policy · Effective Apr 13, 2025
SA regulates AI through Draft Global AI Hub Law.
Draft Global AI Hub Law · effective 2025-04-13
Updated 60 days ago · 3 sources · confidence: medium
Overview
Saudi Arabia’s approach to artificial intelligence is characterized by a highly centralized, top-down strategy designed to fulfill the ambitious objectives of Saudi Vision 2030. At the heart of this transformation is the Saudi Data and AI Authority (SDAIA), established by Royal Order in 2019. The Kingdom views AI not merely as a technological tool but as a primary engine for economic diversification and national sovereignty. Consequently, the regulatory landscape is rapidly evolving from a series of high-level policy aspirations into a structured ecosystem of binding laws, ethical frameworks, and sector-specific guidelines. The maturity level of Saudi AI regulation is high compared to regional peers, with a clear emphasis on data localization, sovereign compute capabilities, and the creation of a 'trustworthy' AI environment that aligns with both Islamic values and international standards. The National Strategy for Data & AI (NSDAI) serves as the primary roadmap, aiming to attract $20 billion in investment and train over 20,000 data and AI specialists by the end of the decade. This strategic focus is supported by the highest levels of government, ensuring that AI development is integrated into every facet of the Kingdom's digital transformation, from smart cities like NEOM to the modernization of government services through the Absher and Tawakkalna platforms. The regulatory philosophy in the Kingdom is dual-faceted: it seeks to be 'innovation-friendly' to attract global tech giants while maintaining strict 'data sovereignty' to protect national interests. This is evidenced by the NSDAI, which sets measurable targets for investment, workforce development, and global rankings. The Kingdom has moved quickly to establish foundational pillars, such as the Personal Data Protection Law (PDPL), which provides the necessary legal certainty for AI developers handling large datasets. Furthermore, the introduction of the 'Global AI Hub' concept suggests that Saudi Arabia is moving toward a model of jurisdictional flexibility, allowing for 'data embassies' and specialized hubs where foreign laws might apply under specific, controlled conditions to foster international collaboration. This approach is intended to mitigate the concerns of multinational corporations regarding data residency while ensuring that the Kingdom remains a central node in the global digital economy.
Regulatory approach
Saudi Arabia utilizes a hybrid regulatory approach that blends horizontal, cross-cutting legislation with principle-based 'soft law' and emerging sectoral rules. The horizontal foundation is anchored by the Personal Data Protection Law (PDPL), which applies to all AI systems involving the processing of personal data. Complementing this is a risk-based governance framework, most notably articulated in the 'Principles and Controls of AI Ethics.' This framework categorizes AI systems into four risk tiers: 'little or no risk,' 'limited risk,' 'high risk,' and 'unacceptable risk.' This classification mirrors the structure of the European Union’s AI Act, allowing the Kingdom to maintain international interoperability while tailoring specific prohibitions (such as social scoring) to its own public order and security requirements. The ethical framework is designed to be applied throughout the AI lifecycle, from initial design and data collection to deployment and decommissioning, ensuring that human-centric values are preserved at every stage. While many current AI-specific instruments—such as the Generative AI Guidelines and the AI Adoption Framework—function as non-binding guidance, they carry significant weight in the public sector. Government entities are often mandated to follow these frameworks through internal directives and SDAIA oversight. The regulatory trend is moving toward increased formalization; for instance, the Draft Global AI Hub Law of 2025 represents a transition toward 'hard law' for AI infrastructure and cross-border data governance. This approach allows the Kingdom to remain agile, issuing guidelines to keep pace with rapid technological shifts (like Generative AI) while building a permanent statutory structure for the underlying data and infrastructure layers. The use of regulatory sandboxes, particularly in the financial and telecommunications sectors, further illustrates this agile approach, allowing for the testing of high-risk AI applications under close supervisory oversight before they are released to the broader market. The governance of AI in Saudi Arabia is centralized under the Saudi Data and AI Authority (SDAIA). Established in 2019, SDAIA serves as the national steward for the AI agenda and reports directly to the Prime Minister. Its mandate is broad, encompassing the development of national strategies, the operation of national data infrastructure (such as the National Data Bank), and the supervision of data protection compliance. Within SDAIA, specialized units like the National Data Management Office (NDMO) and the National Center for AI (NCAI) handle the technical and regulatory nuances of data governance and algorithmic innovation, respectively. The NDMO is responsible for setting the standards for data quality and classification, while the NCAI focuses on driving R&D and implementing the national AI strategy. This centralized structure ensures that AI policy is harmonized across all government ministries and that national security interests are integrated into technological development. In addition to SDAIA, the Communications, Space and Technology Commission (CST) plays a critical role in regulating the digital infrastructure that supports AI, including cloud computing and the proposed Global AI Hubs. The CST ensures that the underlying telecommunications and compute resources are resilient and secure. The National Cybersecurity Authority (NCA) provides the security standards necessary to protect AI models and training data from adversarial attacks, such as data poisoning or model inversion. While SDAIA is the primary regulator, it coordinates closely with sectoral bodies such as the Saudi Central Bank (SAMA) and the Ministry of Health to ensure that AI deployments in sensitive fields meet both general AI ethics and specific sectoral safety standards. This multi-layered but coordinated governance model allows for specialized oversight while maintaining a unified national direction, preventing regulatory fragmentation and providing a single point of contact for international partners.
Enforcement & penalties
Enforcement of AI-related regulations in Saudi Arabia primarily leverages the penalty framework established by the Personal Data Protection Law (PDPL) and other existing statutes. Under the PDPL, administrative fines for violations can reach up to SAR 5,000,000 (approximately USD 1.3 million), with the possibility of doubling for repeat offenses. SDAIA is empowered to conduct inspections, audits, and investigations into entities suspected of non-compliance. In addition to financial penalties, SDAIA can issue corrective orders, suspend data processing activities, and publish warnings or rulings against non-compliant organizations to serve as a reputational deterrent. The authority has established a dedicated compliance department that monitors the activities of data controllers and processors, ensuring that AI systems are not used in ways that violate the privacy rights of Saudi citizens. Criminal penalties are also applicable in specific, high-gravity circumstances. For instance, the unlawful disclosure or publication of sensitive personal data with the intent to harm or for personal gain can lead to imprisonment for up to two years and fines of up to SAR 3,000,000. Similarly, violations related to the unauthorized transfer of data outside the Kingdom can result in imprisonment for up to one year. As the Kingdom introduces more specific AI laws, such as the proposed Global AI Hub Law, enforcement mechanisms are expected to expand to include the revocation of specialized licenses and the exercise of emergency powers to intervene in hub operations for reasons of national security or public order. The judicial system, including specialized commercial courts, is increasingly being trained to handle complex technological disputes, ensuring that enforcement is backed by a competent and technically-aware judiciary.
Data protection
The data protection framework in Saudi Arabia is anchored by the Personal Data Protection Law (PDPL), which became fully enforceable in September 2024 following a transition period. The PDPL is a comprehensive regime that mirrors many aspects of the GDPR, including principles of purpose limitation, data minimization, and the requirement for a lawful basis for processing. It grants data subjects significant rights, such as the right to access, correct, and delete their data, as well as the right to data portability. For AI developers, the PDPL necessitates rigorous Data Protection Impact Assessments (DPIAs) and the appointment of Data Protection Officers (DPOs) for entities processing sensitive data or operating on a large scale. The law also places a heavy emphasis on transparency, requiring controllers to provide clear privacy notices that explain how AI algorithms use personal data for automated decision-making. Data localization and cross-border transfers are key focus areas within this framework. The 'Regulation on Personal Data Transfer Outside the Kingdom' (updated in 2024) mandates that transfers must not prejudice national security or vital interests. Controllers must use approved safeguards, such as Standard Contractual Clauses (SCCs) issued by SDAIA or Binding Common Rules (BCRs). Furthermore, the National Data Governance Interim Regulations provide a baseline for government-held data, emphasizing classification levels (Public, Internal, Restricted, Confidential) that dictate how data can be used in AI training and deployment. This robust framework ensures that the 'fuel' for AI—data—is handled with a high degree of security and legal oversight, fostering a trusted environment for both domestic innovation and international data processing services.
Sector-specific rules
While SDAIA provides the horizontal AI framework, several key sectors have developed their own specific rules to manage the unique risks associated with AI. In the financial sector, the Saudi Central Bank (SAMA) has integrated AI considerations into its broader cybersecurity and data governance frameworks, emphasizing the need for explainability in automated credit scoring and fraud detection. SAMA’s regulatory sandbox has been a primary venue for testing financial AI innovations under controlled conditions, ensuring that new technologies do not undermine the stability of the Kingdom’s financial system or consumer protection standards. SAMA also requires financial institutions to maintain human-in-the-loop oversight for high-impact AI decisions, ensuring that customers have a path for recourse if they are negatively affected by an algorithmic decision. In the healthcare sector, the Ministry of Health and the Council of Health Insurance (CCHI) oversee the deployment of AI in diagnostics and patient management. These bodies require that AI systems used in clinical settings meet stringent validation requirements and maintain alignment with the PDPL’s strict controls on sensitive health data. The Saudi Food and Drug Authority (SFDA) also plays a role in regulating AI-based medical devices, ensuring they meet safety and efficacy standards before they can be marketed. Similarly, the Communications, Space and Technology Commission (CST) manages the Cloud Computing Regulatory Framework, which imposes specific residency and security requirements on cloud service providers (CSPs) that host AI workloads. These sectoral rules act as a necessary layer of 'vertical' regulation, ensuring that high-risk AI applications are subject to domain-specific expertise and safety protocols that go beyond general ethical principles.
International alignment
Saudi Arabia actively seeks to align its AI regulatory framework with international best practices to facilitate global trade and technological exchange. The Kingdom’s 'Principles and Controls of AI Ethics' explicitly reference the recommendations of UNESCO and the OECD AI Principles. During its G20 Presidency in 2020, Saudi Arabia led the advancement of the G20 AI Principles, which emphasize human-centered values and trustworthiness. This commitment to international standards is designed to ensure that AI systems developed or deployed in the Kingdom are recognized as safe and ethical by global partners, thereby reducing barriers to cross-border data flows and investment. The Kingdom also hosts the biennial Global AI Summit, which serves as a platform for international dialogue on AI governance and ethics. Furthermore, the Kingdom’s risk-based approach shows clear influence from the European Union’s AI Act, particularly in its classification of 'unacceptable' and 'high-risk' systems. This alignment is strategic, as it allows Saudi entities to more easily comply with multiple jurisdictions when operating internationally. Saudi Arabia also participates in international standard-setting bodies like ISO/IEC to contribute to the development of technical standards for AI robustness and transparency. By positioning itself as a bridge between Western regulatory models and the unique cultural and economic priorities of the Middle East, the Kingdom aims to become a central node in the global AI governance network. This international outlook is also reflected in the Kingdom's 'AI for the Good of Humanity' initiative, which seeks to leverage AI to solve global challenges such as climate change and pandemic response.
What's next
The most significant upcoming development in the Saudi AI landscape is the finalization and implementation of the Draft Global AI Hub Law. This legislation, which underwent public consultation in mid-2025, is expected to create a revolutionary legal environment for international data hosting. By introducing 'Virtual Hubs' and 'Private Hubs,' the Kingdom intends to allow foreign states and multinational corporations to operate under their own legal frameworks for certain data activities while physically located in Saudi Arabia. This 'data embassy' model is a key part of the strategy to make the Kingdom a global 'sovereign compute' destination and is likely to trigger a new wave of bilateral data treaties. This initiative is closely linked to the development of NEOM, where AI is expected to be the 'operating system' of the city, managing everything from autonomous transport to energy grids. Additionally, SDAIA has signaled that it will continue to iterate on its guidelines for emerging technologies. Expected updates include more granular rules for the use of AI in biometric identification and the refinement of the Deepfakes Guidelines into more formal, enforceable regulations. As the 2030 deadline for Vision 2030 approaches, the Kingdom is also expected to launch more 'regulatory sandboxes' focused on specific AI applications like autonomous mobility and smart city management. There is also a growing focus on 'Sovereign AI,' with the Kingdom investing heavily in its own large language models (such as ALAN) to ensure that AI systems are culturally and linguistically aligned with the Arabic-speaking world. These developments indicate a shift from foundational policy-making toward the operationalization and fine-tuning of a mature, multi-jurisdictional AI ecosystem that can compete on the global stage.
policy · Effective Apr 13, 2025
guideline · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
Sources:
guideline · Effective Jan 1, 2024
Sources:
regulation · Effective Jan 1, 2024
regulation · Effective Apr 24, 2023
guideline · Effective Jan 1, 2023
regulation · Effective Jan 1, 2021
regulation · Effective Jan 1, 2020
policy · Effective Jan 1, 2020
regulation · Effective Jan 1, 2020
regulation · Effective Jan 1, 2019
policy · Effective n/a
Sources:
strategy · Effective n/a
strategy · Effective Jan 1, 2020
code_of_ethics · Effective Jan 1, 2022
enforcement
National authority for AI strategy, data governance, and PDPL supervision.
sectoral
Regulator for digital infrastructure, cloud services, and AI hubs.
enforcement
National entity for cybersecurity affairs in the Kingdom.
Apr 7, 2026 · news
SDAIA issues guide on generative programming
Open source →Apr 2, 2026 · news
Saudi Data and Artificial Intelligence Authority opens consultation on draft Responsible AI Policy
Open source →Mar 18, 2026 · news
KISA announces Physical AI Security Standards and Model Development Project
Open source →Mar 11, 2026 · news
Saudi Arabia designates 2026 as year of AI
Open source →Feb 20, 2026 · news
Saudi Arabia joins Saudi Arabia Joins Global Partnership on AI
Open source →Feb 2, 2026 · international_agreement
Türkiye and Saudi Arabia deepen strategic cooperation with new deals
Open source →Jan 29, 2026 · news
SDAIA launches national data, AI curriculum
Open source →Jan 20, 2026 · international_agreement
Saudi Communications Minister discusses expanding cooperation on AI policy and technological innovation with White House advisors
Open source →Jan 13, 2026 · news
Saudi minister, senior US official discuss expanding AI partnership
Open source →Dec 31, 2025 · law_amended
Saudi Arabia unveils world's largest government data centre in $2.7 billion digital push
Open source →Dec 14, 2025 · international_agreement
China and Saudi Arabia pledge deeper hi-tech cooperation
Open source →Nov 18, 2025 · news
US approves sale of 70,000 AI chips to UAE and Saudi Arabia
Open source →Nov 18, 2025 · news
US and Saudi Arabia sign strategic AI partnership
Open source →Oct 17, 2025 · international_agreement
Saudi Arabia’s GO Telecom launches AI hub in Islamabad to boost digital cooperation
Open source →Sep 25, 2025 · international_agreement
South Korea and Saudi Arabia to expand cooperation in shipbuilding, automotive, AI industries
Open source →Sep 19, 2025 · law_amended
Somalia and Saudi Arabia agree to cooperate on AI and space technology regulation
Open source →Aug 2, 2025 · news
SDAIA releases report on agentic AI and national applications
Open source →Jul 15, 2025 · news
Saudi minister holds strategic AI and tech talks with French institutions in Paris
Open source →May 12, 2025 · law_amended
Saudi Arabia commits $600 billion investment in US, covering AI
Open source →May 11, 2025 · news
Saudi Crown Prince launches new company to develop AI technologies
Open source →Apr 28, 2025 · international_agreement
BRICS+ sign declaration on AI governance
Open source →Apr 22, 2025 · news
Saudi Arabia and India signed $100bn deal, covering AI
Open source →Apr 13, 2025 · law_amended
Saudi Arabia Communications, Space, and Technology Commission opens consultation on draft Global AI Hub Law
Open source →Feb 1, 2025 · law_amended
Arab League calls for AI regulation framework
Open source →Nov 18, 2024 · international_agreement
Saudi ICT minister highlights nation's leadership in AI during G20 Summit
Open source →Sep 17, 2024 · guideline_issued
Saudi Data & AI Authority releases deepfake guidelines
Open source →Sep 10, 2024 · news
SDAIA and OECD sign MoU to enhance AI incident monitoring in the Middle East
Open source →Aug 21, 2024 · international_agreement
Saudi Arabia to host third Global AI Summit
Open source →May 15, 2024 · news
Saudi Arabia announces AI Center for Media
Open source →Jan 10, 2024 · guideline_issued
Generative AI Guidelines published
Open source →Oct 24, 2023 · law_amended
Saudi Arabia-UK roundtable on AI tackles ethics, regulations
Open source →Apr 24, 2023 · law_amended
Amendments to Personal Data Protection Law
Open source →