§ 01Saudi Arabia

Saudi Arabia

AI governance under SDAIA, the PDPL and sectoral supervision

Saudi Arabia has the most developed national AI institution in the Gulf and no binding horizontal AI statute. Both halves of that sentence are load-bearing, and programmes go wrong when a board hears only one of them.

SDAIA sets direction through ethics principles, generative-AI guidance and an adoption framework, and every one of those instruments is guidance rather than law. What carries enforcement is the Personal Data Protection Law, and it is being enforced: SDAIA’s committees issued 48 decisions confirming PDPL violations across 2025 and 2026.

Written by Nabeel Khan, author of AI Governance & Compliance Frameworks for the Middle East · seven years in Kuwait government, the Council of Ministers and the Ministry of Planning · author of the MESA Framework · engagements are taken personally through iSystematic, not staffed to a bench
§ 02What applies

What is actually in force.

Listed by what binds you rather than by what is discussed. Every date here was verified on 9 August 2026; verify again before you rely on it, because these move.

In force
Personal Data Protection LawIn force since September 2023, with fines reaching SAR 5 million. This is the instrument with teeth, and it is where AI exposure in the Kingdom actually lands today. SDAIA enforcement committees issued 48 decisions confirming violations across 2025 and 2026, concentrated on the unglamorous failures: processing without a valid legal basis, unauthorised disclosure, absent technical and organisational safeguards, and marketing communications. None of those require an AI system to occur, and an AI system makes every one of them easier to commit at scale.
Guidance
SDAIA AI Ethics Principles and Generative AI GuidelinesThe Ethics Principles were updated in 2025 and the Generative AI Guidelines were issued in 2024, addressing hallucination, bias and synthetic content directly. Both are non-binding. They are still the clearest statement of what the national authority considers responsible practice, which makes them the reference an examiner or a counterparty is most likely to reach for, and the cheapest thing to align to before anyone asks.
Sept 2024
SDAIA AI Adoption FrameworkFour maturity levels. Useful precisely because it is a maturity model rather than a checklist: it gives a board a defensible way to say where the institution is and what the next level costs. SDAIA itself was certified to ISO/IEC 42001 in July 2024, among the first government bodies in the world to be, which tells you which international standard the Kingdom is aligning to and is the most efficient hint on offer.
Sectoral
SAMA and the financial sectorSAMA has no dedicated AI standard. Governance obligations for a Saudi bank flow through the instruments that already exist, principally the SAMA Cyber Security Framework across its four domains: leadership and governance, risk management and compliance, operations and technology, and third-party. The practical consequence is that AI risk has to be argued inside frameworks that were not written for it, which is harder than following a purpose-built rule and is the ordinary condition of model risk everywhere.
§ 03What does not apply

The rule that does not exist.

Saudi Arabia has designated 2026 the Year of Artificial Intelligence, and that is direction rather than obligation. There is no binding horizontal AI law in the Kingdom. AI is governed through cross-sectoral law and sectoral regimes, with enforcement running mainly through the PDPL. A programme built to comply with a Saudi AI act will produce evidence nobody asked for while leaving the PDPL exposure, which is the one being enforced, untouched.

§ 04Questions

The questions a board actually asks.

Does Saudi Arabia have an AI law?

No binding horizontal AI statute. SDAIA sets the national framework through instruments that are guidance rather than law: the AI Ethics Principles updated in 2025, the Generative AI Guidelines from 2024, and the AI Adoption Framework from September 2024. AI is governed in practice through cross-sectoral law and sectoral regulation, and enforcement runs mainly through the Personal Data Protection Law. Being precise about the difference matters, because guidance and law require different evidence and a board that conflates them will over-document one and under-document the other.

What does the PDPL mean for an AI system?

It is the instrument with enforcement behind it, in force since September 2023 with fines reaching SAR 5 million. SDAIA committees issued 48 decisions confirming violations across 2025 and 2026, and the pattern is instructive: processing without a valid legal basis, unauthorised disclosure, missing technical and organisational safeguards, and marketing communications. An AI system does not create new categories of violation so much as it industrialises the existing ones, which is why the lawful-basis question and the disclosure question have to be answered per model rather than per policy.

Does SAMA regulate AI for banks?

Not through a dedicated AI standard, which does not exist. A Saudi bank meets its AI governance obligations through the frameworks already in place, principally the SAMA Cyber Security Framework across leadership and governance, risk management and compliance, operations and technology, and third-party. This is the ordinary condition of model risk: the obligation is real and the purpose-built rule is absent, so the work is arguing AI risk correctly inside instruments written for something else. That argument is easier to make with a scored baseline than with a narrative.

What standard should we align to?

ISO/IEC 42001 is the most defensible answer available, and the hint comes from the regulator: SDAIA certified itself to it in July 2024, among the first government bodies globally. Aligning to 42001 and the NIST AI Risk Management Framework gives a Saudi institution a governance record recognisable to a domestic supervisor, an international counterparty and a European customer at the same time, which matters more each year as extraterritorial reach grows.

Where do you fit into this?

Independent assessment and architecture. The Teardown scores the estate against the four MESA layers and produces a board-ready reading, which is the input to a PDPL or ISO 42001 programme rather than a substitute for one. The published book on AI governance for Middle East financial institutions carries the method, including Sharia governance and Halal data considerations that a general framework does not reach. Engagements are taken personally rather than staffed to a bench.

Governance an examiner can follow, in the jurisdiction that actually binds you.

Fin · Saudi Arabia
Book the 30-minute Fit Call →