Saudi Arabia's National Cybersecurity Authority (NCA) closed public consultation on its AI Cybersecurity Guidelines on Tuesday, 22 Safar 1448 AH (5 August 2026), moving the framework into finalization. The document — structured around four cybersecurity domains and explicitly targeting generative and agentic AI — applies to every entity in the Kingdom that currently uses or plans to deploy AI systems.
The consultation opened on 5 July 2026 via the Istitlaa public platform. With feedback now closed, publication of the final guidelines is the next step, and Saudi organizations that have not yet mapped their AI stack against the framework are on a shortening runway.
Key Highlights
- Consultation closed 5 August 2026 after a 30-day feedback window on the Istitlaa platform.
- Four cybersecurity domains: governance, defense, resilience, and third-party cybersecurity.
- Scope explicitly covers generative AI and agentic AI — the two categories driving current enterprise AI deployments.
- Applies to every entity in the Kingdom that uses or plans to adopt AI systems, private and public sector alike.
- Purpose: ensure cybersecurity requirements for AI and mitigate risks associated with AI technologies and systems.
Details
The guidelines were drafted by the NCA based on international best practices and the Authority's mandate to set and monitor cybersecurity policies, governance mechanisms, frameworks, standards, controls and guidelines across Saudi Arabia. They sit alongside existing NCA baselines such as the Essential Cybersecurity Controls (ECC) and the Cloud Cybersecurity Controls (CCC), but for the first time carve out a dedicated AI-specific layer.
The four domains map cleanly to how a modern AI system actually fails:
- Cybersecurity governance — who owns the AI system, what data may enter it, how decisions are logged and reviewed.
- Cybersecurity defense — protecting AI models, training data and inference endpoints from prompt injection, model exfiltration, and adversarial inputs.
- Cybersecurity resilience — how the organization detects, contains and recovers from an AI-related incident.
- Third-party cybersecurity — the risk carried by every foundation model, API, plugin, agent framework and vector database in the pipeline.
Naming agentic AI explicitly is the significant part. Most existing regulatory frameworks around the world still treat AI as a bounded prediction system; the NCA framework acknowledges that autonomous agents that call tools, transact, and act on behalf of the organization are already in production in the Kingdom and need their own controls.
Impact
For Saudi enterprises that treated AI adoption as a procurement decision, the guidelines reframe it as a governance obligation. Every model in use — whether a public API, a locally hosted open model, or a vendor-supplied agent — needs an owner, a threat model, a logging path, a third-party assurance record, and a recovery plan.
The third-party domain is likely to hit the hardest. Very few AI deployments in the Kingdom are single-vendor: a typical stack chains a foundation model provider, an orchestration framework, one or more vector stores, a set of tool-calling APIs, and downstream integrations into ERP, HR and finance systems. Under the guidelines each of those links is a controlled surface, not a black box.
Vendors selling agentic AI products into Saudi Arabia — and the systems integrators who wire those products into government and financial workflows — will need to be able to answer NCA-shaped questions on demand: model provenance, data residency, prompt-injection defenses, audit trails, incident-response ownership. Purchase orders will start to reference this framework.
Background
The Kingdom designated 2026 as the Year of Artificial Intelligence, and enterprise adoption has moved decisively from pilot to production over the first half of the year — research over the same period found that only one percent of Saudi banks report no AI use or plans. SDAIA continues to lead the national data and AI mandate under Vision 2030, and HUMAIN is scaling sovereign compute capacity. The NCA guidelines close the loop on that stack by asking a different question: not can we deploy? but can we defend what we deployed?
The Authority has followed a consistent pattern since publishing the Essential Cybersecurity Controls in 2018: draft, consult, publish, and then translate the guidelines into procurement and audit expectations that ripple through every entity that does business with the Saudi public sector or operates critical national infrastructure.
What's Next
- Publication of the final AI Cybersecurity Guidelines is expected in the coming weeks following the close of consultation.
- Mapping exercises — organizations should inventory every AI system in use (including shadow-IT deployments of ChatGPT, Claude, Gemini and locally hosted models) and score each against the four domains.
- Third-party questionnaires to AI vendors and agent-framework providers will need to be updated to reflect the guidelines' controls.
- LEAP 2026 (Riyadh, 31 August–3 September) is likely to be the first major venue where enterprises, regulators and vendors align on the framework's operational implications.
For teams building or integrating AI agents inside Saudi enterprises, the guidelines are not a barrier — they are a stable target to build against. Governance-ready deployments become the ones procurement can approve without escalation.
Related reading on Noqta:
- Enterprise AI governance and the Claude compliance API — how governance controls are being implemented at the model layer.
- Agentic AI testing and autonomous QA — resilience and defense practices for agent systems.
If you are deploying AI agents into a Saudi organization and want a governance-first review of the stack, talk to Noqta — we work with teams to align existing AI systems against NCA-shaped controls before they become procurement blockers.
Source: National Cybersecurity Authority — AI Cybersecurity Guidelines Consultation