Saudi Data & AI Regulation
What actually binds and what merely guides: the PDPL, the AI Ethics Principles and their voluntary compliance mechanism, the generative AI guidelines, the still-draft Global AI Hub Law, the cross-border transfer regime, and the NCA's cybersecurity controls.
Last updated: Sep 10, 2026
General information, not legal advice
Start here: what is actually binding
Saudi Arabia has no binding AI-specific law. SDAIA's AI instruments are described in legal analysis as non-binding unless linked to other enforceable laws. What does bind AI work in the Kingdom is the law around it: the Personal Data Protection Law and its regulations, the NCA's cybersecurity controls, the Anti-Cyber Crime Law, and sector-specific statutes.
The PDPL — the law that does bind
- Issued
- Royal Decree M/19 of 9/2/1443H (16 September 2021), approving Council of Ministers Resolution 98.
- Amended
- Royal Decree M/148 of 5/9/1444H (27 March 2023).
- In force
- 14 September 2023.
- Implementing Regulations
- Published 7 September 2023, together with a separate set of Regulations on Personal Data Transfers outside the Kingdom.
- Full enforcement
- From 14 September 2024, after a one-year transition period.
A dating disagreement worth knowing
The regulator is SDAIA. There is a nuance worth carrying: Council of Ministers Decision 98 made SDAIA the competent authority “for a period of two years, during which consideration shall be given to transferring … to the National Data Management Office.” No such transfer has been announced, so SDAIA remains the regulator — but verify before relying on it.
Scope covers public and private entities processing personal data in the Kingdom, and applies extraterritorially where entities outside Saudi Arabia process the personal data of Kingdom residents.
Core obligations include:
- Registration on the National Data Governance Platform.
- Appointing a data protection officer where a public entity processes at scale, where core activities require regular systematic monitoring, or where core activities involve sensitive data.
- Breach notification to SDAIA within 72 hours.
- Records of processing activities and impact assessments.
- Answering data-subject rights requests within 30 days, extendable by a further 30.
- Relying on a lawful basis: consent, contract, legal obligation, vital interests, and limited legitimate interests — the last of which excludes sensitive data.
On penalties: disclosing or publishing sensitive data with intent to harm or for personal benefit carries up to two years' imprisonment and/or a fine of up to SAR 3 million. Other violations draw warnings or fines of up to SAR 5 million from the PDPL Violations Committee, appealable; fines may be doubled for repeat offenders. Proceeds may be confiscated, judgment summaries published at the violator's expense, and civil compensation is available.
Ignore the “or 2% of annual revenue” formulation
The AI Ethics Principles — binding, or advisory?
This is where most published guidance goes wrong, in both directions. The primary document — read directly — is titled “September 2023, Version 1.0”. It sets out seven principles: Fairness; Privacy and Security; Humanity; Social and Environmental Benefits; Reliability and Safety; Transparency and Explainability; and Accountability and Responsibility.
It then defines four risk tiers. In the document's own words:
- Little or no risk
- “no restrictions … but it is recommended that these systems be ethically compliant”.
- Limited risk
- “subject to the application of the AI ethics principles”.
- High risk
- “must undergo pre- and post-conformity assessments, and … the relevant statutory requirements must be considered”.
- Unacceptable risk
- Systems threatening safety, livelihood and rights — social profiling, or exploitation of children, for example — “are not allowed”.
But look at the compliance mechanism attached to those tiers. The document's own headings say “Optional Registration”. The Authority “may” measure the compliance of registered entities through “optional” reports. Adherence is encouraged with “Motivational Badges”.
The accurate framing
“some ambiguity … in that the way in which the scope of application is described seems to be obligatory in some instances and optional in others”
Check which version you are relying on
Generative AI guidelines
SDAIA published generative AI guidelines for government entities on 10 January 2024, and a version for the public in January 2024. Both are non-binding and risk-based. That does not make misuse consequence-free: it may still trigger obligations and liability under existing laws — the PDPL, cybersecurity rules, and sectoral statutes. SDAIA currently hosts 2025 editions of these documents.
SDAIA has also issued guidelines on deepfakes. Sources disagree on the issue date — May 2025 and May 2026 both appear — and we could not settle it, so no date is stated here.
The Global AI Hub Law — still a draft
CST published the draft Global AI Hub Law on 14 April 2025, with consultation closing on 14 May 2025. It contemplates three hub types — Private, Extended and Virtual — and would apply 60 days after publication in the Official Gazette.
Two errors to avoid here
Cross-border transfer — Saudi Arabia is not a blanket localisation jurisdiction
This is the correction that saves the most wasted architecture work. For personal data, the PDPL regulates the conditions for outbound transfer — it does not set a default rule that data must stay in the Kingdom.
Article 29(1) sets out permitted purposes, alongside three conditions: no prejudice to national security or the Kingdom's vital interests; adequate protection in the recipient jurisdiction as determined by SDAIA; and data minimization.
Adequacy is recommended by SDAIA and issued by the Prime Minister, and is reviewed at least every four years. SDAIA has not published an adequacy list. In its absence, the available safeguards are Standard Contractual Clauses (four modular versions, August 2024), Binding Common Rules for intra-group transfers only, and a Certificate of Accreditation. Updated Transfer Regulations were published on 1 September 2024.
A risk assessment is mandatory where a safeguard is relied on, or where sensitive data goes abroad on a continuous or widespread basis. SDAIA's Risk Assessment Guideline of February 2025 sets six minimum elements; the guideline itself is non-binding, though the underlying assessment requirement is not.
Two separate regimes sit alongside this one
Cybersecurity — NCA controls and the Anti-Cyber Crime Law
ECC-2:2024 is the current version of the Essential Cybersecurity Controls. The NCA's own implementation guide states the scope:
“These Controls are applicable to government agencies in the Kingdom of Saudi Arabia (including ministries, authorities, establishments and others) and their affiliated companies and entities (inside and outside the kingdom), as well as all private sector entities owning, operating, or hosting Critical National Infrastructures (CNIs).”
The controls are structured as four domains and 28 subdomains: Governance (10), Defense (15), Resilience (1), and Third-Party and Cloud (2).
Do not quote a control count
The NCA's other instruments include the Cloud Cybersecurity Controls (CCC-1:2020), Social Media Accounts Controls, Telework Controls, Critical Systems Controls, Operational Technology Controls, Data Cybersecurity Controls, National Cryptographic Standards, SCyber-Edu, and e-commerce guidelines.
The Anti-Cyber Crime Law was issued by Royal Decree M/17 of 8/3/1428H (26 March 2007). Article 3 provides for imprisonment of up to one year and/or a fine of up to SAR 500,000. Article 2 sets out its objectives:
“1. Enhancement of information security. 2. Protection of rights pertaining to the legitimate use of computers and information networks. 3. Protection of public Interest, morals, and common values. 4. Protection of national economy.”
Common mistakes
- “Saudi Arabia has an AI law.”
- There is no binding AI-specific law. The obligations that bite come from the PDPL, NCA controls and existing statutes.
- “All data must stay in the Kingdom.”
- Not for personal data. The PDPL regulates the conditions for outbound transfer rather than prohibiting it by default. Government data and cloud follow separate regimes.
- “The Global AI Hub Law is in force.”
- It is a draft. No royal decree or Official Gazette publication was found as at the date on this page.
- “The AI Ethics Principles carry fines.”
- The compliance mechanism is voluntary — optional registration, optional reports, motivational badges. Penalties come from the surrounding laws.
- “SDAIA has published an adequacy list.”
- It has not. Plan for a safeguard — SCCs, Binding Common Rules or a Certificate of Accreditation — plus a risk assessment.
Related on KSA.ai
Sources
Every claim on this page is traceable to the sources below. Where a source could not be verified, the copy says so rather than resolving it quietly.
- SDAIA — AI Ethics Principles (PDF)
- National Data Governance Platform
- DLA Piper Data Protection — Saudi Arabia
- CMS — AI Regulation Scanner, Kingdom of Saudi Arabia
- King & Spalding — international personal data transfers under the PDPL
- NCA — Essential Cybersecurity Controls
- Anti-Cyber Crime Law — official translation (PDF)