Saudi Defense AI Under a Sovereignty Mandate

Saudi defense AI sits at the intersection of three forces that no other regional buyer faces in the same combination: a national localization mandate that requires 50 percent of military spend to be domestic by 2030, a procurement budget that consistently ranks among the world’s top six, and a US export-control regime that gates access to the most capable inference accelerators and to the most sensitive autonomy stacks. The institutions that navigate this terrain are the General Authority for Military Industries (GAMI), which sets policy and licenses defense industrial activity, and Saudi Arabian Military Industries (SAMI), the PIF-owned national champion that consolidates and operates the manufacturing base. Together they shape every defense AI deal that closes in the Kingdom.

GAMI was established in 2017 as part of the Vision 2030 reorganization of the defense ecosystem. Its remit covers licensing, industrial-participation enforcement, technology-transfer policy, and export controls on Saudi-produced defense goods. SAMI was created the same year as the operating arm, with a mandate to be among the world’s top 25 defense companies by revenue by 2030. SAMI’s portfolio spans aeronautics, land systems, weapons and missiles, defense electronics, and emerging digital and AI capabilities through SAMI Advanced Electronics and SAMI’s joint ventures with foreign primes. The relationship between GAMI and SAMI is intentionally analogous to the relationship between a regulator and a regulated national champion — GAMI sets the rules, SAMI executes within them, and the Ministry of Defense is the dominant customer.

Defense AI Procurement Posture

Saudi defense AI procurement is structured around three procurement vehicles. The first is direct foreign military sales (FMS) through the US government, which remains the dominant channel for major platforms but is increasingly conditioned on industrial-participation commitments routed through SAMI. The second is direct commercial sales (DCS) from foreign primes, which gives the Kingdom more flexibility but requires explicit GAMI licensing and is the channel through which most software and AI capabilities flow. The third, and the most rapidly growing, is sovereign procurement from SAMI and its joint ventures, where the underlying technology is licensed in but the integration, sustainment, and customization are performed domestically.

For AI specifically, the procurement posture has shifted decisively toward sovereign integration over the past three years. The Ministry of Defense and the Ministry of Interior have both signaled that they will not field capabilities — particularly autonomy, ISR analytics, and decision-support — unless the model weights, training data, and inference infrastructure can be operated under Saudi control. This has elevated the importance of joint ventures that include genuine technology transfer over arms-length licensing arrangements, and it has put pressure on foreign vendors to bring their training pipelines, not just their pre-trained models, into the Kingdom.

Sovereignty Mandate and Its AI Implications

The sovereignty mandate is the single most consequential factor shaping defense AI in Saudi Arabia. Operationally, it means that any deployed AI capability must have a domestic sustainment path that does not depend on continuous foreign technical support. For LLM-based decision-support systems, this implies on-Kingdom training infrastructure, which in practice routes through Hexagon, the Tonomus data centers in Oxagon, and the SDAIA-operated facilities supporting the Allam family of Arabic foundation models. For autonomy stacks, it implies access to source code or to a sufficiently complete model artifact that Saudi engineers can retrain, recompile, and redeploy without vendor escort.

The mandate also drives a specific procurement preference for vendors that will license model weights, training datasets, and continuous-integration pipelines, rather than vendors that prefer to operate their AI as a service. Palantir’s Foundry-based offerings, for example, have had to evolve toward more aggressive on-premise deployment patterns to remain competitive in Saudi engagements. Anduril’s Lattice has similarly been positioned as a stack that can be operated on Saudi-managed infrastructure once the appropriate licenses are in place.

US Export-Control Implications

The US export-control regime — the Export Administration Regulations (EAR), the International Traffic in Arms Regulations (ITAR), and the more recent AI diffusion rules administered by the Bureau of Industry and Security — gates the flow of advanced AI capability into Saudi Arabia in ways that defense buyers must navigate carefully. The most consequential gates are on advanced inference accelerators (the H100, H200, B100, and B200 class of NVIDIA parts and their AMD equivalents), on certain categories of autonomy software, and on training datasets that include US persons or US-origin sensitive content.

The Saudi response has been to pursue a layered strategy. At the top tier, the Kingdom has secured significant allocations of advanced accelerators through the Humain partnerships announced in 2024 and 2025, with NVIDIA, AMD, and Qualcomm providing capacity under licenses negotiated at the government-to-government level. At the application tier, defense buyers have leaned into vendors whose stacks are designed to run on a wider range of hardware, including domestically integrated accelerator clusters. At the model tier, SDAIA’s Arabic foundation-model program provides a sovereign substrate that defense applications can be fine-tuned on without exposing them to US-origin model risk.

The export-control posture is not static, and Saudi defense planners assume that any specific license or allocation can be tightened in future administrations. The architectural response is to design defense AI systems to be hardware-portable and weights-replaceable, so that a future tightening of US controls on a specific accelerator family or a specific foundation-model lineage can be absorbed without losing operational capability.

Key Vendors and the Joint-Venture Landscape

The vendor landscape that has formed around Saudi defense AI is concentrated in a handful of relationships. Lockheed Martin’s joint venture with SAMI, focused on aeronautics and land systems, is being extended into AI-enabled mission systems. BAE Systems’ long-standing presence in the Kingdom, which was reorganized as a SAMI joint venture in the late 2010s, is the principal channel for combat aircraft sustainment and the AI-enabled mission-planning that increasingly accompanies it. Raytheon, Boeing, and Northrop Grumman participate primarily through FMS and DCS channels with industrial-participation commitments routed through SAMI subsidiaries.

On the software and AI-native side, the relevant vendors are Palantir, which has had a sustained presence in the Kingdom since the late 2010s; Anduril, which has been actively expanding its Middle East footprint and has been linked publicly to several Saudi pilots; and Shield AI, which is focused on autonomy for unmanned systems. European primes — Leonardo, MBDA, Airbus Defence and Space, Thales, and Hensoldt — participate where the US export-control posture creates room, and they often present a more flexible technology-transfer posture than their American counterparts.

The Saudi-domestic integrators that sit between these foreign primes and the end customers are SAMI Advanced Electronics, Advanced Electronics Company (AEC), and a tier of smaller specialist integrators licensed by GAMI. These integrators are the ones that absorb the technology transfer, train the Saudi workforce, and own the sustainment relationship with the Ministry of Defense, the Ministry of Interior, the General Intelligence Presidency, and the Saudi Arabian Royal Guard.

Localization Requirements

GAMI enforces a layered localization framework that escalates over time. Early-stage capabilities can be procured with relatively modest local-content commitments, but capabilities that are deemed strategic — defined to include most AI-enabled decision-support, autonomy, and ISR analytics — face escalating local-content thresholds that can reach 50 percent or more of total program value. Local content is measured across components, software development, integration labor, sustainment, and training, with software development and AI model engineering increasingly weighted in the calculation.

The practical effect is that foreign vendors selling AI capabilities into Saudi defense must plan for a domestic engineering footprint, typically built either through a SAMI joint venture or through a wholly owned Saudi subsidiary licensed by GAMI. Riyadh and Dhahran are the dominant locations, with KAUST and KFUPM serving as the primary talent pipelines. The most sophisticated foreign vendors are now placing their model-engineering and red-team functions in the Kingdom rather than treating local presence as a sales-and-support function.

Regulatory Considerations Beyond Localization

Beyond GAMI’s localization regime, defense AI in Saudi Arabia is subject to oversight from the National Cybersecurity Authority on the security architecture of any deployed system, from SDAIA on the data-protection posture for any system that touches personal or sensitive data, and from the General Intelligence Presidency on systems that interact with classified intelligence flows. The Royal Saudi Air Force, the Royal Saudi Land Forces, the Royal Saudi Navy, the Royal Saudi Strategic Missile Force, and the Royal Saudi Air Defense Forces each operate their own program offices that overlay these horizontal regulators with service-specific requirements.

Cross-border data flows for defense AI are tightly controlled. Training data that includes Saudi personnel imagery, Saudi terrain at sensitive resolutions, or Saudi-origin signals intelligence cannot leave the Kingdom without specific authorization. This has led most defense AI vendors to stand up Saudi-resident training environments, typically in partnership with Humain-affiliated data centers, with strict air-gapping from their global engineering networks.

Deployment Timeline and Success Metrics

The deployment timeline for Saudi defense AI is being paced by Vision 2030 milestones and by the Ministry of Defense’s modernization roadmap. The headline milestones are the 50 percent localization target by 2030, the maturation of SAMI’s revenue base into the global top 25, and the operational fielding of AI-enabled capabilities across the principal services. Specific programs — including AI-enabled command and control upgrades, ISR analytics modernization, and autonomous-systems pilots — are paced individually but generally aim for initial operational capability within three to five years of contract award.

Success metrics that matter to GAMI and the Ministry of Defense are operational availability, mean time between operator interventions for autonomous systems, time-to-decision for command-and-control workflows, and the share of sustainment performed by Saudi engineering. Vendor-favored metrics such as model accuracy on benchmark datasets carry less weight than these operational measures.

Common Pitfalls

The pitfalls in Saudi defense AI are stark. Vendors that propose pure SaaS deployments are rejected on sovereignty grounds. Vendors that fail to invest in genuine workforce transfer find their localization scores degrading and their follow-on contracts going elsewhere. Vendors that underestimate the speed at which the US export-control posture can shift find their roadmaps stranded. And vendors that mistake GAMI’s licensing process for a procedural formality discover that the licensing is in fact the principal control point through which the Kingdom shapes its defense industrial base.

Border Security, Counter-UAS, and Critical Infrastructure Protection

The defense AI agenda extends into the border-security and counter-unmanned-aerial-system domains that are operationally consequential for the Kingdom given its geographic exposure and the pattern of cross-border threats over the past decade. The Border Guard, the General Directorate of Border Security, and the broader Ministry of Interior security apparatus operate substantial sensor networks across the Kingdom’s land and maritime borders, with AI-augmented detection and classification overlays that have matured significantly. The counter-UAS mission has been a particular priority following the 2019 Abqaiq and Khurais attacks, with substantial investment in radar-and-electro-optical fusion AI, AI-driven track classification across radar, RF, acoustic, and visual sensors, and AI-augmented engagement decision support that ties detection to the layered air-defense architecture.

Critical-infrastructure protection AI extends across the Aramco upstream and downstream installations, the SABIC complexes, the major power and water infrastructure, the airports, and the Two Holy Mosques. The cyber-physical convergence is increasingly central, with AI-augmented threat detection that correlates physical-domain telemetry with cyber-domain indicators. The National Cybersecurity Authority is the principal regulator for the cyber dimension, and its frameworks have shaped the architecture of the AI deployments in important ways. The OT-cyber AI deployments have increasingly drawn on the broader sovereign Allam-derived foundation models for analytical and triage assistance, alongside the specialist OT-cyber AI vendors active in the segment.

Ethics, Governance, and the Responsible-AI Posture

Saudi defense AI is being developed with explicit attention to the responsible-AI posture that the Kingdom has been building under SDAIA’s leadership. The Council on AI Ethics frameworks, the responsible-AI principles published by SDAIA, and the more sector-specific guidance from GAMI for defense applications combine to shape the development practices of the principal vendors and integrators. The frameworks are not formally identical to the US Department of Defense’s AI ethics principles or the EU’s evolving regulatory posture, but they are converging on a set of core commitments around human oversight of consequential decisions, robustness and reliability requirements, and explicit governance for autonomous-systems deployment.

The defense AI vendor base operating in the Kingdom has been progressively aligning with these frameworks, both because they are formal procurement requirements and because the Saudi defense buyer increasingly insists on demonstrable ethics-and-governance maturity as a procurement criterion. The most sophisticated vendors have been building their ethics-and-governance documentation, their red-team practices, and their post-deployment monitoring practices into formal artifacts that are reviewed alongside the technical capability assessments during procurement.

For deeper reading: see GAMI defense industrial policy, SAMI joint-venture portfolio, US export controls and Saudi AI, and Humain compute allocation for defense.