Skip to content

SDAIA AI ethics and generative AI guidelines

SDAIA’s Generative Artificial Intelligence Guidelines for Government, 2025 edition, hold government data users to the Data Classification Policy when they use generative AI tools. Section 3.5 says no data classified restricted or higher enters such a tool, use is limited to data classified public, and nothing that is not properly classified is entered. A prompt to a hosted model is exactly that entry, so this pack puts one rule at the call: only a key classified public reaches a provider that is not the entity’s own. SDAIA’s AI Ethics Principles, May 2025, apply to every AI stakeholder in the Kingdom, and five of their items a gateway can show are mapped to the mechanism and the evidence.

It builds on the NDMO pack and, through it, the Saudi PDPL pack, which are added first. It is a starting point and certifies nothing. The guidelines describe themselves as guidance that supports compliance with the regulations they cite, and the principles are principles; neither is a statute.

The key says what level the caller handles, as classification in its metadata, in the Data Classification Policy’s vocabulary, top_secret | secret | restricted | public, or with confidential for the third level as the interim regulations spell it. The provider says whether it is the entity’s own deployment, as metadata: {cloud: private}.

Rule Refuses Clause
sa-sdaia-ai-only-public-data-reaches-a-genai-tool any request under a key not classified public, bound for a provider not declared the entity’s own section 3.5, items 1, 3 and 5

A key with no classification is refused rather than read as public, because item 5 says not to enter anything that is not properly classified. The key’s level is what its owner declared, and one thing in the request can contradict it: personal data is confidential under the Data Classification Policy whatever the key says. The NDMO pack’s sa-ndmo-public-carries-no-personal-data rule reads the request and refuses that, so this pack attaches sa-sdaia-ai:genai-gov-3.5 to it and the refusal names both regimes. The rule reads no residency: a tool inside the Kingdom is still a tool, and the guideline draws its line at the classification, not the border. A model the entity runs itself is not a tool the data leaves for, and cloud: private says so.

Five items of the principles are mapped rather than enforced: planned de-identification, which the redact action is; classification of all processed data with de-identification by level, which the key’s classification and the rules that read it are; traceable decisions, which the audit record of every decision is; logged failures and breaches, which the trail shipped to monitoring is; and audit and due diligence mechanisms, which the rule suite and the trail are. The mapping says where to look. Whether the item is met is yours to show.

The classification vocabulary is the NDMO pack’s, which holds keys to the four levels and treats an unclassified key as restricted for its own rules. Under this pack the same key is refused at a generative AI tool, which is the stricter of the two readings and the one the guideline states. The redactions this pack’s first mapping points at are the PDPL pack’s, and they act before the request leaves, so personal data under a key classified confidential is replaced on its way to the entity’s own deployment, and under a key classified public it is refused.

  • Whether the provider is a generative AI tool. Every LLM provider is read as one. A provider the entity runs itself declares cloud: private and is exempt; the guideline’s other remedies, tool-specific policies and risk assessment against the principles’ four tiers, are the entity’s.
  • The other items of section 3.5. Checking the tool’s privacy policy and sharing terms, and the risk assessment of the tool, are due diligence.
  • Critical decisions and human review. Section 3 says generative AI is not used in critical decision-making affecting individuals or the Kingdom’s vital interests, and every result is human-reviewed. A gateway sees requests, not what is done with the answers.
  • The Guidelines for the Public. The companion document for developers, deployers and the public is non-binding guidance with the same principles and is not cited.
  • The AI Adoption Framework. SDAIA’s November 2025 framework for public sector adoption is about governance and maturity, and holds nothing a gateway enforces.
  • The rest of the principles. Fairness, humanity, social and environmental benefit, reliability and safety are the AI system owner’s programme, and the checklist in the principles’ Annexure C is where they are assessed.
  • The texts are the 2025 editions on SDAIA’s site. The principles replace the September 2023 version 1.0 and carry document number SDAIA-P114E; the guidelines say they may be updated as the technology changes. Check both are the editions your entity is held to.
  • Adding this pack refuses every request under a key not classified public at every provider without cloud: private. Classify the keys and mark the entity’s own deployments first.
  • The control identifiers name the document, principle, phase and item. Each title is a paraphrase; check it against the text before a reviewer reads the audit trail through it.

Every identifier below is declared in pack.yaml and named by a rule, an attachment or a mapping. A rule that cites one carries it onto every audit record it decides.

Control What it requires Text
sa-sdaia-ai:genai-gov-3.5 Government data users enter no data classified restricted or higher into generative AI tools, limit their use to data classified public, and enter nothing that is not properly classified (Generative AI Guidelines for Government, section 3.5, items 1, 3 and 5). citation
sa-sdaia-ai:p2-plan-6 Security mechanisms for de-identification are planned for the sensitive or personal data in the system (Principle 2, Privacy and Security, Plan and Design, item 6). citation
sa-sdaia-ai:p2-data-4 All processed data is classified for its level of protection, and de-identification mechanisms are employed based on the classification and data protection law (Principle 2, Privacy and Security, Prepare Input Data, item 4). citation
sa-sdaia-ai:p6-plan-1 Decisions are traceable, and the level of transparency for each stakeholder is defined by data privacy, sensitivity and authorization (Principle 6, Transparency and Explainability, Plan and Design, item 1). citation
sa-sdaia-ai:p6-monitor-2 System failures, data breaches and breakdowns are logged and stakeholders informed (Principle 6, Transparency and Explainability, Deploy and Monitor, item 2). citation
sa-sdaia-ai:p7-plan-2 Audit and due diligence mechanisms, impact assessments and redress are put in place (Principle 7, Accountability and Responsibility, Plan and Design, item 2). citation
Rule Kind Action At Controls
sa-sdaia-ai-only-public-data-reaches-a-genai-tool access deny llm sa-sdaia-ai:genai-gov-3.5

Identifiers it puts on another pack’s rules

Section titled “Identifiers it puts on another pack’s rules”

Two regimes that want the same thing done share one rule, so one decision carries both regimes’ identifiers onto the audit record.

Rule Controls added
sa-ndmo-public-carries-no-personal-data sa-sdaia-ai:genai-gov-3.5

A pointer and never an attestation: the mechanism that addresses the control, the evidence it leaves, and the page that describes it.

Control Addressed by Evidence See
sa-sdaia-ai:p2-plan-6 the redact action on guardrail rules, which replaces personal data with a placeholder or a format-preserving ciphertext before the request leaves; the PDPL pack’s three redactions are the shipped instance guardrail.decision records naming a redact rule and the entity types it replaced start-from-a-control-pack
sa-sdaia-ai:p2-data-4 the key’s classification metadata, which every rule reads as key.metadata.classification, and the rules that decide by it, this pack’s and the NDMO pack’s pistra query over the keys lists each key’s metadata; request.auth records name the key and the rule that decided mint-rotate-and-revoke-a-key
sa-sdaia-ai:p6-plan-1 the audit record of every decision, which names the key, the provider, the rule that decided and the controls it carried, so each decision is traceable to the clause it served request.auth and guardrail.decision records carrying sa-sdaia-ai: identifiers audit-trail
sa-sdaia-ai:p6-monitor-2 the signed, hash-chained audit trail exported to the entity’s monitoring, on which a refusal, a redaction and a provider failure are each a record the SIEM export; pistra audit verify over it ship-the-audit-trail-to-your-siem
sa-sdaia-ai:p7-plan-2 the rule suite, which holds every rule to the cases that prove it before the document ships, and the audit trail, which is the record an assessor reads the pack’s suite run against the deployment document; pistra audit verify over the export test-your-rules-before-they-ship

Related: Control packs for what shipped and what a pack is not.