The winners of AI adoption in Saudi Arabia will not be the companies that adopt the most AI. They will be the ones that adopt the right things, in the right order, and can put a number on each one. Here is how to tell the two apart: the test, where AI pays off and where it disappoints, the Saudi rules that shape the design, and a worked example.
The pressure is national. PwC projects AI could contribute about $135bn to the Kingdom’s economy by 2030, the largest gain in the Middle East (PwC, via trade.gov). So every boardroom feels the same push: do something with AI, now. Some rush into projects that never return a riyal. Others freeze and watch competitors pull ahead. The third path wins: deliberate adoption, pointed exactly where AI pays off, and tied honestly to the national agenda (see building an AI strategy aligned to Vision 2030).
The one test that separates the winners
Don’t ask “what can AI do?” Ask three questions, in order, about the idea on your desk: is the outcome clear enough to measure, is the data trustworthy, and can you deploy and govern it under Saudi regulation? Only an idea that survives all three gets a pilot.
flowchart TD
A(["An AI idea lands on your desk"]) --> B{"Is the business outcome clear?"}
B -->|No| X(["Park it. It's theatre, not value."])
B -->|Yes| C{"Is the data trustworthy?"}
C -->|No| D(["Fix the data first. That's the real project."])
C -->|Yes| E{"Can you deploy and govern it under PDPL and your sector rules?"}
E -->|No| F(["Solve that before scaling"])
E -->|Yes| G(["Prove it on one contained use case, with a baseline number"])
Two of the three exits are “not yet”, not “no”, and they name the real project. The gap is measurable: McKinsey found that while a majority of organisations now use generative AI, only around 39% report an enterprise-level EBIT impact, and only about 5 to 6% are genuine “AI high performers” (McKinsey, 2024). Plenty have adopted. Far fewer adopted the right things. Our readiness check in Is my business ready for AI? walks through the same three questions in detail.
Where AI reliably pays off today
Four corners, one pattern: a high-volume job with a clear right answer most of the time, where AI handles the routine cases and a person handles the exceptions.
- High-volume, pattern-heavy work. Supplier invoices going into the ERP, insurance claims before submission, tender documents pulled from Etimad, KYC files, support tickets. AI reads, classifies, extracts and routes; your people handle what it flags. The payoff is hours, and hours are easy to count.
- Customer interaction at scale, in both languages. Support, internal knowledge access and service in Arabic and English, wherever response time and volume matter. The win is answering the same forty questions instantly and handing the rest to a person with a summary.
- Decision support on good data. Demand forecasting on three clean years of sales history, credit and fraud scoring, anomaly detection. The catch is in that first clause: without trustworthy data, the model learns your mistakes.
- Productivity inside existing work. Coding assistants, first drafts of board papers, a first-pass screen of every contract before legal reads the risky ones. AI makes capable people faster; it does not make an unclear process clear.
Scored that way, the winners cluster in one corner.
quadrantChart title Which AI ideas pay off x-axis Data you don't trust --> Data you trust y-axis Outcome vague --> Outcome measurable quadrant-1 Pilot first quadrant-2 Fix the data first quadrant-3 Park it quadrant-4 Define the outcome first "Invoice extraction into the ERP": [0.85, 0.8] "Arabic and English support triage": [0.78, 0.74] "Demand forecasting on clean sales data": [0.8, 0.66] "Fraud scoring on a half-migrated core": [0.25, 0.7] "AI dashboard for the board": [0.7, 0.2] "Chatbot because competitors have one": [0.35, 0.15]
Where AI disappoints, predictably
Each failure comes from skipping one of the three questions.
- Where the data isn’t ready. AI built on inconsistent, untrusted data inherits every flaw. Most “AI problems” are really data problems in a more exciting costume: three spellings of the same customer, product codes that changed two years ago, a CRM nobody updates.
- Where the process isn’t understood. Automate a broken approval chain and you make it fail faster. If two departments cannot agree on what “closed” means for a ticket, an AI that closes tickets starts the argument at machine speed.
- Where the use case was chosen to be seen, not to be useful. A chatbot because a competitor has one, an “AI-powered” dashboard nobody opens. The tell is simple: nobody can say what number should move.
- Where there’s no plan past the demo. A pilot you can’t deploy, govern or trust in production is a cost, not a capability. Gartner predicts at least 30% of generative AI projects will be abandoned after proof of concept by the end of 2025, on poor data quality, inadequate risk controls, escalating costs or unclear business value (Gartner, 2024). We wrote up how to avoid that ending in how to run an AI proof of concept that leads somewhere.
The Saudi layer: rules that shape the design
The third question is where Saudi adoption differs from the generic playbook. The rules decide where the model runs, what data it may see, and who signs off.
- PDPL and SDAIA. The Personal Data Protection Law took effect on 14 September 2023, full compliance was required by 14 September 2024, SDAIA is the regulator, and cross-border transfer is governed by Article 29 and SDAIA’s Transfer Regulations (Morgan Lewis, 2024). If a use case sends customer records to a model outside the Kingdom, data residency is the first design question, before anyone argues about which model is smarter.
- SAMA, in financial services. SAMA’s Regulatory Sandbox has been running since 2018, letting fintechs test under supervision before full authorisation (SAMA). In our experience the questions come fast for any model touching a customer decision: who owns it, how it is explained, what happens when it is wrong.
- NCA ECC, for everyone. Your cybersecurity controls apply to the AI system like any other: hosting, who can read prompts and logs, how access is revoked. The vendor’s console is inside your control boundary.
- NPHIES, in healthcare. Claims run through NPHIES, the national health information exchange built on HL7 FHIR (Healthcare IT News). An AI that prepares claims has to produce FHIR-shaped data, or it stays a demo.
A worked example: one support inbox, two ways to adopt
Say you run a distributor whose support inbox receives 12,000 messages a month, in Arabic and English, about orders and invoices. The numbers are made up to show the shape.
Company A “adopts AI”: it licenses an enterprise platform, rolls it out to five departments and starts a nine-month programme. Nobody measured the inbox first, so nobody can say what improved. A year later the licence renews and the argument begins.
Company B runs the filter. Outcome: hours spent on routine replies. Data: two years of messages and the answers agents gave. Governance: messages carry customer names, so the model runs in-Kingdom and personal fields are masked before any prompt. Then it measures. Each message takes an agent about 4 minutes, so the inbox eats roughly 800 hours a month, and about 60% of messages are the same dozen questions. An assistant drafts those replies and routes the rest to a person. Call it 450 hours saved a month at a loaded 60 riyals an hour: 27,000 riyals gross. Running the assistant costs about 6,000 riyals a month, so the net is around 21,000, and a 150,000-riyal build pays back in about seven months. Company B can show the curve.
Same technology, same budget, one clear outcome. That is the whole difference.
How to start: one use case, one number, then scale
The pattern that works is boring and reliable. Pick one process from the top-right corner of the chart above. Measure what it costs you today, honestly. Run a small, contained pilot on that one thing, with a human reviewing the AI’s work and the PDPL questions settled before the first prompt. Measure again, net of the AI’s own cost. If it pays back, scale it, one use case at a time. If not, you spent a little to learn something cheap. A second pair of eyes on that first choice is exactly what our AI strategy and proof-of-concept work is for.
AI is a powerful tool aimed at the right problem and an expensive distraction aimed at the wrong one. Telling the two apart is the skill, and it is most of the game for the next few years.
Under pressure to adopt AI but not sure where it actually pays off? SDCG helps you put AI to work where it returns measurable value, and steers you away from the projects that won’t. We’re independent, so there’s no product we’re quietly trying to sell you. Book a free 30-minute review.
Sources
- PwC, $135bn AI contribution to Saudi Arabia’s economy by 2030 (via trade.gov)
- McKinsey, The state of AI in 2024
- Gartner, 30% of generative AI projects abandoned after proof of concept by end of 2025
- Morgan Lewis, Saudi PDPL transition period ends September 14
- SAMA, Regulatory Sandbox
- Healthcare IT News, Understanding NPHIES