AI Governance & Compliance in Saudi Arabia: What Enterprises Need to Know About SDAIA and NDMO
Any enterprise building AI in Saudi Arabia today is operating inside a fast-moving but increasingly well-defined governance framework. The Kingdom's Cabinet designated 2026 the Year of Artificial Intelligence, and two bodies sit at the center of what that means in practice for enterprise AI projects: SDAIA and NDMO. This guide explains what each one governs, what it means for your AI roadmap, and how Recursive builds compliance in from day one rather than retrofitting it later.
What is SDAIA?
The Saudi Data and Artificial Intelligence Authority (SDAIA) is the Kingdom's national authority for data and AI policy, established in 2019. SDAIA owns the National Strategy for Data and AI (NSDAI), a long-term strategy first announced in 2020 and formally approved that July, designed to position Saudi Arabia among the world's leading data- and AI-driven economies in line with Vision 2030.
SDAIA operates through two key subsidiaries that matter directly to enterprise AI buyers:
• NCAI (National Center for Artificial Intelligence) — drives AI research, development, and national adoption programs.
• NDMO (National Data Management Office) — owns data governance, classification, and personal data protection regulation.
SDAIA also published a set of AI Ethics Principles in 2023, covering fairness, accountability, transparency, and human oversight — principles that increasingly show up as expectations in government and enterprise AI procurement, even outside formal regulation.
What does NDMO require?
NDMO governs a separate, more operational layer: how data is classified, stored, secured, and handled across its lifecycle. Its National Data Management and Personal Data Protection Standards were issued in January 2021 and apply to public entities in Saudi Arabia along with any business partner handling government data — which in practice includes most enterprise AI vendors working with government-adjacent or regulated clients.
The standards are organized into a detailed set of domains and controls covering areas like data classification, data availability, data protection, and data governance more broadly. A few points matter most for enterprise AI planning:
• Data localization — personal and government data are expected to stay within Saudi Arabia's national borders.
• Two protected data categories — personal data (anything that could identify a Saudi citizen) and government data (any raw or processed data produced or held by a public entity, regardless of form).
• Full-lifecycle coverage — the standards apply across structured databases, documents, emails, and even paper records, not just production systems.
• Formal compliance assessment — entities in scope go through periodic compliance evaluation against the published controls.
• Coordination with cybersecurity regulation — NDMO sets data governance and classification requirements, while Saudi Arabia's National Cybersecurity Authority sets the technical security controls that sit alongside them.
Separately, Saudi Arabia's Personal Data Protection Law (PDPL), enacted in 2023, sets the broader legal baseline for how personal data is processed across the Kingdom — the legal backdrop NDMO's public-sector standards build on top of. The same classification and localization principles apply directly to banking and financial institutions handling customer data under SAMA oversight.

What this means for your AI roadmap
None of this is a reason to slow down an AI initiative — it's a reason to design for it from the start. In practice, that means:
1. Classify before you build. Know which data categories (personal, government, neither) your AI system will touch before architecture decisions are made.
2. Plan for localization by default, not as a late-stage infrastructure change.
3. Build in human oversight and auditability at every decision point an AI system makes, in line with SDAIA's published ethics principles.
4. Treat compliance readiness as a design input, not a post-launch checklist — retrofitting classification and access controls into a live system is dramatically more expensive than designing for them upfront.
This is the same approach Recursive uses on every government and financial-sector AI engagement in the Kingdom: data sovereignty as a first-class engineering requirement, not an afterthought.
Frequently asked questions
What is SDAIA?
What does NDMO require of enterprise AI systems?
Is NDMO compliance mandatory for private companies?
How is NDMO different from SDAIA?
Does data have to be hosted physically inside Saudi Arabia?
Does Saudi data need to stay physically inside the Kingdom?
Can Recursive help assess whether our existing AI system is compliant?
