1 views
20 seconds ago

What Saudi regulators will want from your AI in the end of 2026 and 2027

A sovereign AI project in Saudi Arabia used to begin with a model and a proof of concept, and the delivery team would take governance to a review committee months later, once the interesting engineering was finished. Teams in the Kingdom now run that sequence the other way round. Data classification settles the architecture before anyone opens a discussion about which model to use.

“That single re-ordering has changed almost everything downstream, and entirely for the better,” said Lakshimi Narayanan, General Manager at Mannai Information Technology Saudi Arabia. “The systems being built this way are far more likely to reach production and stay there.”

For most of the past decade, sovereignty in the Gulf meant an address. A deployment counted if the data stayed inside national borders, and suppliers competed on their ability to promise it. Saudi Arabia has answered that question faster than almost anywhere, which is exactly why it has stopped carrying commercial weight. Sami Alfaraj, MEA Head of Technology at Submer, watched the differentiator disappear as the capacity arrived.

“That box is now ticked across the market, which is exactly why it no longer differentiates,” Alfaraj said.

What has replaced it is a harder demand, and one most enterprise AI estates in the region cannot yet meet. Buyers and regulators want to see how a system behaves once it holds Saudi data, who can change it, what it is permitted to do on its own, and whether any of that can be evidenced months after the fact.

Zane Ulhaq, Head of Region at Endava, has watched residency rules get bypassed for reasons that had nothing to do with intent. Organisations went around them because in-country capacity at the standard a regulated bank would accept did not exist, and no amount of policy could conjure a data centre.

“There wasn’t a genuine alternative,” Ulhaq said. “Now there’s no excuse. You’ve got hyperscalers like Google already in the Kingdom for some while, working on architectural patterns that exist in some of the most highly regulated industries like financial services. You’ve got AWS joining at the end of the year.”

The build-out behind that shift is substantial. Saudi Arabia now hosts 9 cloud regions, 4 of them still under construction by global providers. HUMAIN, the Public Investment Fund vehicle created to build sovereign compute, runs campuses in Riyadh and Dammam and has acquired sites for a multi-gigawatt expansion over the coming decade.

In early 2026, the Kingdom inaugurated Hexagon, a 480MW facility the government describes as the world’s largest state data centre, alongside the Shaheen III supercomputer and a national data lake integrating more than 430 government systems. Narayanan credits the pace to a decision taken centrally rather than left to individual sectors to work out for themselves.

“When direction comes from that level, an entire economy moves at once,” he said.

Muhammed Shabreen of CNTXT has spent 17 years in the Gulf and describes a change in the region’s role rather than its size. The old pattern, in which the Gulf waited for a technology to mature elsewhere and then imported it, has weakened considerably.

“Before it was more like we are more of an adopter. Once the technology gets mature, things are imported and adopted in this part of the world,” Shabreen said. “Now things have largely changed. There is a lot of enablement happening from here.”

Executives in the Kingdom also use the word sovereignty to cover far more ground than they did three years ago. It once described where a database lived. It now stretches across the silicon, the models running on it and the applications sitting above them.

“Now they are not just talking about data, they are talking about the compute, the entire compute, the apps, the models,” Shabreen said. “It is more like owning the entire ecosystem within the region.”

Compliance and sovereignty have come apart, and the gap decides who gets to sell

Vendor marketing has used the two words interchangeably for years. Practitioners working in the Kingdom now separate them with some precision, because confusing them has become expensive.

“When you are saying you are compliant, you are compliant with certain regulations, but still you may not be sovereign,” Shabreen said. “You have to be completely within the country, hosting the country, serving the country. That makes it sovereign.”

Alfaraj draws the same line in operational language. An organisation can certify compliance and put the certificate in a drawer. Sovereignty has to be exercised continuously, which costs more and is much harder to fake in a tender document.

“Residency is compliance; sovereignty is capability: the ability to operate, evidence and sustain AI on your own terms,” he said.

Suppliers now meet the question during sales qualification rather than in a compliance annexe at contract stage. Security teams in the Kingdom treat it as a threshold, and failing it removes a vendor from consideration before anyone looks at the technology.

“Sovereignty is no longer a regulation story. It is a market access story,” Shabreen said. “The technology infrastructure entities have to have sovereignty as one of their offerings or their core offering, or else their access to the market will be very limited.”

His version of the entry requirement is unusually direct: applications deployed in the Kingdom, local presence, data held locally and, increasingly, compute drawn from the local ecosystem. Anything short of that closes off the regulated sectors where most of the spending sits.

“You want to come to Saudi, and you want to work with a bank, you have to be sovereign in Saudi,” Shabreen said. “That is the bottom line.”

Waleed Al Basha, Regional Leader for Saudi Arabia at BMC Helix, sees the same movement from the customer side. Eighteen months ago his conversations centred on whether workloads could be hosted inside the Kingdom at all. Today they cover the entire AI lifecycle.

“Sovereignty is about control and accountability,” Al Basha said.

Customers now bring that expectation into the first meeting as an architectural requirement, and it shapes the shortlist before any product demonstration takes place.

“For customers, that means moving from a Saudi-hosted mindset to a Saudi-controlled and Saudi-governed mindset, where sovereignty is embedded across the full technology stack,” he said.

Much of the world is still debating AI principles in the abstract. Saudi Arabia has been converting them into deployment frameworks with document numbers attached.

The Saudi Data and Artificial Intelligence Authority published the National AI Risk Management Framework in April 2026 and launched it publicly in July. It gives public and private entities one methodology for identifying, assessing, treating and monitoring AI risk, built on 4 phases, 7 core principles and 7 risk categories, with risk scored on a matrix weighing likelihood against impact. SDAIA argues that AI needs its own methodology because these risks surface unexpectedly, change over time and can be difficult to explain or reproduce.

“Many jurisdictions are still debating AI principles. The Kingdom has been translating them into scalable deployment frameworks,” Narayanan said.

The scoring method is the unglamorous part of that work, and the part he rates most highly. A shared matrix means a risk register written by one organisation can be read by another, and by a regulator, without translation.

“Two organisations describing a risk are finally describing the same thing,” he said.

The framework sits alongside SDAIA’s AI Adoption Framework and AI Ethics Principles, the Personal Data Protection Law and the National Cybersecurity Authority’s controls. In March 2026 the Cabinet designated the year the Year of Artificial Intelligence, by which point the compute was already in the ground.

“Declaring 2026 the Year of Artificial Intelligence was not a slogan,” Narayanan said. “It came with an architecture behind it.”

The national risk framework remains advisory, which Alfaraj reads as a window rather than a reprieve. Organisations that build to it now will avoid retrofitting later, when the same expectations return with enforcement attached.

“The smart move is to operationalise it before it hardens into mandatory requirements,” he said.

Ulhaq’s reading of the regulatory posture explains how the Kingdom has moved quickly without freezing its own market. America tends to regulate after the activity. Europe tends to regulate ahead of it. Saudi Arabia has left deliberate room for both to happen at once.

“Regulation has to do two things: protect, but be loose enough to allow people to innovate,” Ulhaq said.

Provable behaviour is the new deliverable, and most AI estates cannot supply it

Every executive interviewed for this piece returns to the same requirement. An organisation has to be able to show what its AI did and why, on demand, long after the deployment. Sid Bhatia, Regional Vice President and General Manager for Middle East, Turkey and Africa at Dataiku, reduces the whole problem to one sentence.

“You cannot govern what cannot be seen,” Bhatia said.

Visibility is harder than it sounds, because AI rarely arrives through a single door. It appears inside products already deployed, inside SaaS features switched on by a business unit, and inside departmental experiments nobody registered centrally. Bhatia’s answer is automated asset cataloguing and a continuously maintained registry across model prompts and dataset connections. Over the past year, he says, customers have started treating this as a business question rather than a compliance one.

“This whole sovereignty topic is moving from a mere compliance checkbox to something to do with ROI,” he said.

His second requirement is lineage, built around the question a regulator will eventually ask about a single output. Answering it retrospectively is close to impossible without traceability designed into the pipeline from the start.

“Tomorrow, a tough question is asked by a regulator: how did you arrive at this particular output? What was the input? What was the transformation that took place? What model did you expose this to?” Bhatia said. “It is only possible if you have end-to-end traceability.”

His third test is the one most likely to unsettle a supplier, because it measures how easily a customer could walk away. If a provider changes a model, alters a contract or withdraws a service, the customer should be able to switch without touching its underlying infrastructure. He expects future regulation to discourage dependence on any single cloud provider or model supplier.

“The true test of sovereignty is the aspect of reversibility and the aspect of independence,” he said.

None of this removes the person from the process. Bhatia argues that approval steps carrying legal, risk and IT sign-off have to sit inside the workflow itself, particularly before anything is exposed externally.

“Everything cannot be automated,” he said. “At the end of the day, the human in the loop is very important.”

Ulhaq breaks the same requirement into lenses an enterprise can work through in sequence: data sovereignty extending to prompts, vector stores, logs, backups and support environments; model sovereignty covering versions, updates, fine-tuning and provider dependency; operational sovereignty covering access and administration; behavioural questions including hallucination and language performance; and finally proof.

“You’re demonstrating evidence through repeatable approaches, logs, controls, governance that this is doing what it should be doing,” Ulhaq said.

He is equally firm that a governance inventory has to be willing to reject candidates. Paying inference costs to answer questions a calculator could settle is a discipline failure as much as a budget one.

“Just because I have a screwdriver doesn’t mean everything is automatically a screw. If I have a nail I should probably use a hammer,” he said.

Al Basha sets the same expectation in lifecycle terms, and it is the assumption most likely to catch out organisations that treated their first deployment as a finished project.

“AI systems need to be monitored after deployment, not approved once and left to operate,” he said.

Arabic performance has become a compliance question

Models trained overwhelmingly on Western material carry a particular view of the world, and Ulhaq compares the effect to raising a child on a single account of history.

“If I train my child on one view of history and it only picks on certain key events, it will only be aware of those circumstances,” Ulhaq said. “If I now train models which are more culturally appropriate to the region that it’s in, it then becomes more relevant both linguistically and culturally.”

Evaluation practice has followed the argument. Narayanan says models in Saudi projects are now judged on Arabic-language performance and on Saudi context, terminology and regulatory expectation rather than on an international benchmark score, which reorders the shortlist as often as it confirms it. Ulhaq is candid that Arabic testing capability remains behind English, which leaves enterprises planning for both and budgeting for the difference.

Agentic AI makes identity the control that matters most

Enterprises in the Kingdom are moving from AI that recommends an action to AI that carries it out, and that changes what has to be governed. Sadeen Al Tamimi, Data and AI Architect at NTT DATA Saudi Arabia, says agents interacting directly with enterprise applications create requirements around identity, permissions, auditability and continuous oversight that hosting decisions never touched.

“It is no longer enough to say that an AI workload is hosted locally,” Al Tamimi said. “The question is moving from where is my data, to what is my AI doing with my data, and can I prove it.”

She expects architecture to fragment by sensitivity rather than by preference, with highly regulated workloads on private or sovereign environments, others on approved public cloud, and one governance layer running across them.

“Sovereign AI will not be delivered through one deployment model alone,” she said.

Manual governance breaks first at scale. Moving from a handful of pilots to hundreds of models and agents makes observability a requirement, and third-party AI becomes the parallel exposure: an organisation can govern its own systems well and remain exposed through capability embedded in an external platform. Vendor assessment therefore becomes a question of data processing, retention, sub-processors, model updates and exit terms.

“The next stage of sovereign AI in Saudi Arabia will not be defined by who has the most local compute capacity alone,” Al Tamimi said. “It will be defined by which organisations can combine local control with innovation at scale.”

Narayanan reaches the same conclusion from the delivery side. Once a system executes multi-step tasks, identity and access governance becomes the central control, and the practical work is deciding now how an autonomous process is authenticated, authorised and audited.

Alfaraj adds the layer beneath all of it. Rack densities are moving past 100kW, which turns power and thermal management into a sovereignty concern in its own right, while export-control shifts and hardware concentration have pushed customers to ask where critical infrastructure originates and how resilient that chain is.

“You cannot evidence what your infrastructure cannot see, so the controls have to be built in from day one,” he said.

Clear rules are becoming the Kingdom’s most exportable asset

Integrators, platform vendors and infrastructure specialists working in Saudi Arabia keep returning to the same point: explicit expectations have made the market easier to build in. Organisations here work from published frameworks, classifications and risk methodologies rather than guessing at what a regulator might eventually want.

“Clear rules are a gift to a serious delivery partner,” Narayanan said. “They tell you exactly what good looks like, and they reward the organisations that build properly from the first day.”

Guidelines across the GCC are hardening into regulation, and Shabreen expects that trajectory to continue through 2027, with the region settling into a governance posture comparable to the way the EU and the US manage their own infrastructure. Al Basha’s warning is against leaving any of it to the end of a project, where it becomes an obstacle instead of a design input.

“Compliance cannot be something organisations address immediately before deployment,” he said.

The requirement has also created a job. Narayanan points to the AI assurance engineer, the person who instruments a system so its behaviour can be evidenced, monitored and explained, and argues that capability of this kind belongs inside an organisation rather than rented indefinitely.

“Three years ago that role barely existed,” he said. “Today it is close to a condition of deploying into any regulated environment in the Kingdom.” For a young Saudi engineer choosing what to learn this year, that is the skill the market is short of.

Leave a Reply

Don't Miss

Aramco Ventures co-leads a $20 million round to put an AI clone on every desk

Aramco Ventures has co-led a $20 million seed round in Twin1 AI

LEAP 2026 scheduled in Riyadh from 31 Aug to 3 Sep

The organisers of LEAP have confirmed that LEAP 2026 will take place

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy