
AI Governance · Saudi Arabia
The most misread word in Saudi AI policy is ‘advisory’
SDAIA's National AI Risk Management Framework asks less than a regulation and more than most organisations are ready to give. The entities that treat this year as preparation will set the standard everyone else is measured against.
In late July, the Saudi Data and Artificial Intelligence Authority gathered more than 150 specialists from some 45 public and private entities at Riyadh's AI Oasis to walk them through a document published three months earlier: the National Artificial Intelligence Risk Management Framework. The timing was deliberate. In the Kingdom's declared Year of Artificial Intelligence, with government adoption accelerating and every sector under pressure to show AI results, SDAIA has chosen this moment to publish the country's first unified methodology for managing AI risk.
The cover page classifies the framework as advisory. That word deserves a closer reading than it will get.
The framework rests on solid legal ground. It is issued under Council of Ministers Resolution No. 292 of 1441H, the instrument that established SDAIA as the national reference for all matters relating to data and AI — regulation, development, supervision and integration. What the new framework does is convert that mandate into method: a common way for government and private-sector entities alike to identify, assess, treat and monitor the risks of the AI systems they build, buy and operate.
What the framework actually asks
The methodology itself will feel familiar to anyone who has run enterprise risk in a regulated environment, and that familiarity is a strength, not a weakness. An entity begins by defining context and scope — which AI systems it operates, where they sit, and who they affect. It then identifies risks across the domains the framework names directly: privacy, fairness and bias, ethics, regulatory compliance and cybersecurity.
Each risk is assessed through a matrix linking the likelihood of occurrence to the scale of potential impact, so that a computer-vision system in one ministry and a credit model in one bank can be classified on comparable terms. Treatment follows the classical options: avoid the risk, including restricting or retiring a high-risk system; mitigate it through technical and operational controls; transfer it; or accept it, knowingly and on record. Then monitor and review — continuously, because AI systems drift in ways conventional software does not.
The lineage is recognisably that of established international risk practice, and SDAIA has been open about benchmarking global frameworks during development, alongside local consultation and a study of who would actually use the document. That last step shows. This is a framework written to be applied, not admired.
The most consequential line, however, is the one that limits it. The framework does not replace an entity's own rulebook. It provides the method and the tools, and expects each organisation to build its own internal policies and procedures on top — suited to its sector, its maturity and its risk appetite. The deliverable, in other words, is not a binder from the regulator. It is yours.
The advisory period is not a pause. It is the window in which the benchmark gets set.
Why ‘advisory’ is the beginning, not the verdict
Anyone who has taken a Saudi organisation through the last five years of data regulation will recognise the pattern, and this is a practitioner's observation rather than a legal one. National instruments in the Kingdom tend to arrive as guidance, then reappear as assessment questions, then as procurement clauses, and finally as audit expectations. The data governance and personal data protection journey followed exactly this arc. There is little reason to believe AI risk will travel a different road — least of all in a year when AI adoption is a declared national priority and public-sector entities are being measured on it.
Which means the practical question — show me your AI risk register — is likely to arrive from a board, a client or an internal auditor well before it arrives from a regulator. The advisory period is not a pause. It is the window in which the benchmark gets set.
What does readiness actually require? Less paperwork than most compliance functions fear, and more honesty than most organisations have yet attempted. The first task is an inventory: a true list of the AI in use, including the models embedded invisibly in vendor products and the unofficial tools employees adopted long before anyone approved them. In my experience, few organisations can produce this list today, and no risk cycle can run against systems nobody has counted.
The second is ownership. AI risk is currently an orphan, passed between IT, cybersecurity, data management and legal, each holding one piece. The framework's cycle only works when a named function owns the register and the decisions recorded in it.
The third is evidence. A risk assessment that exists to satisfy a template is worth little; one that would survive an independent review — with the reasoning, the treatment decision and the residual risk acceptance all traceable — is an asset. The distinction between the two is where AI governance will be won or lost, and it costs roughly the same effort either way.
And the fourth is integration. Most AI risk is data risk wearing new clothes. An entity already carrying obligations under the Personal Data Protection Law and the national data management standards should treat this framework as an extension of that programme, not a parallel one. Building a second, disconnected register is the most predictable failure mode of the coming year.
There is a larger point beneath the mechanics. Frameworks like this one are often read as brakes on adoption. This one is better read as the price of speed. The Kingdom's AI ambitions depend on institutions, citizens and investors trusting automated decisions at scale, and trust of that kind is not declared — it is evidenced, system by system, register by register. SDAIA has now published the common language for that evidence.
The organisations that pick it up while the cover still says advisory will find they have written the standard. The ones that wait for the word to change will discover it was written without them.
Key takeaways
- Build a true inventory of AI systems, including models embedded in vendor products and unofficial tools.
- Name the function that owns the AI risk register and the decisions recorded in it.
- Maintain an evidence trail that can survive independent review.
- Integrate AI risk with existing PDPL, data governance and national data management obligations.
Related services
Related Library assets
Sources and further reading
- SDAIA Publications — National AI Risk Management Framework
- Saudi Press Agency — SDAIA Introduces National Framework for Managing AI Risks
This briefing is a practitioner's analysis and does not constitute legal advice.