August 20, 2026
Misraj Team
Team
AI Security in Saudi Arabia: From Protecting Systems to Protecting Automated Decisions
On July 5, 2026, the National Cybersecurity Authority (NCA) opened public consultation on its "AI Cybersecurity Guidelines" document, with the window closing on August 5. The timing does not appear to be coincidental: around the same period, Gartner projected that the share of generative AI applications experiencing five or more minor security incidents annually would rise from 9% in 2025 to 25% by 2028. The gap between the pace of adoption and the pace of protection is no longer theoretical it is now formal regulatory material in the Saudi market.
The NCA's new regulatory document redefines "AI cybersecurity" around four pillars: governance, hardening, resilience, and third-party security.
The document's scope explicitly covers generative and agentic AI a regulatory acknowledgment that autonomous agents represent a fundamentally different attack surface than traditional models.
According to Gartner, enterprise adoption of agentic AI applications is outpacing security teams' ability to build corresponding governance by a factor of seven to eight.
The weakest link is often not the model itself, but the integrations, protocols (such as MCP), and third parties that systems connect to.
For decades, cybersecurity was reduced to a familiar equation: perimeter protection, data encryption, and network monitoring. This equation was designed for systems that execute what they are programmed to do in a deterministic way. Generative and agentic AI breaks this assumption at its root, because it makes decisions rather than merely executing instructions based on inputs that can be poisoned, outputs that can be exploited, and behavior that can be manipulated through indirect prompt injection.
This is precisely what the NCA document conveys when it expands the scope of "AI cybersecurity" to encompass four integrated pillars: cybersecurity governance, cybersecurity hardening, cybersecurity resilience, and third-party-related cybersecurity. The implicit message is clear: an organization that limits itself to securing the model's server has only secured a small fraction of the actual decision-making chain.
The difference between securing a "model" and securing an "agent" is a difference in identity and authority. A traditional model responds to an input and returns an output; an agent acts it opens a ticket, sends a message, modifies a record, calls another system often with elevated privileges and without a fixed identity that can be audited the same way a human employee's identity is audited.
Gartner estimates that 40% of enterprise applications will include task-specific AI agents by the end of 2026, up from less than 5% at the start of the year. By contrast, market research shows that only a small fraction of organizations have an advanced security strategy for these agents. The result: growth in agent adoption that outpaces growth in corresponding governance by a factor of seven to eight, according to recent sector analyses.
The four pillars on which the NCA built its document deserve an analytical reading today:
Governance means that the decision to adopt any AI system must pass through a clear accountability path: who owns the decision over the model's behavior? Who signs off on its risks?
Hardening concerns direct preventive controls: securing training data, tightening access to model interfaces, and preventing data leakage through outputs.
Resilience assumes that a breach will inevitably occur, and asks: does the organization have the ability to detect anomalous behavior by an AI agent and recover from it at the same speed the agent itself operates?
Third-party security is the pillar most historically overlooked, even though as will be discussed below it has become the most likely point of entry for attacks.
According to the Authority's own explanation, this classification is grounded in international best practices and experience, placing Saudi Arabia on a path aligned with global frameworks such as the NIST AI Risk Management Framework, while preserving a local regulatory context.
Most enterprise AI systems today are not a single closed block, but a network of integrations: interoperability protocols between models and tools (such as the Model Context Protocol MCP), third-party APIs, and connectors linking the agent to email systems, calendars, and databases. These protocols were designed primarily for flexibility and ease of use, not security-first which, according to Gartner's latest threat analyses, makes them an open gateway for attacks that target not the model itself, but the connection points around it.
This explains why the NCA dedicated an entire, independent pillar to third-party security rather than folding it into general "hardening." When a system makes an automated decision rejecting a transaction, approving a request, escalating an incident the integrity of that decision depends on the entire chain that produced it: the data, the model, the agent, and every third party it interacted with along the way.
The equation the NCA is putting forward today is a redefinition of what "security" means as organizations move from systems that execute to systems that decide. The organizations that treat this shift seriously now before guidance turns into obligation are the ones that will lead the Saudi market in the next phase of AI adoption.
Contact us to discover how Mesraj's technologies can transform the way your organization works.
Start your journey to smarter solutions