PDPL, SDAIA, and UAE Data Residency: Running AI on Financial Data Without Sending It Abroad
Saudi PDPL is enforced and the CBUAE wants financial data kept in-country. Here is why AI for finance is now an architecture decision, not a policy one.
By The Rexfin team
A controller in Riyadh pastes last quarter’s consolidated trial balance into a chatbot to draft a board summary. The model is hosted in a US region. In that one keystroke, regulated personal and financial data left the Kingdom, crossed a border with no risk assessment, and landed in a system the company cannot audit. Under the Saudi Personal Data Protection Law, that is not a gray area. The compliance grace period ended on 14 September 2024. SDAIA is now running audits, and its enforcement committees have already issued dozens of decisions confirming PDPL violations, with administrative fines reaching SAR 5 million and doubling for repeat offenses.
The uncomfortable part for finance leaders: most of the AI tools your team is already using were never designed with that border in mind.
The rules got specific, and they point at your data, not your intentions
For years, “data protection” in the Gulf was something legal handled and finance ignored. That is over. Two shifts pulled the CFO into the room.
First, Saudi Arabia turned cross-border transfer into a documented, defensible act. In August 2024, SDAIA issued the Regulation on Personal Data Transfer Outside the Kingdom, and in February 2025 it followed with a Risk Assessment Guideline for those transfers. You can move data abroad, but only under conditions: a legal basis, an adequacy view of the destination, approved safeguards such as standard contractual clauses or binding corporate rules, and a risk assessment for continuous or large-scale transfers of sensitive data. SDAIA also reserves the right to halt transfers that touch national security or the Kingdom’s vital interests. None of that happens silently when an employee uses a consumer AI app.
Second, the UAE made residency a hard line for financial institutions. CBUAE rules require licensed institutions to hold consumer and transaction data within the UAE, and to keep the Master System of Record continuously maintained inside the country. Outsourcing a material function or confidential data to a cloud provider needs prior non-objection from the Central Bank. In February 2026 the CBUAE went further, launching a sovereign financial cloud where, by design, financial data stays in UAE jurisdiction. The regulator’s preference is no longer subtle.
So the question is not “is our AI accurate?” It is “can we prove where every regulated figure went, who could read it, and whether we had the right to send it there?” That is an architecture question. A policy that says “don’t paste financials into ChatGPT” is a sticky note on a problem that needs plumbing.
Why “the model is compliant” is the wrong claim
Vendors will tell you their model is SOC 2 audited, encrypted, hosted in a compliant region. Fine. But for an AI that answers finance questions, three things move, and each one is a transfer:
- The data you send in (the prompt context: account balances, customer names, contract values).
- The retrieval the system performs (pulling figures from your ERP, your warehouse, your statements).
- The output and the logs (the answer, plus the trace of what was accessed, stored who-knows-where).
A model can be perfectly secure and still be in the wrong jurisdiction. Residency is about geography and control, not just encryption. And the moment an LLM ingests a row of your general ledger to “reason” over it, that row has been processed by the model. If the model sits abroad and you ran no assessment, you have a finding, regardless of how good the answer was.
This is where the design of the numbers layer underneath the AI decides your exposure. If figures are scattered across QuickBooks, NetSuite, a warehouse, and a folder of PDFs, every AI query becomes an ad hoc transfer with no record of what crossed where. There is no single place to enforce residency, and no clean log to hand an auditor.
Keep the math in-jurisdiction, and keep the LLM out of the math
Rexfin’s view is that the fix is structural. Connect the accounting and financial-data platforms or upload the statements, then build one reconciled financial model that ties out to the ledger. That model is the single source of truth, and it lives where you say it lives. When an AI assistant gets a question, it does not haul raw GL data off to a foreign model to do arithmetic. It retrieves figures from the reconciled model and runs the calculation through a deterministic engine, not the language model. The LLM handles phrasing and reasoning about which figure to fetch; the numbers and the math stay inside the governed boundary.
That separation does two things at once for residency.
It shrinks what ever needs to leave. The deterministic engine computes growth rates, ratios, consolidations, and what-if scenarios in place. The model is not asked to “remember” your revenue and reproduce it; it asks the layer, and the layer answers from source. Far less regulated data needs to touch an external model, and what does can be governed, redacted, or kept in-region by design.
It produces the record the regulator wants. Because every figure traces to source and every calculation is replayable, you get an access log of who and what touched which number, when. That is the lineage SDAIA’s risk assessments assume you can produce and the audit trail CBUAE’s outsourcing rules expect. Our audited-statements guide walks through why traceability has become the price of admission for AI-generated numbers in the region.
The honest limits
This does not make the regulation disappear. If you choose to route any data to an external model, you still owe the legal basis, the assessment, and the safeguards. Sovereign and in-region hosting can carry a cost and latency penalty, and the local model market is younger than the global one. A reconciled layer reduces the surface area and gives you the logs, but it does not sign your contracts or write your transfer risk assessment for you. Anyone promising “fully compliant AI out of the box” is selling the sticky note.
What it does do is move the decision to the place where it can actually be controlled: the architecture. You decide where the source of truth lives. You decide that the math runs deterministically inside that boundary. You decide that the LLM never becomes an unlogged exit door for your trial balance. The same discipline that keeps your figures from drifting across forty SPVs is what keeps them from drifting across a border. The multi-entity consolidation piece makes that connection concrete for groups running dozens of structures.
For the wider picture of sovereign infrastructure meeting sovereign numbers, see the pillar on a trusted numbers layer for AI in the GCC.
The takeaway is blunt: in the Gulf in 2026, compliance is decided before the first prompt is ever typed, by where your numbers live and how your AI reaches them. If you cannot answer “where did that figure go” with a log instead of a guess, the model’s accuracy is beside the point. Book a demo and we will show you what running AI on a reconciled, in-jurisdiction model actually looks like.
Part of AI in Finance for the GCC: A Trusted Numbers Layer