Why do governance, accountability and oversight need to evolve as AI adoption accelerates across the Kingdom? Mohamed El-Kady, Director, Risk Advisory at BDO Saudi Arabia, shares insights on the growing importance of AI governance advisory in Saudi Arabia and explores how organisations can manage the risks associated with accelerating AI adoption.
AI is already embedded in daily operations in Saudi Arabia
Teams are using AI to draft emails, summarise reports, build presentations, analyse information and accelerate workflows. AI functionality is increasingly embedded into vendor platforms and enterprise systems, while external advisors and service providers are also leveraging AI to improve efficiency and delivery.
In practice, the adoption decision has already been made in many organisations, formally or informally. The more important question is whether leadership teams understand how AI is being used, where the risks sit and whether appropriate governance is already in place.
The governance gap most organisations do not yet see
In many executive discussions, the assumption remains: “We have not formally adopted AI yet.”
However, one layer below leadership level, the picture is often very different. Across many organisations, employees are already using generative AI tools to draft reports, analyse information, summarise documents and accelerate day-to-day tasks, frequently without formal oversight or policy guidance.
Commercial, client or employee data may already be finding its way into public AI platforms in the interest of speed and convenience. Vendors may be using AI behind the scenes to accelerate delivery without explicitly disclosing it. Individually, each use case may appear manageable or low risk. Collectively, they create significant operational, regulatory and reputational exposure.
This disconnect is the real governance gap. It is not primarily a technology problem. It is a leadership and oversight challenge.
Why unregulated AI adoption matters more in Saudi Arabia
Vision 2030 AI adoption is accelerating across Saudi Arabia, driving rapid digital transformation and innovation. At the same time, the regulatory landscape is evolving rapidly.
SDAIA Responsible AI Policy has issued AI ethics principles and generative AI governance policy, while the Personal Data Protection Law (PDPL) is now a live compliance requirement. In parallel, NCA cybersecurity controls and expectations continue to shape how organisations manage technology, cloud, data and emerging digital risks.
What does the SDAIA AI Adoption Framework require?
For boards, audit committees and executive leadership teams, this creates a challenging dynamic:
- AI adoption is accelerating
- Regulatory expectations are increasing
- Governance maturity is still evolving
- AI assurance capabilities remain uneven across sectors
Many international organisations have had years to gradually develop AI governance and assurance capabilities, whereas many Saudi entities are accelerating adoption and governance efforts simultaneously.
The five AI risks boards should be discussing
1. Output integrity
AI systems can generate content that appears credible, authoritative and professionally structured, including where the underlying information is inaccurate.
Hallucinated facts, fabricated references and subtle analytical errors have already appeared in external outputs globally. In many cases, these issues are only identified after information has already been distributed externally.
There is also a wider ecosystem risk. Once inaccurate AI-generated content enters the public domain, it can be reused, cited or recycled by other AI systems as though it were verified. Over time, this may weaken confidence not only in individual outputs, but in the reliability of AI-supported information more broadly.
2. Data protection and privacy
How does PDPL apply to AI systems in Saudi Arabia?
Uploading customer information, financial records or HR data into public AI tools may create direct PDPL exposure. This risk becomes more serious where organisations lack clear rules on what data may be entered into AI tools, where data is processed and whether outputs are retained or reused.
The reason this occurs is straightforward: these tools are fast, convenient and often difficult for organisations to monitor effectively. In many cases, organisations have limited visibility over how frequently employees are already interacting with external AI tools.
3. Cybersecurity and model risk
AI is now reshaping both sides of the cyber threat landscape.
Deepfake calls, AI-generated phishing campaigns and prompt-based attacks are becoming increasingly sophisticated. At the same time, AI platforms themselves introduce new vulnerabilities, including model poisoning, prompt injection and unintended data leakage through prompts and outputs.
As AI becomes embedded in enterprise tools and workflows, the cybersecurity perimeter expands beyond traditional systems to include prompts, models, integrations, outputs and user behaviour.
4. Accountability and disclosure
Should AI-generated content be disclosed to regulators?
If AI has materially influenced a deliverable, board paper, investor communication or regulatory submission, should that involvement be disclosed?
This is particularly relevant for listed entities and regulated sectors where governance, disclosure integrity and management accountability are already under heightened scrutiny.
Where AI materially shapes content, silence itself becomes a governance decision.
5. Third-party and vendor AI use
Many organisations are exposed to AI through vendors, advisors, technology platforms and outsourced service providers before leadership has made any formal internal AI adoption decision. This creates a control gap where AI may influence outputs, data handling, service delivery or decision support without the organisation having clear visibility over how it is being used.
Vendor contracts, service-level agreements and procurement processes should therefore address AI use explicitly, including disclosure, data handling, quality review, liability, audit rights and restrictions on using client data to train external models.
Does my organisation need an AI governance policy in Saudi Arabia?
AI governance should not be treated as a technology control exercise alone. It requires integration across governance, cybersecurity, legal, compliance, internal audit, data management, executive decision-making frameworks and AI risk management in Saudi Arabia. It also requires clear ownership, defined escalation mechanisms and alignment between business, technology, risk and compliance functions.
Importantly, effective governance is not designed to slow AI adoption. In practice, stronger governance enables broader and more confident adoption because organisations understand where AI is being used, how it is being controlled and where accountability sits.
The starting point is not a lengthy policy document. It is a clear view of where AI is already being used, which use cases carry material risk, who owns those risks and what level of oversight is required.
Practical starting points include:
- Putting AI formally on the board, audit committee and executive agenda, with a clear reporting cadence
- Establishing a comprehensive AI inventory covering systems, use cases, data flows, owners and third-party dependencies
- Classifying AI use cases by risk level, including customer, employee or public impact, regulatory exposure, data sensitivity and reliance on outputs
- Requiring human review for outputs that influence regulated decisions, external communications, customers, employees or financial reporting
- Defining internal disclosure protocols for AI-generated or AI-supported content
- Expanding internal audit and assurance plans to include AI governance, access controls, data protection and vendor oversight
- Embedding transparency, data-use and audit-right requirements into vendor and advisor arrangements
These discussions are already taking place across audit committees, risk forums and executive leadership teams throughout the Kingdom.
The organisations that will derive the greatest value from AI will not necessarily be those that adopted it first. They will be the organisations that understood what they had already adopted, assessed the risks early and embedded proportionate governance before informal use became unmanaged exposure.
In Saudi Arabia, the pace of digital transformation means AI adoption and AI governance can no longer move on separate tracks. Both now need to evolve in parallel.
The question for leadership teams is no longer whether AI is being used within the organisation. The real question is whether the organisation can explain, with confidence, how that use is governed, controlled and accountable.
AI governance for boards has become a practical priority. For boards, audit committees and executive teams, this means identifying AI use cases, understanding the associated risks, assigning clear ownership and building controls that allow AI to be used confidently rather than quietly.

