SDAIA AI ethics and generative AI guidelines
SDAIA’s Generative Artificial Intelligence Guidelines for Government, 2025 edition, hold government data users to the Data Classification Policy when they use generative AI tools. Section 3.5 says no data classified restricted or higher enters such a tool, use is limited to data classified public, and nothing that is not properly classified is entered. A prompt to a hosted model is exactly that entry, so this pack puts one rule at the call: only a key classified public reaches a provider that is not the entity’s own. SDAIA’s AI Ethics Principles, May 2025, apply to every AI stakeholder in the Kingdom, and five of their items a gateway can show are mapped to the mechanism and the evidence.
It builds on the NDMO pack and, through it, the Saudi PDPL pack, which are added first. It is a starting point and certifies nothing. The guidelines describe themselves as guidance that supports compliance with the regulations they cite, and the principles are principles; neither is a statute.
What it does
Section titled “What it does”The key says what level the caller handles, as classification in its
metadata, in the Data Classification Policy’s vocabulary,
top_secret | secret | restricted | public, or with confidential for
the third level as the interim regulations spell it. The provider says
whether it is the entity’s own deployment, as metadata: {cloud: private}.
| Rule | Refuses | Clause |
|---|---|---|
sa-sdaia-ai-only-public-data-reaches-a-genai-tool |
any request under a key not classified public, bound for a provider not declared the entity’s own | section 3.5, items 1, 3 and 5 |
A key with no classification is refused rather than read as public,
because item 5 says not to enter anything that is not properly
classified. The key’s level is what its owner declared, and one thing
in the request can contradict it: personal data is confidential under
the Data Classification Policy whatever the key says. The NDMO pack’s
sa-ndmo-public-carries-no-personal-data rule reads the request and
refuses that, so this pack attaches sa-sdaia-ai:genai-gov-3.5 to it
and the refusal names both regimes. The rule reads no residency: a
tool inside the Kingdom is still a tool, and the guideline draws its
line at the classification, not the border. A model the entity runs
itself is not a tool the data leaves for, and cloud: private says so.
Five items of the principles are mapped rather than enforced: planned de-identification, which the redact action is; classification of all processed data with de-identification by level, which the key’s classification and the rules that read it are; traceable decisions, which the audit record of every decision is; logged failures and breaches, which the trail shipped to monitoring is; and audit and due diligence mechanisms, which the rule suite and the trail are. The mapping says where to look. Whether the item is met is yours to show.
Alongside the other Saudi packs
Section titled “Alongside the other Saudi packs”The classification vocabulary is the NDMO pack’s, which holds keys to the four levels and treats an unclassified key as restricted for its own rules. Under this pack the same key is refused at a generative AI tool, which is the stricter of the two readings and the one the guideline states. The redactions this pack’s first mapping points at are the PDPL pack’s, and they act before the request leaves, so personal data under a key classified confidential is replaced on its way to the entity’s own deployment, and under a key classified public it is refused.
What it does not cover
Section titled “What it does not cover”- Whether the provider is a generative AI tool. Every LLM provider
is read as one. A provider the entity runs itself declares
cloud: privateand is exempt; the guideline’s other remedies, tool-specific policies and risk assessment against the principles’ four tiers, are the entity’s. - The other items of section 3.5. Checking the tool’s privacy policy and sharing terms, and the risk assessment of the tool, are due diligence.
- Critical decisions and human review. Section 3 says generative AI is not used in critical decision-making affecting individuals or the Kingdom’s vital interests, and every result is human-reviewed. A gateway sees requests, not what is done with the answers.
- The Guidelines for the Public. The companion document for developers, deployers and the public is non-binding guidance with the same principles and is not cited.
- The AI Adoption Framework. SDAIA’s November 2025 framework for public sector adoption is about governance and maturity, and holds nothing a gateway enforces.
- The rest of the principles. Fairness, humanity, social and environmental benefit, reliability and safety are the AI system owner’s programme, and the checklist in the principles’ Annexure C is where they are assessed.
Before you rely on it
Section titled “Before you rely on it”- The texts are the 2025 editions on SDAIA’s site. The principles replace the September 2023 version 1.0 and carry document number SDAIA-P114E; the guidelines say they may be updated as the technology changes. Check both are the editions your entity is held to.
- Adding this pack refuses every request under a key not classified
public at every provider without
cloud: private. Classify the keys and mark the entity’s own deployments first. - The control identifiers name the document, principle, phase and item. Each title is a paraphrase; check it against the text before a reviewer reads the audit trail through it.
Controls this pack cites
Section titled “Controls this pack cites”Every identifier below is declared in pack.yaml and named by a rule, an attachment or a mapping. A rule that cites one carries it onto every audit record it decides.
| Control | What it requires | Text |
|---|---|---|
sa-sdaia-ai:genai-gov-3.5 |
Government data users enter no data classified restricted or higher into generative AI tools, limit their use to data classified public, and enter nothing that is not properly classified (Generative AI Guidelines for Government, section 3.5, items 1, 3 and 5). | citation |
sa-sdaia-ai:p2-plan-6 |
Security mechanisms for de-identification are planned for the sensitive or personal data in the system (Principle 2, Privacy and Security, Plan and Design, item 6). | citation |
sa-sdaia-ai:p2-data-4 |
All processed data is classified for its level of protection, and de-identification mechanisms are employed based on the classification and data protection law (Principle 2, Privacy and Security, Prepare Input Data, item 4). | citation |
sa-sdaia-ai:p6-plan-1 |
Decisions are traceable, and the level of transparency for each stakeholder is defined by data privacy, sensitivity and authorization (Principle 6, Transparency and Explainability, Plan and Design, item 1). | citation |
sa-sdaia-ai:p6-monitor-2 |
System failures, data breaches and breakdowns are logged and stakeholders informed (Principle 6, Transparency and Explainability, Deploy and Monitor, item 2). | citation |
sa-sdaia-ai:p7-plan-2 |
Audit and due diligence mechanisms, impact assessments and redress are put in place (Principle 7, Accountability and Responsibility, Plan and Design, item 2). | citation |
Rules it adds
Section titled “Rules it adds”| Rule | Kind | Action | At | Controls |
|---|---|---|---|---|
sa-sdaia-ai-only-public-data-reaches-a-genai-tool |
access | deny |
llm | sa-sdaia-ai:genai-gov-3.5 |
Identifiers it puts on another pack’s rules
Section titled “Identifiers it puts on another pack’s rules”Two regimes that want the same thing done share one rule, so one decision carries both regimes’ identifiers onto the audit record.
| Rule | Controls added |
|---|---|
sa-ndmo-public-carries-no-personal-data |
sa-sdaia-ai:genai-gov-3.5 |
Controls no rule can enforce
Section titled “Controls no rule can enforce”A pointer and never an attestation: the mechanism that addresses the control, the evidence it leaves, and the page that describes it.
| Control | Addressed by | Evidence | See |
|---|---|---|---|
sa-sdaia-ai:p2-plan-6 |
the redact action on guardrail rules, which replaces personal data with a placeholder or a format-preserving ciphertext before the request leaves; the PDPL pack’s three redactions are the shipped instance | guardrail.decision records naming a redact rule and the entity types it replaced |
start-from-a-control-pack |
sa-sdaia-ai:p2-data-4 |
the key’s classification metadata, which every rule reads as key.metadata.classification, and the rules that decide by it, this pack’s and the NDMO pack’s |
pistra query over the keys lists each key’s metadata; request.auth records name the key and the rule that decided |
mint-rotate-and-revoke-a-key |
sa-sdaia-ai:p6-plan-1 |
the audit record of every decision, which names the key, the provider, the rule that decided and the controls it carried, so each decision is traceable to the clause it served | request.auth and guardrail.decision records carrying sa-sdaia-ai: identifiers |
audit-trail |
sa-sdaia-ai:p6-monitor-2 |
the signed, hash-chained audit trail exported to the entity’s monitoring, on which a refusal, a redaction and a provider failure are each a record | the SIEM export; pistra audit verify over it |
ship-the-audit-trail-to-your-siem |
sa-sdaia-ai:p7-plan-2 |
the rule suite, which holds every rule to the cases that prove it before the document ships, and the audit trail, which is the record an assessor reads | the pack’s suite run against the deployment document; pistra audit verify over the export |
test-your-rules-before-they-ship |
Related: Control packs for what shipped and what a pack is not.