The Saudi AI Policy Stack
Saudi Arabia’s AI policy architecture is more layered than most non-EU jurisdictions and more coordinated than most Gulf peers. The structural shape is a four-layer compliance stack: the Personal Data Protection Law (PDPL) at the data-residency and personal-information layer; the Saudi Data and AI Authority (SDAIA) at the AI strategy, data classification, and National Data Bank layer; sector regulators (CST, SAMA, CMA, MoH) at the workload-specific compliance layer; and US-side export controls administered by the Bureau of Industry and Security (BIS) at the silicon and frontier-technology layer. Every Saudi-resident AI workload sits inside that four-layer stack; every foreign counterparty operating inside the Kingdom has to map its operations against it.
The stack is not static. SDAIA’s mandate has expanded materially since the 2020 National Strategy for Data and AI; PDPL has been operationalized through phased enforcement; the Cloud Computing Special Economic Zone, administered through the Economic Cities and Special Zones Authority (ECZA), has codified hyperscaler operating envelopes; and the post-2024 BIS posture has tightened the silicon end of the stack. Any analytical reading of Saudi compute policy has to be temporal — the stack of 2026 is meaningfully different from the stack of 2022.
SDAIA: The Strategic Center
SDAIA is the Saudi Data and AI Authority, formed in 2019 by royal decree and chaired through a council that reports up to the Prime Minister’s office. Its mandate covers AI strategy, data governance, the National Data Bank, the National Information Center, and Kingdom-wide AI capacity-building. It is not a regulator in the narrow sense; it is the strategic and operational center of the Saudi AI program.
SDAIA’s most important institutional product is the 2020 National Strategy for Data and AI, which set the framework for the Kingdom’s $20 billion AI investment thesis through 2030. The strategy articulated four pillars: data foundations, AI talent, AI ecosystem, and AI applications. Each has been operationalized through subsequent SDAIA programs — the National Data Management Office, the SDAIA AI Academy, the Tuwaiq Academy partnership, and the National Information Center’s expanded capacity-build.
SDAIA’s relationship with Humain is collaborative but separated. SDAIA writes strategy and operates state-classified data infrastructure; Humain operates commercial compute and applied-AI businesses. The two entities co-own initiatives where the policy and operational layers intersect — most notably the Arabic-first foundation model program and the National Data Bank’s AI-readiness work — but their P&Ls and reporting lines are distinct.
PDPL: Data Residency and Personal Information
The Personal Data Protection Law, enforced by SDAIA, is the Kingdom’s primary personal-data regime. It is structurally similar to GDPR in scope — covering personal data, sensitive personal data, data subject rights, controller and processor obligations, breach notification, and cross-border transfer — but is implemented under a Saudi sovereignty perimeter. PDPL became fully effective in September 2024 after a phased grace period.
The cross-border-transfer provisions are the operationally consequential block for compute infrastructure. Personal data of Saudi residents may be transferred outside the Kingdom only under conditions that the implementing regulations specify, including SDAIA-approved adequacy frameworks, contractual safeguards, and explicit data-subject consent under specific conditions. The practical effect is that any Saudi-resident AI workload involving personal data has to architect against PDPL residency, which in most cases means processing inside Kingdom-resident hyperscaler regions or sovereign capacity.
Sector Regulators
The third layer is the workload-specific regulators. The Communications, Space and Technology Commission (CST) regulates communications infrastructure, spectrum, telecom-grade services, and increasingly the connectivity layer of the data-center fabric. The Saudi Central Bank (SAMA) regulates banking and financial-services workloads, with explicit guidance on cloud and AI use cases. The Capital Market Authority (CMA) regulates the securities and asset-management workloads. The Ministry of Health (MoH) governs health-data residency and AI use in clinical settings.
The sector layer is where the compliance burden of Saudi-resident AI deployments actually lands operationally. A Humain customer running a banking workload has to satisfy SAMA cloud-computing requirements on top of PDPL on top of any sector-specific data-residency rules. The platform tracks sector-regulator guidance updates as they propagate into Saudi-resident workload classes.
BIS, CFIUS, and the US-Side Stack
The fourth layer is the US-side export-control and investment-review regime. BIS administers the AI Diffusion Framework, the Foreign Direct Product Rule, the Entity List, and the End-Use and End-User checks that govern silicon flow into Saudi Arabia. Saudi Arabia’s Tier-2 status under the AI Diffusion Framework is the platform on which the silicon pipeline rests; any tightening of that status would reset the Saudi compute trajectory. CFIUS, the Committee on Foreign Investment in the United States, intersects with Saudi outbound capital — particularly the PIF positions in US technology companies — and is a separate but related US-side review regime.
The intersection of the Saudi and US policy stacks is therefore tighter than at most non-Saudi sovereign-AI programs. Saudi domestic policy aligns closely with US export-control expectations, and the Major Non-NATO Ally framework (extended in November 2025) provides the diplomatic scaffolding that keeps Tier-2 access intact. The platform tracks every BIS license action, every CFIUS-relevant Saudi capital flow, and every SDAIA-issued guidance document on a per-action basis.
Cabinet Decrees and the Vision 2030 Frame
The Saudi policy stack rests on a cascade of cabinet decrees that operationalize the Vision 2030 strategic framework. Vision 2030 itself, articulated in 2016, set the diversification thesis. The 2020 National Strategy for Data and AI mapped that thesis onto the AI program. Successive cabinet decrees have established and expanded SDAIA, codified the Cloud SEZ, operationalized PDPL, and created the institutional architecture in which Humain operates.
The cabinet-decree cadence is itself a leading indicator. New decrees on AI labeling, model evaluation, sovereign-cloud certification, and AI talent-pipeline programs are released on a continuous cadence and surface in the Saudi gazette and SDAIA publication channels. The platform tracks every decree as it propagates into the operational layer.
Comparative Posture
Saudi Arabia’s policy posture sits between the EU’s prescriptive AI Act regime and the US’s lighter-touch sectoral approach. The Kingdom has adopted GDPR-style personal-data protection (PDPL), an SDAIA-anchored AI strategy that is more directive than the US equivalent, a Cloud SEZ that codifies hyperscaler operating envelopes, and a sector-regulator stack that is more centralized than the US sectoral pattern but less prescriptive than the EU’s horizontal regime.
The comparative framing matters because hyperscaler operating models, foundation-model deployment patterns, and applied-AI go-to-market motions all have to map against the prevailing policy stack. Saudi Arabia is, on most measures, a faster operating environment than the EU and a more sovereignty-controlled environment than the US — a profile that is structurally attractive to a specific class of sovereign-AI customer and structurally challenging to a specific class of free-tier consumer-AI deployment.
The Cloud Computing Special Economic Zone
The Cloud Computing Special Economic Zone (Cloud SEZ) is the most distinctive single regulatory instrument in the Saudi compute stack. Administered through ECZA and codified in the broader Special Economic Zones framework, the Cloud SEZ creates a regulatory perimeter inside which hyperscalers can operate Saudi-resident regions with a defined set of operational, tax, and data-handling provisions that diverge from the standard Saudi commercial and regulatory frame.
Inside the Cloud SEZ, hyperscaler operating entities benefit from streamlined licensing, defined data-handling exceptions, and tax provisions that have been engineered to make Saudi-resident region buildouts commercially competitive with comparable Gulf and global hyperscale jurisdictions. The trade-off is that the Cloud SEZ also codifies the sovereignty-control mechanisms — Saudi-resident control planes for designated workload classes, audit and inspection regimes for data-handling, and the explicit data-classification framework that flows from PDPL and the sector-regulator stack.
The Cloud SEZ is the regulatory scaffolding that makes the AWS Saudi region, the Microsoft Azure footprint, the Google Cloud commitment, OCI Riyadh, and the broader hyperscaler-resident architecture commercially and legally tractable. Without it, the hyperscaler-resident model would face structurally higher friction inside the Saudi commercial environment.
The Data Classification Framework
Underneath PDPL, the Saudi data-classification framework — published through SDAIA and operationalized through the National Data Bank — establishes the per-classification handling rules that every Saudi-resident workload has to map against. The classification levels range from public data (no handling restrictions) through restricted, confidential, and top-secret (with each higher level imposing more stringent residency, access-control, and audit requirements). Government and ministry data is automatically classified at higher levels; commercial and personal data is classified by reference to PDPL and the sector-specific data-handling rules.
The data-classification framework is the operational mechanism by which the Saudi sovereignty controls translate into per-workload compliance. A Saudi-resident workload handling top-secret-classified data has to run inside SDAIA-managed sovereign capacity with no foreign control-plane access; a workload handling restricted-classified data can run inside the Cloud SEZ envelope with defined sovereignty controls; a workload handling public data has the broadest operational flexibility. The platform tracks SDAIA classification-framework updates and surfaces them on the policy section.
Talent, Skills, and the Tuwaiq Program
The Saudi AI policy stack includes a substantial talent and skills workstream that complements the regulatory framework. The Tuwaiq Academy, operated as a partnership between SDAIA, MCIT, and the Human Resources Development Fund, is the Kingdom’s primary AI and data-skills bootcamp program. The SDAIA AI Academy delivers more advanced certification and post-graduate-equivalent training. The KAUST and KFUPM AI research programs, paired with the broader Saudi university AI programs, anchor the upstream research and PhD-level talent pipeline. The broader Vision 2030 Human Capability Development Program ties the AI-skills workstream to the broader workforce-development thesis.
The structural rationale is that the Saudi compute infrastructure cannot be operated and the Saudi applied-AI economy cannot be commercialized without a labor pool that scales at roughly the rate of the compute footprint. The talent workstream is therefore the human-capital component of the policy stack and is operationally as consequential as the regulatory framework itself.
Enforcement and Penalty Architecture
The Saudi policy stack carries a layered enforcement architecture. PDPL violations are subject to administrative penalties calibrated to the severity of the violation, with cross-border-transfer violations carrying the highest penalty tier. SDAIA-issued AI guidance is enforced through the broader institutional-coordination mechanism, with non-compliance flagged through the National Information Center’s coordination role. Sector-regulator violations (SAMA cloud-computing guidance, CMA capital-markets rules, MoH health-data residency) are enforced through the respective regulator’s standard penalty architecture. BIS license-condition violations carry the most severe consequences across the entire stack: license suspension, future-license denial, and Entity List exposure.
The enforcement architecture is graduated rather than binary. The Saudi posture is that the regulatory regime is effective when it shapes operational behavior at the design stage rather than when it imposes penalties at the violation stage. The platform tracks enforcement actions as they surface and maps them against the prevailing regulatory architecture.
Cross-Stack Coordination
The four-layer policy stack is coordinated through institutional-coordination mechanisms rather than through a single integrated authority. The Council of Ministers, the Council of Economic and Development Affairs, the Vision 2030 program-delivery framework, and the SDAIA-anchored AI strategy together provide the coordination architecture. The CST-SAMA-CMA-MoH cross-regulator coordination handles workload-class-specific issues. The BIS-side coordination with US embassies and consular offices handles silicon-pipeline-specific issues.
The coordination architecture is operationally tighter than at most non-Saudi sovereign-AI programs. The implication is that the Saudi policy stack functions more as an integrated whole than as a collection of independent regulatory regimes. The platform’s policy section tracks the coordination architecture alongside the per-regulator frameworks.
AI Ethics, Safety, and Model Evaluation
The Saudi policy stack includes an AI-ethics and model-evaluation layer that has matured alongside the broader regulatory framework. SDAIA-issued ethics guidelines, model-evaluation standards for Saudi-resident foundation models, and Arabic-specific safety-evaluation harnesses together provide the substantive content of the layer. The Saudi posture aligns broadly with the OECD AI Principles and with the international AI safety architecture (the AI Safety Summits, the Bletchley and subsequent declarations) but is operationalized through the Saudi institutional framework.
The model-evaluation discipline is becoming part of the standard deployment pipeline for Saudi-resident foundation models and for hyperscaler-resident foundation models serving the Saudi market. The platform tracks the evolving evaluation framework as it propagates into the operational layer and surfaces it on the policy and topics sections.
For deeper reading:
- Geopolitics section — the US-Saudi diplomatic architecture
- Silicon section — BIS export controls and the AI Diffusion Tier-2 status
- Methodology — how policy posture flows into SCS components
- Humain section — the operating company governed by the policy stack