What Lebanese Banks Get Wrong About AI Governance
Hilda Maalouf Melki, Oxford-Certified AI Expert Lebanon and the Middle East | Chair, AI & Innovation Committee, Lions Clubs Int'l District 351— on the governance gaps that deployment speed is hiding
I spent twenty five years inside Lebanese banking and digital transformation before I moved into AI advisory work full time. That means I watched Lebanon’s financial sector navigate the consequences of weak governance long before artificial intelligence was part of any conversation. I understand, perhaps more concretely than most commentators on this subject, what it looks like when an institution confuses having a policy with having governance.
What I am seeing now, as an AI expert working across Lebanon and the Arab region, is that same pattern beginning to repeat itself in the AI context. Institutions are deploying AI tools, approving AI strategies, and in some cases already using AI in credit, compliance, and customer service without the governance infrastructure to manage what they are introducing.
I want to be specific about what I mean, because the word governance gets used loosely and that looseness is part of the problem.
Governance in the AI context is not a policy document. It is the set of living structures that determine, on a continuous basis, how AI decisions get made, who is accountable for them, and what happens when they produce outcomes that were not anticipated.
What does AI governance actually mean for a bank?
Governance in the AI context is not a policy document. It is not a committee that meets quarterly to review an AI dashboard. It is the set of living structures that determine, on a continuous basis, how AI decisions get made, who is accountable for them, how they get audited, and what happens when they produce outcomes that were not anticipated.
For a bank in Lebanon, that means several things that most institutions in the sector have not yet addressed seriously.
It means knowing, with precision, which decisions inside your institution are currently being influenced by algorithmic systems and which human beings are accountable for reviewing and overriding those decisions when necessary. It means having an audit trail for AI outputs that is as rigorous as the audit trail you maintain for any other regulated decision. It means having an ethics boundary defined in writing, reviewed by the board, and enforced operationally, not just cited in a sustainability report.
And perhaps most importantly for the Lebanese context specifically, it means having a clear answer to the question of what happens to the AI system and the data it operates on under conditions of institutional stress. Lebanese banks have experienced, within recent memory, conditions that stress tested governance frameworks that many assumed were robust. AI governance needs to be built with the same honest accounting of risk.
Where are the gaps I see most often?
The most common gap is the absence of a clear owner for AI governance at the board level. In most Lebanese banks I encounter in my advisory work, AI is being driven by the technology function or, increasingly, by business development. Governance typically follows technology ownership, which means it ends up sitting with people whose primary incentive is deployment speed rather than risk management. That is not a criticism of those individuals. It is a structural design flaw.
The second gap is the absence of explainability requirements for AI outputs that affect customers. If a credit algorithm influences a lending decision, can the bank explain to the customer, in plain language, the basis for that decision? Under emerging regulatory frameworks across the Arab region, including developing frameworks in Lebanon, the Gulf, and Egypt, this is not a nice to have. It is becoming a legal requirement. Most institutions are not yet building for it.
The third gap is data governance preceding AI governance. Before you can govern an AI system responsibly, you have to govern the data it trains on. In the Lebanese banking sector, where data architecture has historically been fragmented across legacy systems, this foundational requirement is frequently the one that gets skipped because it is unglamorous, expensive, and does not produce a visible output that looks like innovation.
What should Lebanese banks actually do?
The honest answer is that the sequence matters as much as the substance.
Establish board level accountability for AI governance before you scale any AI deployment. Not a subcommittee. A named executive with a defined mandate and reporting line to the board.
Conduct an honest audit of every AI or algorithmic tool currently operating inside the institution, including tools that were not originally classified as AI, such as credit scoring models, fraud detection systems, and customer segmentation tools. Understand what they are doing, what data they use, and who is accountable for their outputs.
Build explainability into AI procurement as a non negotiable requirement. If a vendor cannot tell you how their system produces its outputs in terms your compliance and legal teams can work with, that vendor is not yet ready for regulated environments.
And create a governance framework that is reviewed and updated at least annually, not filed after the initial deployment and revisited only when something goes wrong.
Lebanese banks have a genuine opportunity to build AI governance frameworks that are appropriate for their specific context, their regulatory environment, and the trust relationships they maintain with their customers. But that opportunity closes quickly as deployment outpaces governance. The time to build the structure is before the deployment reaches a scale where correcting it becomes operationally disruptive.
I write about AI governance for Arab region institutions every week here. You can explore more of my thinking on this subject at hildamaaloufmelki.com, and in my book AI Simplified at www.hildamaaloufmelki.com/signature-book.

