Saudi Arabia - Global AI Hub Law (RAI-SA-NA-DGAHPXX-2025)

Draft Global AI Hub Law

مسودة قانون مركز الذكاء الاصطناعي العالمي

Saudi Arabia

RAI-SA-NA-DGAHPXX-2025
Draft(Being written or scoped)
BillGovernance and OversightData Protection and PrivacyInternational Alignment
Export PDF

The Communications, Space and Technology Commission (CST) opened a public consultation on a draft "Global AI Hub Law" on 14 April 2025 (consultation through 14 May 2025). The draft establishes a legal framework for sovereign data centres (so-called data embassies) and three hosting models (Private, Extended, Virtual), setting registration, licensing, jurisdictional and security requirements to attract foreign governments, cloud providers and investors while preserving Saudi sovereign interests.

Summary

On 14 April 2025 the Communications, Space and Technology Commission (CST) published a consultation draft of the Draft Global AI Hub Law and invited feedback through the Saudi Istitlaa public consultation platform and via a dedicated CST mailbox ([email protected]) until 14 May 2025. The proposal is a novel legislative instrument that aims to create a regulatory environment to attract foreign governments, multinational cloud and AI providers, and investors to host data, compute and AI services within the Kingdom under tailored sovereignty and governance arrangements. The draft law defines and differentiates three hub models: Private Hubs (state-to-state, aimed at hosting foreign government data under bilateral agreements), Extended Hubs (for specific privileged corporate operations and customers) and Virtual Hubs (multi-tenant models where hosted customer content may be subject to laws of designated foreign states). The framework contemplates licensing and registration of hub operators, clear roles and obligations for guest countries and designated foreign states, operator responsibilities for security, audit and record-keeping, transparency measures, and mechanisms for conflict resolution between the laws applied by guest states and Saudi authorities.

Key objectives stated by CST include positioning Saudi Arabia as an international AI and sovereign compute hub, encouraging inward investment in data centres and AI services, fostering research & development, and supporting continuity and resilience of critical digital services. The draft emphasises cross-border legal certainty: it proposes processes and prerequisites for recognition of guest countries and designated foreign states, conditions under which foreign law will apply to content hosted in a hub, and explicit safeguards preserving Saudi national security and public order. Those safeguards include emergency powers to access or intervene in hub operations in exceptional circumstances (disaster response, national security, extreme public-safety threats) and authority to revoke approvals where necessary to protect sovereignty.

From a compliance perspective, the draft anticipates new authorization, registration and licensing obligations (managed by CST and related competent authorities), security and cybersecurity requirements aligned with national standards, obligations to cooperate with Saudi enforcement authorities, and requirements to maintain auditable records and to facilitate lawful access requests by both Saudi authorities and relevant foreign authorities within the scheme. The law is designed to interact with existing Saudi data protection and AI regulatory instruments — notably the Personal Data Protection Law (PDPL) supervised by SDAIA and other implementing regulations — and with international treaty frameworks. Legal practitioners and industry commentary emphasise that the proposal represents an innovative “data embassy” model that will require companies and foreign governments to reassess contractual, jurisdictional and incident-response arrangements, update cross-border transfer clauses, and ensure dual-compliance technical designs to meet both Saudi and foreign legal obligations.

Risks highlighted in commentary include complexities of multi-jurisdictional enforcement, tensions between foreign legal orders and Saudi public-order or security exceptions, obligations to support foreign law enforcement requests that could conflict with PDPL safeguards, and operational burdens on providers to implement robust segregation, audit, and emergency-response controls. The consultation seeks input from government entities, private sector operators, investors, civil society and international stakeholders; CST signalled that further implementing regulations and bilateral agreements would be used to operationalise the hub categories and to define specifics for access, oversight and dispute resolution. The consultation materials and CST announcement were published on the CST site and the Istitlaa platform; legal analyses by international law firms and commentators have summarised the main features and urged timely engagement during the consultation window.

Full article

Read full text ↗

Overview

The Communications, Space and Technology Commission (CST) published a consultation draft of a "Global AI Hub Law" on 14 April 2025 to create a legal and regulatory regime for establishing sovereign and foreign-aligned data centres in the Kingdom. The draft law introduces the concept of three hub models (Private, Extended and Virtual) to accommodate different combinations of state-to-state governance, corporate-hosted operations and multi-tenant arrangements. The policy goal is to attract inward investment in data centres, AI infrastructure and related services, while providing legal predictability for foreign governments and multinational technology providers. The consultation was launched via the national public consultation platform Istitlaa and ran from 14 April 2025 until 14 May 2025. Stakeholders were invited to comment on licensing, jurisdictional recognition, security controls, emergency access, and the draft's interaction with existing national instruments such as the PDPL overseen by SDAIA.

Definitions

The draft law sets out specialized definitions to delimit the new legal constructs: "Hub" or "Center" (a geographically-sited data/compute facility and associated services), "Private Hub" (a hub established under a bilateral agreement conferring sovereign legal governance for a guest country), "Extended Hub" (a centre providing privileged corporate hosting arrangements and contractual privileges), and "Virtual Hub" (software/virtual multi-tenant environments where content is governed by designated foreign states). Other key definitions include "Guest Country", "Designated Foreign State", "Operator", "Service Provider", "Customer Content", and "Sovereign Data Embassy". These definitional choices are central to how jurisdiction, lawful requests and enforcement reach will be determined, and the draft separates governance mechanisms and privileges according to the hub category to reduce ambiguity about applicable law and oversight pathways.

Governance and Institutional Framework

The CST is the lead regulator for hub authorisation, licensing and oversight, working alongside national authorities responsible for data protection, cyber security, national security and investment promotion. The draft contemplates cooperation agreements with the Saudi Data and AI Authority (SDAIA), the National Cybersecurity Authority (NCA) and other competent ministries to manage registration, national security vetting, resilience and incident response. CST's role includes evaluating applications, identifying eligible operators, managing approvals of guest countries and designated foreign states, and maintaining a public register of authorised hubs. The framework envisions formal bilateral agreements for Private Hubs (state-to-state instruments) and administrative designation procedures for Virtual Hubs. The draft indicates that implementing regulations and memoranda of understanding will set out detailed roles and cross-agency coordination mechanisms; industry analysts have noted that these secondary instruments will be decisive in how competing legal claims and emergency powers are operationalised.

Key Focus Areas

The law concentrates on: (1) jurisdictional clarity — specifying when a guest country's laws will govern hosted content and when Saudi law will apply; (2) licensing and registration — mandatory authorisation and operational eligibility checks for hub operators; (3) security and resilience — baseline physical and cyber security requirements aligned with national standards and auditability obligations; (4) data governance and privacy — interaction with the PDPL and transfer/processing safeguards for personal data; (5) law enforcement and emergency access — narrowly defined Saudi intervention powers for public-safety and national-security situations; (6) investor protections and incentives — measures to attract capital while preserving sovereignty; and (7) transparency and dispute-resolution — obligations to maintain records, co-operate in cross-border investigations and specify dispute mechanisms. Commentary stresses the novelty of permitting foreign legal regimes to govern data hosted on Saudi soil under strictly controlled conditions and the resulting need for robust contractual and technical isolation controls.

Implementation Framework

Operationalisation will require a multi-step approach: issuance of secondary implementing regulations, bilateral treaties and model contractual terms for guest countries, establishment of CST licensing processes and a central registry, technical standards for segregation and cryptographic controls, clear incident reporting pathways, and coordination protocols for law-enforcement and emergency interventions. The draft anticipates that operators will need to demonstrate capacity for legal separation of data, audit trails, tamper-evident logs and rapid cooperation with both Saudi and guest-country authorities where lawful. It also anticipates economic and regulatory incentives to encourage investment, coupled with obligations for compliance audits and third-party conformity assessments. Several international law firms and advisors have recommended that potential operators begin aligning corporate governance, data-mapping, contractual and incident-response plans to the draft's constructs now to influence the final text during consultation.

Monitoring and Evaluation

CST proposes periodic reviews, reporting requirements for authorised hubs, and powers to inspect and audit compliance. The draft suggests annual reporting to the competent authorities on operational metrics, security incidents and cross-border access requests. An independent or inter-agency review mechanism is envisioned to evaluate whether host arrangements continue to meet national security, public-order and privacy thresholds. The law also contemplates sunset or renewal conditions for authorisations and the capacity to impose corrective measures, including temporary suspension, where systemic risks are identified.

Penalties, Liability, and Appeals

The draft sets out administrative sanctions for non-compliance with licensing, recordkeeping, cybersecurity and cooperation obligations, including fines, suspension and revocation of approvals. It reserves criminal or administrative liability for obstruction of lawful investigations, falsification of records, or willful breaches that materially harm national security or public order. Operators and service providers will be contractually liable under agreements with guest countries and may face civil claims from affected parties under domestic law and PDPL-related rights. The draft also establishes appeal routes against CST decisions through administrative tribunals or competent courts as defined in implementing rules, while ensuring expedited procedures for national-security related actions.

Relationship to Other Instruments

The draft explicitly interacts with the Kingdom's Personal Data Protection Law (PDPL) and implementing regulations; it signals that PDPL requirements for transfers, safeguards and data subject rights remain applicable unless a lawful exception is established under a hub agreement or as provided by CST-approved instruments. The law also references national cybersecurity frameworks, investment laws and international treaties. The relationship between hub privileges and PDPL transfer restrictions will be managed through designated safeguards and authorised channels, and CST envisages coordination with SDAIA to ensure alignment with national data-governance objectives.

International Alignment

The draft positions the Kingdom's model alongside emerging global approaches to sovereign compute, data embassies and cross-border data governance. CST notes alignment with international treaty frameworks and sets out processes to recognise foreign legal regimes as "designated foreign states" or guest countries through formal criteria and bilateral instruments. International law firms and commentators have compared the model to e-embassies and sovereign compute initiatives in other jurisdictions and highlighted potential benefits for foreign states seeking legal continuity for national data, and for providers seeking legal certainty; at the same time they flagged the need for harmonised frameworks for mutual legal assistance, data subject protections and cross-border evidence-sharing to avoid conflicting orders.

Implementation Timeline

MilestoneDate / Window
CST publishes draft & opens public consultation2025-04-14
Public consultation period (Istitlaa & CST submissions)2025-04-14 to 2025-05-14
Analysis of consultation responses & drafting of implementing regulationsMid-2025 (indicative)
Expected publication of final law and implementing regulationsLate 2025 to early 2026 (indicative)
Licensing & registration processes launchedFollowing implementing regulations (TBD)

Sources and References

SourceType
CST: CST Publishes a Public Consultation for the Global AI Hub Law (14 April 2025)Primary Source
Istitlaa public consultation listing (Istitlaa platform)Primary Source
SDAIA – National Data Governance Platform / PDPL guidancePrimary Source

Requirements for a company

What an organisation has to do under Saudi Arabia - Global AI Hub Law (RAI-SA-NA-DGAHPXX-2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

10
  • Register and obtain the necessary license from the CST.Operators of Global AI Hubs
  • Implement baseline physical and cyber security requirements aligned with national standards.Operators of Global AI Hubs
  • Comply with the Personal Data Protection Law (PDPL) and implement transfer/processing safeguards.Operators of Global AI Hubs
  • Cooperate rapidly with Saudi and guest-country authorities for lawful requests and emergency access.Operators of Global AI Hubs
  • Do not obstruct lawful investigations, falsify records, or willfully breach security.Operators and service providers of Global AI Hubs
  • Maintain records, audit trails, and tamper-evident logs for hosted content and operations.Operators of Global AI Hubs
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Determine the appropriate hub model (Private, Extended, or Virtual) for your operations.Applicants for Global AI Hub licenses
  • Align corporate governance, data-mapping, contractual, and incident-response plans with the draft's constructs.Potential operators of Global AI Hubs

Should not do

0

Nothing in this category.

Who must do what

The obligations under Saudi Arabia - Global AI Hub Law (RAI-SA-NA-DGAHPXX-2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Operators of Global AI HubsRegister and obtain the necessary license from the CST.
Register & obtain license from CST Compile governance docs, security certifications, and evidence of financial capacity
Before operations commenceKey Focus Areas (2)Critical
2Operators of Global AI HubsImplement baseline physical and cyber security requirements aligned with national standards.
Security & audit readiness Implement NCA-aligned controls, tamper-evident logs, and audit trails
Before operations commenceKey Focus Areas (3)Critical
3Operators of Global AI HubsComply with the Personal Data Protection Law (PDPL) and implement transfer/processing safeguards.
Data protection / PDPL mapping Map personal data flows; identify lawful bases and transfer safeguards; coordinate with SDAIA
OngoingKey Focus Areas (4)Critical
4Operators of Global AI HubsCooperate rapidly with Saudi and guest-country authorities for lawful requests and emergency access.
Incident reporting & cooperation Draft incident response playbooks for Saudi & foreign authorities; test escalation
OngoingKey Focus Areas (5)Critical
5Operators and service providers of Global AI HubsDo not obstruct lawful investigations, falsify records, or willfully breach security.
reserves criminal or administrative liability for obstruction of lawful investigations, falsification of records
OngoingPenalties, Liability, and AppealsCritical
6Operators of Global AI HubsMaintain records, audit trails, and tamper-evident logs for hosted content and operations.
obligations to maintain records, co-operate in cross-border investigations and specify dispute mechanisms.
OngoingKey Focus Areas (7)Important
7Operators of Global AI HubsDemonstrate capacity for legal separation of data and cryptographic controls.
operators will need to demonstrate capacity for legal separation of data, audit trails, tamper-evident logs
Before operations commenceImplementation FrameworkImportant
8Operators of Global AI HubsUndergo compliance audits and third-party conformity assessments.
obligations for compliance audits and third-party conformity assessments.
OngoingImplementation FrameworkImportant
9Authorised Global AI HubsSubmit periodic reports on operational metrics, security incidents, and cross-border access requests.
The draft suggests annual reporting to the competent authorities on operational metrics, security incidents and cross-border access requests.
AnnuallyMonitoring and EvaluationImportant
10Operators of Global AI HubsSpecify dispute resolution mechanisms for cross-border investigations and claims.
obligations to maintain records, co-operate in cross-border investigations and specify dispute mechanisms.
Before operations commenceKey Focus Areas (7)Important
11Applicants for Global AI Hub licensesDetermine the appropriate hub model (Private, Extended, or Virtual) for your operations.
Determine hub model (Private / Extended / Virtual) Assess contractual, jurisdictional & technical segregation needs; prepare application to CST
Before applying for a licenseRecommended
12Potential operators of Global AI HubsAlign corporate governance, data-mapping, contractual, and incident-response plans with the draft's constructs.
potential operators begin aligning corporate governance, data-mapping, contractual and incident-response plans to the draft's constructs now
Before applying for a licenseImplementation FrameworkRecommended

© Regulations.AI · updated on 13-Jun-2026