Data & AI Governance · MENA · Kingdom of Saudi Arabia
Powerful AI is easy. Defensible AI is the hard part.
Diagnostic, readiness mapping, and independent audits powered by our proprietary engine — against PDPL, SDAIA, NCA, and the EU AI Act. Oxford PhD precision. Paris Bar legal rigor.
Our audits map to the frameworks now shaping AI governance in the Kingdom: the PDPL (in force and enforced), SDAIA's AI Adoption Framework (2025), the emerging Responsible AI Policy with its four-tier risk classification, and NCA cybersecurity controls — alongside the EU AI Act for organizations with European exposure. Where your sector adds its own layer — SAMA frameworks for financial services, health-data and SFDA rules for healthcare, policyholder-data requirements for insurers — we map those controls in the same pass as PDPL and SDAIA.
Who We Help
You don't need a new AI law to need this.
AI-specific regulation in the Kingdom is still taking shape — but the obligations that reach your AI systems are already here. They arrive through five doors:
Personal data — already binding
The PDPL is in force and actively enforced, with fines up to SAR 5M. Any AI system that processes personal data falls within it. If you can't evidence lawful processing, you're exposed today — no new law required.
Your sector's own rules
Finance, healthcare, insurance: if a sector regulator supervises you, its controls reach your AI — SAMA frameworks, health-data and SFDA rules, policyholder-data requirements. We reconcile them with PDPL and SDAIA in the same pass, so you get one position, not one checklist per regulator.
Deals, tenders & due diligence
SDAIA accreditation and demonstrable AI governance are increasingly required to sell to Saudi government entities — and enterprise buyers and investors ask the same questions in procurement and due diligence. Being able to answer wins tenders, deals and raises — well before it's legally mandatory.
Selling into Europe
Exporting AI-driven products or services to the EU triggers immediate duties. The GDPR already applies today to automated decision-making, transparency, and human review. The EU AI Act adds dated obligations on top — starting with Article 50 transparency requirements now, followed by high-risk deadlines under Regulation (EU) 2026/1744. We map what you must document before an EU buyer, notified body, or regulator asks.
Your head office's rules
If you're the Saudi arm of an international group, your parent is likely bound by the EU AI Act. Group governance flows down to you. We help you meet it locally, mapped to PDPL and SDAIA in one pass.
Not sure which door applies to you?
Whether you need a quick diagnostic, a tender-ready exposure assessment, or a complete regulatory audit, a short conversation is usually enough to define your path.
The Deliverable
Every assessment distills deep technical and legal review into one defensible scorecard.
Behind each score: evaluation of your documentation and architecture, multi-framework legal mapping, and a prioritized remediation plan your team can act on — whether you build models or deploy third-party AI.
Reproducible
Same inputs · same score
Dual review
Technical testing + legal analysis
Sample scorecard
Client A
78
Overall
Each score is backed by documented findings, evidence references and remediation steps.
Illustrative — sample client. Not an actual assessment result.
Service Offerings
Assurance calibrated to your risk.
From rapid exposure mapping to continuous governance — a structured path to defensible, regulator-ready AI.
Exposure Mapping
3–5 working days
Which obligations actually reach you, and in which role. We settle the regime, the sector overlay and your qualification — provider or deployer, controller or processor — before anyone starts assessing anything. The answer changes everything downstream, and most organisations have never had it written down.
Design & Readiness Diagnostic
1–2 weeks
A control-by-control assessment of your AI system against the obligations that apply to it, returned with what has to change. Works on a system already running and on one still being designed — where the system is not built yet, the output is written as specifications your engineering team can act on, not as a list of gaps.
Full AI & Data Compliance Audit
4–8 weeks
For organisations that have to prove it to someone: a regulator, a board, or an enterprise buyer. Deep technical analysis of models and datasets paired with legal review by qualified counsel, producing an assessment that survives being challenged — not whether a control exists, but whether the record would hold.
AI Governance & Retainer
Ongoing
Frameworks evolve, models get retrained, new deployments ship every quarter. A standing governance function: the organisational framework, the audit-trail infrastructure, and the continuous monitoring that keep your position current after the initial assessment.
Our Technology
A proprietary five-component audit engine.
Most organizations treat data protection and AI governance as separate projects — and pay for it twice.
Our engine maps every framework in a single pass — parsing, scoring, reconciling — so our team can focus on what machines can't do: probing models hands-on, interpreting the law, and defending the result.
Automated Document Analysis
Your documentation — model cards, policies, data descriptions — is analyzed automatically, with structured questionnaires to close any gaps.
Multi-Framework Scoring
Simultaneous scoring against SDAIA, PDPL, NCA and the EU AI Act — one audit, every framework.
Unified Findings
Where PDPL, SDAIA, NCA and the EU AI Act overlap or contradict, you receive one consistent set of obligations — not four conflicting checklists.
Reproducible Reporting
Auditable remediation reports — the same inputs always produce the same result.
Bilingual Output — AR / EN
Native Arabic and English remediation guidance for KSA enterprise teams.
Where the engine stops
The engine produces the scores. Our auditors probe what it can't — testing models and datasets hands-on — and qualified counsel signs off every conclusion. Defensibility takes both.
Trajectory
From audits to continuous governance.
An audit tells you where you stand today. Regulation doesn't stand still — and neither do your models. Every Oxon engagement is built on the same engine, which is why assurance compounds instead of expiring.
Point-in-time audit
A defensible scorecard of your AI systems against PDPL, SDAIA, NCA and the EU AI Act — the baseline every serious conversation starts from.
Assisted monitoring
Re-runs of the engine on your updated documentation and models, tracking remediation and flagging regulatory drift between audits.
Continuous governance platform
Always-on compliance posture: your frameworks, obligations and evidence maintained as living infrastructure — audit-ready on any given day.
The engine is the product. Diagnostics and audits are how it enters your organization.
Insights & Regulatory Briefings
Where regulation meets engineering.
View all insightsConcise briefings on the frameworks shaping AI in the Kingdom — and technical notes from inside our auditing engine.
Cross-border data transfer under PDPL: an operational checklist
Your data leaves the Kingdom every day — remote support, group HR, cloud backups. Since SDAIA's enforcement went live, "we'll formalize it later" is no longer a defensible position. Seven questions every Saudi controller must be able to answer, with the evidence behind each.
Read briefingHigh-risk classification: what MENA deployers must document
The EU just moved the high-risk deadline to December 2027. That's not a reprieve — it's a deadline for the hard part: knowing which of your systems are high-risk at all. What MENA deployers must document, and why the inventory work can't wait.
Read briefingReproducibility is becoming an audit requirement — is your AI assessment defensible?
If two auditors reach two different conclusions on the same system, neither is evidence. Why regulators, courts and procurement teams will increasingly demand assessments that can be re-run and verified — and what that means for how audits must be built.
Read briefingThe Founding Team
A moat built on rare expertise.
Elite research and hard legal qualification under one roof — a combination unmatched across the MENA region.

Dr. Marion S.
Founder & CEO
PhD in Computer Science — University of Oxford
Paris Bar Legal Background
Combining an Oxford PhD in Computer Science with a background as a Paris Bar advocate, Marion bridges automated model testing with strict legal analysis to deliver defensible compliance.

Dr. Moayad H.
Co-Founder & Strategic Advisor
PhD in Computer Science — Taibah University
Associate Professor — Taibah University, Madinah
Deeply rooted in Saudi Arabia's research and enterprise ecosystem, Moayad leads Oxon's operations and market presence across the Kingdom, bridging high-level technical depth with direct insight into KSA's regulatory and institutional landscape.
Contact
Start with a diagnostic or schedule an audit.
Tell us about your AI deployment. We will respond with a tailored scope and next steps within two business days.
Write to us directly
No forms, no data collection. Send us a brief note and we'll come back with a tailored audit scope.
Every engagement starts with a scoping conversation: what is in scope, what is not, and what the deliverable will be — agreed in writing before any work begins.
contact@oxonx.saOpens your email client with the subject pre-filled — replace [Company name] with yours.