SDAIA AI Adoption Framework: is your company ready for AI?
The SDAIA AI Adoption Framework is guidance, not a law, and it was written with large entities in mind. This guide shows what a smaller company in Saudi Arabia, or one serving customers there, can borrow from it, with a 12-question readiness check and SDAIA's 2026 risk matrix worked on one AI use case.

Key takeaways
- The SDAIA AI Adoption Framework (Version 2, May 2025) is guidance. What binds a company is law, above all the PDPL and its Implementing Regulation. Check the version before you quote a summary.
- Borrow the habits (a real use case, an owner, measures, a risk check, a pilot), not large-entity targets such as an AI unit or 8% budget savings.
- Score one use case: 12 readiness questions (pilot only at 18+ with no zero), then SDAIA's likelihood × impact matrix: 1–2 low, 3–6 medium, 8–12 high, 16 catastrophic.
- Where you rely on consent, solely automated decisions about people need it to be explicit, and some AI uses need a written impact assessment (Implementing Regulation, Articles 11 and 25).
- Ask your AI supplier the checklist items SDAIA marks Yes for third parties, as questions rather than legal duties: human oversight, bias, data control, security and disclosure.
On this page
- What is the SDAIA AI Adoption Framework, and which version are you reading?
- Is it mandatory? What binds your company and what only guides it
- What a smaller company can borrow, and what it can leave to large entities
- A 12-question AI readiness assessment, built on the three pillars
- Score the risks with SDAIA's AI risk management framework: a worked example
- SDAIA AI ethics principles and PDPL checks before go-live
- Questions for your AI supplier, taken from SDAIA's checklist
- If your company is outside Saudi Arabia
- Four steps for this week
The SDAIA AI Adoption Framework is guidance, not a law. It groups AI readiness into three pillars: Directions (strategy, governance), Enablers (data, infrastructure, people) and Outcomes (applications, impact). It was written with large entities in mind, but a smaller company can use it as a checklist for one AI use case [1, pp. 5–9; 2].
SDAIA is the Saudi Data & AI Authority, the national authority for data and AI [1, p. 4]. Through its National Data Management Office it also regulates personal data protection and publishes Saudi Arabia's Personal Data Protection Law (PDPL) and the Implementing Regulation that holds its detailed rules [2]. This guide is for companies in Saudi Arabia, and for companies elsewhere in the Gulf Cooperation Council (GCC) and beyond that sell to Saudi customers or operate there.
This article is general information, not legal advice. Check your company's obligations against the current text of the law and its implementing regulations.
What is the SDAIA AI Adoption Framework, and which version are you reading?
It is a guidance document built as three pillars, seven dimensions and 23 sub-dimensions [1, p. 9]. It "targets all government and private entities" and offers "guiding principles and enablers" rather than detailed technical standards [1, p. 6].
Its stated audience is government entities and policymakers [1, p. 5], and none of its examples is sized for a 20-person firm.
Version 1 (2024) or Version 2 (2025)? Check before you quote
SDAIA unveiled the first edition in September 2024; the Saudi Press Agency's summary describes four maturity levels: Emerging, Developed, Proficient and Advanced [3]. The PDF now at the same address is Version 2 (May 2025, SDAIA-P121), built on the three pillars without those levels [1, p. 48]. Many online summaries still describe 2024, so check the "Version Number" on the last page of SDAIA's PDF before quoting one.
The framework on one page (structure from [1, p. 9]; right-hand column is our reading):
| Pillar | Dimensions and sub-dimensions | In plain words |
|---|---|---|
| Directions | Strategy (plan and performance; initiatives; budget) · Governance (frameworks and policies; organisational empowerment; trustworthiness and safety; regulatory compliance) | Know why you use AI, who decides, and which rules apply |
| Enablers | Data (availability and access; quality and integration; reliability) · Infrastructure (technical standards; availability and follow-up; operational flexibility) · Human capacity (number and diversity; professional development; academic cooperation; job stability) | Have the data, systems and people the use case needs |
| Outcomes | Applications (development and deployment; privacy and safety; operation and management) · Impact (operational efficiency; employee productivity; service quality) | Run it safely, and show it changed something |
Is it mandatory? What binds your company and what only guides it
Short answer: no. The Adoption Framework is guidance, and in our reading so are SDAIA's other AI documents, though the ethics principles are firmer in places. What binds a company is law, above all the PDPL, and its sector regulator's rules.
| Document | Latest version (checked 29 September 2026) | Status (our reading) and its own words |
|---|---|---|
| AI Adoption Framework | Version 2, May 2025 [1] | Guidance. "A guiding reference" for all sectors [2]; its back page files it under "Regulatory Documents", a document category [1, p. 48] |
| AI Ethics Principles | 2025 edition, SDAIA-P114E [4] | Guidance, firmer in places. It "shall apply to all AI stakeholders" in Saudi Arabia, and says unacceptable-risk systems "are not allowed" [4, p. 9] |
| National AI Risk Management Framework | Version 1, April 2026, launched 14 July 2026 [5; 6] | Guidance. An "advisory framework" for government and private-sector entities [7] |
| Generative AI Guidelines for Public | Version 1, May 2025 [8] | Guidance. Says the ethics principles "apply to all segments of society", private entities included [8, p. 8] |
| PDPL and its Implementing Regulation | As amended [9; 10] | Law. Covers processing of personal data in Saudi Arabia, and of residents' data from abroad [9, Art. 2] |
The Adoption Framework itself points to the law: entities "are also obligated to implement the 'Personal Data Protection Law' and its Implementing Regulations" [1, p. 20].

One item to watch: SDAIA put a draft Responsible AI Policy to public comment on 2 April 2026 [11]; check whether it has been finalised.
What a smaller company can borrow, and what it can leave to large entities
| What the framework describes | A workable version at 10–250 staff (our reading) |
|---|---|
| An AI strategy with a two-year timeline for pilots [1, p. 15] | One page: the problem, one use case, its owner, two or three measures, a stop rule |
| An AI unit of "35 employees across 10 career tracks", plus a supervisory committee and a compliance officer [1, pp. 20, 34] | One owner who can stop the project, one person who checks outputs, a decision log |
| An innovation fund with "an annual allocation of SAR 5 million" [1, p. 19] | A budget per use case, from a supplier's written quote (what drives the cost) |
| Savings of "at least 8% of the annual operating budget" and productivity gains "exceeding 15-20%" [1, pp. 43–44] | Don't copy these as targets. Set your own go and stop thresholds from a time-and-cost worksheet |
Habits worth keeping at any size:
- Start from "actual user needs or existing operational challenges" [1, p. 16].
- Assess risks "across all use cases before adopting any AI system" [1, p. 22].
A 12-question AI readiness assessment, built on the three pillars
This AI readiness assessment scores one use case at a time: 12 questions, four per pillar, 0 to 2 points each, 24 in total. Answer it with the person who does the task today: 0 = no, 1 = partly, 2 = yes, and you can show it.

An AI feasibility study asks two questions: are we ready, and is it worth it? For the second, SDAIA's executive guide lists "estimating required commitments, determining expected return" [12, p. 14], and our one-task guide has a worksheet and a two-week pilot. The table below, your readiness questionnaire, answers the first.
| No. | Question | Evidence | Score (0–2) |
|---|---|---|---|
| Directions | |||
| 1 | Can you name the task and what it costs today in cases, minutes or errors? | Last month's count, and the time for 10 cases | |
| 2 | Is there one owner who can stop the project, and one person who checks outputs? | Two names | |
| 3 | Have you written two or three measures, with today's baseline and a stop rule? | The one-page plan | |
| 4 | Do you know which rules apply: personal data, a sector regulator, customers in another country? | A list of rules | |
| Enablers | |||
| 5 | Is the data in one place, current and exportable (or still in chats and paper files)? | A sample export | |
| 6 | Do you know which fields are personal or sensitive, and who may see them? | Field list with access rights | |
| 7 | Can the tool connect to your systems, or will someone copy and paste? | Supplier's written answer | |
| 8 | Does someone have time to review outputs, and is there a written rule on what never goes into public AI tools? | Rota hours; the rule [8, §5.4] | |
| Outcomes | |||
| 9 | Have you scored this use case's risks (next section)? | The risk table | |
| 10 | Is there a human approval step, and a manual fallback? | Written workflow | |
| 11 | If customers see the output, will they be told AI is involved and offered a person? | The message text | |
| 12 | Will you log errors and complaints and review them on a schedule? | Log and review date |
Records stuck in scanned Arabic PDFs? Fix question 5 first with a checked OCR workflow.
Reading the score (our rule of thumb, not SDAIA's):
- 18–24, and no question at 0: run a limited pilot, with a person approving every output.
- 11–17, or 18 or more with any 0: fix the 0 and 1 answers first, then re-score.
- 0–10: not ready. Fix the process or data first, or pick another task. Some tasks only need simple automation without AI.
Score the risks with SDAIA's AI risk management framework: a worked example
The National AI Risk Management Framework scores the risks of one AI system at a time on a 4×4 likelihood × impact matrix [5]. It is published in full in Arabic, with a six-page English summary [7]; the English labels below are our translations.
- Set the context: what the system may and may not do, its data inputs and outputs, its level of automation and the person's role, and its change plan [5, p. 17].
- Identify risks under seven types: bias, discrimination and abuse; privacy and security; misinformation; malicious use; human–machine interaction; social, economic and environmental impacts; safety and limitations [5, pp. 18–20].
- Rate likelihood 1–4 from exposure, controls, ease of occurrence and past incidents. The scale is not built on percentages, though SDAIA says its levels match annual bands some frameworks use: under 1%, 1–10%, 10–50%, 50% or more [5, pp. 22–23].
- Rate impact 1–4: low, medium, high, catastrophic [5, p. 23].
- Multiply: 1–2 low, 3–6 medium, 8–12 high, 16 catastrophic [5, pp. 24–25].
- Treat: avoid, mitigate, transfer or accept. Transferring risk through contracts, insurance or supplier obligations "does not cancel the entity's responsibility for governance and compliance" (our translation) [5, p. 26].
The matrix behind step 5 [5, p. 25]:
| Likelihood ↓ / Impact → | 1 Low | 2 Medium | 3 High | 4 Catastrophic |
|---|---|---|---|---|
| 4 Almost certain | 4 | 8 | 12 | 16 |
| 3 Likely | 3 | 6 | 9 | 12 |
| 2 Unlikely | 2 | 4 | 6 | 8 |
| 1 Rare | 1 | 2 | 3 | 4 |
SDAIA's own appendix scores eight risks of a large language model that drafts a government entity's internal reports. All eight come out medium and are accepted, most with continued monitoring; two, including leaks of internal information, only with immediate escalation if an incident is suspected [5, pp. 32–44].
Illustrative example (not a client case): a spare-parts distributor in Dammam, in eastern Saudi Arabia, with customers across Saudi Arabia and the Gulf, wants AI to draft email replies to "where is my order?" and "is this part in stock?" from its order system, with a staff member approving every reply. Scores are judgments, with the listed controls in place.

| # | Risk | SDAIA type | Score | Treatment and controls |
|---|---|---|---|---|
| 1 | Wrong stock level or delivery date | Misinformation | 3 × 2 = 6, medium | Mitigate: answer only from order-system fields; if data is missing, hand to a person; log corrections |
| 2 | Customer details go into a personal AI account, or to a supplier without a proper contract | Privacy and security | 2 × 3 = 6, medium | Mitigate, partly avoid: business account only, written data rule, processor agreement; check transfer rules if data leaves Saudi Arabia |
| 3 | Staff approve replies without reading them | Human–machine interaction | 3 × 2 = 6, medium | Mitigate: weekly spot-check of approved replies |
| 4 | Tool goes down, or changes after a supplier update | Safety and limitations | 2 × 2 = 4, medium | Mitigate: manual fallback; re-test after updates, which can arrive "without informing end users" [8, §5.7] |
| Contrast | AI rejects job applicants automatically | Bias, discrimination and abuse | 3 × 3 = 9, high | Avoid: AI may sort applications; a person decides |
| Your risk |
All four are medium with controls, so the distributor can pilot, accept what remains and watch SDAIA's monitoring signals: complaints, repeated objections to decisions, and more requests for human review [5, p. 28].
SDAIA AI ethics principles and PDPL checks before go-live
The seven principles and four risk categories
The seven principles: fairness; privacy and security; humanity; social and environmental benefits; reliability and safety; transparency and explainability; accountability and responsibility [4, pp. 12–26].
The same document has four risk categories: little or no risk, such as spam filters (no restrictions); limited risk (the principles apply); high risk to basic rights (pre- and post-conformity assessments plus statutory requirements); and unacceptable risk, such as social profiling (not allowed) [4, p. 9]. SDAIA's generative AI guideline asks users to place their tools in these categories [8, §4.5]. Most drafting and data-entry uses look like "limited" candidates; someone in your company should decide, using the ethics checklist.
Three PDPL checks that AI adds
- Solely automated decisions. Consent is the PDPL's default basis [9, Art. 5]; where you rely on it, it must be explicit for decisions made solely by automated processing [10, Art. 11(2)(c)]. The law lists cases where consent is not needed [9, Art. 6], so check which basis applies before AI decides anything about a person on its own. Processing with new technologies or automated decisions, on a large scale or repeatedly, also means telling people whether decisions are solely automated [10, Art. 4(5)(c)].
- A written impact assessment is required in listed cases, among them when you process sensitive data, link personal datasets from different sources, or, on a large scale or repeatedly, process data with newly adopted technologies or for automated decisions [10, Art. 25(1)]. For Articles 4 and 25 we follow the official Arabic ("or repeatedly") [13, Arts. 4(5), 25(1)]; SDAIA's English translation of Article 25 says "large scale and repetitive".
- Your AI supplier is usually a processor. Choose one that provides "sufficient guarantees", with an agreement covering purpose, data categories, duration, breach notification, exposure to other countries' laws, and subcontractors [10, Art. 17(1)].
If customers will deal with the AI. This one comes from SDAIA's guidance, not the PDPL: its generative AI guideline says to "clearly communicate when GenAI is used in interactions with the public" and offer "alternative, non-automated communication channels" [8, §4.3]. Planning a WhatsApp assistant? Build both in from day one.
Questions for your AI supplier, taken from SDAIA's checklist
When a third party builds the system, SDAIA's ethics principles ask its owner for "an AI Ethics due diligence" before procurement or sign-off [4, p. 25]. Their checklist (Annexure C) marks items Yes or No under "Binding for Third-party" [4, pp. 41–47]. The column is undefined, so treat the Yes items as questions, not a legal duty on the supplier. Checklist stages: PD plan and design, PID prepare input data, DM deploy and monitor.
- Where can our staff review, edit or stop an output before it reaches a customer? (PD.1, PD.2)
- What does the contract say about liability and about protecting the people whose data we process? (PD.5)
- How do you test and monitor for unfair bias before and after launch, including with Gulf and other Arabic dialects and non-Arabic names? (PD.10, DM.9; the example is ours)
- How do you flag and control personal data, including consent and its withdrawal? Is our data used to train models? (PID.1, PID.4; the training question is ours)
- How is data kept confidential, and has the system been tested against attacks and leaks? (PID.5, DM.2)
- Will users know they are dealing with AI? (DM.1)
- How do we report errors, and how does that feedback reach the system? (DM.8)
Add the Article 17 contract items above and our ten questions to ask before you sign.
If your company is outside Saudi Arabia
The PDPL covers personal data about people residing in Saudi Arabia, including processing "by any means from any party outside the Kingdom" [9, Art. 2]; the ethics principles address AI stakeholders "within KSA" [4, p. 9]. So if you serve customers in Saudi Arabia from Dubai, Cairo or London, the three PDPL checks above can apply to you, and SDAIA's frameworks are useful guidance. For transfers and registration, see what the PDPL asks of companies outside Saudi Arabia.
SDAIA's ethics document cites NIST's AI RMF and ISO 23894 as references [4, p. 34].
| If you already use… | Reuse | Add for Saudi Arabia |
|---|---|---|
| NIST AI RMF (voluntary; Govern, Map, Measure, Manage) [14] | Your risk register and roles | SDAIA's 4×4 matrix if a Saudi client asks; the PDPL checks; Arabic testing; alignment with "KSA's cultural values" under the humanity principle [4, p. 19] |
| EU AI Act tiers (unacceptable, high, transparency, minimal) [15] | Your inventory of AI uses by tier | SDAIA's four categories are similar in shape, not in legal effect: map each use case again |
Four steps for this week
- Pick one AI use case and write down what it costs today.
- Answer the 12 questions with the person who does the task.
- Score three to five risks and the controls you would use.
- Send the supplier questions before you sign, and ask for written answers.
This is how O AI, a Saudi AI and software company in Al Khobar, works:
A good first step is one slow, repetitive task: documents, customer replies, reports or data spread across systems. O AI studies that task, checks whether AI is worth it, then connects AI to the systems you already use or builds a new one. The first consultation and proposal come with no commitment.
Tell us which task you want to test and book a free consultation; we reply within one business day.
Frequently asked questions
Is the SDAIA AI Adoption Framework mandatory for private companies?
SDAIA presents it as guidance: "a guiding reference" for AI adoption across all sectors (SDAIA, Regulations and Policies index). It offers "guiding principles and enablers", not detailed technical standards (SDAIA, AI Adoption Framework, p. 6). What binds a company is law, above all the PDPL and its Implementing Regulation, which the framework itself says entities are obligated to implement (AI Adoption Framework, p. 20). This is general information, not legal advice.
Is there an AI law in Saudi Arabia, and which rules apply when my company uses AI?
The duties you can be held to come from existing law. Whenever personal data is involved, the PDPL and its Implementing Regulation apply: explicit consent for solely automated decisions where you rely on consent, impact assessments in listed cases, and processor contracts (Implementing Regulation, Articles 11, 17 and 25). Your sector regulator may add rules. SDAIA's AI frameworks and guidelines guide how you meet these duties. SDAIA also put a draft Responsible AI Policy to public consultation in April 2026 (SPA, 2 April 2026), so check for updates.
How is the AI Adoption Framework different from SDAIA's AI risk management framework?
The Adoption Framework looks at the whole organisation: strategy, governance, data, infrastructure, people, applications and impact, grouped in three pillars (SDAIA, AI Adoption Framework, p. 9). The risk framework looks at one AI system: set its context, identify its risks, score them on a 4×4 likelihood-and-impact matrix, treat them and monitor them (SDAIA, National AI Risk Management Framework, April 2026). Use the first to judge readiness, and the second before each go-live.
Do these rules apply to a company outside Saudi Arabia?
The PDPL can. It covers processing of personal data about people residing in Saudi Arabia, including processing "from any party outside the Kingdom" (PDPL Article 2). SDAIA's ethics principles address AI stakeholders within Saudi Arabia (SDAIA, AI Ethics Principles, p. 9), and its AI frameworks are guidance. A foreign company serving customers in Saudi Arabia should treat the PDPL points in this guide as applying to it.
Is there an official AI readiness score or certificate for companies?
We found none for companies that buy AI. SDAIA's National AI Index measures the readiness of government entities (Saudi Press Agency, 22 July 2025). For AI products and systems, SDAIA offers optional registration and incentive badges through the National Data Governance Platform (Saudi Press Agency, 26 May 2025; SDAIA, AI Ethics Principles, pp. 31–32). A company that buys AI does not need a badge, but it can ask its supplier whether it holds one.
Can a small company do an AI readiness assessment itself?
Yes, for one use case. The owner and the person who does the task answer the 12 questions together, then score three to five risks with SDAIA's matrix. Bring in a lawyer where personal data or automated decisions about people are involved; SDAIA's generative AI guideline itself advises consulting legal professionals (SDAIA, Generative AI Guidelines for Public, section 4.4).
How this article was made: Researched from SDAIA's AI frameworks and guidelines, the PDPL and its Implementing Regulation, SPA announcements, NIST and the European Commission, opened on 29 September 2026. Drafted with AI assistance, then checked against those sources. Images are AI-generated illustrations.
Sources
- Artificial Intelligence Adoption Framework (Version 2, May 2025, SDAIA-P121) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- SDAIA Laws & Regulations (index page describing the AI Adoption Framework and SDAIA's data regulation role) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- SDAIA Launches AI Framework to Promote Ethical, Responsible Use of Advanced Technologies in Saudi Arabia (1 December 2024) (opens in a new tab)Saudi Press Agency (SPA) · spa.gov.sa
- AI Ethics Principles (2025, SDAIA-P114E, Version 1) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- National Artificial Intelligence Risk Management Framework, full text in Arabic (April 2026, SDAIA-P145, Version 1) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- SDAIA Introduces National Framework for Managing AI Risks (14 July 2026) (opens in a new tab)Saudi Press Agency (SPA) · spa.gov.sa
- National Artificial Intelligence Risk Management Framework: Executive Summary (April 2026, SDAIA-P145EN) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- Generative Artificial Intelligence Guidelines for Public (May 2025, SDAIA-P115E) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- Personal Data Protection Law (English translation, as amended by Royal Decree M/148; the Arabic text on laws.boe.gov.sa is the official version) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- Implementing Regulation of the Personal Data Protection Law (English translation) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- SDAIA Invites Public, Entities to Share Views on Responsible AI Policy Draft (2 April 2026) (opens in a new tab)Saudi Press Agency (SPA) · spa.gov.sa
- Adopting AI Systems (Artificial Intelligence for Executives Series, 2nd edition, April 2024) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- Implementing Regulation of the Personal Data Protection Law, official Arabic text (اللائحة التنفيذية لنظام حماية البيانات الشخصية) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
- AI Risk Management Framework (opens in a new tab)National Institute of Standards and Technology (NIST) · nist.gov
- AI Act: Regulatory framework for AI (opens in a new tab)European Commission · digital-strategy.ec.europa.eu
- SDAIA launches the National AI Index to measure government entities' readiness to adopt AI (22 July 2025, in Arabic) (opens in a new tab)Saudi Press Agency (SPA) · spa.gov.sa
- SDAIA Urges AI Firms to Register on National Data Governance Platform for Incentive Badges (26 May 2025) (opens in a new tab)Saudi Press Agency (SPA) · spa.gov.sa
AI


