Saudi Arabia's National Cybersecurity Authority (NCA) closed public consultation on its draft AI Cybersecurity Guidelines on 5 August 2026. The consultation opened on 5 July on the Istitlaa public-consultation platform, according to the NCA's consultation listing. The final text has not been published. The draft is organised around four domains: governance, defense, resilience and third-party cybersecurity. It reaches every entity in the Kingdom that uses or plans to deploy generative or agentic AI, public or private.
The design is mostly sound. The open question is how it will be applied.
The strongest case for the NCA's approach
The case for a dedicated AI security baseline is serious. Generative and agentic systems create failure modes that conventional IT controls were not written for. A summary of the draft lists several: prompt injection, model theft and adversarial manipulation, plus dependence on foundation models, APIs and frameworks the deploying organisation does not control. An autonomous agent that can call tools and move data can turn a single compromised prompt into a real incident. Organisations deploying such agents also tend to underinvest in audit trails and recovery plans, because the productivity gains are visible and the risks are not. A regulator that says "log decisions, assign ownership, plan for containment" is asking for things a careful operator would do anyway.
The approach is also incremental. Saudi Arabia has no dedicated AI statute. As CMS's AI regulation scanner describes it, the Kingdom governs AI through policy instruments from the Saudi Data & AI Authority (SDAIA), which are largely non-binding. They are enforced indirectly through the Personal Data Protection Law and sectoral regulators, the NCA among them. Layering security guidance onto that model, rather than writing a comprehensive AI act on the EU template, fits a pro-innovation posture.
Where the draft could go wrong
The first risk is legal ambiguity. The Digital Policy Alert record classifies the draft, designated AICG-1:2026, as non-binding recommendations. Yet the draft is framed as applying to every entity in the Kingdom. Both can be true. The NCA's existing Essential Cybersecurity Controls (ECC-2:2024) are mandatory for government bodies and for private organisations that own, operate or host Critical National Infrastructure, as Clyde & Co explains. The ECC-2 text is published on the NCA's own file host. Guidance that is nominally voluntary for most firms can still become binding in practice. Regulated entities may be audited against it. Government procurement can require it. Customers may demand it contractually.
That is not necessarily bad. It becomes a problem when a bank, a ministry and a ten-person startup are all measured against one list of expectations. The draft's four domains mirror the structure the NCA already uses for ECC. Clyde & Co reports that ECC-2 trimmed the control count from 114 to 108, which suggests the authority has been willing to streamline rather than only accumulate. The AI guidelines should follow that instinct.
The second risk is the third-party domain. Almost no Saudi organisation trains its own frontier model. Most consume foundation models and APIs from a handful of global providers. A third-party risk requirement that demands deep assurance from those providers will fall on deploying firms, and it will not move providers. The likely result is paperwork: questionnaires nobody can verify and attestation checklists, with little gain in security. A better design would accept recognised international attestations and focus deployer effort on what deployers control, such as access scoping, data minimisation, monitoring and incident response.
The third risk is the pace of change. Agentic AI is the right thing to name, because systems that act autonomously are already in production. But definitions drawn in mid-2026 can age quickly. If the final text hard-codes specific technical measures rather than outcomes, it will lag the threat landscape within a year.
What the final version should do
Three changes would keep the framework's strengths and limit its costs:
- State the legal status plainly. The final text should say who is bound, who is merely encouraged, and what an audit against it means. Ambiguity pushes compliance costs onto the smallest firms, who cannot afford to interpret it.
- Tier obligations by risk. An agent that can move money or touch critical systems warrants stricter controls than a drafting assistant. The NCA already distinguishes Critical National Infrastructure operators in ECC, and it can apply the same logic here.
- Publish consultation outcomes. The 30-day Istitlaa window is a good practice. Releasing a summary of comments received, and how they shaped the final text, would show the consultation worked and help industry plan.
The NCA is also asking the right question in the right place. Security of deployed AI is a narrower and more tractable problem than regulating AI as a whole, and it avoids the speech and innovation costs of broad content or model-licensing rules. The authority has chosen a guidance-led route consistent with SDAIA's approach. Whether that proves proportionate depends on details the final text will settle.
Until it is published, Saudi organisations deploying agents have a clear signal of direction. They should map their AI systems, assign owners, log agent actions and plan for containment now. Those steps are cheap, and they are worth doing whether or not the guidelines end up binding.