SDAIA's fourth Global AI Summit (GAIN) was scheduled for 15–17 September 2026 at the King Abdulaziz International Convention Center in Riyadh, according to Mubasher's report of SDAIA's announcement. SDAIA said the event would feature "presentations, agreements, and major initiatives". I could not find a verified account of what was actually announced or signed, so this piece does not claim any outcome. It asks a narrower question that the summit keeps raising: how does the Kingdom govern AI while trying to lead it?
The strategy came first, the law did not
The summit is tied to the strategy that SDAIA launched at the first Global AI Summit on 21 October 2020. Argaam's coverage of the launch lists the National Strategy for Data and AI (NSDAI) targets for 2030. They include a place among the top 15 countries in AI, SAR 75 billion in data and AI investment, and more than 300 data and AI startups. Those are ambitious and measurable goals, and the strategy is about building capacity rather than constraining it.
The legal architecture is much thinner than the industrial one. CMS's AI regulation scanner for Saudi Arabia says the Kingdom has no dedicated AI law and that no formal legislative process for one has been announced. Instead there is a stack of non-binding instruments: the National AI Ethics Principles, Generative AI guidelines for government and for the public, Deepfakes Guidelines and an AI Adoption Framework. CMS says these bind only where they connect to an enforceable law such as the Personal Data Protection Law (PDPL).
The strongest case for a binding AI statute
The case for legislating deserves a fair hearing. Soft law gives affected people no remedy: a citizen wrongly denied a service by an automated system cannot sue over a principle. Investors and enterprise buyers also want legal certainty, and guidelines can change without notice. A statute with defined duties for high-risk systems would give both groups something to rely on. That is the logic behind the EU's AI Act.
Why the present approach is defensible
The Saudi position nonetheless has real advantages for a country at an early stage of AI adoption. Risk-based AI statutes require regulators to define categories of harm before the market has shown where harm occurs. Writing those categories into law early tends to lock in guesses. Guidance can be revised in months, and that matters while generative AI practice is still shifting.
The gap is also smaller than it looks, because AI systems run on personal data and Saudi Arabia has an enforceable data law. The PDPL took effect on 14 September 2023, and organisations had until 14 September 2024 to comply, per DLA Piper's Saudi data protection guide. DLA Piper reports that SDAIA is the regulator and that the penalties are real. A warning or a fine of up to SAR 5 million applies to most breaches, repeat offenders can face double that, and intentional disclosure of sensitive data can bring up to two years in prison and/or a fine of up to SAR 3 million. Affected people can also claim compensation. SDAIA's own National Data Governance Platform offers controller registration, breach notification, complaint filing and privacy impact assessment requests, so the compliance machinery exists in practice.
That design puts the legal weight on the input to AI (personal data) rather than on the technology itself. It is proportionate, because it targets a concrete and well-understood harm, and it avoids the compliance overhead of regulating model development as such.
Where the real risk sits
The weak point is institutional rather than legislative. SDAIA is at once the strategy's architect, the promoter of the summit, the author of the ethics guidance and the PDPL regulator. DLA Piper notes that sector bodies such as the Saudi Central Bank and the Communications, Space and Technology Commission (CST) keep data protection jurisdiction within their own sectors. That makes a clear division of roles between a promoter and an enforcer important for credibility, especially for foreign firms deciding where to put workloads.
The draft Global AI Hub Law shows how this could play out. CST issued it for consultation on 14 April 2025, with comments due by 14 May 2025, according to Clyde & Co. Despite its name, it does not regulate AI systems. It creates "data embassies": foreign-governed data centres in the Kingdom, in Private, Extended and Virtual forms. CMS's analysis notes that the draft leaves the designation of the competent authority to a Council of Ministers resolution and that it is unclear whether that authority would be CST, SDAIA or another body. I could not confirm whether the law has been finalised since then.
This is the right kind of rulemaking for a hub strategy: it regulates infrastructure and jurisdiction, which investors need to know, and says little about model behaviour. The open question is who will supervise it.
What to watch
Three things would show whether the light-touch model holds up:
- Published enforcement. A regulator whose PDPL fines and decisions are public gives developers a working picture of the rules. DLA Piper says SDAIA is actively enforcing, but I found no verified reporting of specific penalties.
- Clear roles. A written split between promotion, standard-setting and enforcement would reduce the conflict-of-interest concern.
- Binding duties only where harm is shown. If Riyadh later legislates, it should do so for demonstrated problems, such as automated decisions with legal effects, rather than copying a template.
The absence of a Saudi AI Act is not, by itself, a failure. The test is whether guidance, the PDPL and clear institutions can give people recourse while the industry grows. The summit's agenda is a reminder that the Kingdom is betting it can.