AI governance for Saudi Arabia: sovereign, autonomous, inside the Kingdom.
Saudi organizations are adopting AI under a national framework: SDAIA sets the principles and the adoption and risk frameworks, the PDPL governs personal data, the NCA sets cybersecurity controls for national entities, and SAMA sets them for banks. NeueCode 7 gives ministries, banks and critical-infrastructure operators an autonomous AI system that runs on their own infrastructure inside the Kingdom, with every action governed and evidence mapped to those controls.
A mapping that gives your compliance team a starting point, not a certification, and no Saudi authority endorses NeueCode.
What Saudi frameworks ask for, and what runs at runtime
Frameworks describe outcomes. For each authority: what it asks for, and the control that runs in NeueCode 7 while the agent is working.
SDAIA
What it asks for
The AI Ethics Principles, the AI Adoption Framework for government and private sectors, and the National AI Risk Management Framework (2026): accountability, transparency, privacy and security, reliability and safety, and risk managed across the lifecycle.
The control in NeueCode 7
A deny-by-default capability registry set per role; human approval before risky actions; a deterministic verifier that checks the agent's claims; and a hash-chained, tamper-evident Flight Recorder that names who approved what.
PDPL
What it asks for
Governs the processing of personal data in the Kingdom, including the rules for transferring it across borders.
The control in NeueCode 7
The system runs on your own infrastructure inside the Kingdom, on local open-weight models. In strict mode a deny-by-default egress broker makes the agent's cloud and network paths unreachable, and each run emits a signed non-egress manifest that is verified offline.
NCA Essential Cybersecurity Controls
What it asks for
The Essential Cybersecurity Controls for national organizations: identity and access management, logging and monitoring, and data protection.
The control in NeueCode 7
SSO via AD/LDAP and SAML 2.0 with group-to-role mapping and instant deprovisioning; capability tokens on every privileged call; and an audit-evidence export mapped to NCA controls.
SAMA Cyber Security Framework
What it asks for
The cyber security framework for financial institutions: governance, operational controls, and evidence for review.
The control in NeueCode 7
A two-person rule on the highest-risk actions through break-glass dual control; reviewable diffs before any commit; and a compliance portal with a read-only auditor pass and an evidence export mapped to SAMA.
No. NeueCode maps its controls and evidence export to those frameworks so your compliance team has a starting point. It is a mapping, not a certification, and no Saudi authority endorses NeueCode. Your governance program decides what conforms.
Does data or source code leave the Kingdom?
NeueCode 7 runs on your servers inside the Kingdom, on local open-weight models. In strict mode the agent's cloud and network paths are made structurally unreachable, and each run emits a signed non-egress manifest an auditor verifies offline. In hybrid and open modes you define what is allowed, and everything is recorded.
Does it work in Arabic?
Yes. The workbench is fully bilingual, Arabic and English with complete right-to-left support, in the product itself and not only on the website. Support is available in both languages.
Can government entities run it air-gapped?
Yes. It installs with a one-command SSH install on your own GPU server, needs no internet connection to install or to run, and does not phone home. Licenses are hardware-bound and validate offline.
How does a Saudi bank start?
With a scoped pilot on the bank's own server, inside its network, on one test repository, ending with a security review and exported audit evidence mapped to SAMA and NCA that the risk team can set against the framework themselves.
Start with evidence, inside the Kingdom.
A scoped pilot on your server, inside your network, on one test repository, ending with a security review and exported audit evidence mapped to the frameworks you report against.