Saudi Arabia social media disinformation enforcement

Saudi Arabia's Soft-Law Deepfake Guidelines Are Sound on Consent, but Its Criminal Speech Law Sets the Real Rules

SDAIA's voluntary deepfake guidance favors consent and watermarking over bans, yet the Anti-Cyber Crime Law's elastic Article 6 looms over synthetic media.

Saudi Deepfake Rules at a Glance People of Internet Research · Saudi Arabia 5 years Max prison, Article 6 Anti-Cyber Crime Law penalty for c… SAR 3M Max fine, Article 6 Fine up to three million riyals, o… 6 Legitimate-use sectors named Marketing, entertainment, retail, … peopleofinternet.com
Saudi Deepfake Rules at a Glance People of Internet Research · Saudi Arabia 5 years Max prison, Article 6 SAR 3M Max fine, Article 6 6 Legitimate-use sectors named peopleofinternet.com

Key Takeaways

Biometric Update reported on August 26, 2026 that the Saudi Data and Artificial Intelligence Authority (SDAIA) is promoting its Deepfakes Guidelines: Mitigating Risks While Fostering Innovation. The guidelines call for explicit consent before biometric or identity data is used, and for digital watermarks and source verification, to counter AI-generated fraud, impersonation and misinformation. A note on dating: Arab News reported the issuance in May 2025, and the document carries a reference of SDAIA-P119 (May 2025). The August report is therefore renewed promotion of existing guidance, not a new instrument.

The strongest case for the guidelines

The case for acting is real. Voice and face cloning can defeat security checks that rely on biometrics. Biometric Update notes that Saudi Arabia's Absher platform and the UAE Pass serve millions of users, so a spoofing weakness at that scale is a genuine fraud risk. Victims of impersonation cannot easily disprove a convincing clip once it circulates. Provenance tools like watermarking and consent records address that gap directly, and they do so without deciding what anyone may say.

What the guidelines actually do

As reported by Arab News, the document defines deepfakes as hyper-realistic synthetic media built with deep learning. It names legitimate uses across six sectors: marketing, entertainment, retail, education, healthcare and culture. It separates malicious uses from benign ones and treats the technology as neither inherently good nor bad. The obligations fall on developers and creators: protect personal data, obtain explicit consent, embed watermarks and enable source verification. Neither Biometric Update nor Arab News describes penalties attached to the guidelines themselves, and Arab News characterises the document as regulatory guidance rather than binding law.

That design is the right instinct. Provenance and consent target the mechanism of harm, which is deceptive impersonation. They do not require a regulator to rule on whether a given piece of content is true.

Where the soft law meets hard law

Guidelines never operate in isolation. Saudi Arabia's Anti-Cyber Crime Law, as published by WIPO Lex, sets a penalty in Article 6 of up to five years' imprisonment and a fine of up to three million riyals, or either, for distributing material that violates public order, religious values, morals or privacy through information networks. That wording is broad. A deepfake used for fraud probably falls inside it, but so could satire, political commentary or a genuine recording that someone claims is fake.

This is the gap that matters for a publication committed to free expression. A consent-and-watermark regime is proportionate when the consequence of failing it is a compliance remedy, such as takedown of a non-consensual likeness. It is much less so when the operative sanction is a criminal statute whose trigger is as elastic as "public order." Consent to use a person's biometric data is a well-defined test. Whether a post disturbs public order is not, and whoever decides carries considerable discretion.

There is a second question the guidelines leave open: what a watermark proves. A watermark can show that content was machine-generated. It cannot show that the content is false or harmful. If enforcement treats a missing or stripped mark as evidence of bad intent, honest creators who use tools that do not embed marks are exposed, while determined fraudsters simply remove them. Provenance standards work best as a voluntary signal that helps audiences decide, not as a trigger for liability.

What a proportionate approach looks like

Three adjustments would keep the benefits and limit the risks.

Leading with guidance rather than a ban is more innovation-friendly than approaches that impose blanket takedown duties on platforms. Consent, provenance and developer accountability are the sound core. The risk is that they get read through a criminal speech statute that offers little predictability.

The takeaway for the wider debate

The transferable lesson is that soft-law deepfake rules are only as speech-protective as the harder law beside them. Jurisdictions borrowing the consent-and-watermark model should also borrow its restraint: narrow definitions of harm, remedies scaled to the injury, and transparency about enforcement. Without those, a sensible technical standard can become a broad tool for policing what people are allowed to say online.

Sources & Citations

  1. Biometric Update: Saudi Arabia issues deepfake guidelines
  2. Arab News: SDAIA issues deepfakes guidelines
  3. WIPO Lex: Saudi Anti-Cyber Crime Law
  4. SDAIA: Deepfakes Guidelines (PDF)
  5. SPA: SDAIA issues deepfakes guidelines