Summary
- The official announcement describes guidance. A universal adoption duty, new penalty or statutory safe harbour is not established by the available official record. Contractual incorporation can create separate obligations. (SPA, N2633725; Civil Transactions Law, art. 46.)
- An internal risk rating cannot authorise otherwise unlawful personal-data processing. An adverse statutory assessment requires corrective action; management approval cannot replace the applicable legal basis. (Personal Data Protection Law, arts. 5–6; Implementing Regulation, arts. 16(4), 25(4).)
- Outsourcing does not discharge a controller’s responsibility. Supplier indemnities may allocate financial loss between contracting parties, but cannot remove duties owed to individuals or SDAIA. (Personal Data Protection Law, art. 8; Implementing Regulation, art. 17.)
- Overseas processing requires a separate transfer analysis. Cybersecurity duties depend on the entity’s category and applicable directions, including the newer controls for non-critical-infrastructure businesses. (Personal Data Protection Law, art. 29; ECC 2:2024, p. 8; NCNICC 1:2025, pp. 7–9.)
- Incident response must distinguish operational faults from legally reportable breaches. Qualifying personal-data breaches trigger a 72-hour authority-notification period measured from awareness. An unfavourable risk score does not itself establish compensable injury. (Implementing Regulation, art. 24(1); Personal Data Protection Law, art. 40.)
Legal Status and Publication Dates
SDAIA’s public announcement establishes an advisory starting point, subject to any separate binding instrument. The Saudi Press Agency described the publication as a guidance reference for government and private entities on 14 July 2026. SDAIA’s catalogue assigns an April 2026 document date. Neither date, by itself, establishes commencement of a new statutory duty. The distinction matters when procurement teams propose a compliance deadline based solely on the launch announcement. (SPA, N2633725; SDAIA Publications, National AI Risk Management Framework catalogue entry.)
The strongest opposing argument is that SDAIA issued the document in its official capacity to organisations already under binding duties. A recipient may also hold an applicable direction incorporating the guidance, and contracting parties can adopt it by reference. Official authorship therefore does not settle every recipient’s position. Conversely, an organisational recommendation cannot acquire a statutory penalty merely because a vendor describes it as mandatory. The operative adoption instrument and its scope must supply that legal consequence. (Civil Transactions Law, arts. 46, 94–95.)
The available full Arabic text is a non-official reproduction of SDAIA-P145, edition 1, dated April 2026. It could not be authenticated against the agency-hosted file. Its operational provisions receive descriptive, non-controlling weight here. No universal filing requirement, certification obligation, transition period or enforcement tariff is established for this publication. An organisation holding a separate circular, licence condition or procurement requirement needs a different, instrument-specific assessment.
Coverage, Risk Categories and Implementation
The reproduced methodology addresses developers, operators and policymakers across public and private organisations. Its five stages are scope-setting, identification, assessment, treatment, and monitoring or review. General principles, AI rules, data rules and sector rules supply its reference points. Seven risk groups cover bias, discrimination and abuse; privacy and security; misinformation; harmful use; human-machine interaction; socioeconomic and environmental effects; and safety and limitations. Treatment options comprise avoidance, reduction, transfer and acceptance. (SDAIA-P145, non-official reproduction, pp. 7–8, 13–20, 26–29.)
An organisation applying those stages should start with a defined use, rather than approve a model for every purpose. A drafting assistant and an automated eligibility decision can use the same underlying model while exposing different people to different harms. The assessment should identify permitted inputs, affected persons, decision authority, testing evidence and escalation responsibility. These are recommended implementation choices; this assessment does not treat them as newly enacted universal duties.
A security-only inventory would omit several of the stated risk groups. Privacy controls do not establish the truth of generated content, and accuracy tests do not establish lawful data collection. The proposed control record should therefore pair each identified harm with its responsible owner and applicable legal rule. Where no binding provision has been identified, the organisation should describe its control as an internal commitment rather than invent a statutory obligation.
The reproduced government drafting illustration restricts its own hosting and inputs. Those assumptions cannot establish a national prohibition on all overseas AI processing or all sensitive-data use. Applying an illustrative condition universally would require an additional legal premise. The binding transfer and processing provisions must determine whether that premise exists for the deployment concerned. (SDAIA-P145, non-official reproduction, p. 32; Personal Data Protection Law, arts. 5–6, 29.)
AI Ethics Categories and Residual Risk
SDAIA’s earlier AI Ethics Principles require separate consideration. In its September 2023 English edition, SDAIA uses mandatory wording for high-risk assessments and states that unacceptable-risk uses are prohibited. The same publication describes registration and associated reports as optional. Optional registration cannot establish that every substantive expectation is voluntary. Equally, directive wording alone does not establish a statutory offence or its penalty. The applicable adoption and enforcement instruments remain material. (SDAIA, AI Ethics Principles, September 2023, pp. 8, 32.)
An organisation should therefore test any proposed residual-risk acceptance against the earlier categories and applicable law. The reproduced treatment option does not establish permission to disregard an unacceptable-risk classification. No verified provision establishes that the July publication repealed the earlier principles. A claim of supersession would require the operative text or a later official direction, neither of which is established here.
Risk Ratings and Statutory Assessments
A risk score cannot substitute for a statutory trigger. Under the Implementing Regulation, processing sensitive personal data or collecting, comparing or linking two or more personal datasets obtained from different sources requires a written, documented impact assessment. Article 25 also requires assessments for specified large-scale or repeated activities and products or services presenting serious privacy harm. The presence of AI alone does not resolve every condition in that provision. (Personal Data Protection Law, art. 22; Implementing Regulation, art. 25(1).)
Consider a proposed system that links identifiable customer records from two separate sources. That factual condition engages article 25(1)(b), even where management assigns a low internal rating. Calling the exercise a pilot does not remove the dataset-linking condition. A single combined document can serve operational and statutory purposes only if it contains the required statutory assessment, including the processing basis and adequacy of safeguards. The document’s title cannot cure missing content. The controller must provide a copy of the impact assessment to each processor acting on its behalf for the relevant processing. (Implementing Regulation, art. 25(1)(b), (2)–(3).)
Multiplication also loses information that may matter legally. In a hypothetical scoring system, likelihood 1 multiplied by severity 4 equals 4; likelihood 4 multiplied by severity 1 also equals 4. These are derived calculations, not SDAIA acceptance thresholds or observed incidents. Equal products cannot establish equal consequences for privacy or safety. A decision-maker should retain the underlying severity and legal triggers rather than use the product as permission to proceed.
Where the statutory assessment predicts privacy harm, article 25(4) requires correction of its causes and reassessment. The argument that a responsible manager accepted the remaining risk fails when that acceptance replaces a required corrective step. Equally, a duty to reassess does not establish that every system must achieve zero residual risk. The proposed processing must satisfy the relevant substantive conditions after correction. (Implementing Regulation, art. 25(4).)
Lawful Processing and Human Review
Personal-data processing requires consent or an applicable statutory alternative. A private controller relying on legitimate interests must satisfy the conditions in article 16, which exclude sensitive data and public controllers. The controller must document necessity, lawful purpose, reasonable expectations and a balance that preserves the individual’s rights and interests. A commercial desire to improve a model cannot, without those conditions, establish a lawful basis. The organisation should identify the basis for training, live prompts and later reuse separately where their purposes differ. (Personal Data Protection Law, arts. 5–6; Implementing Regulation, arts. 11(1)(e), 16.)
Article 11(2)(c) requires explicit consent for decisions based wholly on automated personal-data processing within the consent regime. That provision must be read with the statutory alternatives in article 6. It should not be converted into a statement that every automated decision always requires consent regardless of another lawful basis. Nor does adding a nominal reviewer prove that a decision ceases to be wholly automated. The reviewer’s actual authority and conduct require examination. (Personal Data Protection Law, art. 6; Implementing Regulation, art. 11(2)(c).)
Human review should address the harm that justifies it. A reviewer unable to inspect the relevant information or reject an output cannot reliably provide the proposed safeguard. That is an implementation inference, not a universal staffing rule. A regulator or court would still need the facts and applicable duty before attributing legal consequences to an inadequate review process.
Known inaccuracies can require suspension of the affected processing. Article 22(3) applies where incorrect or incomplete personal data could harm the individual. If an AI-generated allegation enters an identifiable person’s record, an organisation cannot treat the problem solely as model performance. It must examine the correction duty and halt the affected processing when the statutory conditions are met. Not every inaccurate answer concerns personal data, so that factual boundary matters. (Implementing Regulation, art. 22(3)–(4).)
Supplier Accountability and Contractual Adoption
The controller retains responsibility after selecting a processor. A processor acting outside its instructions or agreement incurs controller responsibility. Contract labels therefore require comparison with actual purposes and conduct. A supplier that reuses customer prompts for an independent purpose needs separate scrutiny, even where the commercial agreement calls it only a processor. (Personal Data Protection Law, arts. 1(18)–(19), 8; Implementing Regulation, art. 17(3)–(4).)
Processor agreements must specify purpose, data categories, duration and breach notice without undue delay. They must address foreign legal exposure, onward recipients and mandatory disclosure under Saudi law. (Implementing Regulation, art. 17(1).)
An organisation should seek enforceable access to the information needed for its own assessment. Proposed terms should cover authorised uses, subprocessors, change notification, incident escalation, evidence access and deletion. Before contracting with a subprocessor, the processor must ensure adequate data-protection guarantees and obtain the controller’s prior approval, giving advance notice and an opportunity to object within an agreed period. Each term should respond to the deployment’s identified exposure. An indemnity does not supply missing testing evidence, prevent unauthorised reuse, or discharge the controller’s statutory duties. Its availability and limits depend on the actual agreement. (Personal Data Protection Law, art. 8; Implementing Regulation, art. 17.)
Contractual incorporation creates a separate route to enforceability. Article 46 permits express or implied incorporation; articles 94–95 require performance of valid obligations. Parties should identify the adopted edition, required deliverables, responsibility for later changes and agreed remedies. A generic promise to follow all SDAIA publications leaves avoidable uncertainty about documents and versions. No supplied contract establishes whether such a promise exists in this matter. (Civil Transactions Law, arts. 46, 94–95.)
A supplier can dispute incorporation, the meaning of a deliverable, breach or the claimed loss. Contractual exclusions also require scrutiny. Article 173 limits exemption for fraud or gross negligence and prohibits agreed exemption from liability for a harmful act. An indemnity and an exclusion of liability therefore require different examination. Internal approval does not prove that a supplier accepted every later amendment. Government procurement may engage additional rules; no government tender or contract has been supplied for that analysis. (Civil Transactions Law, art. 173.)
Overseas Processing and Cybersecurity Scope
The Personal Data Protection Law (PDPL) applies to processing in Saudi Arabia and relevant overseas processing of residents’ personal data. Article 29 permits transfers only through its conditions and applicable regulatory routes. These include national-security protection, adequate protection abroad and data minimisation, subject to the stated exceptions. A Saudi customer, server location or supplier nationality does not alone determine the whole arrangement. The assessment should trace prompts, retrieval data, support access, logs and backups to determine whether an overseas transfer or disclosure occurs. No particular transfer route is approved here. (Personal Data Protection Law, arts. 2(1), 29.)
Domestic hosting can reduce one category of exposure without establishing full compliance. A locally hosted service can still use data unlawfully or disclose them through overseas support. Conversely, the existence of foreign processing does not itself establish a blanket statutory prohibition. The destination, purpose, safeguards and applicable exceptions must be examined alongside any sector or classified-data restrictions. Those deployment facts are not stated in the available materials. (Personal Data Protection Law, art. 29.)
Cybersecurity obligations also require classification of the entity. ECC 2:2024 applies to government entities, their affiliates, and private owners, operators or hosts of critical national infrastructure within its stated scope. Its risk-assessment controls address project initiation, major infrastructure changes, third-party planning and prerelease decisions. An AI approval should be coordinated with those existing decision points when ECC applies. (National Cybersecurity Authority, Essential Cybersecurity Controls, ECC 2:2024, p. 8, control 1-5-3, p. 13.)
Being outside that ECC category does not settle the position for a private business. NCA issued NCNICC 1:2025 for non-critical-infrastructure private entities on 28 December 2025. Applicability depends on category and NCA circulation; individual controls distinguish mandatory requirements from recommendations. The risk-management controls are mandatory for category A and recommended for category B, subject to additional NCA requirements. A small-business label therefore cannot replace examination of the applicable direction and control. (NCA, NCNICC 1:2025, pp. 7–9, controls 1-3-1 to 1-3-3, pp. 14–15.)
The Implementing Regulation separately requires applicable NCA measures or recognised cybersecurity practices where NCA controls are not binding. The proposed AI assessment should record which route applies and why. This legal mapping remains incomplete for an unidentified bank, healthcare provider or classified-data system; their specific instruments must be checked before deployment approval. (Implementing Regulation, art. 23(2).)
Monitoring, Incident Decisions and Records
Operational monitoring and statutory breach reporting require different decisions. The authority-notification trigger concerns a breach capable of harming personal data or the individual, or conflicting with the individual’s rights or interests. A qualifying breach requires notification within 72 hours of awareness. An organisation should not wait for its next AI committee meeting or a final root-cause report before testing that trigger. Missing details require prompt supplementation with reasons, rather than treating incomplete investigation as a general extension. Other applicable reporting duties remain preserved. (Implementing Regulation, art. 24(1)–(4).)
A hallucination without a personal-data breach does not automatically engage that reporting clock. A disclosure through generated output may do so, depending on the data and threatened harm. The incident owner should record awareness time, the affected processing and the notification decision. Notice to affected individuals requires a separate assessment under article 24(5), which uses an undue-delay standard rather than the same fixed period. (Implementing Regulation, art. 24(1), (5).)
Recordkeeping should preserve the decision without collecting unnecessary personal data. Controllers must retain processing-activity records throughout the activity and for five years afterwards. That requirement does not authorise keeping every raw prompt or training record for the same period. The organisation should distinguish its activity register, incident evidence and underlying personal data, then apply the relevant retention rule to each. (Implementing Regulation, art. 33(1); Personal Data Protection Law, art. 18.)
Enforcement, Compensation and Evidential Limits
Liability depends on the breached duty and its elements. Article 36 permits warnings or fines up to SAR 5 million against covered private persons for PDPL or regulatory violations not specifically addressed by article 35. Article 35 concerns unlawful disclosure or publication of sensitive data with intent to harm the individual or obtain personal benefit. That offence carries up to two years’ imprisonment, a fine up to SAR 3 million, or both. Both provisions preserve any harsher penalty under another law. Repeat offences can attract fines up to twice the respective statutory maximum. These sanctions attach to the specified PDPL violations; an AI assessment error does not alone establish the offence. Public employees face a separate disciplinary provision. (Personal Data Protection Law, arts. 35–36, 39.)
A claimant seeking compensation must connect injury to the relevant violation or fault. Article 40 permits recovery for material or moral harm caused by a PDPL or regulatory breach. Under the Civil Transactions Law, fault-based liability and causation rules remain relevant, including the rebuttable rule for direct harmful acts. A completed assessment can support an account of precautions, but cannot itself establish absence of fault, causation or loss. (Personal Data Protection Law, art. 40; Civil Transactions Law, arts. 120–121.)
The reverse inference is also unsafe. Departing from nonbinding guidance does not, without another legal premise, establish an offence or automatic compensation. A decision-maker must identify the applicable duty, the departure and the required causal connection. No adjudicated application of this new publication is established in the available primary record, so its future evidential weight cannot be stated as a settled judicial rule.
Remedial routes have separate procedural requirements. The Implementing Regulation generally gives an individual 90 days from the incident or awareness to complain, subject to an exception for substantiated impediments. A private-sector penalty decision is challengeable before the competent court. The correct forum for damages or a supplier dispute depends on the parties, claim and any valid dispute-resolution agreement. No particular court, arbitration clause or case deadline can be selected without those facts. (Implementing Regulation, art. 37(1); Personal Data Protection Law, arts. 36(3), 40.)
