Executive summary

Legal risk in an AI tool does not begin only when an output is produced. It begins with the purpose, data, provider and hosting location, and continues through transparency, security, accuracy, human oversight, retention and destruction. AI governance should be integrated with privacy, contracts, procurement and risk management.

The use lifecycle

Purpose. Define the intended use and the decision the tool will support, and determine whether the purpose is lawful, specific and capable of being explained to data subjects.

Data. Identify data used for training, configuration or operation, the legal basis, minimum necessary scope, sensitive categories and data-subject rights.

Provider and contract. Allocate controller and processor roles, processing location, model-training rights, security, incident notice, audit, deletion and liability.

Transfers outside Saudi Arabia. Assess hosting, support and remote access, and apply the Personal Data Transfer Regulations and appropriate safeguards before transfer.

Use and oversight. Define when human review is required, the permitted reliance on outputs, and how error, bias or unauthorised use will be detected.

Retention and destruction. Set periods for inputs, outputs and logs, and define secure destruction or anonymisation when the purpose ends.

Questions before buying an AI tool

  • Will our data or user prompts train a general model?
  • Where is data stored, who can access it, and from which countries?
  • Can data be deleted, and can the provider evidence deletion?
  • What are the known accuracy limits, and who bears the consequences of error?
  • Are logs sufficient for audit and incident investigation?
  • Which decisions must not be implemented without human review?

Official sources

See the sources listed with this article.