Saudi Arabia / Banking and financial services
What AI rules apply to banks in Saudi Arabia?
There is no SAMA AI rulebook. SDAIA's instruments reach banks through a 2021 SAMA circular.
No dedicated AI instrument for Saudi banks was identified at the verification date. What binds instead is a transmission chain: a SAMA circular requires supervised institutions to align internal policies with the Personal Data Protection Law and with policies and controls issued by SDAIA. SDAIA's AI instruments are non-binding in themselves, which makes the circular the mechanism that gives them supervisory weight. A draft Responsible AI Policy that would change this closed consultation on 3 May 2026 and has not been adopted.
Absence not conclusively verified
This page states that no such instrument was identified as of its verification date. That is a claim about the completeness of a search rather than proof of absence: an instrument published outside the register searched, or in a language the search did not cover, would not necessarily surface.
Scope
Who this applies to
- Banking sector institutions supervised by SAMA
- Finance companies, payment systems and payment service providers
- Money exchange sector and credit bureaus
- Regulatory Sandbox participants
What pulls a system into scope
- Any processing of personal data by an AI system, which brings the Personal Data Protection Law and SDAIA's data instruments into scope through SAMA Circular 43045328
- Cybersecurity exposure created by AI systems, assessed under the existing SAMA Cyber Security Framework rather than any AI-specific standard
- Deployment of AI in a supervised institution generally, where SAMA expects internal policies to be reviewed against SDAIA-issued policies, controls, regulations and rules
Obligations
What is actually required
Align internal policies with the PDPL and SDAIA instruments
SAMA Circular 43045328Supervised institutions must review approved internal policies and procedures and ensure compatibility with, or amendment to, both the Personal Data Protection Law and policies and controls issued by SDAIA. This is the clause through which SDAIA's non-binding AI instruments acquire supervisory weight in the financial sector.
Gap analysis with board-approved remediation
SAMA Circular 43045328Institutions must evaluate organizational gaps against the Law and the applicable policies, controls and rules, and develop corrective action plans for Board approval.
Customer personal data protection
SAMA Circular 43045328Full adherence to protection of customers' personal data, including review of disclosure practices, security controls, and use of data only for its original purpose. Applied to AI, this constrains reuse of customer data as training data.
Cybersecurity maturity for AI systems
SAMA Cyber Security FrameworkNo AI-specific security standard binding on banks was identified as of August 31, 2026. AI systems are assessed through the existing SAMA Cyber Security Framework, which means AI exposure has to be mapped onto controls written for conventional systems.
If you already built for the EU AI Act
An institution that has built to the EU AI Act for Annex III high-risk systems: risk management under Article 9, data governance under Article 10, technical documentation under Article 11, human oversight under Article 14, and deployer duties under Article 26.
| Dimension | EU AI Act | Saudi Arabia | Delta |
|---|---|---|---|
| Risk tiers and who assigns them | Four tiers: unacceptable, high, limited and minimal risk, with a closed statutory list at Annex III. | No risk tiering binding on banks was identified as of August 31, 2026. The draft Responsible AI Policy is reported to propose four levels (critical, high, limited and low), a structure close enough to the EU model that an existing EU classification would largely survive the mapping. | EU is stricter |
| Underlying data protection regime | GDPR, operating alongside the AI Act. | The Personal Data Protection Law, reaching supervised financial institutions through SAMA Circular 43045328. Different text, similar function: it is the binding floor under any AI system processing personal data. | Already covered by EU work |
| Recurring disclosure to the supervisor | Article 49 requires registration in the EU database for Annex III high-risk systems, an obligation falling on providers and on public-authority deployers rather than private-sector deployers generally. | No registration duty binding on banks was identified as of August 31, 2026. The draft policy is reported to propose mandatory registration for certain AI applications, which would be a new duty for private institutions rather than a transfer of EU work. | Does not map |
| Sector-specific AI supervision | The AI Act sits above sectoral financial regulation, with obligations attaching to the system rather than the license. | No sector-specific AI instrument binding on banks was identified as of August 31, 2026, in a search of the SAMA Rulebook and of English-language secondary reporting. Requirements arrive through data protection and cybersecurity frameworks that were not written with AI systems in mind. | Does not map |
| When it bites | A regime and a deadline. High-risk obligations for standalone Annex III systems apply from 2 December 2027, and for Annex I embedded systems from 2 August 2028. | Neither identified as of August 31, 2026. A search of the SAMA Rulebook and of English-language secondary reporting found no AI-specific instrument binding on banks and no AI-specific compliance date. SDAIA has issued AI-specific guidance, but it was not confirmed against primary Arabic-language sources for this entry and is not addressed to banks. What does bind are the data protection and cybersecurity obligations reaching banks through SAMA Circular 43045328, in force since 2021 and examinable now. |
Instruments
What the requirements rest on
Circular No. 43045328, Adherence to the Personal Data Protection Law and Data Governance Policies, Regulations and Rules
Saudi Central Bank (SAMA)
The transmission mechanism. It predates the current AI debate entirely, which is exactly why it gets missed: institutions look for an AI circular and there isn't one.
SAMA Rulebook. Dated 23 December 2021 (19/5/1443H).
Personal Data Protection Law
Kingdom of Saudi Arabia
The binding floor for any AI system touching personal data.
Referenced as the operative law in SAMA Circular 43045328. The PDPL text itself was not separately reviewed for this entry.
AI Ethics Principles
SDAIA
Non-binding in itself, but reachable through the SAMA circular's reference to SDAIA-issued policies and controls.
Seven principles reported as fairness, privacy and security, humanity, social and environmental benefits, reliability and safety, transparency and explainability, and accountability. Issue year and content from Tier 2 reporting; not confirmed against the SDAIA primary text for this entry.
Generative AI Guidelines
SDAIA
Non-binding, but the guidelines themselves note that misuse of generative AI can carry consequences under existing laws including the PDPL and cybersecurity regulations.
Reported as covering transparency, accountability, privacy, human oversight and risk management, with separate versions for government entities. Not confirmed against the primary text for this entry.
Draft Responsible AI Policy
SDAIA
The instrument that would move this cell from indirect to binding. Reported to propose four risk levels: critical, high, limited and low. It also proposes mandatory registration for certain AI applications, ethics labeling tied to compliance maturity, audit requirements for high-risk systems, and a regulatory sandbox. Not adopted.
Public consultation reported as closing 3 May 2026. Contents from Tier 2 reporting; the draft text was not reviewed for this entry.
Cyber Security Framework
Saudi Central Bank (SAMA)
Written before AI was a supervisory concern. It is currently the main instrument under which AI system security is actually examined.
SAMA Rulebook.
Enforcement
How this is actually supervised
- Supervisor
- Saudi Central Bank (SAMA) for supervised institutions; SDAIA as the national data and AI authority
- Mechanism
- SAMA supervision of the binding circulars and frameworks. AI shortfalls surface as data protection, data governance or cybersecurity findings, since no AI-specific examination standard binding on banks was identified as of August 31, 2026.
- Observed to date
- No AI-specific enforcement action against a Saudi financial institution identified at the verification date.
Action
What to do Monday morning
- 1Stop looking for a SAMA AI circular. Read Circular 43045328 instead, and treat its reference to SDAIA-issued policies and controls as the live channel.
- 2Run the gap analysis the circular already requires, scoped to AI systems specifically. The obligation to gap-analyze and take board-approved corrective action has been in force since 2021 and predates most institutions' AI deployments.
- 3Check whether customer personal data has been reused as training data. The circular's use-limitation requirement bites here and is the most common failure point.
- 4Map AI systems onto the existing Cyber Security Framework controls now rather than waiting for an AI-specific standard, since that is the framework an examiner currently has to work with.
- 5Classify the AI portfolio against the draft policy's reported four levels. If the draft is adopted broadly as consulted, institutions that already hold a classification will be starting from a position others will need months to reach.
This page tells you what applies. It cannot tell you what you are running.
The Diagnostic maps your actual AI systems against these requirements and returns the gaps in priority order, with the evidence an examiner would ask for. Built once against the most demanding specification you face, it answers the questions in every other jurisdiction you operate in.
Request the DiagnosticWatch list
What would change this verdict
- Whether the draft Responsible AI Policy is adopted, in what form, and with what transition period. This is the single development that would move this cell from indirect to binding.
- Whether SAMA issues sector-specific AI guidance of its own, as the CBUAE and the Qatar Central Bank have done, or continues to rely on the SDAIA channel.
- Whether the reported registration and ethics-labeling mechanisms survive consultation, since both would impose duties with no current equivalent for private institutions.
Questions
Common questions
Does SAMA have AI regulations for banks?
No dedicated AI instrument was identified at the verification date. SAMA Circular 43045328 requires supervised institutions to align internal policies with the Personal Data Protection Law and with policies and controls issued by SDAIA, which is how AI expectations currently reach the sector.
Is there an AI law in Saudi Arabia?
No AI-specific law was identified as of August 31, 2026. SDAIA's AI Ethics Principles and Generative AI Guidelines are AI-specific but non-binding. A draft Responsible AI Policy went to public consultation, reported as closing on 3 May 2026, and had not been adopted at the verification date.
How does Saudi Arabia compare with the UAE for banking AI?
They arrive from opposite directions. The UAE has sector-specific central bank guidance that is examinable now through the instruments it cross-references. For Saudi Arabia no sector-specific AI instrument binding on banks was identified as of August 31, 2026, and obligations reach banks through data protection and cybersecurity frameworks instead. The Saudi draft policy, if adopted, would be the more structured of the two.
If we comply with the EU AI Act, are we covered in Saudi Arabia?
For what is currently in force, largely yes, because the binding obligations are data protection and cybersecurity ones that GDPR-aligned institutions have generally addressed. That would change if the draft Responsible AI Policy is adopted with the reported registration and audit duties, which have no EU equivalent for private-sector deployers.
Verification notes
- The central claim on this page is a negative one: that no dedicated SAMA AI instrument binding on banks was identified as of August 31, 2026. It rests on a search of the SAMA Rulebook and on Tier 2 sources reporting the same absence. A register search cannot prove absence, and an instrument published outside the Rulebook, or in Arabic only, would not necessarily surface. Treat this verdict as the current best reading rather than a settled fact.
- SAMA Circular 43045328 was read on the SAMA Rulebook and is the only requirement on this page confirmed against a primary source. The SDAIA instruments and the draft Responsible AI Policy rest on Tier 2 reporting and are marked as such.
- The draft Responsible AI Policy contents, including the four risk levels and the registration and labeling mechanisms, are as reported in secondary coverage. The draft text was not reviewed.
Last verified August 31, 2026 by Rabii Agoujgal.
This entry is provided for informational purposes and does not constitute legal advice. Applicability of any regulation, guidance, or standard discussed depends on the facts, deployment context, and relevant jurisdiction. Regulatory positions change; check the verification date before relying on this page.