Data & AI Governance  ·  MENA  ·  Kingdom of Saudi Arabia

Powerful AI is easy. Defensible AI is the hard part.

Diagnostic, readiness mapping, and independent audits powered by our proprietary engine — against PDPL, SDAIA, NCA, and the EU AI Act. Oxford PhD precision. Paris Bar legal rigor.

Regulatory coveragePDPLSDAIAISO/IEC 42001NCAEU AI Act

Our audits map to the frameworks now shaping AI governance in the Kingdom: the PDPL (in force and enforced), SDAIA's AI Adoption Framework (2025), the emerging Responsible AI Policy with its four-tier risk classification, and NCA cybersecurity controls — alongside the EU AI Act for organizations with European exposure. Where your sector adds its own layer — SAMA frameworks for financial services, health-data and SFDA rules for healthcare, policyholder-data requirements for insurers — we map those controls in the same pass as PDPL and SDAIA.

Who We Help

You don't need a new AI law to need this.

AI-specific regulation in the Kingdom is still taking shape — but the obligations that reach your AI systems are already here. They arrive through five doors:

01

Personal data — already binding

The PDPL is in force and actively enforced, with fines up to SAR 5M. Any AI system that processes personal data falls within it. If you can't evidence lawful processing, you're exposed today — no new law required.

02

Your sector's own rules

Finance, healthcare, insurance: if a sector regulator supervises you, its controls reach your AI — SAMA frameworks, health-data and SFDA rules, policyholder-data requirements. We reconcile them with PDPL and SDAIA in the same pass, so you get one position, not one checklist per regulator.

03

Deals, tenders & due diligence

SDAIA accreditation and demonstrable AI governance are increasingly required to sell to Saudi government entities — and enterprise buyers and investors ask the same questions in procurement and due diligence. Being able to answer wins tenders, deals and raises — well before it's legally mandatory.

04

Selling into Europe

Exporting AI-driven products or services to the EU triggers immediate duties. The GDPR already applies today to automated decision-making, transparency, and human review. The EU AI Act adds dated obligations on top — starting with Article 50 transparency requirements now, followed by high-risk deadlines under Regulation (EU) 2026/1744. We map what you must document before an EU buyer, notified body, or regulator asks.

05

Your head office's rules

If you're the Saudi arm of an international group, your parent is likely bound by the EU AI Act. Group governance flows down to you. We help you meet it locally, mapped to PDPL and SDAIA in one pass.

Not sure which door applies to you?

Whether you need a quick diagnostic, a tender-ready exposure assessment, or a complete regulatory audit, a short conversation is usually enough to define your path.

The Deliverable

Every assessment distills deep technical and legal review into one defensible scorecard.

Behind each score: evaluation of your documentation and architecture, multi-framework legal mapping, and a prioritized remediation plan your team can act on — whether you build models or deploy third-party AI.

Reproducible

Same inputs · same score

Dual review

Technical testing + legal analysis

Sample scorecard

Client A

78

Overall

PDPL82
SDAIA74
Fairness71
Transparency80
Robustness76
P1 · 3P2 · 5P3 · 4

Each score is backed by documented findings, evidence references and remediation steps.

Illustrative — sample client. Not an actual assessment result.

Service Offerings

Assurance calibrated to your risk.

From rapid exposure mapping to continuous governance — a structured path to defensible, regulator-ready AI.

Our Technology

A proprietary five-component audit engine.

Most organizations treat data protection and AI governance as separate projects — and pay for it twice.

Our engine maps every framework in a single pass — parsing, scoring, reconciling — so our team can focus on what machines can't do: probing models hands-on, interpreting the law, and defending the result.

01

Automated Document Analysis

Your documentation — model cards, policies, data descriptions — is analyzed automatically, with structured questionnaires to close any gaps.

02

Multi-Framework Scoring

Simultaneous scoring against SDAIA, PDPL, NCA and the EU AI Act — one audit, every framework.

03

Unified Findings

Where PDPL, SDAIA, NCA and the EU AI Act overlap or contradict, you receive one consistent set of obligations — not four conflicting checklists.

04

Reproducible Reporting

Auditable remediation reports — the same inputs always produce the same result.

05

Bilingual Output — AR / EN

Native Arabic and English remediation guidance for KSA enterprise teams.

Where the engine stops

The engine produces the scores. Our auditors probe what it can't — testing models and datasets hands-on — and qualified counsel signs off every conclusion. Defensibility takes both.

Trajectory

From audits to continuous governance.

An audit tells you where you stand today. Regulation doesn't stand still — and neither do your models. Every Oxon engagement is built on the same engine, which is why assurance compounds instead of expiring.

01Available now

Point-in-time audit

A defensible scorecard of your AI systems against PDPL, SDAIA, NCA and the EU AI Act — the baseline every serious conversation starts from.

02Rolling out

Assisted monitoring

Re-runs of the engine on your updated documentation and models, tracking remediation and flagging regulatory drift between audits.

03Roadmap

Continuous governance platform

Always-on compliance posture: your frameworks, obligations and evidence maintained as living infrastructure — audit-ready on any given day.

The engine is the product. Diagnostics and audits are how it enters your organization.

The Founding Team

A moat built on rare expertise.

Elite research and hard legal qualification under one roof — a combination unmatched across the MENA region.

Dr. Marion S.

Dr. Marion S.

Founder & CEO

PhD in Computer Science — University of Oxford

Paris Bar Legal Background

Combining an Oxford PhD in Computer Science with a background as a Paris Bar advocate, Marion bridges automated model testing with strict legal analysis to deliver defensible compliance.

Dr. Moayad H.

Dr. Moayad H.

Co-Founder & Strategic Advisor

PhD in Computer Science — Taibah University

Associate Professor — Taibah University, Madinah

Deeply rooted in Saudi Arabia's research and enterprise ecosystem, Moayad leads Oxon's operations and market presence across the Kingdom, bridging high-level technical depth with direct insight into KSA's regulatory and institutional landscape.

Contact

Start with a diagnostic or schedule an audit.

Tell us about your AI deployment. We will respond with a tailored scope and next steps within two business days.

RegionAl Madinah · Kingdom of Saudi Arabia
Response timeWithin 2 business days

Write to us directly

No forms, no data collection. Send us a brief note and we'll come back with a tailored audit scope.

Every engagement starts with a scoping conversation: what is in scope, what is not, and what the deliverable will be — agreed in writing before any work begins.

contact@oxonx.sa

Opens your email client with the subject pre-filled — replace [Company name] with yours.

Oxon X

Oxon X

Oxford research × Paris Bar law · Data & AI governance · MENA

Al Madinah Al Munawwarah, Kingdom of Saudi Arabia·CR 7054827998·MISA 24926260750

© 2026 Oxon X. All rights reserved.

Privacy PolicyTerms of UsePDPL · SDAIA · ISO/IEC 42001 · NCA · EU AI Act