Article · 7 min read

Shadow AI under Saudi PDPL and UAE PDPL: what the auditor will ask

A prompt that holds customer data is processing. If the AI provider sits abroad, it may also be a cross-border transfer. Here are the eight questions an auditor is likely to ask, and the evidence that answers each one.

SovereignAI Security Labs · September 2026
General information, not legal advice. This article describes data protection laws in general terms. It does not interpret them for your organisation. Confirm your obligations with your legal counsel and your data protection officer.

Most data protection teams in the Gulf have a register for systems, vendors and transfers. Few have a register for prompts. Yet a single prompt can carry a customer name, a national ID and an account number to a service the organisation never approved.

This article explains why that matters under the Saudi and UAE data protection laws, and how to prepare for the questions an auditor will ask.

Why a prompt is processing, and may be a transfer

Data protection laws define processing broadly. Collecting, recording, using, disclosing and transmitting personal data all count. When an employee pastes a customer complaint into a public AI chat, the organisation discloses that data to a third party. The AI provider then stores and processes it on its own systems.

Three consequences follow.

The scale is not small. The Verizon 2026 DBIR found that 67% of employees access AI from non-corporate accounts on corporate devices. It also found that shadow AI is the third most common non-malicious insider action in DLP datasets. When the account is personal, the organisation has no contract and no log.

INSIDE KSA / UAE · ORGANISATION CONTROL ABROAD · PROVIDER CONTROL Employee device "Summarise the complaint for ID 1xxxxxxxxx" PROMPT Redaction gate NATIONAL ID → [ID] IBAN → [IBAN] DECISION LOGGED CLEANPROMPT BORDER · TRANSFER RULES APPLY Foreign AI provider STORES · PROCESSES INSIDE KSA / UAE Employee device "Summarise the complaint for ID 1xxxxxxxxx" Redaction gate NATIONAL ID → [ID] IBAN → [IBAN] DECISION LOGGED CLEAN PROMPT BORDER TRANSFER RULES APPLY ABROAD Foreign AI provider STORES · PROCESSES

Figure 1. Remove the identifier before the prompt crosses the border. Sample prompt and ID are illustrative.

Saudi PDPL: penalties and active enforcement

The Saudi Personal Data Protection Law was issued by Royal Decree M/19. Its penalties are material, as summarised by DLA Piper:

The timing also matters. SDAIA moved to active PDPL enforcement in 2026. The law is no longer only a readiness project. Organisations should expect questions about how they control processing by third parties and transfers abroad. Shadow AI touches both.

For banks and insurers, the PDPL sits beside sector rules. The SAMA Cyber Security Framework expects data leakage protection, logging and third-party security. The NCA Essential Cybersecurity Controls expect asset management, event logging and control of external and cloud services. An auditor may test all of these with the same evidence.

UAE PDPL, DIFC and ADGM

In the UAE, three regimes may apply, depending on where the entity is set up.

The details differ, but the themes are shared. Processing must have a lawful basis. Processors must work under set obligations. Transfers abroad need a lawful route. For banks, CBUAE regulations and standards add expectations on outsourcing and third-party controls, consumer data protection and incident reporting. The UAE Information Assurance Regulation adds asset inventory, data classification, monitoring and logging.

A public AI tool used through a personal account meets none of these by default. There is no processor agreement, no transfer assessment and no log.

The eight questions the auditor will ask

Auditors tend to follow the data. Expect questions in this order. The right column shows the evidence that answers each one.

#QuestionEvidence that answers it
1Which AI tools do your staff use?AI app inventory, including extensions and agents, split into corporate and personal accounts
2Who used them, and in what role?User and role attribution from SSO and SCIM
3What personal data went into them?Policy decision log by data class, across prompt, paste and upload
4Where did the data go? Was it a transfer abroad?App inventory joined with your vendor records on where each provider processes data
5Which tools are approved, and on what terms?App classes (sanctioned, tolerated, unsanctioned) and the processor contracts for sanctioned tools
6What stopped regulated data from leaving?Timestamped coach, redact and block decisions, with redaction records by data class
7Who approved the exceptions, and when do they end?Exceptions register with approver and expiry date
8How do these controls map to the law, and can you prove the records are unaltered?Regulator clause map and a signed export with a hash

Notice what is missing from the right column: a policy document. The policy is where the audit starts. It is not what closes a finding.

How to build the evidence

Build the evidence in the same order as the questions. Each step feeds the next.

  1. Inventory. Discover every AI app, AI browser extension, agent and MCP server in use. Record whether each session used a corporate or personal account.
  2. Attribution. Tie each session to a named user and role through SSO and SCIM. Without this, you cannot scope a notification.
  3. Policy log. Record every decision with a timestamp: allow, coach, redact or block. Set rules per app, per user group and per data class, such as Saudi National ID, Iqama, Emirates ID, IBAN and card number.
  4. Redaction proof. For each redact decision, keep a record of the data class removed. Keep the class, not the identifier itself. This shows that the identifier did not cross the border.
  5. Exceptions. Every exception needs an approver and an expiry date. Review the register before each audit.
  6. Clause map. Map each control to the frameworks that apply to you: PDPL, SAMA CSF, NCA ECC, CBUAE, DIFC or ADGM. Keep the map in plain language.
  7. Signed export. Export the pack with a hash, so the auditor can check it was not changed. Send the same decisions to your SIEM for day-to-day monitoring.

SentraGuard produces these as an AI Usage Evidence Pack in PDF, CSV and as a SIEM feed, for Splunk, IBM QRadar, Microsoft Sentinel or ArcSight. In on-premise and air-gapped deployments, no data is sent to SOAISEC, which avoids adding a new transfer to answer a transfer question.

Start with the inventory. You cannot answer question 1 by survey. Deploy first and see what is really in use on day 0, before you write rules.

Sources

  1. DLA Piper, Data Protection Laws of the World, Saudi Arabia, enforcement: dlapiperdataprotection.com
  2. Global Privacy Blog, "Active enforcement of Saudi Arabia privacy regime", May 2026: globalprivacyblog.com
  3. Verizon 2026 Data Breach Investigations Report, as summarised by Suzu Labs: suzulabs.com
  4. UAE PDPL (Federal Decree-Law 45 of 2021), DIFC Data Protection Law 2020, ADGM Data Protection Regulations 2021, SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, CBUAE regulations and standards, UAE Information Assurance Regulation: described in general terms. Check the current official text.

Answer question 1 on the day you deploy

A one-week pilot in one business unit. Day 0: your first shadow AI inventory. Day 7: full shadow AI governance with all four actions live and an Evidence Pack.

Start a one-week pilot
Read next