No — Saudi Arabia has no AI law. As of 31 July 2026 there is no binding AI-specific statute in the Kingdom, and no legislative process to enact one has been announced [S6]. Every instrument carrying “artificial intelligence” in its title and issued by the Saudi Data and Artificial Intelligence Authority is guidance: no penalty, no cause of action, no regulator empowered to fine you for breaching it.
AI is not unregulated, though. Saudi Arabia AI regulation works as it does in most of the world outside Brussels — through instruments of general application that happen to catch AI systems. The binding obligations come from the Personal Data Protection Law, promulgated by Royal Decree M/19 in September 2021 and amended by M/148 in March 2023, from its implementing and transfer regulations, from National Cybersecurity Authority controls, and from whichever regulator supervises the customer [S3][S8][S9].
Most coverage runs those instruments together as one regime. They are four different kinds of thing — binding law, binding regulation, non-binding guidance, and draft — with four different consequences. What follows grades each. This is legal information, not legal advice; anyone with a live exposure should take Saudi-qualified counsel.
Last verified: 31 July 2026.
Does Saudi Arabia Have an AI Law?
No. The CMS AI Regulation Scanner, surveying the position as at 17 February 2026, states that “Saudi Arabia does not currently have an AI-specific law and has not announced any formal legislative process to enact one” [S6]. The Regulations.ai inventory agrees [S7].
The nearest candidate is the draft Global AI Hub Law, published for consultation by the Communications, Space and Technology Commission (CST) in April 2025 and closing 14 May 2025 [S5][S13]. Its name misleads: it does not regulate AI systems, models or training. It creates a regime for data embassies — three hosting models (Private, Extended and Virtual Hubs) letting a foreign state or firm host data inside the Kingdom while remaining under its own jurisdiction [S13]. Fifteen months on it remains a draft.
The Kingdom nonetheless designated 2026 the Year of Artificial Intelligence [S14]. The declaration and the absent statute are not in tension: the choice is to regulate AI through data law and through the state’s position as dominant buyer, not through a horizontal AI act.
Saudi Arabia AI Regulation: What Actually Binds an AI Deployment
The legal-status column is the load-bearing one.
| Instrument | Issuer | Legal status | Binds | Requires | Penalty |
|---|---|---|---|---|---|
| Personal Data Protection Law, M/19 (2021), amended M/148 (2023) | Royal Decree | Binding law | Processing in KSA; foreign processing of residents’ data | Legal basis, rights, DPO, records, breach notice, transfer rules | SAR5m ($1.33m); SAR3m and 2 years for sensitive data |
| PDPL Implementing Regulations (2023) | SDAIA | Binding regulation | Same population | Registration, DPO triggers, impact assessments, 72-hour notice | Via the PDPL |
| Personal Data Transfer Regulation (2023, updated 2024) | SDAIA | Binding regulation | Controllers exporting personal data | Adequacy or approved safeguard, plus risk assessment | Via the PDPL |
| National Data Governance policies | NDMO | Binding on public entities | Government bodies and suppliers | Classification, sharing, open data | Administrative |
| Essential, Data, Critical Systems and Cloud Cybersecurity Controls | NCA | Binding within scope | Government, critical infrastructure, suppliers | Technical and organisational security controls | Administrative |
| Circular 43045328 (2021) | SAMA | Binding on supervised entities | Banks, finance and payment firms, credit bureaus | Align internal policy with PDPL and SDAIA rules | Supervisory action |
| AI Ethics Principles v1.0 (2023); v2.0 (2025) | SDAIA | Non-binding guidance | Stated scope all AI stakeholders; enforcement voluntary | Seven principles, four risk tiers | None |
| Generative AI Guidelines, government and public (2024) | SDAIA | Non-binding guidance | Government entities; public | Acceptable use, disclosure, oversight | None |
| AI Adoption Framework (2024) | SDAIA | Non-binding guidance | Adopting entities | Maturity assessment, internal governance | None |
| MDS-G010 (2023) | SFDA | Binding market-access condition | Makers of AI/ML-enabled medical devices | Marketing-authorisation requirements | No market access |
| Draft Global AI Hub Law (2025) | CST | Draft, not in force | Would bind data-embassy hosts | Hub models, licensing | n/a |
| Copyright Law, M/169, Article 26 | Royal Decree | Binding from 12 August 2026 | Anyone reproducing works to build AI | Statutory training exception | Copyright regime |
Two rows carry nearly all the practical weight: the PDPL and its transfer regulation. One carries almost none despite dominating the coverage: the AI Ethics Principles.
What Is SDAIA, and What Legal Authority Does It Have?
SDAIA is the Saudi Data and Artificial Intelligence Authority, created by Royal Order on 30 August 2019 and reporting directly to the Prime Minister — an office held by Crown Prince Mohammed bin Salman [S15]. The same order created the National Data Management Office (NDMO), its regulatory arm for data governance, and the National Center for AI. See SDAIA’s full profile.
Its rule-making authority predates the PDPL. SDAIA’s own framework cites Council of Ministers’ Resolution No. 292, dated 27/04/1441 AH — late December 2019 — whose Article 10(1) mandates SDAIA “to develop policies, governance mechanisms, standards, and controls related to data and artificial intelligence and monitor compliance therewith upon issuance” [S1]. That is the hook on which every SDAIA instrument hangs.
Two consequences follow. SDAIA is both policy-maker and data-protection supervisor, so the supervisory function is not independent of the AI-promotion function. And it is not the only regulator: CST, successor to CITC, governs infrastructure through the Cloud Computing Regulatory Framework and sponsored the draft hub law [S13], while the National Cybersecurity Authority, created in 2017, owns the security controls. SDAIA regulates the data and the model, CST the pipes, NCA the locks. Its operational surface is the National Data Governance Platform at dgp.sdaia.gov.sa; see NDMO data governance policies for classification.
Are Saudi Arabia’s AI Ethics Principles Legally Binding?
No — and the document says so itself, if you read past the scope clause.
SDAIA published the AI Ethics Principles, Version 1.0, in September 2023; version 2.0 followed in 2025, adding tiered risk categorisation and self-assessment tools [S1][S2]. The seven principles are fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, and accountability.
The scope clause reads like a statute. Verbatim: “This AI Ethics Framework shall apply to all AI stakeholders designing, developing, deploying, implementing, using, or being affected by AI systems within KSA, including but not limited to public entities, private entities, non-profit entities, researchers, public services, institutions, civil society organizations, individuals, workers, and consumers” [S1]. Read alone, that is a universal mandatory obligation.
The enforcement chapter says otherwise. Its heading is “Optional Registration.” Under “Compliance,” SDAIA “may follow up and measure the level of commitment and compliance of registered entities” and support them in “submitting optional reports.” The next section is headed “Motivational Badges” [S1]. There is no penalty provision, no breach register, and no route to a fine or an order anywhere in the document.
The compliance mechanism is therefore: register if you like, report if you like, collect a badge. That is a maturity programme, not a regulation. Its four risk tiers — little or no risk, limited, high, and unacceptable, the last “not allowed” [S1] — mirror the EU AI Act’s architecture while importing none of its enforcement. Where the framework does bind, it does so by pointing elsewhere: high-risk systems must undergo conformity assessments and “the relevant statutory requirements must be considered” [S1] — meaning the PDPL and the sector rules.
It still bites indirectly, through procurement, sector regulators and contracts. Our Saudi AI ethics principles page treats them as a governance framework; this page addresses their legal status.
What Status Do SDAIA’s Generative AI Guidelines Have?
Non-binding, in two editions. SDAIA issued Generative AI Guidelines for Government and for the Public in 2024, alongside an AI Adoption Framework and draft deepfake guidelines [S6][S7]. They cover synthetic-content disclosure, hallucination and bias risk, human oversight and acceptable use.
The government edition matters operationally: as guidance it creates no legal duty, but as an instruction from the body setting government data policy it works as an internal directive for public entities and reaches their suppliers through procurement terms. Sell a model into a Saudi ministry and it is effectively contractual.
The PDPL Is Where the Enforceable Obligations Live
The PDPL came into force on 14 September 2023 with a one-year grace period; full enforcement began 14 September 2024 [S3][S16]. It covers processing inside the Kingdom and — the provision foreign model providers most often miss — processing by entities outside it of the personal data of individuals residing in Saudi Arabia [S3]. A foreign vendor with no Saudi entity and no Saudi infrastructure can sit inside the regime.
Legal basis. Consent is the default. The 2023 amendment added grounds for processing without it — contract performance, legal obligation, vital interests, public-entity functions and a proportionality-based legitimate-interests route — though the ICLG 2026 chapter notes that last ground is not articulated as cleanly as GDPR Article 6(1)(f) [S8][S9].
The one provision that regulates AI directly. The PDPL requires explicit consent where a decision is based solely on automated processing of personal data [S9]. This is the sharpest point in Saudi Arabia AI regulation: the only binding rule that speaks to what an AI system does, rather than to the data it consumes, sits in the data-protection statute — not in any instrument with “AI” in its title. An automated credit decision, hiring screen or claims denial is regulated. A recommendation engine stopping short of a decision is not.
Officers, registration, records. A data protection officer is mandatory for public entities processing at scale, for controllers whose core activities involve regular large-scale monitoring, and for those processing sensitive data. Registration on the National Data Governance Platform applies to those categories plus controllers whose main activity is processing [S8][S9]. A record of processing activities is required, and SDAIA must be notified of a breach within 72 hours, with data subjects told without undue delay [S9]. See Saudi data protection and privacy and Saudi data privacy and cyber compliance.
Can You Transfer Personal Data Out of Saudi Arabia?
Yes, on conditions — and the widely repeated claim that the Kingdom mandates personal-data localisation does not survive the current text.
Article 29, operationalised by the Regulation on Personal Data Transfer Outside the Kingdom issued in 2023 and updated 1 September 2024, permits transfer for listed purposes; the 2024 version added central processing, service provision and scientific research [S10][S17]. No transfer may prejudice national security or the Kingdom’s vital interests, and each must be limited to the minimum data necessary [S10].
The mechanism then splits. Either the destination sits on SDAIA’s list of jurisdictions assessed as offering adequate protection — not yet published [S10] — or the controller implements one of three approved safeguards: SDAIA standard contractual clauses, in four controller-processor models; binding common rules for intra-group transfers; or a certificate of accreditation [S9][S10]. A transfer risk assessment is required, with exemptions for small-volume transfers under SCCs without sensitive data, public-entity and approved intra-group transfers, and approved research [S10].
On localisation, here is the resolution. DLA Piper states localisation is “not explicitly mandated, though transfers remain heavily restricted and regulated” [S8]. Coverage asserting a statutory residency rule generally reflects the 2021 text before the March 2023 amendment. Localisation does bite — through NDMO classification of government data, NCA cloud controls, and sector regulators — but it attaches to the class of data and the identity of the customer, not to personal data generally. That is why hyperscalers built in-Kingdom regions. See cloud computing and digital sovereignty and the Saudi data center pipeline.
What Are the Penalties Under the PDPL?
Two tiers, plus private action. Disclosing or publishing sensitive personal data with intent to cause harm or obtain benefit carries up to two years imprisonment, a fine of up to SAR3m (about $800,000), or both. Any other violation attracts a warning or a fine of up to SAR5m (about $1.33m), which a court may double for repeat offences — a ceiling of SAR10m (about $2.67m) [S8][S9]. Data subjects may separately claim material or moral damages, and must lodge a complaint within 90 days of becoming aware [S9].
On enforcement the primary evidence is thin: SDAIA publishes no decisions register. Squire Patton Boggs’ Global Privacy & Security Compliance Blog reported in May 2026 that SDAIA’s specialised committees had issued 48 enforcement decisions across 2025 and 2026, concentrated on processing without a valid legal basis, unauthorised disclosure, inadequate safeguards, and marketing without consent [S11][S12]. That post refused automated retrieval here; treat the figure as reported rather than documented. No published decision has applied the SAR5m ceiling to a named respondent, so anyone modelling Saudi enforcement risk off European fine tables is modelling the wrong distribution.
Where the NCA’s Cybersecurity Controls Bite on AI Systems
The National Cybersecurity Authority publishes a control stack rather than a statute. Its regulatory-documents register lists the Data Cybersecurity Controls, published 18 September 2022, alongside the Critical Systems and Operational Technology controls, both dated 2 June 2022 [S4]. The Essential Cybersecurity Controls are the baseline; Cloud Cybersecurity Controls govern cloud deployments.
They bite in three places: training data under the Data Cybersecurity Controls; cloud inference infrastructure under the cloud controls, which carry residency conditions; and, where the system supports a critical system such as a grid or payments rail, the Critical Systems controls on top. The scope limitation is what to internalise — these bind government entities and critical national infrastructure operators, reaching private companies through the supply chain. A vendor with no government customer is largely outside them; one selling to a ministry inherits them by contract. See the Saudi cybersecurity framework.
Sector Overlays: SAMA for Finance, SFDA for Health
Financial services carries the most explicit overlay. The Saudi Central Bank issued Circular 43045328 on 23 December 2021, binding banks, finance companies, payment providers, money exchangers, credit bureaus and sandbox participants. It requires them to “review the approved internal policies and procedures and ensure their compatibility and/or amendment” with the PDPL, and to align with “policies, controls and rules issued by” SDAIA [S18]. That converts SDAIA’s data rules into supervised obligations enforceable by SAMA against a licensed entity — a harder constraint than the PDPL alone.
On devices, the Saudi Food and Drug Authority published MDS-G010, “Guidance for Artificial Intelligence and Machine Learning (AI/ML)-Enabled Medical Devices,” on 3 January 2023, setting out Medical Devices Marketing Authorisation requirements [S19]. Styled as guidance, it works as a market-access condition: without authorisation the device cannot be sold. That makes SFDA, not SDAIA, the regulator with the sharpest teeth over a specific class of AI system.
Health data itself is sensitive personal data under the PDPL, attracting the higher penalty tier and the DPO trigger. The Ministry of Health and the National Health Information Center run health data governance policies alongside it, but neither publishes a consolidated English instrument list, and no named health-data regulation could be verified from a primary source here.
Deploying an LLM in Saudi Arabia: A Compliance Walkthrough
In order, for a model going into production in the Kingdom.
- Establish whether the PDPL reaches you, and fix your role — controller or processor. Every downstream obligation keys off it.
- Register on the National Data Governance Platform if you fall into a registration category.
- Establish a legal basis for each processing operation. If the system decides solely by automated means, you need explicit consent — the step most often missed.
- Appoint and register a DPO if any of the three triggers applies.
- Build the record of processing activities, treating training, fine-tuning, evaluation and inference as distinct operations — most teams document inference and forget training.
- Map every flow out of the Kingdom, run a transfer risk assessment unless exempt, and put SDAIA clauses or binding common rules in place. Do not wait for an adequacy list that does not exist.
- Apply NDMO classification for government data and NCA controls if you or your customer is a public entity or critical infrastructure operator.
- Check the sector overlay — SAMA Circular 43045328 for supervised financial institutions, SFDA MDS-G010 for medical devices.
- Stand up 72-hour breach notification with an owner, a template and a tested escalation path.
- Run the AI Ethics Principles self-assessment, and treat training-data copyright as a separate exercise.
EU AI Act, UAE and Saudi Arabia Compared
The timing is pointed. On 2 August 2026 — two days after this page was verified — the bulk of the EU AI Act begins to apply, with Article 6(1) high-risk obligations following on 2 August 2027; prohibitions have applied since 2 February 2025 and general-purpose model obligations since 2 August 2025 [S20].
| Saudi Arabia | UAE | European Union | |
|---|---|---|---|
| Binding AI statute | None | None [S21] | AI Act, in force 1 August 2024 |
| Risk tiers | Four, in non-binding guidance | None binding | Four, statutory |
| Main binding instrument | PDPL (M/19, as amended) | Federal Decree-Law 45 of 2021 | AI Act plus GDPR |
| Extraterritorial reach | Foreign processing of residents’ data | Via the federal PDPL | Output used in the Union [S22] |
| AI-specific penalties | None | None | €35m or 7% of worldwide turnover for prohibited practices; €15m or 3% otherwise; €7.5m or 1% for misleading information [S22] |
| Data-protection penalties | SAR5m ($1.33m), doubling; SAR3m and 2 years for sensitive data | Federal PDPL regime | GDPR: €20m or 4% |
| Other AI instruments | AI Ethics Principles; Generative AI Guidelines; draft hub law | UAE Charter for AI Development (2024); National AI Strategy 2031; DIFC Data Protection Law No. 5 of 2020, amended 2023 [S21] | Harmonised standards |
The reconciliation problem runs one way. Build to the EU AI Act and you clear the Saudi and UAE bars on system governance — but you will still fail Saudi compliance without the PDPL registration, the transfer risk assessment and the SDAIA clauses, because none has an EU analogue you can reuse. The Gulf regimes are lighter on the model and heavier on the paperwork around the data: building to Brussels does not exempt you from Riyadh’s filing cabinet. And where the EU publishes a timetable, Saudi Arabia is discretionary — what is required depends on who your customer is, and the state is the largest customer.
HUMAIN and the Regulator-Operator Problem
Here is the governance question an outside investor should be asking, and it deserves a straight answer rather than either a defence or an insinuation.
Saudi Arabia is simultaneously the regulator of AI and, through the Public Investment Fund, the largest AI operator in the country. HUMAIN, launched 13 May 2025 under chief executive Tareq Amin, is a wholly PIF-owned AI company building gigawatt-scale compute and a sovereign Arabic frontier model; HUMAIN’s full company profile has the structure, and its announced model-layer relationships, graded by instrument show how much of that model layer is bought rather than built. PIF’s board is chaired by Crown Prince Mohammed bin Salman, who is also Prime Minister — the office to which SDAIA reports. The chain from supervisory authority to supervised operator closes at a single person. It goes beyond ownership: in January 2026 SDAIA itself laid the foundation stone for a 480MW government data center in Riyadh [S23]. The body supervising the PDPL is also building national compute.
What independence safeguards exist? Few of the kind a European or American investor would recognise: no data protection commissioner separate from the AI-promotion function, no appointments process insulating the supervisor from the executive, no published decisions register, and no settled administrative court practice on PDPL appeals. The separations that exist are functional rather than structural — NCA outside SDAIA for cybersecurity, CST outside it for infrastructure, SAMA and SFDA independently powerful in their sectors.
The fair reading is that this is a feature of the model, not a defect in its execution. Saudi Arabia has chosen developmental regulation — the state as promoter, buyer and supervisor at once — the model that built its petrochemical and telecom sectors. The exposure is not that SDAIA will be captured; it is that a private competitor to a PIF portfolio company has no forum in which to argue that a decision was made for competitive reasons. That is an unpriced risk worth pricing. It cuts the other way too: the binding constraint on the build-out has turned out to be grid power rather than chips, a physical limit no regulator controls. The status of HUMAIN’s Riyadh and Dammam sites tests execution; US export controls on AI accelerators are the external constraint no domestic framework resolves.
Training Data: The Data-Protection Side
Two separate regimes govern what you may train on, and confusing them is the most common error in the market. The copyright question belongs to a different statute on a different clock: Article 26 of the new Copyright Law, promulgated by Royal Decree M/169 and in force from 12 August 2026, permits reproduction of a published work without the author’s permission and without compensation to develop AI products and algorithms, with no rights-holder opt-out. Our sibling analysis of Article 26 of the 2026 Copyright Law covers it in full; see also the Saudi intellectual property framework.
The data-protection question is untouched by Article 26, and this is what practitioners miss. A copyright exception is not a lawful basis for processing personal data. If a training corpus contains personal data — names, images, biometric identifiers, health or location data — the PDPL applies to it independently, with its own legal-basis requirement, its own transfer conditions if training runs offshore, and its own penalty tier if the data is sensitive. A scraped Arabic web corpus almost certainly contains all of it. Article 26 disposes of the author’s claim; it does nothing about the data subject’s.
Why This Matters for Vision 2030
Vision 2030’s digital-economy targets depend on foreign AI capital and operators choosing the Kingdom over the UAE, and regulatory legibility is part of that calculus. No AI act means no conformity assessments, no notified bodies and no €35m exposure — a speed advantage over Europe at precisely the moment the EU’s obligations bite, and the national AI strategy is built on it.
The liability is predictability. An investor can price a known compliance cost; harder to price is a regime where the operative constraint may be a procurement condition or an unpublished enforcement posture rather than a published rule. The draft hub law suggests some awareness of this — the data-embassy concept is an offer to let foreign operators bring their own legal certainty with them. See how laws work in Saudi Arabia and the foreign investment law.
Risks, Contradictions and Open Questions
The adequacy list does not exist. The transfer regulation is built around a list of jurisdictions offering adequate protection, and SDAIA has published none [S9][S10]. Every exporter is forced down the safeguards route — the largest single gap in Saudi Arabia AI regulation as it stands.
AI Ethics Principles 2.0 is imperfectly dated. Version 1.0 carries September 2023 on its own cover [S1]. Version 2.0 exists and the SDAIA-hosted file shows 2025 [S2], but SDAIA’s main domain blocked automated retrieval, so the exact date could not be pinned to a primary source. Some secondary coverage dates the first version to 2022; trust the cover.
The enforcement record is reported, not documented. The 48-decision figure rests on one law-firm post and its downstream summaries [S11][S12]. Without a public register there is no verifying the count, the respondents, or whether any fine approached the ceiling. Health-sector instruments likewise could not be fully verified, so the position above is deliberately conservative.
Nobody knows whether a Saudi AI act is coming. The trackers say no legislative process has been announced [S6][S7]; the hub law has sat as a draft for fifteen months. That is consistent both with a deliberate choice not to legislate and with a slow process not yet public.
What to Watch Next
- 2 August 2026. The bulk of the EU AI Act applies. Watch whether Saudi-domiciled model providers serving EU users adjust, since the Union’s reach follows the output, not the developer.
- 12 August 2026. Article 26 of the Copyright Law enters into force; implementing regulations were still unwritten at publication.
- 14 September 2026. Two years since full PDPL enforcement began — a natural point for SDAIA to publish aggregate statistics, and for the adequacy list whose absence forces every exporter down the safeguards route.
- A binding AI instrument. Enactment of the hub law, or an AI Ethics Principles 3.0 attaching a penalty to registration, is the moment this article’s grading changes.
Related Vision 2030 Context
- SDAIA institutional profile — mandate, structure and the NDMO relationship
- Saudi data protection and privacy framework — the general PDPL overview
- NDMO data governance policies — the national classification layer
- Article 26 of the 2026 Copyright Law — the AI training exception
- Saudi AI strategy — the policy programme the regulation sits inside
- HUMAIN company profile — the PIF-owned operator
Sources
- [S1] Saudi Data and Artificial Intelligence Authority, AI Ethics Principles, Version 1.0, framework document, September 2023. Hosted on SDAIA’s National Data Governance Platform. https://dgp.sdaia.gov.sa/wps/wcm/connect/4c56ed1c-1b82-447d-ac29-638f5f99c12e/ai-principles-EN.pdf
- [S2] Saudi Data and Artificial Intelligence Authority, AI Ethics Principles, current edition dated 2025. https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf — SDAIA’s main domain refused automated retrieval; version 2.0 details here are drawn from secondary coverage of the document.
- [S3] Personal Data Protection Law, Royal Decree No. M/19 of 09/02/1443 AH (16 September 2021), amended by Royal Decree No. M/148 of 05/09/1444 AH (27 March 2023). Text and status as summarised in [S8] and [S9].
- [S4] National Cybersecurity Authority (Saudi Arabia), Regulatory Documents register, accessed 31 July 2026. https://nca.gov.sa/en/regulatory-documents/
- [S5] National Competitiveness Center, Istitlaa consultation platform, Global AI Hub Law (Communications, Space and Technology Commission), April to May 2025. https://istitlaa.ncc.gov.sa/en/Transportation/citc/globalailaw/Pages/default.aspx
- [S6] CMS, AI Regulation Scanner — Kingdom of Saudi Arabia, expert guide, position as at 17 February 2026. https://cms.law/en/int/expert-guides/ai-regulation-scanner/kingdom-of-saudi-arabia
- [S7] Regulations.ai, Saudi Arabia AI Regulation Overview, regulatory inventory, 2026. https://regulations.ai/regulations/saudi-arabia-summary
- [S8] DLA Piper, Data Protection Laws of the World — Saudi Arabia, country guide, February 2026. https://www.dlapiperdataprotection.com/?c=SA
- [S9] International Comparative Legal Guides, Data Protection Laws and Regulations 2026 — Saudi Arabia, practitioner chapter. https://iclg.com/practice-areas/data-protection-laws-and-regulations/saudi-arabia/
- [S10] Securiti, An Overview of the Regulation on Personal Data Transfer Outside the Kingdom, regulatory analysis. https://securiti.ai/regulation-on-personal-data-transfer-outside-the-kingdom/
- [S11] Squire Patton Boggs, Active Enforcement of Saudi Arabia Privacy Regime — Implications for Businesses, Global Privacy & Security Compliance Blog, May 2026. https://www.globalprivacyblog.com/2026/05/active-enforcement-of-saudi-arabia-privacy-regime-implications-for-businesses/ — the post refused automated retrieval; enforcement figures cited here are as reported in [S12].
- [S12] SGC Consulting, SDAIA and the Saudi Personal Data Protection Law — What Saudi Organizations Must Know in 2026, compliance guide, 2026. https://www.sgc.consulting/sdaia-saudi-personal-data-protection-law-pdpl-compliance-guide/
- [S13] DGA Group, Saudi Arabia Introduces a Draft Global AI Hub Law, policy insight, 2025. https://dgagroup.com/insight/saudi-arabia-introduces-a-draft-global-ai-hub-law/
- [S14] Saudi Press Agency, Saudi Arabia Emerges as AI Powerhouse under Vision 2030, Declares 2026 the Year of Artificial Intelligence, official release, 2026. https://www.spa.gov.sa/en/N2533339
- [S15] National Platform (my.gov.sa), Saudi Data and Artificial Intelligence Authority agency profile. https://my.gov.sa/en/agencies/17828
- [S16] Morgan Lewis, Saudi Arabia Personal Data Protection Law — Transition Period Ends September 14, client alert, September 2024. https://www.morganlewis.com/pubs/2024/09/saudi-arabia-personal-data-protection-law-transition-period-ends-september-14
- [S17] Mayer Brown, Updates to Saudi Arabia’s Personal Data Protection Regulations — SCCs, Guidelines and More, client alert, October 2024. https://www.mayerbrown.com/en/insights/publications/2024/10/updates-to-saudi-arabias-personal-data-protection-regulations-sccs-guidelines-and-more
- [S18] Saudi Central Bank (SAMA), Adherence to the Personal Data Protection Law and Data Governance Policies, Regulations and Rules, Circular No. 43045328, 19/05/1443 AH (23 December 2021), SAMA Rulebook. https://rulebook.sama.gov.sa/en/adherence-personal-data-protection-law-and-data-governance-policies-regulations-and-rules
- [S19] Saudi Food and Drug Authority, Guidance for Artificial Intelligence and Machine Learning (AI/ML)-Enabled Medical Devices, MDS-G010, 3 January 2023. https://www.sfda.gov.sa/sites/default/files/2023-01/MDS-G010ML.pdf
- [S20] EU Artificial Intelligence Act, Implementation Timeline. https://artificialintelligenceact.eu/implementation-timeline/
- [S21] CMS, AI Regulation Scanner — United Arab Emirates, expert guide, 2026. https://cms.law/en/int/expert-guides/ai-regulation-scanner/united-arab-emirates
- [S22] EU Artificial Intelligence Act, Article 99 (Penalties) and Article 2 (Scope), Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/99/
- [S23] w.media, SDAIA Lays Foundation Stone for 480MW Hexagon Government Data Center in Riyadh, trade report, 5 January 2026. https://w.media/sdaia-lays-foundation-stone-for-480mw-hexagon-government-data-center-in-riyadh/