Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Understanding Saudi Arabia’s Global AI Hub Law

Author

Syeda Eimaan Gardezi

Associate Data Privacy Analyst at Securiti

Published May 8, 2025

Listen to the content

Introduction

In a major move to position the country as a global leader in digital technology and artificial intelligence, Saudi Arabia’s  Communications, Space and Technology Commission (CST)  has introduced a draft for the Global AI Hub Law, a legal framework for operating various types of data centers, called “Hubs”. Open for public consultation till May 14, 2025, the Global AI Hub Law allows foreign governments and companies to store and process data within Saudi Arabia under their own legal regimes, while maintaining local oversight. Taking  effect 60 days after publication in the official gazette, it aims to:

  • position Saudi Arabia as a global leader in digital technologies, attracting foreign governments and businesses for peaceful technological development;
  • utilize Saudi Arabia’s strategic location to offer tech solutions that bridge the global digital divide;
  • create sovereign data centers to strengthen international partnerships with secure, cross-border data sovereignty; and
  • foster innovation, research, and development by expanding opportunities in Saudi Arabia’s digital economy.

This not only positions Saudi Arabia as a neutral, secure hub for cross-border data hosting and a key player in global AI and digital infrastructure but is expected to boost foreign investment and enhance Saudi Arabia’s digital economy.

This blog breaks down the law’s main features in an easy-to-read format.

Key Definitions to Understand the Global AI Hub Law

Before diving into the law itself, it is essential to understand the following key terms:

Key Term  Description
Competent Authority The official body (or bodies) chosen by Saudi Arabia’s Council of Ministers (CoM) to oversee the AI Hub Law.
Guest Country A foreign country that signs an agreement with Saudi Arabia to set up a private hub or an extended hub.
Private Hub A data center inside Saudi Arabia used only by a guest country to host its own data, apps, and services under its own country’s rules.
Extended Hub A data center inside Saudi Arabia used by an operator to host its own or its subscribers’ data, apps, and services under the rules of a guest country.
Virtual Hub A data center inside Saudi Arabia where a service provider hosts its customers’ data, apps, and services under the rules of a specific foreign country.
Operator A company that makes an agreement with the competent authority to run an extended hub under a deal with a guest country.
Service Provider A company based in Saudi Arabia that is officially approved to offer virtual hub services under this law.
Customer A party that has contracted with a service provider to use a virtual hub.
Customer Content Any software, data, text, audio, video, or images stored, transmitted, or processed by a customer or its end users via a virtual hub.
Bilateral Agreement An international agreement between Saudi Arabia and a foreign state for the purpose of the Global AI Hub Law and subject to international law.

Understanding AI Hubs

In the context of the Global AI Hub Law, a “hub” refers to a data center located in Saudi Arabia that not only hosts data, applications, and services but also operates under the legal framework of a foreign government or entity. It therefore serves as a centralized platform for storing and processing data, while being governed by a bilateral agreement between Saudi Arabia and the relevant country.  Consequently, foreign countries can have their data hosted in Saudi Arabia but governed by their own laws (with Saudi oversight).

The law introduces three types of data hubs, each with unique roles and governance structures:

Private Hub Extended Hub Virtual Hub
Who operates it? Guest Country Operator Service Provider
What is the purpose of hubs? Host the guest country’s own data, applications, and services under its own laws. Host data, applications, and services of the operator or its subscribers under the guest country’s laws. Host customer content under the foreign state’s laws.
Who has the legal jurisdiction? Guest country’s laws apply inside the hub as per the bilateral agreement. Guest country’s laws apply inside the hub as per the bilateral agreement. Laws of the foreign state apply to customer content as per the bilateral agreement.
What is the role of Saudi Arabia?  They must provide protection, connectivity, resources; grants immunities/privileges (as per bilateral agreement).

Entry by authorities allowed in emergencies

They must provide protection, connectivity, resources; grants immunities/privileges (as per bilateral agreement).

Entry by authorities allowed in emergencies

They must support the enforcement of valid orders from the foreign state.

Authorities can act if hosting/processing harms Saudi Arabia or interferes with another state’s internal affairs

What are compliance obligations? Ensure compliance and cooperation with:

  • international law,
  • Global AI Hub Law,
  • international restrictions on data and technology, and
  • local authorities to support digital infrastructure (as per bilateral agreement).
Ensure compliance and cooperation with:

  • international law,
  • Global AI Hub Law,
  • international restrictions on data and technology, and
  • local authorities to support digital infrastructure (as per bilateral agreement).

Operators must also comply with international best practices.

Ensure compliance and cooperation with:

  • Global AI Hub Law,
  • Saudi Arabia’s laws, unless exempted; and
  • competent authority.

The competent authority monitors compliance and ensures adherence to treaties and agreements. It is further tasked with collecting summaries of orders issued about service providers from foreign states and maintaining a register of all hubs, countries, operators, and agreements. Furthermore, bilateral agreements are pivotal in enforcement as they set the specific terms, conditions, and privileges for private, extended, or virtual hubs, ensuring mutual obligations are clearly defined while protecting Saudi Arabia’s national interests.

It’s also important to note that the CoM can end agreements or approvals to protect national security, sovereignty, or diplomatic relations. However, even after termination, some privileges may continue for a set time to ensure a smooth transition, for example, if a virtual hub is cancelled, the law remains in effect for 120 days after cancellation, or longer if specified.

Key Considerations & Challenges

The Global AI Hub Law represents an ambitious and forward-looking attempt to redefine data sovereignty and cross-border data governance. As Saudi Arabia moves toward finalizing and implementing the law, key opportunities and challenges will shape its trajectory. Despite these strategic benefits, the Global AI Hub Law raises complex legal and operational questions that will require careful navigation.

One major challenge lies in reconciling conflicting legal regimes: by allowing foreign jurisdictions to apply within Saudi territory, the law introduces an overlap of legal authorities. This hybrid model could create uncertainty around which law prevails in disputes when multiple legal systems assert incompatible rules regarding data privacy, national security, intellectual property, or content moderation. Hence, creating a risk of legal fragmentation or enforcement deadlock within the hubs.

Moreover, the Global AI Hub law’s reliance on bilateral agreements adds complexity and potential asymmetry. Each agreement could vary in terms, scope, and enforcement provisions, making consistency across hubs difficult to achieve. This raises questions about regulatory fairness and transparency, as well as the operational burden on regulators to oversee diverse agreements while safeguarding national interests.

Conclusion

Despite the complexities, the Global AI Hub Law signals Saudi Arabia’s bold commitment to shaping the future of global data governance. It represents a pioneering approach, creating a hybrid legal framework that combines extraterritorial data jurisdiction with national oversight, redefining traditional models of data localization and control.

Thus, whether you’re a policymaker, tech investor, or legal professional, it opens new opportunities for data collaboration, AI innovation, and international partnerships, setting a precedent that may shape global data governance in the years to come.

How Securiti Can Help

Securiti is the pioneer of the Data + AI Command Center, a centralized platform that enables the safe use of data and GenAI. It provides unified data intelligence, controls and orchestration across hybrid multicloud environments. Large global enterprises rely on Securiti's Data Command Center for data security, privacy, governance, and compliance.

Securiti Gencore AI enables organizations to safely connect to hundreds of data systems while preserving data controls and governance as data flows into modern GenAI systems. It is powered by a unique knowledge graph that maintains granular contextual insights about data and AI systems.

Gencore AI provides robust controls throughout the AI system to align with corporate policies and entitlements, safeguard against malicious attacks and protect sensitive data. This enables organizations to comply with the AI regulations.

Request a demo to learn more.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...
AWS Startup Showcase Cybersecurity Governance With Generative AI View More
AWS Startup Showcase Cybersecurity Governance With Generative AI
Balancing Innovation and Governance with Generative AI Generative AI has the potential to disrupt all aspects of business, with powerful new capabilities. However, with...

Spotlight Talks

Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Latest
View More
Introducing Agent Commander
The promise of AI Agents is staggering— intelligent systems that make decisions, use tools, automate complex workflows act as force multipliers for every knowledge...
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About View More
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About
Boards are tuned in to the AI conversation, but there’s a blind spot many organizations still haven’t named: risk silos. Everyone agrees AI governance...
Largest Fine In CCPA History_ What The Latest CCPA Enforcement Action Teaches Businesses View More
Largest Fine In CCPA History: What The Latest CCPA Enforcement Action Teaches Businesses
Businesses can take some vital lessons from the recent biggest enforcement action in CCPA history. Securiti’s blog covers all the important details to know.
View More
AI & HIPAA: What It Means and How to Automate Compliance
Explore how the Health Insurance Portability and Accountability Act (HIPAA) applies to Artificial Intelligence (AI) in securing Protected Health Information (PHI). Learn how to...
Indiana, Kentucky & Rhode Island Privacy Laws View More
Indiana, Kentucky & Rhode Island Privacy Laws: What Changed & What Businesses Should Do Now
A breakdown of new data privacy laws in Indiana, Kentucky, and Rhode Island—key obligations, consumer rights, enforcement timelines, and what businesses should do now.
Consent-Aware GenAI: Enterprise Blueprint View More
Consent-Aware GenAI: Enterprise Blueprint
Download the whitepaper to learn how to align AI use with consent, prevent purpose creep, and operationalize governance controls for safe, scalable GenAI.
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Strategic Priorities For Security Leaders In 2026
Securiti's whitepaper provides a detailed overview of the three-phased approach to AI Act compliance, making it essential reading for businesses operating with AI. Category:...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New