Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomeAI laws › PDPL (M/19, amended M/148) + SDAIA
AI governance law · Saudi Arabia

๐Ÿ‡ธ๐Ÿ‡ฆ PDPL (M/19, amended M/148) + SDAIA

Saudi Arabia pairs a binding data-protection law with a strong ethics-led AI framework under one authority. The Personal Data Protection Law (Royal Decree M/19, amended by M/148) and its Implementing Regulations supply the hard duties - a DPIA that is mandatory for automated decisions, records, a DPO, 72-hour breach notification and controlled transfers. SDAIA, the same regulator, issues the AI Ethics Principles, Generative AI guidelines and an AI Adoption Framework as the governing soft law.

Cited to primary sources
PDPL + Implementing Regulations
Governing framework
SDAIA (data protection + AI); NDMO; NCA
Supervisory authority
5
Controls this market requires
11
Required or strongly expected
Good to know: SDAIA's AI Ethics Principles, Generative AI guidelines and Adoption Framework are soft law, but they are issued by the same regulator that enforces the binding PDPL, so they carry real weight. NCA cybersecurity controls and NDMO data-management standards bind on hosting and government work.
Status: provisional overview (v0.1), reviewed against primary sources dated 24 Aug 2026; not legal advice.

What Saudi Arabia expects of you

All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.

Required mandated by binding law Expected near-mandatory / guidance-backed Prudent advisable Optional emerging n/a not applicable
AI RiskRequired

AI risk classification & impact assessment

Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). PDPL Article 22 / IR Article 25 DPIA - mandatory for automated decisions.

Closes with: AI risk classification + impact assessment (AIA/FRIA)
AI DataRequired

Data governance for AI

Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. PDPL lawful-basis and minimisation duties govern AI training data.

Closes with: AI data-governance standard
AI TransparencyRequired

Transparency & disclosure

Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. SDAIA transparency expectations plus Generative AI guidelines on disclosure.

Closes with: AI transparency + disclosure notices
AI SecurityRequired

Security of AI systems

AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. PDPL security plus NCA ECC/CCC cybersecurity controls.

Closes with: AI security controls statement
AI IncidentRequired

AI incident response & serious-incident reporting

Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. PDPL 72-hour breach notification to SDAIA.

Closes with: AI incident-response plan + reporting templates
AI GovernanceExpected

AI governance ownership & policy

A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI governance expected under SDAIA's AI Ethics Principles.

Closes with: AI policy + governance charter
AI InventoryExpected

AI system inventory / register

A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor. AI inventory expected to support DPIA and records duties.

Closes with: AI system register
AI OversightExpected

Human oversight & automated decisions

Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. Human oversight expected; confirm whether a standalone human-review right exists.

Closes with: Human-oversight + automated-decision safeguards note
AI Supply ChainExpected

Third-party / vendor AI & foundation models

Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Vendor and foundation-model diligence expected under processor duties.

Closes with: Vendor AI due-diligence + model cards
AI UseExpected

Acceptable use of AI by staff

An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Staff generative-AI use expected to follow SDAIA Generative AI guidelines.

Closes with: Acceptable-use policy for generative AI
AI AssuranceExpected

Record-keeping, logging & conformity

Keeping the logs, technical documentation and conformity evidence regulators expect. IR Article 31 records support logging and conformity evidence.

Closes with: AI logging + technical-documentation pack
AI AssurancePrudent

Accuracy, robustness & drift monitoring

Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.

Closes with: Model monitoring + drift-review plan

Get Saudi-ready against PDPL and SDAIA ethics

PrivMatrix maps the PDPL duties and SDAIA's AI Ethics and Generative AI guidelines onto your systems, then generates the DPIAs, disclosures and policies that satisfy the Kingdom's one-authority regime.

Other markets

See all AI laws →
๐Ÿ‡ช๐Ÿ‡บ EU๐Ÿ‡ฌ๐Ÿ‡ง UK๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ฎ๐Ÿ‡ณ India๐Ÿ‡ถ๐Ÿ‡ฆ Qatar