All jurisdictions

Saudi Arabia / Banking and financial services

What AI rules apply to banks in Saudi Arabia?

IndirectVerified August 31, 2026

There is no SAMA AI rulebook. SDAIA's instruments reach banks through a 2021 SAMA circular.

No dedicated AI instrument for Saudi banks was identified at the verification date. What binds instead is a transmission chain: a SAMA circular requires supervised institutions to align internal policies with the Personal Data Protection Law and with policies and controls issued by SDAIA. SDAIA's AI instruments are non-binding in themselves, which makes the circular the mechanism that gives them supervisory weight. A draft Responsible AI Policy that would change this closed consultation on 3 May 2026 and has not been adopted.

Absence not conclusively verified

This page states that no such instrument was identified as of its verification date. That is a claim about the completeness of a search rather than proof of absence: an instrument published outside the register searched, or in a language the search did not cover, would not necessarily surface.

Scope

Who this applies to

  • Banking sector institutions supervised by SAMA
  • Finance companies, payment systems and payment service providers
  • Money exchange sector and credit bureaus
  • Regulatory Sandbox participants

What pulls a system into scope

  • Any processing of personal data by an AI system, which brings the Personal Data Protection Law and SDAIA's data instruments into scope through SAMA Circular 43045328
  • Cybersecurity exposure created by AI systems, assessed under the existing SAMA Cyber Security Framework rather than any AI-specific standard
  • Deployment of AI in a supervised institution generally, where SAMA expects internal policies to be reviewed against SDAIA-issued policies, controls, regulations and rules

Obligations

What is actually required

Align internal policies with the PDPL and SDAIA instruments

SAMA Circular 43045328

Supervised institutions must review approved internal policies and procedures and ensure compatibility with, or amendment to, both the Personal Data Protection Law and policies and controls issued by SDAIA. This is the clause through which SDAIA's non-binding AI instruments acquire supervisory weight in the financial sector.

Gap analysis with board-approved remediation

SAMA Circular 43045328

Institutions must evaluate organizational gaps against the Law and the applicable policies, controls and rules, and develop corrective action plans for Board approval.

Customer personal data protection

SAMA Circular 43045328

Full adherence to protection of customers' personal data, including review of disclosure practices, security controls, and use of data only for its original purpose. Applied to AI, this constrains reuse of customer data as training data.

Cybersecurity maturity for AI systems

SAMA Cyber Security Framework

No AI-specific security standard binding on banks was identified as of August 31, 2026. AI systems are assessed through the existing SAMA Cyber Security Framework, which means AI exposure has to be mapped onto controls written for conventional systems.

If you already built for the EU AI Act

An institution that has built to the EU AI Act for Annex III high-risk systems: risk management under Article 9, data governance under Article 10, technical documentation under Article 11, human oversight under Article 14, and deployer duties under Article 26.

DimensionEU AI ActSaudi ArabiaDelta
Risk tiers and who assigns themFour tiers: unacceptable, high, limited and minimal risk, with a closed statutory list at Annex III.No risk tiering binding on banks was identified as of August 31, 2026. The draft Responsible AI Policy is reported to propose four levels (critical, high, limited and low), a structure close enough to the EU model that an existing EU classification would largely survive the mapping.EU is stricter
Underlying data protection regimeGDPR, operating alongside the AI Act.The Personal Data Protection Law, reaching supervised financial institutions through SAMA Circular 43045328. Different text, similar function: it is the binding floor under any AI system processing personal data.Already covered by EU work
Recurring disclosure to the supervisorArticle 49 requires registration in the EU database for Annex III high-risk systems, an obligation falling on providers and on public-authority deployers rather than private-sector deployers generally.No registration duty binding on banks was identified as of August 31, 2026. The draft policy is reported to propose mandatory registration for certain AI applications, which would be a new duty for private institutions rather than a transfer of EU work.Does not map
Sector-specific AI supervisionThe AI Act sits above sectoral financial regulation, with obligations attaching to the system rather than the license.No sector-specific AI instrument binding on banks was identified as of August 31, 2026, in a search of the SAMA Rulebook and of English-language secondary reporting. Requirements arrive through data protection and cybersecurity frameworks that were not written with AI systems in mind.Does not map
When it bitesA regime and a deadline. High-risk obligations for standalone Annex III systems apply from 2 December 2027, and for Annex I embedded systems from 2 August 2028.Neither identified as of August 31, 2026. A search of the SAMA Rulebook and of English-language secondary reporting found no AI-specific instrument binding on banks and no AI-specific compliance date. SDAIA has issued AI-specific guidance, but it was not confirmed against primary Arabic-language sources for this entry and is not addressed to banks. What does bind are the data protection and cybersecurity obligations reaching banks through SAMA Circular 43045328, in force since 2021 and examinable now.

Instruments

What the requirements rest on

BindingTier 1 source· Issued 2021-12-23

Circular No. 43045328, Adherence to the Personal Data Protection Law and Data Governance Policies, Regulations and Rules

Saudi Central Bank (SAMA)

The transmission mechanism. It predates the current AI debate entirely, which is exactly why it gets missed: institutions look for an AI circular and there isn't one.

SAMA Rulebook. Dated 23 December 2021 (19/5/1443H).

BindingTier 1 source

Personal Data Protection Law

Kingdom of Saudi Arabia

The binding floor for any AI system touching personal data.

Referenced as the operative law in SAMA Circular 43045328. The PDPL text itself was not separately reviewed for this entry.

GuidanceTier 2 source· Issued 2023

AI Ethics Principles

SDAIA

Non-binding in itself, but reachable through the SAMA circular's reference to SDAIA-issued policies and controls.

Seven principles reported as fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, and accountability. Issue year and content from Tier 2 reporting; not confirmed against the SDAIA primary text for this entry.

GuidanceTier 2 source

Generative AI Guidelines

SDAIA

Non-binding, but the guidelines themselves note that misuse of generative AI can carry consequences under existing laws including the PDPL and cybersecurity regulations.

Reported as covering transparency, accountability, privacy, human oversight and risk management, with separate versions for government entities. Not confirmed against the primary text for this entry.

DraftTier 2 source· Issued 2026-04

Draft Responsible AI Policy

SDAIA

The instrument that would move this cell from indirect to binding. Reported to propose four risk levels: critical, high, limited and low. It also proposes mandatory registration for certain AI applications, ethics labeling tied to compliance maturity, audit requirements for high-risk systems, and a regulatory sandbox. Not adopted.

Public consultation reported as closing 3 May 2026. Contents from Tier 2 reporting; the draft text was not reviewed for this entry.

BindingTier 1 source

Cyber Security Framework

Saudi Central Bank (SAMA)

Written before AI was a supervisory concern. It is currently the main instrument under which AI system security is actually examined.

SAMA Rulebook.

Enforcement

How this is actually supervised

Supervisor
Saudi Central Bank (SAMA) for supervised institutions; SDAIA as the national data and AI authority
Mechanism
SAMA supervision of the binding circulars and frameworks. AI shortfalls surface as data protection, data governance or cybersecurity findings, since no AI-specific examination standard binding on banks was identified as of August 31, 2026.
Observed to date
No AI-specific enforcement action against a Saudi financial institution identified at the verification date.

Action

What to do Monday morning

  1. 1Stop looking for a SAMA AI circular. Read Circular 43045328 instead, and treat its reference to SDAIA-issued policies and controls as the live channel.
  2. 2Run the gap analysis the circular already requires, scoped to AI systems specifically. The obligation to gap-analyze and take board-approved corrective action has been in force since 2021 and predates most institutions' AI deployments.
  3. 3Check whether customer personal data has been reused as training data. The circular's use-limitation requirement bites here and is the most common failure point.
  4. 4Map AI systems onto the existing Cyber Security Framework controls now rather than waiting for an AI-specific standard, since that is the framework an examiner currently has to work with.
  5. 5Classify the AI portfolio against the draft policy's reported four levels. If the draft is adopted broadly as consulted, institutions that already hold a classification will be starting from a position others will need months to reach.

This page tells you what applies. It cannot tell you what you are running.

The Diagnostic maps your actual AI systems against these requirements and returns the gaps in priority order, with the evidence an examiner would ask for. Built once against the most demanding specification you face, it answers the questions in every other jurisdiction you operate in.

Request the Diagnostic

Watch list

What would change this verdict

  • Whether the draft Responsible AI Policy is adopted, in what form, and with what transition period. This is the single development that would move this cell from indirect to binding.
  • Whether SAMA issues sector-specific AI guidance of its own, as the CBUAE and the Qatar Central Bank have done, or continues to rely on the SDAIA channel.
  • Whether the reported registration and ethics-labeling mechanisms survive consultation, since both would impose duties with no current equivalent for private institutions.

Questions

Common questions

Does SAMA have AI regulations for banks?

No dedicated AI instrument was identified at the verification date. SAMA Circular 43045328 requires supervised institutions to align internal policies with the Personal Data Protection Law and with policies and controls issued by SDAIA, which is how AI expectations currently reach the sector.

Is there an AI law in Saudi Arabia?

No AI-specific law was identified as of August 31, 2026. SDAIA's AI Ethics Principles and Generative AI Guidelines are AI-specific but non-binding. A draft Responsible AI Policy went to public consultation, reported as closing on 3 May 2026, and had not been adopted at the verification date.

How does Saudi Arabia compare with the UAE for banking AI?

They arrive from opposite directions. The UAE has sector-specific central bank guidance that is examinable now through the instruments it cross-references. For Saudi Arabia no sector-specific AI instrument binding on banks was identified as of August 31, 2026, and obligations reach banks through data protection and cybersecurity frameworks instead. The Saudi draft policy, if adopted, would be the more structured of the two.

If we comply with the EU AI Act, are we covered in Saudi Arabia?

For what is currently in force, largely yes, because the binding obligations are data protection and cybersecurity ones that GDPR-aligned institutions have generally addressed. That would change if the draft Responsible AI Policy is adopted with the reported registration and audit duties, which have no EU equivalent for private-sector deployers.

Verification notes

  • The central claim on this page is a negative one: that no dedicated SAMA AI instrument binding on banks was identified as of August 31, 2026. It rests on a search of the SAMA Rulebook and on Tier 2 sources reporting the same absence. A register search cannot prove absence, and an instrument published outside the Rulebook, or in Arabic only, would not necessarily surface. Treat this verdict as the current best reading rather than a settled fact.
  • SAMA Circular 43045328 was read on the SAMA Rulebook and is the only requirement on this page confirmed against a primary source. The SDAIA instruments and the draft Responsible AI Policy rest on Tier 2 reporting and are marked as such.
  • The draft Responsible AI Policy contents, including the four risk levels and the registration and labeling mechanisms, are as reported in secondary coverage. The draft text was not reviewed.

Last verified August 31, 2026 by Rabii Agoujgal.

This entry is provided for informational purposes and does not constitute legal advice. Applicability of any regulation, guidance, or standard discussed depends on the facts, deployment context, and relevant jurisdiction. Regulatory positions change; check the verification date before relying on this page.