Legal Requirements for Employing Artificial Intelligence Technologies in Saudi Financial Institutions in Light of the Personal Data Protection Law, the Civil Transactions Law of 2023, and International Conventions

This article has been Reviewed by the following groups

Read the full article

Abstract

The Saudi sector has witnessed a significant digital transformation within the framework of Vision 2030, through the expansion of innovation in artificial intelligence and financial technology (FinTech). Despite the considerable benefits of these developments, they also present challenges, including the need for transparency and accountability This necessitates that the Saudi Central Bank establish clear regulations to ensure the protection of customer rights. This research aims to analyze the legal requirements for using artificial intelligence technologies in Saudi financial institutions and assess the extent to which the current legal framework aligns with relevant international standards and instruments, The study adopted a descriptive, analytical, and comparative approach, through analyzing relevant Saudi legislation and comparing it with international principles. The findings revealed the existence of a charter regulating the ethics of using artificial intelligence in financial institutions, under the supervision of the General Authority for Data and Artificial Intelligence and the Saudi Central Bank, but the regulation still needs development. The study recommends the need to establish a unified legal framework to regulate the use of artificial intelligence in the financial sector that is consistent with international standards and promotes trust, transparency and data protection.

Article activity feed

  1. This Zenodo record is a permanently preserved version of a PREreview. You can view the complete PREreview at https://prereview.org/reviews/22949874.

    PREreview: Legal Requirements for Employing Artificial Intelligence Technologies in Saudi Financial Institutions in Light of the Personal Data Protection Law, the Civil Transactions Law of 2023, and International Conventions

    Reviewer: Julian Rodriguez, Jr., FRSA, MRES, M.ISRM

    Preprint DOI: 10.20944/preprints202511.1271.v1

    Author: Zubaida Abdalhadi Ahmed

    Review Summary

    In this comparative legal analysis, Zubaida Abdalhadi Ahmed evaluates the regulatory infrastructure governing artificial intelligence adoption within Saudi Arabian financial institutions under Vision 2030. The study examines how the Personal Data Protection Law (PDPL), the Civil Transactions Law of 2023, and Saudi Central Bank (SAMA) guidelines intersect with international FinTech standards. While acknowledging the Saudi Data and Artificial Intelligence Authority (SDAIA) AI ethics charter, the author highlights critical regulatory gaps—specifically regarding transparency, civil liability, and data privacy enforcement—advocating for a unified, binding legal framework to stabilize AI-mediated banking operations.

    Strengths & Key Contributions

    1. Pivotal Jurisdictional Focus: The paper fills a major gap in Middle Eastern FinTech literature by systematically analyzing the operational reality of Saudi Arabia's updated civil and data protection codes against automated financial tools.

    2. Clear Institutional Mapping: The author effectively bridges high-level economic policy (Vision 2030) with central bank oversight (SAMA) and algorithmic accountability standards.

    3. Pragmatic Reform Recommendations: The call for a unified legal framework rather than fragmented administrative circulars provides a clear path forward for regional banking regulators.

    Constructive Considerations & Theoretical Context

    To further enrich the analysis, the author might consider incorporating a few structural compliance dimensions:

    • Accounting for Regulatory "Shadows" and Latency: While the paper calls for unified regulations, adding layers of automated compliance tools often creates Systemic Intent Shadows (Rodriguez, 2026)—where financial institutions face severe administrative latency as algorithmic decision tools struggle to reconcile SAMA mandates with international cross-border data transfer rules.

    • The Risk of Behavioral Collapse in Compliance Teams: Strict liability standards under the 2023 Civil Transactions Law can trigger what I term the Zero-Defect Paradox (Rodriguez, 2025/2026). When banking compliance officers fear legal penalties for minor data handling errors, they often institute hyper-cautious artificial verification procedures that paralyze automated credit scoring and transaction clearance.

    • Cross-Border Enforcement Friction: As Saudi financial institutions integrate with global markets, they inevitably confront The Glass Border (Rodriguez, 2025/2026)—where digital trade visibility exists on paper, but conflicting jurisdictional privacy regimes create hidden operational drag for foreign investors.

    Recommended References for Integration

    • Rodriguez, J., Jr. (2026). The Systemic Intent Shadow: Mapping Organizational Collapse and Regulatory Friction in the Era of AI-Driven Governance. Zenodo.

    • Rodriguez, J., Jr. (2025). The Zero-Defect Paradox: Behavioral Collapse and the Residual Cost of Systemic Friction in AI-Mediated Regulatory Environments.

    • Rodriguez, J., Jr. (2025). The Glass Border: Behavioral Risk and Forensic Realities in U.S.-Mexico Cross-Border Compliance. Zenodo.

    Final Recommendation

    Accept for open-access indexing. A timely, necessary analysis of FinTech legal governance in the Gulf region.

    Competing interests

    The author declares that they have no competing interests.

    Use of Artificial Intelligence (AI)

    The author declares that they used generative AI to come up with new ideas for their review.