Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    AI & Automated Decision-Making Governance

    under Saudi PDPL

    Masterclass #69 April 2026Aben Pagar and Skanda Reddy

    A recap of the Pyxos masterclass with Aben Pagar and Skanda Reddy.

    Under the PDPL, artificial intelligence is not a separate regulatory category. It is personal data processing with the volume turned up, and the obligations that already apply simply apply harder. That was the orienting idea in this masterclass on AI and automated decision-making, led by Aben Pagar and Skanda Reddy of Konexo (Eversheds Sutherland). The law is technology-agnostic, they stressed; what changes with AI is the scale, the opacity, and the questions of fairness and explainability that come with it.

    The distinction the session kept returning to was between analytics and automated decision-making. Analytics supports a human decision; automated decision-making replaces it. That line is not academic, because automated decisions with significant impact on a person carry obligations, including a consent requirement where no meaningful human intervention exists, that ordinary decision-support analytics does not trigger. And meaningful was the operative word: a human in the loop only counts if that person genuinely can examine the inputs, override the output, and correct an error, rather than rubber-stamping an algorithm under time pressure.

    Transparency ran alongside that as a hard requirement, not a courtesy. People have to be able to understand how their data is used and how decisions affecting them are reached, which is difficult precisely where models are most opaque, and that difficulty is the organization's problem to solve, not the data subject's to absorb.

    Pagar and Reddy were direct that AI risk is dynamic in a way that breaks the one-and-done assessment habit. Models drift and retrain, so a DPIA done once and filed is insufficient; the assessment has to be revisited as the system evolves, and an AI-specific assessment should weigh bias, fairness, and ethical impact alongside privacy risk. They also flagged the quieter exposures: third-party AI tools that introduce unclear data-sharing and residency questions, and default-enabled AI features in ordinary SaaS products that can surface sensitive data if nobody governs them.

    One discipline they urged is upstream of all the controls: ask whether AI is actually necessary for the use case at all, rather than reaching for automation by default. Where it is necessary, the work is to govern it across a lifecycle, from defining the use case, through the impact assessment and transparency, to the controls and ongoing monitoring, with an AI inventory analogous to the records of processing giving the organization visibility into what it is running, on what data, owned by whom, at what risk level.

    A theme that matters for any organization adopting these tools is that accountability does not move. Even where the AI is automated or outsourced, the organization answers for it. Pagar made the point that securing executive attention depends on translating AI risk into business terms, reputational, financial, and regulatory, rather than presenting it as a technical abstraction. The high-risk use cases and the full lifecycle the session set out are best taken from the recording and the takeaways.

    Reddy closed on a note worth carrying: AI is not a fad, and the value it is creating across industries is real and durable. The work is not to resist it but to govern it deliberately, which begins, he argued, with getting boards trained on the language and the risks so the organization can decide what to do about them. The judgment about acceptable risk stays human; the goal of governance is to make that judgment informed.

    πŸŽ₯

    πŸ“˜ Read the key takeaways and FAQs β†’

    About the presenters

    • Aben Pagar

      Aben Pagar

      Aben Pagar is Head of Digital Risk Consulting at Konexo (Eversheds Sutherland), advising on data protection programs across Saudi Arabia and the region.

    • Skanda Reddy

      Skanda Reddy

      Skanda Reddy is a Senior Associate at Konexo (Eversheds Sutherland), focused on PDPL and data protection implementation across Saudi Arabia and the wider region.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.