Saudi NCA AI Cybersecurity Guidelines: Control Mapping for Agentic AI
The NCA's draft AI Cybersecurity Guidelines (AICG-1:2026) mapped to practical agentic AI controls, ECC-2:2024 and the OWASP Top 10 for Agentic Applications.
Saudi Arabia’s NCA AI Cybersecurity Guidelines (AICG-1:2026) are still a draft. NCA consulted on them from 5 July to 5 August 2026, the draft says they are not mandatory, and we found no final version as of 9 October 2026. They already name agentic AI explicitly, so mapping your agent controls to them now is cheap preparation.
This post walks through what the draft contains, maps its agent-relevant guidelines to practical controls, and shows how they line up with NCA’s ECC-2:2024 and the OWASP Top 10 for Agentic Applications. Treat every clause number below as draft numbering that may change in the final text.
What are the NCA AI Cybersecurity Guidelines?
The National Cybersecurity Authority published the draft for public consultation in July 2026. According to the consultation draft itself:
- It contains 4 main domains, 15 subdomains and 42 guidelines.
- The scope “includes emerging AI technologies such as generative AI and agentic AI”.
- It covers the whole lifecycle: design and development, deployment, operation, and retirement.
- NCA “advises every entity in the Kingdom that adopts or plans to adopt” AI systems to follow it, while stating plainly that “these guidelines are not mandatory”.
The draft also says it applies cybersecurity requirements previously defined in other NCA documents to the AI context specifically. It borrows definitions from SDAIA’s AI Adoption Framework, which tells you NCA sees this as part of the national AI governance stack rather than a standalone rulebook.
What we do not know yet: whether the final version keeps the same numbering, whether any guidelines become mandatory for government entities or critical national infrastructure operators, and whether sector regulators will reference it. Plan for the content; do not hard-code the clause numbers into contracts yet.
How is the draft structured, and how does it relate to ECC-2:2024?
The four domains deliberately mirror the Essential Cybersecurity Controls (ECC-2:2024), which are already mandatory for government organisations and operators of critical national infrastructure in the Kingdom.
| Draft AICG domain | Subdomains in the draft | ECC-2:2024 domain it builds on |
|---|---|---|
| 1. Cybersecurity Governance | Risk management; cybersecurity in IT project management; human resources; awareness and training | Cybersecurity Governance |
| 2. Cybersecurity Defense | Asset management; identity and access; network security; data protection; backup and recovery; vulnerability management; penetration testing; event logs and monitoring; web application security | Cybersecurity Defense |
| 3. Cybersecurity Resilience | Cybersecurity resilience aspects of business continuity management | Cybersecurity Resilience |
| 4. Third-Party Cybersecurity | Third-party cybersecurity | Third-Party and Cloud Computing Cybersecurity |
The practical consequence: if you already run an ECC compliance programme, you do not need a second framework. You need an AI overlay on the controls you have, plus evidence for the agent-specific items below.
Which draft guidelines matter most for agentic AI?
Most of the 42 guidelines are general AI hygiene. About a dozen are directly about how agents plan, call tools and act. Here they are, with a practical control for each and the closest OWASP Top 10 for Agentic Applications risk (published December 2025, ASI01 to ASI10).
| Draft guideline (theme) | What to implement | OWASP agentic risk |
|---|---|---|
| 1-1-2 Classify agent actions by impact, likelihood and reversibility | An action register per agent: every tool call rated, with irreversible actions (payments, deletes, external emails) gated | ASI02 Tool Misuse, ASI03 Identity and Privilege Abuse |
| 1-2-2 Treat data from tools, memory and third-party APIs as untrusted | Input validation and content isolation before anything enters the context window; no instructions accepted from retrieved data | ASI01 Agent Goal Hijack |
| 1-2-3 Avoid uncontrolled learning in production | Freeze model and prompt versions in prod; changes go through release, not runtime learning | ASI06 Memory and Context Poisoning |
| 1-2-5 Review, test and approve AI-generated code | SAST and human review on agent-written code before it reaches dev, integration or prod | ASI05 Unexpected Code Execution |
| 1-2-6 Approval process for high-impact AI | A go-live gate with a named approver and a recorded risk decision | ASI10 Rogue Agents |
| 1-2-7 Graduated autonomy with human oversight | Autonomy levels per agent (suggest, act with approval, act and report), promoted only on evidence | ASI09 Human-Agent Trust Exploitation |
| 2-1-1 / 2-1-2 Inventory and lifecycle status of AI components | Register of models, agents, prompts, tools and MCP servers, tagged experimental, pilot, production or retired | ASI04 Agentic Supply Chain |
| 2-2-1 / 2-2-2 Role-based permissions for AI agents; review tokens | Each agent gets its own identity, least-privilege scopes and short-lived tokens; quarterly access review | ASI03 Identity and Privilege Abuse |
| 2-2-3 Rate limits and usage thresholds | Per-agent and per-user rate limits, spend caps, anomaly alerts | ASI08 Cascading Failures |
| 2-3-1 Restrict egress to approved destinations | Allow-listed egress for agent runtimes; block arbitrary URLs and ports | ASI01, ASI02 |
| 2-4-3 Protect memory from poisoning | Write controls on long-term memory, provenance tags, periodic validation of stored content | ASI06 Memory and Context Poisoning |
| 2-4-4 Guardrails tested before production and after changes | Input and output filters plus a regression suite that reruns on every material change | ASI01, ASI02 |
| 2-7-2 Red teaming, adversarial evaluation, validate human override | Agent red team that includes trying to bypass approval steps and kill switches | ASI09, ASI10 |
| 2-8-1 / 2-8-2 Log tool invocations and AI-initiated actions | Structured logs of every tool call, prompt config change and data upload or download, fed to your SIEM | ASI10 Rogue Agents |
| 3-1-1 Rollback, safe shutdown and manual alternatives | A tested kill switch and a documented manual fallback for each business process an agent runs | ASI08 Cascading Failures |
| 4-1-2 / 4-1-3 Third-party AI components and developer contracts | Security clauses for AI vendors, assessment of third-party models, plugins and tools before use | ASI04 Agentic Supply Chain |
ASI07 (insecure inter-agent communication) has no dedicated guideline in the draft, though network segmentation (2-3) and identity controls (2-2) cover part of it. If you run multi-agent systems, add authenticated, integrity-protected messaging between agents anyway.
For how these risks show up in real attacks, our posts on prompt injection in AI agents and pentest.ae’s how AI agents get hijacked cover the mechanics. Tool connectors deserve special attention; pentest.ae’s MCP server security assessment shows what testing them involves.
Where do SDAIA’s AI Ethics Principles fit?
SDAIA, not NCA, owns AI ethics. Its AI Ethics Principles (version 2.0, published September 2023) set out seven principles: fairness; privacy and security; humanity; social and environmental benefits; reliability and safety; transparency and explainability; and accountability and responsibility.
The NCA draft is the security layer underneath two of those: privacy and security, and reliability and safety. The accountability principle lines up with the draft’s governance asks: named owners, approval gates and human oversight. If your organisation has done an SDAIA self-assessment, reuse the AI inventory and risk classification from it; it is the same starting point the NCA draft asks for in 1-1 and 2-1.
How does this compare with the EU AI Act?
Different instruments, overlapping evidence. The EU AI Act is binding law with risk tiers, conformity assessment for high-risk systems and fines. The NCA draft is non-mandatory security guidance focused on how AI systems are protected and operated. A GCC company selling into both markets will find that the same artefacts serve both: AI inventory, risk assessments, adversarial test results, logging and human oversight design.
If Europe is also on your roadmap, see our EU AI Act compliance checklist and the EU AI Act security requirements breakdown.
What should you do before the final version lands?
- Inventory every AI component, including agents, prompts, tools, MCP servers and third-party models, with an owner and lifecycle status.
- Write the action register for each agent: what it can do, how reversible each action is, and which actions need human approval.
- Give agents their own identities with least-privilege scopes and short-lived credentials.
- Turn on tool-call logging and route it to the SIEM you already use for ECC.
- Test the kill switch and manual fallback, then run an adversarial test against your highest-impact agent, following an approach like pentest.ae’s AI agent penetration testing field guide.
- Add AI clauses to vendor contracts for any third party that builds or hosts AI components for you.
None of this is wasted if the final text changes. These are the controls every serious agent framework asks for, and they map to ECC controls you are probably already audited on.
Get a KSA AI security gap assessment
infosec.qa runs a fixed-scope KSA AI security gap assessment against the draft NCA AI Cybersecurity Guidelines, cross-referenced to ECC-2:2024 and the OWASP Top 10 for Agentic Applications. We inventory your AI estate, check each draft guideline against real evidence, test your riskiest agent paths, and hand you a prioritised remediation plan that we update when NCA publishes the final text. Book a KSA AI security gap assessment.
Frequently Asked Questions
Are the NCA AI Cybersecurity Guidelines mandatory?
Not as drafted. The consultation draft states that the guidelines are not mandatory and are intended to help entities in the Kingdom that adopt or plan to adopt AI systems. That can change in the final text, and sector regulators or government contracts may still reference them, so treat them as the expected baseline rather than optional reading.
Has NCA published the final AI Cybersecurity Guidelines?
As of 9 October 2026 we could not find a final version. NCA ran a public consultation on the draft AI Cybersecurity Guidelines (AICG-1:2026) from 5 July to 5 August 2026. Check the NCA public consultations page before relying on any clause number or wording, because the final document may restructure or reword guidelines.
How do the NCA AI guidelines relate to ECC-2:2024?
The draft reuses the ECC-2:2024 domain structure: cybersecurity governance, defense, resilience and third-party. NCA describes the document as applying cybersecurity requirements already defined in its other publications to the AI context. In practice, your ECC controls are the foundation and the AI guidelines tell you what to add for models, agents, prompts and tools.
What do the NCA guidelines say about AI agents specifically?
The draft names agents directly. It asks entities to classify AI agents' actions by impact, likelihood and reversibility, implement graduated autonomy with continuous human oversight, define role-based permissions for AI agents alongside humans and service accounts, protect memory from poisoning, log plugin and tool invocations, and validate human override during testing.
How long does a KSA AI security gap assessment take?
For one or two production agents, a focused gap assessment against the draft NCA guidelines usually fits in two to three weeks: inventory and architecture review, control-by-control evidence check, targeted testing of the riskiest agent paths, and a prioritised remediation plan. Larger estates with many agents or third-party AI vendors take longer.
Complementary NomadX Services
Related Articles
Know Your AI Attack Surface
Request a free AI Security Scorecard assessment and discover your AI exposure in 5 minutes.
Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian
Get Your Free Scorecard