Saudi Arabia - AI Ethics Principles

Principles and Controls of AI Ethics (SDAIA AI Ethics Principles)

Saudi Arabia

RAI-SA-NA-PCAESXX-2023
Effective: 1 Sep 2023
In Force(In Force)As published at sdaia.gov.sa · checked 9 Sep 2026

Saudi Arabia - AI Ethics Principles is In Force in Saudi Arabia as of 9 Sep 2026, according to sdaia.gov.sa.

GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

The SDAIA AI Ethics Principles guides public, private, and non-profit entities in Saudi Arabia on embedding ethics across the AI lifecycle, published by the Saudi Data and Artificial Intelligence Authority in 2023. Monitored by SDAIA, the framework took effect on September 1, 2023, establishing core ethical principles and a four-tier risk model.

Summary

The Principles and Controls of AI Ethics is currently in force as non-binding guidance, having been published by the Saudi Data & Artificial Intelligence Authority (SDAIA) in September 2023, followed by supporting Generative AI Guidelines issued in January 2024. Because this instrument consists of non-binding guidelines, no body directly enforces it or imposes administrative fines under it, though SDAIA oversees the national framework and monitors compliance through self-assessments and alignment with statutory frameworks. Enforceable legal obligations instead derive from underlying laws such as the Personal Data Protection Law (PDPL).

The framework establishes a lifecycle approach to artificial intelligence development and deployment across public, private, and non-profit entities in Saudi Arabia. It sets out seven core principles: fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, and accountability and responsibility. These principles guide entities in embedding ethics from project inception through model design, testing, deployment, and continuous monitoring.

To operationalize ethical AI governance, the framework introduces a four-tier risk classification model dividing AI systems into unacceptable risk, high risk, limited risk, and little or no risk categories. Higher-risk systems require formal impact assessments, detailed logging, robust human oversight, and specialized governance roles such as Responsible AI Officers and Chief Data Officers within public organizations.

The Principles are designed to align Saudi Arabia with international trustworthy AI recommendations, including OECD and UNESCO frameworks, while advancing Vision 2030 digital economy goals. Organizations operating within the Kingdom are expected to map their AI solutions against the framework's controls, maintain comprehensive data and model documentation, and ensure alignment with national data protection and cybersecurity rules.

Full article

Read full text ↗

Overview

The "Principles and Controls of AI Ethics" published by the Saudi Data & Artificial Intelligence Authority (SDAIA) in September 2023 is a national ethics framework designed to guide responsible AI development and use across the Kingdom of Saudi Arabia. The document sets out seven core ethical principles and a risk-based classification model to be applied across an AI system's lifecycle, from design and data selection through deployment, monitoring and decommissioning. SDAIA positions itself as the national steward for implementation and monitoring, and the framework is intended to align with broader national strategies such as Vision 2030 and Saudi's National Strategy for Data & AI. For the official text and supporting materials see SDAIA - Principles and Controls of AI Ethics (PDF) and SDAIA's public pages describing the initiative.

Definitions

The Principles include operative definitions to clarify scope: "AI system" is defined as systems employing methods that gather data to predict, suggest or make decisions with varying degrees of autonomy; "stakeholder" covers designers, developers, deployers, users and those affected by AI systems; and "lifecycle" covers conception, design, development, testing, deployment, monitoring, maintenance and retirement. The framework distinguishes between risk categories (little/no risk; limited risk; high risk; unacceptable risk) and defines key roles (Head of Entity, Chief Data Officer for public bodies, Responsible AI Officer, Chief Compliance Officer, AI System Assessor) to ensure governance, oversight and accountability throughout the lifecycle.

Governance and Institutional Framework

SDAIA is established as the national authority responsible for promulgation, oversight and measurement of compliance with the Principles. The framework prescribes that entities must adopt internal governance structures: senior leadership engagement, a defined AI ethics governance committee, appointment of Responsible AI Officers and a clear accountability chain up to the Head of Entity (or Chief Data Officer in public bodies). Sectoral regulators (health, finance, telecommunications, etc.) are expected to apply the Principles within their remits and enforce sector-specific obligations. The framework emphasises cross-agency cooperation: for example, entities must align with the Personal Data Protection Law for privacy matters and with the National Cybersecurity Authority (NCA) best practices for model security and incident response. See SDAIA materials and explanatory guidance for governance templates: SDAIA - AI Ethics Principles and analysis by international law firms summarising SDAIA's supervisory role.

Key Focus Areas

The document organises controls and expectations around seven principles: (1) Fairness — avoiding bias and discrimination through data and model governance; (2) Privacy & Security — complying with PDPL, minimizing data collection and applying strong security controls; (3) Humanity — ensuring human dignity and oversight and preventing uses that undermine fundamental human rights; (4) Social & Environmental Benefits — promoting AI uses that create net social value and support sustainability; (5) Reliability & Safety — testing and validation, resilience and robustness across operating conditions; (6) Transparency & Explainability — documenting datasets, model design and decision logic to the extent feasible and appropriate; and (7) Accountability & Responsibility — clear ownership, incident reporting and remediation channels. The Principles embody a lifecycle approach that requires organizations to integrate these focus areas into procurement, development, deployment, monitoring and decommissioning phases. International commentary notes SDAIA's alignment of these areas with global instruments such as the EU AI Act, OECD and UNESCO recommendations (White & Case - AI Watch).

Implementation Framework

Implementation is operationalised through a combination of tools and organizational requirements: risk classification templates, ethics impact assessments (similar in purpose to data protection impact assessments), mandatory documentation and logging for higher-risk systems, validation/testing regimes, and defined roles (Responsible AI Officer and AI System Assessor). The framework encourages maturity-based adoption using SDAIA's maturity model that ranges from "Emerging" to "Advanced" and provides checklists to assist entities. Public entities are expected to appoint a Chief Data Officer and ensure their AI practices meet mandatory controls. SDAIA also issued related guidance for generative AI in January 2024 that operationalises particular controls for large language models and generative systems (SDAIA - AI Adoption Framework (example resource)).

Monitoring and Evaluation

SDAIA retains the authority to measure and monitor ethics compliance: periodic assessments, audits, self-reporting and targeted investigations are part of the monitoring toolkit. Entities are expected to demonstrate compliance via documented evidence: impact assessments, model cards, test results, incident logs and governance records. SDAIA will coordinate with sectoral regulators to evaluate compliance where systems fall under specialised rules (e.g., health or financial services). External assurance and third-party assessments are encouraged for high-risk systems. Monitoring also includes maturity assessments and public reporting of progress to raise awareness and drive sectoral alignment.

Penalties, Liability, and Appeals

The Principles themselves function as a supervisory and normative framework rather than a primary statute prescribing fixed fines. SDAIA's approach is to monitor adherence and to escalate non-compliance issues to sectoral regulators or apply relevant statutory instruments — for example, enforcement under the Personal Data Protection Law (PDPL), cybersecurity regulations, or other sector laws. The document also clarifies responsibilities for remediation, incident response and redress: entities must provide mechanisms for affected persons to seek correction or appeal decisions. Legal commentators indicate that failure to meet the Principles could trigger administrative or civil measures under existing laws and regulatory action in sector-specific contexts (White & Case - Saudi Arabia AI Tracker).

Relationship to Other Instruments

The Principles are complementary to the Kingdom's National Strategy for Data & AI and operate alongside the Personal Data Protection Law, National Cybersecurity Authority controls, and sectoral rules. SDAIA's subsequent guidance (e.g., Generative AI Guidelines, AI Adoption Framework) serve to operationalise the Principles for particular technologies or sectors. The framework also references intellectual property considerations and encourages alignment with international standards to facilitate cross-border interoperability and trade.

International Alignment

SDAIA designed the Principles with international alignment in mind, citing conceptual similarities to the EU AI Act's risk-based approach, OECD trustworthy AI recommendations, and UNESCO's AI ethics guidance. The Kingdom's framework aims to be interoperable with international standards to support cross-border investment and collaboration while maintaining national priorities set out in Vision 2030. External legal analyses explicitly compare SDAIA's four-tier risk model to the EU's approach and note SDAIA's effort to harmonize controls for high-risk use cases.

Implementation Timeline

PhasePeriodMilestones
PublicationSeptember 2023Release of Principles and Controls of AI Ethics by SDAIA
Guidance follow-upJanuary 2024Generative AI Guidelines published (Government & Public versions)
Adoption & capacity building2024-2025Entities adopt governance roles, maturity assessments and begin compliance mapping
Monitoring & assurance2025 onwardsSDAIA and sector regulators conduct assessments, audits and maturity measurement

Sources and References

SourceType
Principles and Controls of AI Ethics (SDAIA) - PDFPrimary Source
AI Watch: Global regulatory tracker - Saudi Arabia (White & Case)Secondary Source
SDAIA Reveals AI Ethics Principles 2.0 (GCCBDI)Secondary Source

Requirements for a company

What an organisation has to do under Saudi Arabia - AI Ethics Principles, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

7
  • Establish internal AI ethics governance structures and appoint a Responsible AI Officer to oversee compliance.Organizations developing or deploying AI systems
  • Conduct ethics impact assessments for higher-risk AI systems prior to deployment across the system lifecycle.Organizations developing or deploying higher-risk AI systems
  • Minimize personal data collection and implement security controls across the AI system lifecycle.Organizations processing personal data in AI systems
  • Document dataset sources, model architecture choices, and decision logic to ensure transparency.AI system developers and deployers
  • Establish mechanisms for affected individuals to challenge automated AI decisions and seek remediation.Organizations deploying AI decision-making systems
  • Maintain model cards, testing records, incident logs, and impact assessments to demonstrate ethics compliance.Organizations operating AI systems
  • +1 more in the table below

Should not do

2
  • Do not deploy AI models that produce unfair bias or discrimination against individuals.Organizations developing or deploying AI systems
  • Do not deploy AI systems that undermine fundamental human rights or lack appropriate human oversight.Organizations deploying AI systems

Who must do what

The obligations under Saudi Arabia - AI Ethics Principles, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organizations developing or deploying AI systemsEstablish internal AI ethics governance structures and appoint a Responsible AI Officer to oversee compliance.
“entities must adopt internal governance structures: senior leadership engagement, a defined AI ethics governance committee, appointment of Responsible AI Officers”
—Governance and Institutional FrameworkRecommended
2Organizations developing or deploying AI systemsDo not deploy AI models that produce unfair bias or discrimination against individuals.
“Fairness — avoiding bias and discrimination through data and model governance”
—Key Focus AreasRecommended
3Organizations deploying AI systemsDo not deploy AI systems that undermine fundamental human rights or lack appropriate human oversight.
“ensuring human dignity and oversight and preventing uses that undermine fundamental human rights”
—Key Focus AreasRecommended
4Organizations developing or deploying higher-risk AI systemsConduct ethics impact assessments for higher-risk AI systems prior to deployment across the system lifecycle.
“ethics impact assessments (similar in purpose to data protection impact assessments), mandatory documentation and logging for higher-risk systems”
Before deploymentImplementation FrameworkRecommended
5Organizations processing personal data in AI systemsMinimize personal data collection and implement security controls across the AI system lifecycle.
“complying with PDPL, minimizing data collection and applying strong security controls”
—Key Focus AreasRecommended
6AI system developers and deployersDocument dataset sources, model architecture choices, and decision logic to ensure transparency.
“documenting datasets, model design and decision logic to the extent feasible and appropriate”
—Key Focus AreasRecommended
7Organizations deploying AI decision-making systemsEstablish mechanisms for affected individuals to challenge automated AI decisions and seek remediation.
“entities must provide mechanisms for affected persons to seek correction or appeal decisions.”
—Penalties, Liability, and AppealsRecommended
8Organizations operating AI systemsMaintain model cards, testing records, incident logs, and impact assessments to demonstrate ethics compliance.
“Entities are expected to demonstrate compliance via documented evidence: impact assessments, model cards, test results, incident logs”
—Monitoring and EvaluationRecommended
9Saudi public sector entitiesAppoint a Chief Data Officer to lead AI governance and enforce mandatory data controls.
“Public entities are expected to appoint a Chief Data Officer and ensure their AI practices meet mandatory controls.”
—Implementation FrameworkRecommended

© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 9 Sep 2026 using Gemini 3.6 Flash