

Either the Express (three-week) or Full (six-to-eight-week) version. Establishes the evidence base for all subsequent work and produces the roadmap that defines the scope of Layers 2 and 3.

Step 03

Build and Run

Implementation of the highest-value initiatives identified in the Diagnostic. Followed by the MAOps retainer to keep the system governed and performing.

Step 04

Scale

Platform access and talent programmes introduced as the organisation's AI capability matures, converting a successful Build and Run engagement into lasting enterprise value.

Scope limits

Clarity about scope is part of the service. There are categories of work Nuhaa AI does not engage in.

  • 01We do not resell hyperscaler technology. We are not an AWS, Azure, or Google Cloud reseller. Our recommendations are vendor-neutral.
  • 02We do not provide body-shop staffing. Our engagements have named outcomes, fixed fees, and accountable delivery leads.
  • 03We do not engage in open-ended advisory retainers without scope. If we are in an ongoing relationship, there is a defined scope and a defined review cycle.
  • 04We do not build or deploy AI for harmful, surveillance, or legally non-compliant purposes. This is not a legal caveat; it is a founding principle.
  • 05We do not take engagements where we cannot deliver to institutional standard. If a mandate requires capabilities we do not currently have, we will say so.

Exploring a sovereign AI mandate?

A 45-minute executive briefing tailored to your institutional context.