Insights & Regulatory Briefings
Where regulation meets engineering.
Every briefing and technical note we publish — on SDAIA, PDPL, NCA, the EU AI Act, and the engineering behind defensible AI audits.
Cross-border data transfer under PDPL: an operational checklist
Your data leaves the Kingdom every day — remote support, group HR, cloud backups. Since SDAIA's enforcement went live, "we'll formalize it later" is no longer a defensible position. Seven questions every Saudi controller must be able to answer, with the evidence behind each.
Read briefingHigh-risk classification: what MENA deployers must document
The EU just moved the high-risk deadline to December 2027. That's not a reprieve — it's a deadline for the hard part: knowing which of your systems are high-risk at all. What MENA deployers must document, and why the inventory work can't wait.
Read briefingReproducibility is becoming an audit requirement — is your AI assessment defensible?
If two auditors reach two different conclusions on the same system, neither is evidence. Why regulators, courts and procurement teams will increasingly demand assessments that can be re-run and verified — and what that means for how audits must be built.
Read briefing