Saudi Arabia - Deepfakes Guidelines
Deepfakes Guidelines (SDAIA)
Saudi Arabia
RAI-SA-NA-DEEGUSD-2024The Saudi Data & Artificial Intelligence Authority (SDAIA) issued the Deepfakes Guidelines (Version 1.0) to provide non-binding but practical guidance for developers, platforms, content creators and public-sector entities on the responsible creation, labelling, mitigation and remediation of synthetic media (deepfakes). The Guidelines emphasise transparency, consent, privacy protection, accountability and risk-management measures including watermarking, traceability, consent forms and consumer awareness.
Summary
Read full text ↗Plain English
Overview
The Deepfakes Guidelines (Version 1.0) were published by the Saudi Data & Artificial Intelligence Authority (SDAIA) in September 2024 as a practical, ethics-informed policy instrument to address synthetic media risks in the Kingdom. The Guidelines are designed to inform developers, publishers, platforms, public-sector entities and the public about responsible creation, labelling, verification, and remediation of AI-generated audio, image and video content. They were launched during the Global AI Summit and opened to public consultation via a national e-participation platform; SDAIA framed the document as part of a continuing agenda that includes the AI Ethics Principles and related generative AI guidance. For the consultation and access to the published draft, see Deepfakes guidelines (eParticipation consultation) and SDAIA's repository Deepfakes Guidelines (PDF).
Definitions
The Guidelines define key terms used throughout the instrument, including "synthetic content" (media created or substantively altered by AI), "deepfake" (high-fidelity synthetic audio/visual content representing a real person), "non-consensual intimate imagery" (NCII), "provenance" (origin and transformation history of the content), and "labelling/watermarking" (visible or embedded markers indicating synthetic origin). Definitions emphasise intent and material impact — distinguishing minor edits and acceptable transformations (e.g., restoration, stylistic filters) from deceptive manipulations intended to mislead or harm. The document also uses established concepts from data protection ("personal data", "processing") aligning terms with the Kingdom's Personal Data Protection Law (PDPL).
Governance and Institutional Framework
The Guidelines set out a layered governance model for addressing deepfakes: (1) SDAIA as national coordinator for AI policy and convenor of multi-stakeholder consultation; (2) Sectoral regulators (e.g., Communications, Space & Technology Commission) to adopt sector-specific controls; and (3) Platform-level governance where content hosts implement detection, labelling and response workflows. SDAIA recommends internal governance for creators and vendors — AI ethics committees, documented risk assessments, incident response teams and data protection officers. The Guidelines reference collaboration channels with law enforcement for serious harms and propose public reporting and transparency mechanisms on takedown and remediation activities. See SDAIA's public consultation page and related announcements for institutional context: SDAIA eParticipation and news coverage summarising the launch at the Global AI Summit: Saudi Press Agency (SPA) summary coverage.
Key Focus Areas
The document organises guidance under several focus areas: (a) Consent & rights protection — requiring explicit and auditable consent when using an identifiable person's likeness or voice, and recommending standard consent forms and templates; (b) Transparency & disclosure — mandatory visible labels for published synthetic content and machine-readable provenance markers to allow automated detection and platform filtering; (c) Documentation & accountability — model cards, dataset documentation, training provenance and versioning records to enable audits; (d) Safety testing & evaluation — pre-deployment risk assessments, robustness testing against misuse and adversarial attacks, and ongoing red-team / external evaluation; (e) Privacy & data minimisation — alignment with PDPL for training data, retention limits and secure deletion; (f) High-risk use cases — special controls for political advertising, elections-related content, financial and health advice, and NCII; and (g) Public literacy — guidance for awareness campaigns and tools to help citizens identify manipulated media. SDAIA recommends watermarking and cryptographic provenance as preferred mitigation techniques and provides examples and templates for risk assessment and consent capture.
Implementation Framework
The Guidelines recommend a three-tiered implementation approach: (1) Baseline practices for all creators and platforms (labelling, basic documentation, notice-and-respond channels); (2) Enhanced controls for regulated sectors and medium/high-risk deployments (identity verification, provenance standards, faster takedown procedures); and (3) Technical integration for developers and vendors (SDKs for watermarking, metadata schemas and APIs for provenance exchange). SDAIA suggests pilot projects and regulatory sandboxes to test practical solutions and invites cross-sector pilots via the National Data Governance Platform. Entities are encouraged to adopt documented policies, staff training, and incident response exercises. For programmatic support and sandbox participation, see SDAIA's regulatory sandbox information: SDAIA National Data Governance Platform.
Monitoring and Evaluation
SDAIA's Guidelines propose a monitoring framework combining self-reporting from covered entities, platform transparency reports, third-party audits (e.g., conformity assessment bodies), and periodic public reviews. Key performance indicators include prevalence of labelled synthetic content, response times for takedown of non-consensual material, results of robustness tests, consumer-reported harms, and cross-border incident statistics. SDAIA recommends establishing a public registry of major synthetic-content platforms and periodic publication of aggregated metrics to track progress and inform potential conversion of guidance into binding rules. The Guidelines encourage international cooperation on detection capabilities and shared repositories for indicators of compromise.
Penalties, Liability, and Appeals
While the Guidelines themselves are non-binding guidance, they make clear that many prohibited behaviours (e.g., fraud, identity theft, distribution of NCII, defamation) remain subject to existing laws and may trigger civil or criminal liability. The document recommends that platform terms enforce takedown and repeat-offender sanctions and encourages contractual liability clauses for vendors. It also sets out remediation pathways for affected individuals: notice-and-takedown request templates, evidence preservation and escalation to regulators or law enforcement. SDAIA indicates that persistent or harmful non-compliance could inform future regulatory or enforcement action by sectoral authorities.
Relationship to Other Instruments
The Guidelines are positioned to complement existing national instruments: the Personal Data Protection Law (PDPL), SDAIA's AI Ethics Principles, Generative AI Guidelines (public and government versions), sectoral rules and the Kingdom's cybersecurity framework. They are intended to act as operational guidance that can be referenced by sectoral regulators when drafting binding rules or enforcement guidance. Internationally, the Guidelines reference UNESCO recommendations, OECD and other international workstreams to maximise compatibility with emerging global standards.
International Alignment
SDAIA frames the Guidelines within a policy objective of aligning Saudi practice with international norms on transparency, provenance, and labelling. The document cites global practice trends — EU labelling approaches, China's deep synthesis rules, and U.S. state-level NCII statutes — and encourages adoption of interoperable watermarking and provenance standards to facilitate cross-border detection and takedown cooperation. SDAIA's engagement in the Global AI Summit and OECD/UNESCO forums is presented as part of a strategic agenda for international alignment and standardisation.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Public launch & consultation opened | 2024-09-18 | Launched at Global AI Summit; public consultation via eParticipation. |
| Public consultation closed (initial) | 2024-10-11 | Stakeholder feedback period for Version 1.0. |
| Publication of Version 1.0 (consultation draft) | 2024-09 | Document circulated as Version 1.0 for input; finalisation planned subject to feedback. |
| Planned iterative review | Ongoing (annual review recommended) | SDAIA signalled intention to revise after monitoring results and sectoral input. |
Compliance Checklist
| Requirement | Compliant (Y/N) | Evidence |
|---|---|---|
| Obtain explicit consent for use of identifiable persons | Signed consent forms / logs | |
| Apply visible or embedded labelling for synthetic content | Watermark samples / metadata records | |
| Maintain training data documentation and model cards | Data inventories / model documentation | |
| Conduct pre-deployment risk assessment | Risk assessment reports / test logs | |
| Establish incident response and takedown workflows | Playbooks / contact points |
Sources and References
| Source | Type |
|---|---|
| Deepfakes guidelines (eParticipation consultation page) | Primary Source |
| SDAIA Deepfakes Guidelines (Version 1.0 PDF) | Primary Source |
| Saudi Press Agency (SPA) — coverage of SDAIA launch at Global AI Summit | Primary/Official Coverage |
Saudi Arabia's Deepfakes Guidelines, published by the Saudi Data & Artificial Intelligence Authority (SDAIA), provide practical, non-binding guidance for anyone involved in creating or managing synthetic media, commonly known as deepfakes. These guidelines apply to a broad range of entities, including developers, platforms, content creators, and government bodies.
Released as a consultation draft in September 2024, the guidelines aim to address risks associated with AI-generated audio, image, and video content. Key recommendations for compliance include: - Obtaining explicit and auditable consent when using an identifiable person's likeness or voice. - Applying mandatory visible labels and machine-readable provenance markers to all published synthetic content. - Maintaining thorough documentation, such as model cards and dataset records, and conducting pre-deployment risk assessments. - Implementing robust incident response and takedown procedures for harmful content.
While the guidelines themselves are not legally binding, they clearly state that existing laws still apply. This means activities like fraud, identity theft, or distributing non-consensual intimate imagery using deepfakes can lead to civil or criminal liability under Saudi law. Platforms are encouraged to enforce these standards through their terms of service, and persistent non-compliance could influence future binding regulations from sectoral authorities.
A crucial point for professionals is that these are currently *draft* guidelines, meaning they are subject to change based on public consultation. However, they signal the direction of future regulation and best practices in Saudi Arabia, making early adoption of their principles a wise move. The guidelines officially became available as a published document on September 18, 2024, marking the start of the public consultation period.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Saudi Arabia - Deepfakes Guidelines. Not legal advice — verify against the official text before relying on it.
- #1CriticalKey Focus Areas (a)
Applies to: Creators of synthetic content featuring identifiable persons.
“requiring explicit and auditable consent when using an identifiable person's likeness or voice”
- #2CriticalKey Focus Areas (b)
Applies to: Publishers of synthetic content.
“mandatory visible labels for published synthetic content”
- #3CriticalKey Focus Areas (e)
Applies to: Developers of AI systems using personal data for synthetic content.
“alignment with PDPL for training data, retention limits and secure deletion”
- #4CriticalKey Focus Areas (f)
Applies to: Creators and platforms dealing with high-risk synthetic content.
“special controls for political advertising, elections-related content, financial and health advice, and NCII”
- #5ImportantKey Focus Areas (b)
Applies to: Developers and publishers of synthetic content.
“machine-readable provenance markers to allow automated detection and platform filtering”
- #6ImportantKey Focus Areas (d)
Applies to: Developers and deployers of AI systems generating synthetic content.
“pre-deployment risk assessments”
- #7ImportantKey Focus Areas (c)
Applies to: Developers of AI systems generating synthetic content.
“model cards, dataset documentation, training provenance and versioning records to enable audits”
- #8ImportantImplementation Framework
Applies to: All creators and platforms of synthetic content.
“Baseline practices for all creators and platforms (labelling, basic documentation, notice-and-respond channels)”
- #9ImportantPenalties, Liability, and Appeals
Applies to: Platforms and creators of synthetic content.
“sets out remediation pathways for affected individuals: notice-and-takedown request templates”
- #10RecommendedGovernance and Institutional Framework
Applies to: Creators and vendors of synthetic media.
“SDAIA recommends internal governance for creators and vendors — AI ethics committees, documented risk assessments, incident response teams”
- #11RecommendedImplementation Framework
Applies to: Entities dealing with synthetic content.
“Entities are encouraged to adopt documented policies, staff training, and incident response exercises.”
- #12RecommendedKey Focus Areas
Applies to: Developers and publishers of synthetic content.
“SDAIA recommends watermarking and cryptographic provenance as preferred mitigation techniques”
Related Regulations
Generative AI Guidelines for Government (SDAIA)
Saudi Arabia93% similar
Deepfake Guide (UAE National Programme for Artificial Intelligence)
United Arab Emirates92% similar
AI Adoption Framework (SDAIA)
Saudi Arabia92% similar
Principles and Controls of AI Ethics (SDAIA AI Ethics Principles)
Saudi Arabia91% similar
Saudi Arabia AI Regulation Overview
Saudi Arabia90% similar
© Regulations.AI — created on 13-Jun-2026