All Masterclasses
    Past Masterclass April 9, 2026

    AI and Automated Decision-Making Governance under Saudi PDPL

    Artificial intelligence and automated decision-making are becoming embedded across business operations in Saudi Arabia, and under the PDPL they are treated not as a separate regulatory category but as an extension of personal data processing, often with amplified risk. This masterclass examines how PDPL's technology-agnostic obligations apply to AI systems, how to distinguish decision-support analytics from automated decision-making that replaces human judgment, and when explicit consent and meaningful human oversight are required. It addresses the high-risk use cases that trigger a DPIA under Article 25 of the Implementing Regulations, the risks introduced by third-party and default-enabled AI features, and why accountability remains with the organization.

    Presenters

    Aben Pagar
    Aben Pagar
    Head of Digital Risk Consulting, KONEXO/ Eversheds Sutherland
    Skanda Reddy
    Skanda Reddy
    Senior Associate, KONEXO/Eversheds Sutherland

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • AI governance under the Saudi Personal Data Protection Law (PDPL) is about managing personal data risk in AI systems, not regulating AI in isolation.
    • The PDPL is technology-agnostic: the same obligations apply whether processing is manual, automated, or AI-driven, with AI treated as an extension of personal data processing that often amplifies risk through scale, opacity, bias, and limited explainability.
    • Most organizations adopt AI governance reactively, but the defensible approach is to embed it from the outset and across the lifecycle, because AI risk is dynamic. Models evolve, so a one-time Data Protection Impact Assessment (DPIA) is insufficient and risk must be continuously reassessed.
    • High-risk AI use cases concentrate in a recognized set of applications that typically trigger DPIA, transparency, bias-testing, and meaningful human oversight obligations.
    • There is a critical distinction between analytics, which supports human decisions, and automated decision-making, which replaces them, and the two carry materially different obligations.
    • Automated decisions with significant impact require explicit consent or another robust legal basis where no meaningful human intervention exists.
    • Human-in-the-loop is a key safeguard, but only where the human review is real and actionable: sufficient information, authority, and time to examine inputs and to override or correct outputs, not procedural rubber-stamping.
    • Transparency is essential: individuals must understand how their data is used and how decisions affecting them are made.
    • Organizations should first ask whether AI is necessary for a use case rather than defaulting to automation.
    • Third-party AI tools introduce additional risks around data sharing, residency, and unclear liability, and default-enabled AI features in SaaS tools can expose sensitive data if not properly governed.
    • Data residency and cross-border transfer rules are critical for AI systems hosted outside Saudi Arabia.
    • AI-specific DPIAs should assess not only privacy risk but also bias, fairness, and ethical implications, and be revisited as models change.
    • An AI inventory, analogous to the Record of Processing Activities (RoPA), is foundational for visibility into use cases, data, ownership, and risk levels, and documentation more broadly is central to defensibility.
    • Accountability remains with the organization even when AI is automated or outsourced to third parties, so translating AI risk into business impact, reputational, financial, and regulatory, is what secures executive alignment and enables responsible adoption.

    Frequently Asked Questions