Biometric Update reported on August 26, 2026 that the Saudi Data and Artificial Intelligence Authority (SDAIA) is promoting its Deepfakes Guidelines: Mitigating Risks While Fostering Innovation. The guidelines call for explicit consent before biometric or identity data is used, and for digital watermarks and source verification, to counter AI-generated fraud, impersonation and misinformation. A note on dating: Arab News reported the issuance in May 2025, and the document carries a reference of SDAIA-P119 (May 2025). The August report is therefore renewed promotion of existing guidance, not a new instrument.
The strongest case for the guidelines
The case for acting is real. Voice and face cloning can defeat security checks that rely on biometrics. Biometric Update notes that Saudi Arabia's Absher platform and the UAE Pass serve millions of users, so a spoofing weakness at that scale is a genuine fraud risk. Victims of impersonation cannot easily disprove a convincing clip once it circulates. Provenance tools like watermarking and consent records address that gap directly, and they do so without deciding what anyone may say.
What the guidelines actually do
As reported by Arab News, the document defines deepfakes as hyper-realistic synthetic media built with deep learning. It names legitimate uses across six sectors: marketing, entertainment, retail, education, healthcare and culture. It separates malicious uses from benign ones and treats the technology as neither inherently good nor bad. The obligations fall on developers and creators: protect personal data, obtain explicit consent, embed watermarks and enable source verification. Neither Biometric Update nor Arab News describes penalties attached to the guidelines themselves, and Arab News characterises the document as regulatory guidance rather than binding law.
That design is the right instinct. Provenance and consent target the mechanism of harm, which is deceptive impersonation. They do not require a regulator to rule on whether a given piece of content is true.
Where the soft law meets hard law
Guidelines never operate in isolation. Saudi Arabia's Anti-Cyber Crime Law, as published by WIPO Lex, sets a penalty in Article 6 of up to five years' imprisonment and a fine of up to three million riyals, or either, for distributing material that violates public order, religious values, morals or privacy through information networks. That wording is broad. A deepfake used for fraud probably falls inside it, but so could satire, political commentary or a genuine recording that someone claims is fake.
This is the gap that matters for a publication committed to free expression. A consent-and-watermark regime is proportionate when the consequence of failing it is a compliance remedy, such as takedown of a non-consensual likeness. It is much less so when the operative sanction is a criminal statute whose trigger is as elastic as "public order." Consent to use a person's biometric data is a well-defined test. Whether a post disturbs public order is not, and whoever decides carries considerable discretion.
There is a second question the guidelines leave open: what a watermark proves. A watermark can show that content was machine-generated. It cannot show that the content is false or harmful. If enforcement treats a missing or stripped mark as evidence of bad intent, honest creators who use tools that do not embed marks are exposed, while determined fraudsters simply remove them. Provenance standards work best as a voluntary signal that helps audiences decide, not as a trigger for liability.
What a proportionate approach looks like
Three adjustments would keep the benefits and limit the risks.
- Keep the guidelines separate from criminal sanctions. Fraud and impersonation are already offences. Deepfake-specific liability should be tied to demonstrable deception and harm, not to the general public-order clause.
- Publish enforcement data. Neither report describes how many cases have been brought or on what grounds. Without that, businesses and researchers cannot judge whether the rules are proportionate.
- Protect clearly labelled satire and commentary. The guidelines already recognise legitimate creative and cultural uses. Prosecutors and regulators should apply the law in a way that makes that recognition explicit.
Leading with guidance rather than a ban is more innovation-friendly than approaches that impose blanket takedown duties on platforms. Consent, provenance and developer accountability are the sound core. The risk is that they get read through a criminal speech statute that offers little predictability.
The takeaway for the wider debate
The transferable lesson is that soft-law deepfake rules are only as speech-protective as the harder law beside them. Jurisdictions borrowing the consent-and-watermark model should also borrow its restraint: narrow definitions of harm, remedies scaled to the injury, and transparency about enforcement. Without those, a sensible technical standard can become a broad tool for policing what people are allowed to say online.