VOCE Balkans, Africa & Middle East

VOCE Balkans, Africa & Middle East VOCE is a research-led platform exploring how digital environments reshape attention, emotional regulation and human connection.

VOCE - Academy of Invisible Realities
AI • Human Behaviour • Digital Health • Cognition
Museums • Cultural Heritage • Technology • APIs
Applied Research • Training • Seminars • Independent Media
Europe • Balkans • GCC
Born from Romain’s legacy At the intersection of cognitive science, mental health and creative expression, VOCE translates complex scientific and clinical insights into accessible programs, content and experiences designed for high-performance and cultural environments . Through VOCE Association, the initiative develops research, educational programs and public awareness around technoference, emotional health and relational dynamics in the digital age. In parallel, VOCE Media operates as a content platform, producing narratives, essays and visual formats that bring clarity to the psychological and cultural impact of constant digital stimulation. VOCE is currently expanding its presence across Montenegro, Dubai and Casablanca, building a network of strategic locations where research, content and experiential formats can be deployed within international, high-demand environments. The ambition is simple and sharp, to restore clarity, strengthen emotional resilience and rebuild meaningful human connection in a world where attention is increasingly fragmented.

02/10/2026

Une IA peut produire une explication parfaitement convaincante tout en dissimulant les facteurs qui ont réellement déterminé sa réponse.

Ce phénomène est désormais mesurable.

En avril 2025, Katie Matton, Robert Osazuwa Ness, John Guttag et Emre Kiciman présentent à l'ICLR une recherche de Microsoft consacrée à la fidélité des explications produites par les LLM.

Leur méthode consiste à modifier des concepts présents dans les données d'entrée, puis à mesurer leur influence causale sur les réponses à l'aide d'un modèle bayésien hiérarchique.

Les expériences révèlent des situations dans lesquelles les explications dissimulent l'influence de biais sociaux. Dans des tâches médicales, les modèles attribuent parfois leurs conclusions à des éléments qui n'ont pas réellement déterminé leurs réponses.

Le problème dépasse la simple hallucination. Un système peut produire une justification cohérente sans restituer fidèlement son mécanisme de décision.

En juillet 2026, Harry Mayne et ses collègues publient à l'ICML une étude portant sur 18 modèles, dont GPT-5.2, Gemini 3 et Claude 4.5, évalués sur 7.000 situations contrefactuelles.

Les explications permettent d'améliorer la prédiction du comportement des modèles, avec un gain NSG compris entre 11 et 37 %. Mais, selon les modèles évalués, 5 à 15 % des auto-explications sont gravement trompeuses.

Une explication peut donc être utile sans constituer une preuve suffisante.

À l'ACL 2026, Bar Alon, Itamar Zimerman et Lior Wolf proposent une méthode baptisée Faithful Serum.

Elle utilise des cartes d'attribution au niveau des tokens et des interventions sur l'attention pour orienter la génération des explications vers les éléments effectivement influents. Des tests contrefactuels permettent d'en évaluer la fidélité.

La méthode améliore les résultats expérimentaux sans garantir une transparence causale exhaustive.

Pour une banque, un recruteur ou une administration, cette distinction est fondamentale.

Un rapport généré par un LLM ne certifie ni les facteurs réellement utilisés par un système de scoring ni l'absence de discrimination. Des variables apparemment neutres, comme un code postal, peuvent également servir de substituts à des caractéristiques protégées.

Une gouvernance sérieuse doit pouvoir confronter la justification aux données, au modèle et à la trajectoire effective de la décision.

ULTRA®

L'architecture de la contestabilité

L'explicabilité opérationnelle exige une chaîne de preuves indépendante de la génération linguistique.

Chaque décision sensible doit pouvoir être rattachée à une version du modèle, aux données effectivement utilisées et aux interventions humaines documentées.

Les méthodes SHAP, les analyses contrefactuelles et les tests de sensibilité apportent des éléments complémentaires. Leurs hypothèses et leurs limites doivent rester vérifiables. Aucune méthode isolée ne démontre l'absence de discrimination.

Les écarts entre groupes, notamment les taux de faux positifs et de faux négatifs, doivent être examinés en fonction du contexte et des conséquences des erreurs.

La contestabilité ajoute une exigence institutionnelle: conserver les éléments nécessaires pour qu'une personne puisse comprendre une décision, signaler une erreur et obtenir un réexamen effectif.

L'article 86 de l'AI Act prévoit, dans les cas relevant de son champ, un droit à une explication claire et pertinente. L'article 22 du RGPD prévoit également des garanties de contestation et d'intervention humaine dans certaines situations de décision entièrement automatisée.

PORTIA, dans Le Marchand de Venise d'André Tchaikowsky, maîtrise admirablement l'argumentation juridique. Mais sa position personnelle dans le procès interroge son impartialité.

Le pouvoir devient difficile à contester lorsque celui qui décide contrôle aussi le récit de sa décision.

Sources

Matton et al., ICLR 2025 ; Mayne et al., ICML 2026
Alon et al., ACL 2026 ; AI Act, art. 86 ; RGPD, art. 22

25/09/2026

For generations, cancer was named primarily by where it appeared. Breast, lung, colon, gallbladder: anatomy largely determined where oncologists looked for treatment.

As precision oncology expands across the GCC, another map is increasingly being placed over the anatomical one.

A South Korean study published on 22 September 2026 in "Nature Medicine" shows how far that shift may go.

HERBOT enrolled 40 patients with advanced HER2-positive biliary tract cancer across 12 university centres. Twenty-nine had gallbladder cancer.

HER2 is much better known because of its role in some breast cancers. Yet approximately 15% of biliary tract cancers show HER2/ERBB2 overexpression or amplification.

The researchers therefore chose not to wait until later lines of therapy to exploit that molecular characteristic.

From first-line treatment, patients received trastuzumab targeting HER2, nivolumab blocking PD-1, and gemcitabine plus cisplatin.

The biological logic extends beyond simply combining drugs.

HER2 is a receptor involved in signalling pathways that can promote tumour growth when overexpressed or amplified. Trastuzumab binds to it and interferes with that biology, but antibody binding can also help immune effector cells recognise HER2-expressing cancer cells.

Nivolumab acts elsewhere in the system. By blocking the PD-1 immune checkpoint, it attempts to release one of the brakes limiting antitumour immune responses.

HERBOT therefore tested whether a molecular vulnerability and immune activation could be exploited together while chemotherapy attacked the tumour through another mechanism.

Among the 40 patients, 22 achieved an objective response.

That is 55%.

One response was complete and 21 were partial. Disease control reached 95%. Median duration of response was 12.6 months, while median progression-free survival was 10.6 months.

After a median follow-up of 17 months, median overall survival had not yet been reached.

For GCC cancer centres investing in genomic profiling, molecular pathology and immuno-oncology, however, one of the most tangible findings involved only two patients.

Both had initially been considered inoperable.

After several months of treatment, their tumours responded sufficiently for surgery with curative intent to become possible.

A molecular characteristic observed in tumour tissue had contributed to changing what a surgeon could eventually attempt.

That is precision oncology in unusually concrete form.

The biopsy did not merely refine the name of the disease.

It altered the therapeutic path.

HERBOT also suggests that even the label "HER2-positive" may eventually prove too crude.

Using digital analysis of histological slides, researchers measured the actual proportion of tumour cells showing strong HER2 expression.

When at least 10% of cells were HER2 3+, the objective response rate reached 80%.

Below that threshold, it was 40%.

This analysis was exploratory and should not be treated as a validated clinical decision rule.

But it points towards a deeper problem for precision medicine.

A therapeutic target may not simply be present or absent.

Its distribution within the tumour may matter.

For the Gulf, this is where the convergence of molecular pathology, digital histology and AI could become particularly consequential. The future diagnostic question may not stop at identifying a mutation or receptor. Computational pathology can increasingly help quantify where a biomarker appears, how strongly it is expressed and how heterogeneous its distribution is across tissue.

The tumour becomes less like a label and more like a spatial biological system.

HERBOT nevertheless requires considerable caution.

The trial included only 40 patients and had no control group. Gallbladder cancers dominated the cohort, and overall-survival data remain immature.

The study therefore cannot establish that adding trastuzumab improves survival compared with current standard treatment.

The cost of treatment intensification is also visible.

Grade 3 or higher neutropenia occurred in 57.5% of patients.

Randomised trials will now need to determine whether the signal observed in South Korea translates into a genuine therapeutic advance.

For GCC oncology programmes, that distinction matters. Precision medicine should not mean adopting every molecularly sophisticated combination as soon as a promising response rate appears.

It means building the infrastructure capable of identifying the right tumour biology, testing it accurately, connecting it to evidence and changing treatment only when that evidence justifies the change.

Yet HERBOT already illustrates something larger.

Saudi Arabia, the UAE, Qatar and other Gulf health systems are investing in genomics and precision medicine at a moment when the definition of cancer itself is becoming more layered.

The anatomical address remains essential. A gallbladder tumour is still biologically and clinically shaped by the organ in which it developed.

But anatomy is becoming only one coordinate.

Another is molecular.

And sometimes that second coordinate can reopen a door the first one appeared to have closed.

ULTRA®

THE SECOND MAP OF CANCER

Medicine taught generations of patients to understand cancer as a geography of the body: breast, lung, liver, gallbladder. Precision oncology adds a second, invisible map made of receptors, genomic amplifications and biological signatures. HER2 shows why this matters for GCC cancer medicine. The same molecular alteration can become therapeutically relevant across different organs, while two tumours originating in the same organ may no longer justify exactly the same strategy. This also changes the psychological representation of disease. The question becomes not only "Where is my cancer?" but "What biological feature makes it vulnerable?" In HERBOT, that information went further: for two patients initially considered inoperable, response to molecularly informed treatment reopened the possibility of surgery with curative intent.

ARIADNE

We sometimes believe escape depends on finding the end of the labyrinth. Sometimes it begins with discovering the thread that finally makes the labyrinth readable.

Sources

"Nature Medicine", 22 September 2026

HERBOT, KCSG-HB23-05

ClinicalTrials.gov, NCT05749900

Korean Cancer Study Group



中文摘要 | VOCE GCC

# 海湾正在重新绘制癌症地图:肿瘤发生在哪个器官,已经不再是完整的诊断

很长时间里,人类首先按照解剖位置理解癌症。

乳腺癌、肺癌、结肠癌、胆囊癌。肿瘤出现在哪里,基本决定医生应该进入哪一套治疗体系。

如今,随着Saudi Arabia、UAE、Qatar以及整个GCC加速建设精准肿瘤学、基因组医学和分子诊断能力,这张传统的身体地图正在叠加第二张地图。

它肉眼看不见。

它由受体、基因扩增和肿瘤生物学组成。

2026年9月22日,"Nature Medicine"发表的一项韩国研究HERBOT,让这种变化变得非常具体。

研究在12家大学医疗中心纳入40名HER2阳性的晚期胆道癌患者,其中29人患胆囊癌。

HER2最广为人知的临床角色来自部分乳腺癌。然而,大约15%的胆道癌同样存在HER2/ERBB2过度表达或基因扩增。

研究人员因此提出一个重要问题:如果这种分子弱点已经存在,为什么一定要等到前面的治疗失败以后才利用它?

HERBOT从一线治疗就开始攻击HER2。

患者接受针对HER2的曲妥珠单抗,同时使用阻断PD-1的纳武利尤单抗,并联合吉西他滨和顺铂化疗。

这里真正值得理解的是几种机制怎样相遇。

HER2是一种参与细胞生长信号传导的受体。当它过度表达或扩增时,可以推动肿瘤生长。曲妥珠单抗与HER2结合,不仅干扰相关信号,还可能帮助部分免疫效应细胞更容易识别表达HER2的癌细胞。

纳武利尤单抗则从另一个方向介入,通过阻断PD-1这个免疫检查点,解除限制抗肿瘤免疫反应的一部分"刹车"。

HERBOT因此不是简单地增加药物,而是在尝试同时利用肿瘤的分子弱点和免疫系统。

40名患者中,22人出现客观缓解,缓解率达到55%。

其中1人完全缓解,21人部分缓解,疾病控制率达到95%。缓解持续时间中位数为12.6个月,无进展生存期中位数为10.6个月。

在中位随访17个月时,总生存期中位数尚未达到。

但对于正在建设精准肿瘤医学体系的GCC而言,研究中最具体的数字也许不是55%,而是2。

两名患者最初被认为无法手术。

经过数月治疗后,肿瘤缩小到足以重新考虑手术,而且手术目标是根治。

这意味着一项最初只存在于活检组织中的分子信息,最终改变了外科医生能够做什么。

分子诊断不再只是给癌症增加一个更复杂的名字。

它开始改变治疗路径。

HERBOT还发现,甚至"HER2阳性"这个标签本身都可能过于粗糙。

研究人员利用数字化病理图像分析,测量真正呈现强HER2表达的肿瘤细胞比例。

当至少10%的肿瘤细胞达到HER2 3+强表达时,客观缓解率达到80%。

低于这一比例时,缓解率为40%。

这一结果仍然属于探索性分析,不能直接成为临床决策标准。

但它揭示了精准医学下一阶段可能面对的问题。

一个治疗靶点并不一定只是"存在"或者"不存在"。

它在肿瘤内部出现在哪里、有多少细胞表达、表达强度如何,以及分布是否均匀,都可能具有意义。

这也是GCC投资数字病理和AI可能真正发挥价值的地方。

未来的病理诊断不会只问有没有某个受体或突变。

数字化组织切片结合计算分析,可以逐渐帮助医生量化生物标志物的表达强度、空间分布以及肿瘤内部的异质性。

癌症因此不再只是一个标签。

它越来越像一个具有空间结构的生物系统。

但HERBOT远远没有证明问题已经解决。

研究只有40名患者,没有对照组,而且队列主要由胆囊癌构成。总生存数据仍不成熟,因此目前无法证明加入曲妥珠单抗比现行标准治疗真正延长生存。

强化治疗本身也有代价。

57.5%的患者发生3级或以上中性粒细胞减少。

接下来仍然需要随机对照试验,才能确定韩国观察到的信号是否真正转化为治疗进步。

对于Gulf health systems,这种谨慎尤其重要。

精准医疗不能意味着看到一个漂亮的分子靶点和一个令人印象深刻的缓解率,就立即采用更加复杂的治疗。

真正的精准,需要能够准确识别肿瘤生物学,把它与可靠证据连接起来,然后只在证据足以支持时改变治疗。

ULTRA®

癌症正在出现第二张地图

几代人通过身体地理学习癌症:乳腺、肺、肝脏、胆囊。精准肿瘤学正在增加一张看不见的地图,它由受体、基因扩增和生物学特征构成。

HER2解释了为什么这对GCC肿瘤医学如此重要。同一种分子异常可以在不同器官中成为治疗靶点,而两个生长在同一器官的肿瘤,也可能因为分子特征不同而不再适合完全相同的治疗策略。

这种变化甚至会改变患者理解疾病的方式。问题不再只是"我的癌症在哪里?",而开始变成"它有什么特征,可以成为治疗能够利用的弱点?"

HERBOT中,这种分子信息最终为两名原本被认为无法手术的患者重新打开了根治性手术的可能。

ARIADNE

我们有时以为,走出迷宫需要先找到出口。其实,有时真正改变一切的,是终于找到那根让迷宫变得可以阅读的线。

#沙特阿拉伯 #阿联酋 #卡塔尔 #癌症 #胆囊癌 #精准肿瘤学 #基因组医学

25/09/2026

Across the GCC, ISO/IEC 42001 is beginning to appear in AI procurement, governance programmes and conversations between technology providers, boards and institutional buyers.

A company obtains ISO/IEC 42001 certification.

The conclusion is tempting:

Its AI has been audited.

Not exactly.

ISO/IEC 42001 is a management-system standard. It establishes requirements for how an organisation creates, maintains and continually improves an AI management system.

It can provide evidence that governance responsibilities, processes and controls have been organised within a defined certification scope.

It does not, by itself, certify that a particular language model, agent or AI application is accurate, safe or technically effective.

For GCC organisations procuring AI for government, financial services, energy, healthcare, aviation or large corporate groups, that distinction is fundamental.

A governance system and an AI system are not the same object.

The ISO architecture itself increasingly makes this separation visible.

On 7 July 2025, ISO published ISO/IEC 42006.

This standard adds requirements for bodies auditing and certifying AI management systems based on ISO/IEC 42001.

The significance is easy to miss.

ISO is no longer standardising only how organisations govern AI.

It is also establishing requirements for organisations that claim to certify that governance.

There is a reason.

Auditing AI governance cannot be reduced to checking whether a policy document exists.

An auditor needs appropriate competence to examine how an organisation handles AI-specific risks, data, transparency, responsibilities, controls and evidence that those controls actually operate.

For GCC boards, regulators, procurement teams and investment committees, this creates a useful distinction between possessing governance documentation and possessing an independently assessed management system.

Then another layer appears.

In August 2026, ISO/IEC DIS 42007 entered the enquiry stage. The draft concerns conformity-assessment schemes for AI systems themselves.

Meanwhile, ISO/IEC TS 42119-2:2025 already addresses testing of AI systems through a risk-based approach.

The architecture is becoming clearer.

ISO/IEC 42001 asks whether an organisation has a management system capable of governing AI responsibly within its defined scope.

That does not automatically answer a different question:

Does this specific AI system actually perform as required?

Imagine a GCC bank procuring an AI agent capable of interacting with customer information, or a healthcare group evaluating a clinical AI application.

The supplier may possess ISO/IEC 42001 certification.

That is relevant evidence.

But it does not, by itself, demonstrate the accuracy of the agent's outputs, robustness against particular failures, cybersecurity of a deployment, effectiveness of human oversight or suitability for that specific use case.

Those claims require evidence at the system level.

This matters particularly as Gulf organisations move from generative-AI pilots towards agents capable of taking actions inside operational systems.

An organisation may have excellent AI governance processes while an individual system still performs poorly.

The reverse problem can also exist: an impressive technical model can sit inside an organisation with weak governance, unclear accountability or inadequate monitoring.

Mature AI assurance needs to distinguish both layers.

For procurement, this changes the question.

"Are you ISO 42001 certified?" remains useful.

It simply cannot be the final question.

A GCC buyer should understand what legal entity and organisational scope were certified, which activities and AI-related processes fall within that scope, what system-level testing has been performed, what risks were evaluated and what technical evidence supports the claims being made about the product being purchased.

The same distinction matters in board reporting.

A green box marked "ISO 42001 certified" should not silently become shorthand for "our AI systems have been technically validated".

Those statements mean different things.

The analogy is familiar from other industries.

A manufacturer's quality-management system can be certified.

That does not mean every individual product leaving the factory has automatically passed every test required for its intended use.

For the GCC, where AI assurance is becoming part of sovereign technology, procurement and institutional risk management, precision in this language matters.

Certification can demonstrate governance capability.

System testing can provide evidence about system behaviour.

Conformity assessment can establish whether defined requirements have been met.

The mistake is not using ISO 42001.

The mistake is asking it to prove something it was never designed to prove.

ULTRA®

THE CERTIFICATE HAS A SCOPE. SO SHOULD THE QUESTION.

The emerging ISO architecture separates different layers of AI assurance. ISO/IEC 42001 addresses the AI management system. ISO/IEC 42006 establishes requirements for bodies auditing and certifying those management systems. ISO/IEC TS 42119-2:2025 addresses risk-based AI-system testing. ISO/IEC DIS 42007, still a draft, moves towards conformity-assessment schemes for AI systems themselves. For GCC procurement, "Are you ISO 42001 certified?" is therefore only the beginning. Buyers should establish the certification scope, the AI activities it covers, which deployed systems have actually been tested, against which requirements, using which methods and with what technical evidence. A management-system certificate can demonstrate governance capability. It does not automatically demonstrate the quality of every AI system deployed under it.

VOCE AI GOVERNANCE INSTITUTE

Good governance can be certified. The behaviour of a particular machine still has to be demonstrated.



中文摘要 | VOCE GCC

VOCE AI GOVERNANCE INSTITUTE

# 你的企业获得了ISO 42001认证。你的AI并没有因此自动获得认证。

在Saudi Arabia、UAE、Qatar以及整个GCC,ISO/IEC 42001正在越来越频繁地出现在AI procurement、enterprise governance以及board-level discussions中。

一家technology provider告诉buyer:

"We are ISO 42001 certified."

很容易产生一个自然的理解:

这家公司的AI已经被audit过了。

但这并不是ISO/IEC 42001真正证明的事情。

ISO/IEC 42001是一项AI management-system standard。

它关注的是organisation如何建立、实施、维护并持续改善自己的AI management system,包括responsibilities、risk management、governance processes、controls以及相关documentation。

换句话说,它认证的核心对象是organisation怎样管理AI。

它并不会仅仅因为company取得certificate,就自动证明某一个LLM、agent或者AI application本身准确、安全、robust或者适合某个具体use case。

对于GCC,这个区别非常重要

Gulf organisations正在把AI从experiments带入真正的operational systems。

Government services开始使用AI。

Banks探索agents。

Healthcare systems评估clinical applications。

Energy、aviation、hospitality以及large corporate groups都在考虑怎样把generative AI连接到真实data与workflows。

因此,当supplier拿出ISO 42001 certificate时,procurement team需要知道它究竟证明什么。

它可以证明organisation在某个defined scope内建立了经过assessment的AI management system。

但它不能单独回答:

这个specific AI system到底表现怎样?

ISO自己的standard architecture正在把这种区别变得越来越清楚

2025年7月7日,ISO发布ISO/IEC 42006。

这项standard并不是另一个AI model benchmark。

它针对的是audit和certify ISO/IEC 42001 management systems的certification bodies。

这一步非常重要。

ISO不仅开始规范organisation怎样govern AI。

它也开始规定:

谁有资格评估这种governance,以及这种certification process本身应该满足什么requirements。

原因并不复杂。

真正的AI governance audit不能只是检查company有没有一份policy。

Auditor还必须理解AI-specific risks、data、transparency、responsibilities、controls,以及这些controls是否真正运行。

拥有document与拥有operational governance system并不是同一件事。

然后,ISO体系又增加了一层

2026年8月,ISO/IEC DIS 42007进入enquiry stage。

这个draft开始关注AI systems本身的conformity-assessment schemes。

与此同时,ISO/IEC TS 42119-2:2025已经针对AI-system testing提供risk-based guidance。

于是整个structure开始变得清楚。

ISO/IEC 42001主要回答:

Organisation有没有能力系统地govern AI?

ISO/IEC 42006进一步回答:

负责audit和certify这种management system的机构应该满足什么requirements?

ISO/IEC TS 42119-2关注:

AI system应该怎样根据risk进行testing?

而仍处于draft阶段的ISO/IEC 42007,则进一步走向AI systems本身的conformity assessment。

这些问题互相关联。

但它们绝不是同一个问题。

想象一家GCC bank采购一个能够接触customer data并执行actions的AI agent

Vendor拥有ISO 42001 certification。

这是有价值的evidence。

但bank仍然需要知道这个agent在自己的deployment中表现怎样。

它的accuracy是多少?

面对异常inputs时是否robust?

Permissions是否真正限制agent可以执行的actions?

Cybersecurity怎样验证?

Human oversight在什么情况下介入?

Failure怎样被detected?

Logs是否足够支持audit?

Model或者underlying system更新以后,testing是否重新进行?

这些都不能仅仅从organisation-level management certificate中推导出来。

Healthcare中的区别更加明显

一个healthcare AI provider可以拥有成熟的AI management system。

但这不能自动证明某一个clinical model对于特定patient population具有足够performance。

同样,一个技术表现非常优秀的model,也可能被部署在一个accountability模糊、monitoring不足或者change management薄弱的organisation中。

真正成熟的AI assurance必须同时看到两层:

Organisation怎样govern。

System实际上怎样behave。

因此,GCC procurement的问题需要升级

"Are you ISO 42001 certified?"

仍然值得问。

但它应该成为conversation的开始,而不是结束。

Buyer还需要确认certificate覆盖的是哪个legal entity和organisational scope,哪些AI activities真正位于certification boundary内,正在采购的specific system接受过什么testing,测试针对哪些risks和requirements,以及vendor能够提供什么technical evidence。

这对Gulf boards同样重要。

Dashboard上一个绿色的"ISO 42001 certified"不能悄悄被理解成:

"Our AI systems have been technically validated."

这两句话并不等价。

可以把它理解成制造业中的一个熟悉区别

Manufacturer拥有经过certification的quality-management system。

这说明它具有系统管理quality的能力。

但这并不意味着factory生产出来的每一个individual product都自动通过了所有与specific intended use相关的tests。

AI也是如此。

Management-system certification证明一种organisational capability。

System testing证明特定machine behaviour。

Conformity assessment则针对defined requirements建立另一层evidence。

对于正在把AI assurance纳入sovereign technology、enterprise procurement和institutional risk management的GCC,这种语言上的precision非常重要。

真正的问题从来不是ISO 42001有没有价值。

它当然有价值。

问题是不要要求一张management-system certificate证明它从来没有声称能够证明的东西。

ULTRA®

Certificate有Scope。Procurement Question也应该有。

正在形成的ISO ecosystem把AI assurance拆成不同层次。ISO/IEC 42001关注AI management system;ISO/IEC 42006规定audit和certify这些management systems的机构需要满足什么要求;ISO/IEC TS 42119-2:2025进入risk-based AI-system testing;仍处于draft阶段的ISO/IEC DIS 42007则走向AI systems自身的conformity-assessment schemes。

因此,对于GCC procurement,"你们是否ISO 42001 certified?"只能是第一问。

还需要确认certification scope、覆盖哪些AI activities、specific deployed systems是否真正经过testing、针对什么requirements、采用什么methods,以及有哪些technical evidence。

Management-system certificate可以证明governance capability。

它不会自动证明旗下每一个AI system的quality。

VOCE AI GOVERNANCE INSTITUTE

良好的治理可以被认证。但一台具体机器怎样表现,仍然必须被证明。

#人工智能治理 #沙特阿拉伯 #阿联酋 #卡塔尔

25/09/2026

A marketing manager in Dubai opens an SEO dashboard.

A page is losing visibility in generative search. The manager retrieves the data, moves to a social-media platform, prepares a post, then opens the CRM to identify the people who engaged with it.

The workflow looks entirely digital.

Yet much of the work still consists of a human moving information between software interfaces.

On 23 September 2026, Positive Group changed that architecture by opening three of its products to AI agents through Model Context Protocol, MCP.

Positive Surfer, Positive Iconosquare and Positive Signitic now operate active MCP servers. Users can connect them to Claude, ChatGPT, Copilot or Positive's own Uma and ask the model to access their data and functions directly.

This is not simply a chatbot placed on top of SaaS.

Surfer can expose SEO audits, keyword analysis and competitive visibility in AI-generated answers. Iconosquare can analyse social performance, benchmark competitors and schedule publications. Signitic exposes signature management, brand-compliance controls and banner campaigns.

For GCC marketing teams managing multilingual brands, hospitality groups, luxury portfolios, retail networks or regional operations across several markets, the important change is where the work begins.

The user can ask which pages have lost visibility, receive the analysis inside the conversation, prepare the corresponding content and request publication without necessarily opening the underlying dashboards.

MCP becomes a standardised layer between the assistant and professional software.

The agent is not merely given documents to read.

The MCP server exposes structured tools that the model can call to retrieve information or execute functions.

That distinction matters.

For two decades, enterprise AI largely sat outside operational software. It could explain what should be done, but a human still had to enter the application and do it.

Agentic infrastructure begins to connect reasoning with ex*****on.

Positive retains existing permissions. The agent remains constrained by what the authenticated human user is authorised to see or do.

And the fourth product reveals why that constraint is becoming central to enterprise AI governance.

Positive User, which handles customer data and CRM automation, is expected from the fourth quarter of 2026.

But the rollout will begin with analysis and read access.

Write actions will follow only after agent authentication and action-level permissions reach the security level Positive considers appropriate.

Reading social-media performance and changing a customer record are therefore not treated as equivalent risks.

That is particularly relevant for GCC organisations adopting agents across customer experience, luxury, tourism, financial services and large corporate groups. Once AI moves from summarising information to modifying operational systems, identity and authorisation become part of the agent architecture itself.

The question is no longer simply:

What can the model understand?

It becomes:

What is this model allowed to do, on behalf of whom, inside which system, and for which individual action?

Positive includes MCP access within existing subscriptions, without requiring an additional seat, separate login or contract change. Public pricing remains attached to the underlying products, with Surfer advertised from €20 and Iconosquare from €33.

For marketing operations, the workforce implication may be substantial.

A meaningful part of junior and operational work consists of extracting data, moving between screens, assembling preliminary analyses, scheduling content and checking ex*****on.

Those activities do not all disappear.

But their human interface can.

A GCC marketing director, SEO specialist, social-media manager or small regional agency can increasingly control part of this chain from an assistant already used throughout the working day.

This is another form of the "light workforce".

It does not require a spectacular autonomous agent capable of replacing an entire department.

It removes hours spent transporting information between applications that were already capable of performing each individual task.

And that may point towards a deeper transformation of SaaS itself.

For twenty years, much of the visible value of professional software was its interface: menus, dashboards, forms, screens and workflows. Companies invested enormous amounts in persuading employees to enter these environments and learn how to navigate them.

MCP begins to separate software capability from software interface.

The SaaS remains essential.

It still owns the data, business logic, permissions, audit trail and ex*****on.

But the employee may increasingly stop entering it.

For Gulf organisations evaluating the next generation of enterprise software, that distinction could become decisive.

The question may no longer be whether a SaaS product has the best dashboard.

It may be whether an authorised agent can use the software without needing the dashboard at all.

ULTRA®

THE MODEL IS NOT THE ARCHITECTURE

Positive's central mechanism is not its own AI but MCP, Model Context Protocol. Each product exposes structured tools to compatible assistants: retrieve data, launch an analysis, schedule content or control a signature. The model interprets intent and calls the MCP server without requiring the user to navigate the underlying SaaS. Positive Surfer, Iconosquare and Signitic have supported this architecture since 23 September 2026, while human-account permissions remain the boundary. Positive User follows from Q4, initially with read capabilities before write actions receive stronger authentication and action-level controls. For GCC light-workforce strategies, the implication is concrete: fewer human hours opening, exporting, copying and reconfiguring software. SaaS retains data, permissions and ex*****on. The agent becomes the operational interface.

Sources

Positive Group, official announcement, 23 September 2026

Positive Group, Trust Center

Zoho Creator, release notes

Bitdefender, VPN for AI Agents announcement



中文摘要 | VOCE GCC

# Positive Group正在让SaaS的Dashboard变成可选项。GCC应该注意这个变化。

一名Dubai的marketing manager发现某个网页在generative search中的visibility正在下降。

过去,他需要进入SEO platform找到数据,再打开social-media tool准备内容,然后进入CRM寻找与内容互动的customers。

所有环节都已经digitalised。

但真正连接这些software的,仍然是一个human。

2026年9月23日,Positive Group开始改变这种结构。

Positive Surfer、Positive Iconosquare和Positive Signitic正式通过Model Context Protocol,也就是MCP,向AI agents开放。

用户可以把这些products连接到Claude、ChatGPT、Copilot或者Positive自己的Uma,让assistant直接调用software中的data与functions。

真正重要的变化不是SaaS增加了一个chatbot。

而是用户开始不必进入SaaS。

Surfer可以向agent提供SEO audits、keyword analysis以及品牌在AI-generated answers中的competitive visibility。Iconosquare能够分析social performance、比较competitors并安排publications。Signitic则开放signature management、brand-compliance controls以及banner campaigns。

对于管理luxury、hospitality、retail、tourism或者multilingual regional brands的GCC marketing teams,这意味着workflow的起点开始移动。

Marketing manager可以直接询问哪些pages正在失去visibility,在conversation中获得analysis,根据结果生成content,再要求system安排publication。

过去需要human在多个interfaces之间搬运information。

现在assistant可以直接调用software。

MCP在这里扮演的不是database,而是一层standardised operational interface。

Server向AI暴露structured tools。Model理解用户intent以后,可以调用对应function完成查询或者执行任务。

于是AI不再只是告诉employee应该做什么。

它开始进入真正执行工作的software。

这对GCC enterprise AI尤其重要

因为agent一旦能够执行action,问题就不再只是model intelligence。

Identity与permission开始成为architecture的一部分。

Positive仍然保留原有account permissions。AI agent只能访问authenticated user本人有权查看或者操作的内容。

而Positive的第四个product恰好揭示了真正困难的地方。

Positive User负责customer data和CRM automation,预计从2026年第四季度开始接入MCP。

但Positive不会立即开放所有能力。

Deployment首先从analysis和read access开始。

Write actions将在agent authentication和action-level permission达到要求以后逐步开放。

原因非常简单。

读取social performance与修改customer record不是同一种risk。

当GCC organisations开始把AI agents接入CRM、customer experience、luxury operations、tourism、financial services或者其他enterprise systems以后,这种区别会变得越来越重要。

Governance必须能够回答的不只是:

Model能做什么?

还包括:

它代表谁执行?

可以进入哪个system?

可以读取哪些data?

哪一个具体action被授权?

Action完成以后是否留下audit trail?

这也解释了为什么MCP可能改变SaaS商业逻辑

过去二十年,professional software的大量价值都通过interface表现出来。

Menus。

Dashboards。

Forms。

Screens。

Workflows。

Enterprise购买software以后,还必须training employees,让他们知道应该进入哪里、点击什么、怎样把一个system中的information带到另一个system。

MCP开始把software capability与software interface分开。

SaaS仍然非常重要。

Data仍然在那里。

Business logic仍然在那里。

Permissions仍然在那里。

Execution也仍然在那里。

改变的是human不一定需要亲自进去。

这就是GCC值得关注的"light workforce"

它并不意味着一个super-agent突然替代整个marketing department。

变化更加现实。

Junior或者operational profiles过去需要花大量时间extract data、切换screens、准备preliminary analysis、schedule content并检查ex*****on。

这些工作不会全部消失。

但其中大量navigation work可能消失。

一个GCC marketing director、SEO specialist、social-media manager或者small regional agency,可以越来越多地从每天已经使用的AI assistant控制整条software chain。

Productivity improvement因此不一定来自AI比human更加creative。

它可能只是因为human不再需要成为不同SaaS之间的transport layer。

还有一个更深的变化

过去,选择enterprise software时,公司经常比较dashboard。

哪一个interface更清晰?

哪一个workflow更容易?

哪一个product需要更少training?

Agentic software时代可能提出另一个问题:

如果employee以后很少直接进入software,那么dashboard还有多重要?

真正具有strategic value的部分可能逐渐向下移动到data architecture、APIs、permissions、identity、auditability以及可以被agents安全调用的tools。

对于正在大量投资enterprise AI的GCC,这可能改变下一轮software procurement。

未来最重要的SaaS,不一定是拥有最好interface的SaaS。

而可能是那个即使human不再打开interface,仍然能够被authorised agent安全使用的软件。

ULTRA®

真正的Architecture不是Model,而是MCP

Positive此次变化的核心并不是Uma,也不是Claude、ChatGPT或Copilot,而是位于它们与software之间的Model Context Protocol。

Positive products通过MCP server向compatible assistants暴露structured tools。Agent可以retrieve data、launch analysis、schedule publication或者管理signature,而不要求human进入原来的SaaS interface。

Surfer、Iconosquare和Signitic已经从2026年9月23日采用这一architecture,同时继续受到human account permissions约束。Positive User将在Q4加入,并先开放read capabilities,再在authentication和action-level controls加强以后开放write actions。

对于GCC的light-workforce strategy,这个变化非常具体:减少human用于打开、导出、复制、切换和重新配置多个software的hours。

SaaS没有消失。

它继续拥有data、permissions与ex*****on。

消失的可能是human必须亲自进入它的理由。

#沙特阿拉伯 #阿联酋 #卡塔尔 #企业人工智能 #营销

Address

Valdanos B. B
Ulcinj
85360

Alerts

Be the first to know and let us send you an email when VOCE Balkans, Africa & Middle East posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share

Category