
Saudi Arabia's AI Cyber Power: How the Kingdom Is Building a Sovereign AI-Enabled Cybersecurity and Digital-Warfare Capability
Saudi Arabia is assembling a sovereign AI-cyber stack — centralized NCA governance, HUMAIN GPU compute, the ALLAM 34B Arabic model, SITE sovereign cloud, and defense AI partnerships — positioning the Kingdom to evolve from a top-tier cyber-defense state into a sovereign AI-cyber power.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Middle East
- Confidence:
- High Confidence
- Source:
- Encrygma Threat Intel Unit
- Read Time:
- 9 min
Saudi Arabia's AI Cyber Power: How the Kingdom Is Building a Sovereign AI-Enabled Cybersecurity and Digital-Warfare Capability
Detailed research description
Saudi Arabia should increasingly be viewed as an emerging major AI-cyber power, rather than simply as a country purchasing foreign cybersecurity products. The Kingdom is assembling several pieces that, when combined, could create one of the most capable AI-enabled cyber ecosystems in the Middle East: a highly centralized national cybersecurity architecture, rapidly expanding sovereign AI computing infrastructure, Saudi-developed foundation models, substantial cybersecurity spending, a growing specialist workforce, advanced research into AI-driven cybersecurity and critical-infrastructure protection, and increasingly close defense-technology relationships with the United States, Turkey, Pakistan and major Western technology companies.
The important point is that these capabilities are developing simultaneously.
A powerful cybersecurity foundation already exists
Saudi Arabia begins the AI-cyber race from a comparatively strong cybersecurity position. The National Cybersecurity Authority, or NCA, acts as the Kingdom's central national cybersecurity authority, responsible for policy, standards, governance, national cybersecurity posture and protection of government systems and critical infrastructure. Saudi Arabia retained first place in the cybersecurity indicator of the IMD World Competitiveness Yearbook in 2026, according to the NCA, while also being classified in the highest "Role-modelling" tier of the ITU cybersecurity framework.
This institutional structure is important because advanced AI cyber defense requires something more than individual AI products. It requires enormous quantities of telemetry, coordinated threat intelligence, national incident-response structures, cybersecurity standards and the ability to implement security requirements across government agencies and critical infrastructure.
Saudi Arabia increasingly possesses this foundation.
The country's cybersecurity economy is also substantial. NCA figures show that Saudi cybersecurity spending reached approximately SAR 15.2 billion in 2024, around $4.05 billion, representing 14% annual growth. Saudi Arabia had approximately 21,700 cybersecurity specialists, up 9% from the previous year.
This gives Saudi Arabia a human and organizational base upon which AI-assisted SOCs, automated threat hunting, malware analysis, vulnerability prioritization and incident-response systems can be built.
Saudi Arabia is now explicitly preparing for AI and agentic-AI cybersecurity
Perhaps one of the most important findings of the research is what happened in July 2026.
Saudi Arabia's NCA released draft AI Cybersecurity Guidelines covering not merely conventional machine learning and generative AI, but explicitly agentic AI. The framework covers four areas: cybersecurity governance, cybersecurity defense, cybersecurity resilience and third-party cybersecurity.
This is significant.
It demonstrates that the Saudi cybersecurity establishment is already preparing for an environment in which autonomous or semi-autonomous AI agents interact with sensitive government, corporate and critical-infrastructure systems.
The guidelines are primarily defensive and regulatory; they are not evidence of an offensive AI cyber program. However, they demonstrate that Saudi authorities understand that agentic systems fundamentally change cyber risk.
They also provide the regulatory architecture necessary to deploy AI inside national-security environments.
HUMAIN gives Saudi Arabia something it previously lacked: sovereign AI compute
The biggest transformation is the creation of HUMAIN, the PIF-owned national AI company launched in May 2025.
HUMAIN is designed as a full-stack AI company covering data centers, cloud infrastructure, AI models and applications.
This matters enormously for cybersecurity.
Advanced cyber AI increasingly depends upon very large amounts of GPU compute. AI systems capable of analyzing billions of security events, training specialist cyber models, conducting automated malware analysis, running multiple security agents or simulating adversarial networks require exactly the type of infrastructure Saudi Arabia is now attempting to construct.
Saudi Arabia has negotiated extraordinary access to advanced American AI hardware.
NVIDIA and HUMAIN announced plans for AI factories representing as much as 500 MW of computing capacity, involving several hundred thousand advanced GPUs over five years, with an initial planned deployment involving 18,000 Blackwell-class GPUs. AMD separately announced a $10 billion collaboration involving another planned 500 MW of AI infrastructure.
By May 2026, Reuters reported that HUMAIN was seeking financing for GPU and data-center infrastructure totaling around 2 GW of capacity, approximately one-third of its longer-term target.
One caution is essential: agreements, financing plans and chip allocations should not be confused with fully installed operational computing capacity. Saudi Arabia's announced AI infrastructure remains under rapid construction and expansion.
Nevertheless, the strategic direction is unmistakable.
If even a fraction of this infrastructure is ultimately dedicated to national-security workloads, Saudi Arabia would possess the compute resources necessary to train and operate extremely sophisticated AI cybersecurity systems.
The Kingdom now has its own Arabic sovereign foundation model
Another strategically important development is ALLAM 34B, HUMAIN's Arabic-first large language model.
HUMAIN says ALLAM 34B is built and operated in Saudi Arabia and trained using more than 500 billion Arabic tokens, with infrastructure allowing future enterprise RAG systems and role-controlled AI agents.
This has major potential cybersecurity implications.
A Saudi-controlled Arabic model could theoretically become the foundation for specialized cyber-intelligence agents capable of understanding Arabic-language threat intelligence, hacker forums, malware documentation, social-media activity, regional dialects, intercepted or collected text, technical documentation and security logs.
It could also support defensive analyst assistants capable of correlating thousands of alerts, summarizing incidents and searching historical intelligence.
Those applications are logical potential uses rather than publicly confirmed deployments. But sovereign language capability removes an important dependency on foreign LLM providers.
And because future HUMAIN systems are intended to support enterprise AI agents, Saudi Arabia is effectively building the infrastructure from which specialized national-security agents could eventually be created.
AI-driven protection of Saudi critical infrastructure is particularly important
Saudi Arabia has one of the world's most strategically important concentrations of oil, gas, petrochemical, electricity, desalination, transportation and financial infrastructure.
Consequently, industrial cybersecurity is a national-security requirement rather than merely an IT issue.
KAUST researchers are already conducting work involving AI-driven cybersecurity, operational-technology networks, critical-infrastructure protection, blockchain and cloud security.
This represents an important direction for Saudi cyber capabilities.
AI can potentially be used to continuously model normal behavior inside industrial networks and identify anomalies suggesting intrusion, sabotage, compromised credentials or manipulation of industrial processes.
For Saudi Arabia, a sophisticated AI system monitoring energy infrastructure could therefore become as strategically important as conventional military defensive systems.
Saudi Arabia is constructing a sovereign cyber-technology industry
Another important element is SITE — Saudi Information Technology Company, established as the strategic and technical partner of the NCA.
SITE provides cybersecurity, secure cloud and digital services, while SITE Cloud markets Saudi-hosted sovereign infrastructure covering computing, artificial intelligence and security capabilities.
The STC ecosystem also contains sirar by stc, a dedicated Saudi cybersecurity provider offering cyber-defense services to businesses.
This means Riyadh is pursuing something broader than purchasing CrowdStrike, Palo Alto, Microsoft or other foreign cybersecurity platforms.
The long-term objective appears to be technological sovereignty: Saudi infrastructure, Saudi data centers, Saudi cloud environments, Saudi cyber companies and increasingly Saudi AI models.
That combination is strategically important.
Human capability remains one of Saudi Arabia's biggest priorities
Hardware alone cannot create cyber power.
Saudi Arabia therefore continues investing heavily in cybersecurity education, cryptography and research.
In just July and August 2026, the NCA announced specialist national cyber-readiness training, a cybersecurity research initiative with Carnegie Mellon University, an updated higher-education cybersecurity framework and a new postgraduate program to develop cryptography experts.
KAUST is simultaneously building research capability across cybersecurity, AI and critical infrastructure.
Together with an existing cybersecurity workforce of more than 21,000 professionals, this provides Saudi Arabia with an increasingly deep talent pipeline.
Military AI is moving closer to cyber and electronic warfare
There is another development that deserves considerable attention.
In August 2026, Saudi Arabia, Turkey and Pakistan formalized a new defense framework involving deeper military exercises and defense-industry cooperation. According to Turkey's Defense Ministry, the areas being prioritized include unmanned and autonomous systems, electronic warfare and artificial intelligence.
Although this does not establish the existence of Saudi autonomous cyberattack systems, it creates an increasingly important convergence.
Modern electronic warfare, signals intelligence, cyber operations, autonomous drones and AI-driven command systems increasingly share data, compute and analytical infrastructure.
A future Saudi military network could therefore potentially combine:
AI-enabled intelligence → electronic warfare → cyber intelligence → autonomous systems → human command and control.
That would represent a far more advanced form of digital warfare capability than conventional hacking alone.
What about Saudi offensive cyber capabilities?
This is where the research requires caution.
There is credible historical evidence that Saudi-linked operators have possessed sophisticated offensive surveillance capabilities.
Citizen Lab documented Pegasus operators it linked to Saudi Arabia, including the operators it called KINGDOM and MONARCHY. One Saudi-linked operation used sophisticated zero-click mobile exploitation against journalists.
This demonstrates Saudi willingness or ability historically to employ highly advanced commercial offensive cyber capabilities.
It does not, however, demonstrate that Saudi Arabia developed those zero-day exploits itself. Pegasus was developed externally.
More importantly, I found no convincing public evidence as of August 2026 demonstrating that Saudi Arabia currently operates autonomous AI systems that independently discover vulnerabilities, generate exploits, penetrate networks and conduct cyber operations without significant human control.
Claims that Saudi Arabia already possesses an operational autonomous "AI cyber army" would therefore go beyond the available evidence.
Where Saudi AI cyber capability is likely heading
The most interesting conclusion emerges when all these developments are combined.
Saudi Arabia now has nearly every ingredient needed to build far more autonomous cybersecurity systems:
AI supercomputing infrastructure; sovereign cloud infrastructure; domestic Arabic foundation models; national cybersecurity telemetry; centralized cybersecurity governance; critical-infrastructure networks; cyber-research laboratories; cybersecurity companies; a growing specialist workforce; and defense partnerships covering AI, autonomous systems and electronic warfare.
This means the technical barrier separating today's Saudi AI-assisted cyber defense from tomorrow's autonomous cyber-defense agents is becoming considerably smaller.
The same technologies are inherently dual-use.
A model trained to identify vulnerable software can assist defenders in patching systems — or attackers in prioritizing targets.
An autonomous agent capable of validating vulnerabilities across Saudi government networks could potentially be adapted to investigate external networks.
An AI system trained to understand malware could potentially assist in malware generation.
And an Arabic intelligence model capable of monitoring hostile cyber activity could potentially become part of a much broader information-warfare and intelligence system.
That is why Saudi Arabia's emerging cyber capability should be understood not simply as a cybersecurity program, but as the beginning of a national AI-security stack.
Overall assessment
My assessment is that Saudi Arabia can currently be categorized as a high-capability cyber-defense state with rapidly emerging sovereign AI capabilities.
Its strongest demonstrated capabilities today are national cybersecurity governance, critical-infrastructure protection, security operations, cybersecurity investment, sovereign cloud, cybersecurity workforce development and increasingly large-scale AI infrastructure.
Its AI-cyber integration is emerging rapidly, particularly around agentic AI governance, security research, sovereign models, threat analysis and automated defense.
Its military AI capability is also expanding, especially through autonomous systems, electronic warfare and international defense partnerships.
However, its autonomous offensive AI-cyber capability remains unverified publicly.
The strategic significance lies in what happens next.
If Saudi Arabia succeeds in combining HUMAIN-scale compute, Saudi-controlled foundation models, NCA cybersecurity intelligence, SITE's sovereign infrastructure and military AI programs, the Kingdom could evolve during the second half of this decade from one of the Middle East's strongest cyber-defense states into one of the world's more important sovereign AI-cyber powers.
The next stage is therefore unlikely to be simply "AI used by cybersecurity analysts."
It is likely to be AI agents operating alongside cybersecurity analysts — continuously identifying threats, investigating vulnerabilities, correlating intelligence and executing approved defensive actions at machine speed.
That would represent the real beginning of Saudi Arabia's transition from traditional cybersecurity toward autonomous cyber defense.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Nation-State Cyber Warfare: Critical Infrastructure Under Siege in 2026

Escalation in 2026 Iran War: State-Sponsored Cyber Operations Target Global Critical Infrastructure

