Saudi Arabia has the most developed national AI institution in the Gulf and no binding horizontal AI statute. Both halves of that sentence are load-bearing, and programmes go wrong when a board hears only one of them.
SDAIA sets direction through ethics principles, generative-AI guidance and an adoption framework, and every one of those instruments is guidance rather than law. What carries enforcement is the Personal Data Protection Law, and it is being enforced: SDAIA’s committees issued 48 decisions confirming PDPL violations across 2025 and 2026.
Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.
Saudi Arabia has designated 2026 the Year of Artificial Intelligence, and that is direction rather than obligation. There is no binding horizontal AI law in the Kingdom. AI is governed through cross-sectoral law and sectoral regimes, with enforcement running mainly through the PDPL. A programme built to comply with a Saudi AI act will produce evidence nobody asked for while leaving the PDPL exposure, which is the one being enforced, untouched.
No binding horizontal AI statute. SDAIA sets the national framework through instruments that are guidance rather than law: the AI Ethics Principles updated in 2025, the Generative AI Guidelines from 2024, and the AI Adoption Framework from September 2024. AI is governed in practice through cross-sectoral law and sectoral regulation, and enforcement runs mainly through the Personal Data Protection Law. Being precise about the difference matters, because guidance and law require different evidence and a board that conflates them will over-document one and under-document the other.
It is the instrument with enforcement behind it, in force since September 2023 with fines reaching SAR 5 million. SDAIA committees issued 48 decisions confirming violations across 2025 and 2026, and the pattern is instructive: processing without a valid legal basis, unauthorised disclosure, missing technical and organisational safeguards, and marketing communications. An AI system does not create new categories of violation so much as it industrialises the existing ones, which is why the lawful-basis question and the disclosure question have to be answered per model rather than per policy.
Not through a dedicated AI standard, which does not exist. A Saudi bank meets its AI governance obligations through the frameworks already in place, principally the SAMA Cyber Security Framework across leadership and governance, risk management and compliance, operations and technology, and third-party. This is the ordinary condition of model risk: the obligation is real and the purpose-built rule is absent, so the work is arguing AI risk correctly inside instruments written for something else. That argument is easier to make with a scored baseline than with a narrative.
ISO/IEC 42001 is the most defensible answer available, and the hint comes from the regulator: SDAIA certified itself to it in July 2024, among the first government bodies globally. Aligning to 42001 and the NIST AI Risk Management Framework gives a Saudi institution a governance record recognisable to a domestic supervisor, an international counterparty and a European customer at the same time, which matters more each year as extraterritorial reach grows.
Independent assessment and architecture. The Teardown scores the estate against the four MESA layers and produces a board-ready reading, which is the input to a PDPL or ISO 42001 programme rather than a substitute for one. The published book on AI governance for Middle East financial institutions carries the method, including Sharia governance and Halal data considerations that a general framework does not reach. Engagements are taken personally rather than staffed to a bench.
Governance an examiner can follow, in the jurisdiction that actually binds you.