This workbook operationalizes AI security governance for next-generation banking in the GCC. It maps the AI attack surface, benchmarks against the OWASP LLM Top 10, hardens RAG pipelines, enforces zero-trust for multi-agent systems, applies STRIDE + PASTA + ATLAS threat modelling, tracks regulatory compliance (PDPL, CBUAE, ISO 42001, NIST AI RMF), secures the MLOps lifecycle, monitors observability & guardrails, reviews cloud security posture, and evidences ROI through case studies — all dynamically scoped to the bank selected above.