Authored By: Renad Mohammed Haroun Ali
- Introduction
Artificial intelligence (‘AI’) presents a regulatory problem that conventional legal frameworks were not designed to address. AI systems can influence decisions concerning employment, healthcare, finance, public administration and access to services, while generative AI can produce information and synthetic content at unprecedented scale. The principal legal difficulty is therefore not whether AI should be regulated, but how regulation can allocate responsibility and protect individual rights without unnecessarily restricting technological development.
Saudi Arabia has responded through a developing governance framework centered on the Saudi Data and AI Authority (‘SDAIA’), the AI Ethics Principles, the AI Adoption Framework, generative AI guidance and the National AI Risk Management Framework (‘NAIRMF’). This approach is significant because it does not presently depend upon a single comprehensive AI statute. Instead, it combines ethical standards, governance mechanisms, risk management and existing legislation such as the Personal Data Protection Law (‘PDPL’). SDAIA identifies itself as the competent national authority concerned with data and AI, while the National Strategy for Data and AI seeks simultaneously to promote AI development and responsible use.¹
This paper argues that Saudi Arabia’s approach is a rational first stage of AI governance because its flexibility is better suited to rapidly changing technology than rigid legislation alone. However, an ethics- and risk-based framework cannot, by itself, provide sufficient legal certainty, accountability or remedies where AI causes significant harm. Saudi Arabia should therefore retain its flexible governance model while progressively converting high-risk principles into enforceable legal obligations. The European Union (‘EU’) AI Act provides a useful comparative model, but not necessarily one that Saudi Arabia should replicate in its entirety.
- The Institutional and Legal Architecture
SDAIA occupies a central position in Saudi Arabia’s AI governance architecture. Its mandate covers data and AI, and its regulatory publications include the AI Ethics Principles, AI Adoption Framework and other AI-related guidance.²
The significance of SDAIA is not merely institutional. It demonstrates that Saudi Arabia has chosen a centralised governance model rather than allowing AI regulation to develop exclusively through separate sectoral regulators. This can improve consistency and reduce regulatory fragmentation. Nevertheless, centralisation does not automatically resolve the question of legal enforceability. A governance authority may issue principles and frameworks that influence organisational behaviour without those instruments necessarily creating the same rights, duties and remedies as legislation.
This distinction is particularly important when AI causes harm. The PDPL, for example, creates legally enforceable obligations concerning the processing and protection of personal data.³ By contrast, the AI Ethics Principles function primarily as an ethical and governance framework. SDAIA itself describes the AI Adoption Framework as a ‘guiding reference’ rather than as a comprehensive statutory regime.⁴
The resulting framework is therefore best understood as layered regulation. Existing binding laws provide legal controls in particular areas, while SDAIA’s AI-specific instruments provide standards for responsible development and deployment. The advantage is adaptability; the weakness is that the boundary between ethical expectation and enforceable legal obligation can become uncertain.
- AI Ethics Principles: From Ethical Values to Legal Duties
SDAIA’s AI Ethics Principles identify core values including fairness, privacy and security, reliability and safety, transparency and explain ability, and accountability and responsibility.⁵
These principles are important because they identify the principal values that AI regulation must protect. However, their legal significance depends on whether they are capable of being translated into concrete duties.
Consider fairness. An AI system used in recruitment or credit assessment could systematically disadvantage a particular group because of biased training data. An ethical principle against discrimination identifies the problem, but it does not by itself answer the legal questions of who is liable, what standard of care applies, what evidence a claimant must produce, or what remedy should be available.
Similarly, transparency is valuable only if it creates meaningful accountability. Requiring an organisation to acknowledge that AI was used does not necessarily enable an affected person to understand why a decision was made or challenge its accuracy. Transparency therefore should not be treated as an end in itself. Its regulatory purpose is to facilitate contestability and accountability.
The same problem arises with accountability. AI systems commonly involve developers, providers, deployers and end-users. Where harm results from the interaction between these actors, assigning responsibility becomes difficult. A general ethical requirement that organisations remain accountable does not establish the precise allocation of liability.
The critical weakness, therefore, is not the content of the principles but their normative status. Ethical principles can influence organisational conduct, but serious violations affecting life, liberty, property or fundamental rights require rules capable of producing predictable legal consequences.
- AI Adoption: Regulation Should Not Become a Barrier to Innovation
The AI Adoption Framework reveals a second dimension of Saudi policy: regulation is intended to facilitate AI adoption rather than merely restrict it. SDAIA describes the framework as a comprehensive guide for AI adoption across sectors, with emphasis on governance, innovation and responsible implementation.⁶
This approach is defensible. Excessively prescriptive regulation can impose compliance costs before the risks associated with emerging technologies are sufficiently understood. A flexible framework can instead permit experimentation while requiring organisations to consider governance and risk.
Nevertheless, the argument that flexibility promotes innovation should not be accepted without qualification. Legal certainty can itself encourage innovation. Businesses may be reluctant to invest in AI where they cannot predict regulatory expectations or potential liability. Consequently, the choice is not simply between regulation and innovation. The more important distinction is between uncertain regulation and predictable regulation.
Saudi Arabia should therefore aim for a framework in which organisations can clearly identify which obligations are mandatory, which are recommended and which are still developing. The AI Adoption Framework is strongest when it operates as a bridge between technological experimentation and eventual legal standardisation.
- Generative AI and the Problem of Human Accountability
Generative AI creates particularly difficult regulatory questions because it can produce apparently authoritative content that is factually incorrect, disclose confidential information, reproduce protected material or generate deceptive synthetic content.
SDAIA has issued specific guidance for the government use of generative AI, applying its broader ethical principles to practical uses of the technology.⁷
The central legal issue is human accountability. If a public employee relies on an AI-generated answer that contains a serious error, responsibility cannot sensibly be assigned to the AI system itself. The relevant legal question is whether the human user and the organisation exercised reasonable oversight.
This suggests that Saudi AI governance should move beyond the principle of ‘human oversight’ and develop more precise requirements for when human review is mandatory. The stricter the potential harm, the stronger the justification for requiring a human decision-maker to verify the AI output.
The issue also demonstrates the importance of connecting AI governance with existing laws. Where generative AI processes personal information, the PDPL may already impose legally binding restrictions.⁸ Thus, Saudi Arabia does not necessarily need an entirely new law for every AI-related harm; instead, it should determine where existing legislation is adequate and where AI creates regulatory gaps.
- The National AI Risk Management Framework
The NAIRMF represents a significant development because it introduces a systematic methodology for identifying, assessing, treating and monitoring AI risks. SDAIA presents the framework as a practical mechanism for organisations to manage AI risks throughout the AI lifecycle.⁹
Its principal strength is its adaptability. AI risks are not static: a system that appears safe during development may behave differently when deployed at scale, exposed to new data or used for an unintended purpose. Continuous risk monitoring is therefore more suitable to AI than a regulatory model based solely on one-time approval.
However, risk management has an inherent limitation: risk assessment does not necessarily establish legal responsibility. An organisation may identify a risk, classify it as significant and adopt mitigation measures, yet an affected person may still have no clear statutory route to compensation or judicial review if harm occurs.
Risk governance should therefore be regarded as a complement to law, not a substitute for it. The NAIRMF can establish a valuable preventative layer, but binding rules are required where society has decided that certain conduct is unacceptable regardless of an organisation’s internal risk assessment.
- Saudi Arabia and the EU: Two Different Models
The EU AI Act provides a useful comparison because it combines risk management with binding legislation. Regulation (EU) 2024/1689 establishes four broad risk categories and imposes different legal requirements depending on the level and nature of risk.¹⁰
The distinction is therefore not that Saudi Arabia uses risk management while the EU does not. Both systems recognise risk as the basis for differentiated regulation. The fundamental difference is the legal mechanism through which risk is controlled. The EU converts risk classifications into statutory obligations, whereas Saudi Arabia currently relies more heavily on principles, frameworks and guidance alongside existing legislation.
The EU model offers greater legal certainty. For example, certain prohibited practices are identified by law, while high-risk systems are subject to specified compliance requirements. The AI Act also establishes transparency obligations for certain AI systems.¹¹
Yet the EU model also demonstrates the disadvantages of detailed legislation. Its implementation requires extensive guidance, technical standards and institutional coordination. The need for continuing clarification illustrates a fundamental problem: legislation cannot completely eliminate uncertainty in a technology that is itself continuously evolving.
Saudi Arabia can therefore learn from the EU without simply copying it. A more suitable approach would be to preserve the flexibility of the existing governance framework while identifying categories of AI where binding legal obligations are justified by the severity of potential harm.
- The Case for Progressive Hard-Law Regulation
The strongest argument for Saudi Arabia’s current approach is that AI regulation is still developing. Premature comprehensive legislation could freeze regulatory assumptions that may soon become technologically obsolete.
However, the opposite risk is equally significant. If ethical frameworks remain non-binding for too long, organisations may have insufficient incentives to comply, particularly where compliance is costly. This creates a potential accountability gap between ethical expectations and legal consequences.
Saudi Arabia should therefore adopt a principle of progressive hard-law regulation. Low-risk AI could remain subject primarily to flexible guidance and voluntary standards. High-risk applications—particularly those affecting employment, healthcare, financial access, public services, personal data or fundamental interests—should progressively become subject to enforceable duties concerning risk assessment, documentation, human oversight, transparency, incident reporting and accountability.
Such an approach would preserve innovation while ensuring that the most serious risks are not left to voluntary compliance.
- Conclusion
Saudi Arabia has developed a sophisticated foundation for AI governance, but it would be inaccurate to describe the existing framework as equivalent to a comprehensive AI law. Its strength lies precisely in its combination of ethical principles, risk management, responsible adoption and existing legislation.
The central weakness is the gap between governance and enforceability. Ethical principles can establish desirable standards, and risk frameworks can improve organisational decision-making, but neither necessarily provides individuals with the same legal protection as a binding statutory duty.
The EU experience demonstrates that risk-based governance can be transformed into enforceable legal obligations, although it also shows the difficulty of regulating rapidly changing technology through detailed legislation.
Accordingly, Saudi Arabia should not abandon its current model in favour of wholesale legislative transplantation. Instead, it should use the existing SDAIA framework as the foundation for targeted, risk-sensitive legislation. The most serious AI risks should trigger mandatory duties and clear accountability mechanisms, while lower-risk applications should remain governed by flexible standards.
The appropriate question is therefore not whether Saudi Arabia needs ‘more regulation’, but where ethical governance should end and binding law should begin. The success of Saudi AI governance will ultimately depend on its ability to draw that boundary clearly, revise it as technology evolves, and ensure that innovation remains compatible with accountability and the protection of individual rights.
Footnote(S): — OSCOLA
- Saudi Data and AI Authority (‘SDAIA’), ‘National Data & AI Strategy’ https://sdaia.gov.sa/en/SDAIA/SdaiaStrategies/Pages/NationalStrategyForDataAndAI.aspx accessed 22 August 2026.
- SDAIA, ‘Saudi Data & AI Authority: Laws and Regulations’ https://sdaia.gov.sa/en/SDAIA/about/Pages/RegulationsAndPolicies.aspx accessed 22 August 2026.
- Personal Data Protection Law, Royal Decree No M/19 (9 Safar 1443 AH), as amended; see SDAIA, ‘Personal Data Protection Law’ https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf accessed 22 August 2026.
- SDAIA, ‘AI Adoption Framework’ (15 May 2025) https://sdaia.gov.sa/en/MediaCenter/KnowledgeCenter/Pages/SDAIAPublications.aspx accessed 22 August 2026.
- SDAIA, ‘AI Ethics Principles’ (September 2023) https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf accessed 22 August 2026.
- SDAIA, ‘Artificial Intelligence Adoption Framework’ (2025).
- SDAIA, ‘Generative Artificial Intelligence Guidelines for Government’ https://sdaia.gov.sa/en/SDAIA/about/Files/GenAIGuidelinesForGovernmentENCompressed.pdf accessed 22 August 2026.
- Personal Data Protection Law, Royal Decree No M/19 (9 Safar 1443 AH), arts 5–6 and related provisions.
- SDAIA, ‘National Artificial Intelligence Risk Management Framework’ (2026) https://sdaia.gov.sa/en/MediaCenter/KnowledgeCenter/ResearchLibrary/ExecutiveSummaryEn.pdf accessed 22 August 2026.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence [2024] OJ L 2024/1689 (‘EU AI Act’), arts 5–7.
- EU AI Act, art 50; European Commission, ‘Guidelines on the Transparency Obligations for Providers and Deployers of Certain AI Systems’ (20 July 2026).
Selected Bibliography
Legislation and official instruments
- Personal Data Protection Law, Royal Decree No M/19 (9 Safar 1443 AH), as amended.
- Regulation (EU) 2024/1689 (‘EU AI Act’).
- SDAIA, AI Ethics Principles (2023).
- SDAIA, Artificial Intelligence Adoption Framework (2025).
- SDAIA, National Artificial Intelligence Risk Management Framework (2026).
Academic literature
- ‘Regulating AI-Based Medical Devices in Saudi Arabia: New Legal Paradigms in an Evolving Global Legal Order’ (2024) Law, Innovation and Technology. The article is particularly useful for demonstrating how Saudi Arabia is already developing more concrete, sector-specific AI requirements in healthcare.
- ‘From Algorithms to Accountability: Saudi Arabia’s Path to AI Healthcare’ (2026) Journal of Medical Internet Research/related interdisciplinary literature. The analysis identifies the PDPL as providing important protection while remaining comparatively underspecified for certain healthcare-AI accountability questions.
- ‘Governing Artificial Intelligence in the Financial Sector: Regulatory …’ (2026) examines the interaction between AI adoption, accountability and risk governance specifically in Saudi Arabia’s financial sector.





