How to Choose an AI Development Company in Saudi Arabia

Ehtisham ul Haq

Ehtisham ul Haq

Founder of SeedInov. AI engineer building production-ready AI systems for businesses in 8 countries.

How to Choose an AI Development Company in Saudi Arabia
Eleven questions to ask before signing, covering PDPL, SDAIA's principles, data residency, Arabic delivery and scoping discipline. Plus three answers that should end the conversation.

Search for an AI development company in Saudi Arabia and you will get two kinds of result: directory listicles ranking twenty firms by criteria nobody explains, and offshore agencies with a Riyadh address on the contact page and no one in the country. Neither tells you what you actually need to know, which is whether a given supplier can deliver a system that survives your compliance review.

This is a buyer's guide rather than a list. Eleven questions, the answers that should worry you, and the order to ask them in. It is written to be usable whoever you end up hiring, including if that is not us.

Ask the compliance questions first, not last

The most expensive mistake in Saudi AI procurement is treating data residency as a detail to settle after the technical evaluation. It is not a detail. It determines which providers, which regions and which architectures are available to you, and discovering it late means rebuilding a system that performed perfectly well.

The regulatory picture is layered, and a vendor who cannot describe the layers has not delivered here:

  • PDPL governs personal data: lawful basis, minimisation, transfer outside the Kingdom, and retention.
  • SDAIA's AI Ethics Principles govern the AI system itself, across seven principles including fairness, reliability and accountability.
  • NCA controls (the Essential Cybersecurity Controls and Cloud Cybersecurity Controls) govern the platform underneath.
  • Sector regulators add their own: SAMA for financial services, the Ministry of Health for patient data, CST for telecom and subscriber data.

Question 1: Where will our data be processed, specifically?

Not "we are compliant". The name of the cloud region, and whether inference happens there or somewhere else. Many vendors host the application in-Kingdom and send prompts to a model API in another continent, which is a different answer to the one they think they are giving.

Question 2: What happens to prompts, logs and embeddings?

These contain your underlying records and are routinely left out of retention policies written with databases in mind. Ask where they are stored, for how long, whether they are used for training, and whether the answer is contractual or a preference.

Question 3: Who are your subprocessors?

Ask for the list in writing before signature, along with a data processing agreement and an incident response plan. A vendor who has delivered in a regulated Saudi environment will have these ready. One who has not will offer to produce them later.

Question 4: Show us your pre-deployment review against SDAIA's principles.

Ask to see the artefact, redacted, from a previous engagement. A supplier who treats the seven principles as a checklist with evidence attached will have one. A supplier who treats them as a values statement on a slide will explain why they cannot share it.

No consultancy can certify your compliance on its own authority. A vendor claiming to is describing something that does not work that way. What they can do is design against the requirements and produce the evidence; your counsel and your regulator confirm the position.

Then ask about delivery reality

Question 5: Who will actually be on the calls?

Ask for the names and roles of the people who will do the work, not the people in the pitch. The gap between the two is the single most reliable predictor of how an engagement goes. Ask whether you get a senior engineer on the call or an account manager relaying questions to a delivery team in another timezone.

Question 6: Does anyone work on our calendar?

The Saudi week runs Sunday to Thursday. A supplier operating Monday to Friday from elsewhere loses two overlapping days every week, which on a ten-week build is a month of latency nobody puts in the plan. Ask how Ramadan hours and the Eid periods are handled, because a delivery plan that ignores them is a plan written by someone who has not delivered here.

Question 7: Do you work in Arabic, or translate at the end?

These are different things. Operator interviews conducted in Arabic surface process detail that English interviews do not, because the people who actually run the workflow are not always comfortable describing exceptions in a second language. Ask whether the runbook and handover documentation arrive in Arabic, since documentation your staff cannot read does not transfer ownership regardless of what the closing meeting concluded.

For text workloads, also ask whether the evaluation set is written in Arabic or translated from English. Translated evaluation sets systematically miss dialect, transliteration and mixed-script inputs, which is most of what real Saudi user text looks like.

Question 8: Describe a system you have running in production in the Kingdom or the GCC.

Architecture, how long it has been live, how it is monitored, and whether a reference is available. "Production" and "pilot" are different words and vendors use them interchangeably when it suits. A supplier with nothing live in the region is not disqualified, but you should know that is what you are buying.

Then ask the questions that reveal scoping discipline

Question 9: What would you tell us not to automate?

This is the most informative question on the list. A supplier who says everything is a good candidate has not measured anything and is selling capacity. A serious answer names categories: processes running a few times a month where integration cost cannot be repaid, decisions with no consistent right answer, workflows nobody has documented or owns.

Question 10: How will we know in six months whether this worked?

The answer should involve a baseline recorded before the build, an accuracy threshold agreed against it, and an evaluation set you own. If the answer is a dashboard of usage statistics, you are being offered activity metrics in place of outcome metrics, and those are not the same thing.

Question 11: How does this engagement end?

Ask what you receive at handover, who owns the intellectual property, whether the evaluation set is yours, and what it would take to move to another supplier. A vendor whose commercial model depends on you being unable to leave will answer this vaguely. The healthy version is a runbook, the prompts, the evaluation set, documented failure modes, and a named owner on your side.

Three answers that should end the conversation

  1. "We can guarantee 99% accuracy." Nobody can guarantee accuracy before seeing your data. The honest answer is a threshold set against your current process error rate, with uncertain cases routed to a human.
  2. "We are SDAIA certified." Ask what that means and who issued it. Designing against SDAIA's principles is delivery practice; a certification claim is a factual assertion you should be able to verify.
  3. "We will scope it during the project." This is an open-ended retainer wearing a project's clothes. Fixed-scope engagements with a written deliverable protect both sides, and a supplier who resists one is telling you something.

What Vision 2030 changed, and what it did not

Vision 2030 and the National Strategy for Data and AI moved AI from an experiment to a board-level expectation, which is good for budgets and hard on scoping. The pattern we see most often is a mandate to adopt AI arriving without a specified workflow, a metric or an owner. That produces procurement that is difficult to evaluate, because there is no stated problem to evaluate proposals against.

What has not changed is the arithmetic. A supplier proposal is only judgeable against a baseline you recorded yourself. If you measure one process before going to market, every proposal you receive becomes comparable, and the vendors who cannot describe how they would beat your number disqualify themselves without you having to argue.

The short version

  • Settle data residency and processing location before the technical evaluation, not after.
  • Ask for the subprocessor list, DPA and incident response plan before signature.
  • Get the names of the people who will do the work, and confirm they work Sunday to Thursday.
  • Treat Arabic delivery and Arabic evaluation sets as requirements, not preferences.
  • Ask what they would tell you not to automate. The answer tells you whether they measure.
  • Measure one process yourself before going to market, so every proposal is comparable.

We are a Riyadh-based AI software agency and we work to exactly this standard, so it is fair to say we wrote the list we would want to be judged against. If it is useful, take it to whoever you are evaluating. Our own position on SDAIA, PDPL and in-Kingdom residency is written up in detail, as is the AI workflow audit that produces the baseline this guide keeps telling you to record. For build work specifically, see custom AI development in Saudi Arabia.

GLOBAL PRESENCE

We're Everywhere You Need Us

Three hubs, one mission, dedicated teams across time zones delivering seamless collaboration and round-the-clock coverage for every client.

Florida
USHeadquarters

United States

Florida

EST • UTC−5·Mon-Fri • 9:00, 18:00
Karachi
PKEngineering Hub

Pakistan

Karachi

PKT • UTC+5·Mon-Sat • 10:00, 19:00
Riyadh
SARegional Office

Saudi Arabia

Riyadh

AST • UTC+3·Sun-Thu • 9:00, 18:00
How to Choose an AI Development Company in Saudi Arabia | SeedInov