Saudi Arabia does not yet have a binding AI law. The Saudi Data and Artificial Intelligence Authority (SDAIA) closed public consultation on its draft Responsible AI Policy on 3 May 2026, and as of this month no final version has been published, according to Digital Policy Alert's tracking of the process.
Meanwhile, SDAIA's enforcement committees have issued 48 confirmed rulings under the Personal Data Protection Law (PDPL) across 2025 and 2026, with fines reaching SAR 5 million for a first offence and up to SAR 10 million for repeat violations, per Squire Patton Boggs' Global Privacy & Security Compliance Blog. Programmes that treat the absence of an AI-specific statute as licence to wait are reading the wrong signal. The enforcement muscle is already live. It is simply routed through data protection law rather than AI law, and the gap between the two is where most procurement teams are getting caught out.
What the draft actually says
2026 is SDAIA's declared "Year of Artificial Intelligence," and the Responsible AI Policy is the centrepiece. The draft, opened for public and institutional comment on 3 April 2026, sorts every AI system into one of four risk tiers — critical, high, limited, and low — each carrying its own proportionate obligations on documentation, testing, monitoring, and registration, as set out by the Saudi Press Agency's official notice on the consultation.
Access Partnership's analysis of the draft describes the intent as moving from principle to practice: a "preventive approach based on continuous assessment," with clear roles and responsibilities assigned to deployers, developers, and operators depending on where their system sits in the tiering. That is a materially different exercise from the ethics-principles-and-guidelines approach SDAIA has run since 2023. Tiering means a chatbot handling FAQ triage and a model making credit decisions no longer sit under the same compliance bar.
What the draft does not yet have is legal force. A consultation closing is not a policy taking effect, and nothing public confirms a date for that.
What is already being enforced
The PDPL is not draft. It has been in force since 2023, and SDAIA's enforcement committees have spent the past year proving it. Fyntralink's review of the 48 published decisions shows the violations clustering around familiar ground: processing personal data without a valid legal basis, unauthorised disclosure, inadequate technical safeguards, and marketing communications sent without consent — much of it surfaced through financial institutions' own AI-driven customer analytics and scoring tools.
None of those 48 rulings needed an AI law to land. They were PDPL cases. But the underlying activity in a growing share of them was an AI system making or informing a decision about a customer, with no AI-specific framework yet dictating how that system should have been governed, tested, or documented. The enforcement committees are, in effect, applying data protection scrutiny to AI-driven processing today, ahead of the AI-specific rules that will eventually formalise exactly what "adequate" looks like.
Why the sequencing matters for procurement
SDAIA alignment is already becoming a de facto gate on public sector contracts, even without a finished AI law behind it. Vendors and consultancies bidding into Saudi government and quasi-government work are increasingly being asked to demonstrate governance maturity against SDAIA's published frameworks — the 2023 AI ethics principles, the November 2025 AI Adoption Framework for public entities, and now the direction signalled by the draft risk tiers — before any of it is legally mandatory.
That creates a specific trap for programmes still waiting for "the law" before investing in compliance design:
- The procurement bar moves before the statute does. Buyers reference the draft tiering in RFPs today, whether or not it is binding.
- PDPL exposure is live now, not later. Any AI system processing personal data in the Kingdom already sits inside an active enforcement regime, with real fines being issued.
- Retrofitting is more expensive than designing in. A system built against the ethics principles and the Adoption Framework's five pillars — data governance, model accountability, transparency, human oversight, risk management — will need far less rework when the tiering does become law than one built with no reference to either.
What we tell clients now
We do not advise clients to build against a draft as if it were final law — that risks over-engineering for provisions that still change before publication. We do advise mapping every AI system touching Saudi personal data against the existing, binding PDPL obligations first, since that is where the confirmed enforcement is happening. Then, for anything likely to fall in the draft's "high" or "critical" bands — credit, health, employment, or safety-relevant decisions — we build the documentation and human-oversight trail the Adoption Framework already expects, so the tiering, once finalised, is a formality rather than a redesign.
The mistake we see most often is treating the absence of a published AI law as an absence of AI risk. In the Kingdom, right now, it is the opposite: the law is still being written, and the enforcement is already reading from a different, older, very live rulebook.