Beyond serving as a tool for digital transformation, AI is becoming firmly embedded in Saudi Arabia’s workforce. As the Kingdom advances its Vision 2030 goals and accelerates investment in smart cities and digital infrastructure, enterprises are rapidly embracing tools for greater workplace efficiency. With this, human employees, machine identities, and AI tools are now increasingly operating side by side.
As well as introducing new ways of working, the shift to AI is also changing the nature of insider risk. Organizations are relying more on AI agents and automated workflows, meaning that non-human identities are gaining access to data, triggering actions and making decisions at machine speed. While this undoubtedly brings new productivity, it also accelerates risk at a pace that traditional models can’t keep up with.
Rising insider risk combined with dispersed work environments and ever-evolving deepfake tactics is driving a growing challenge for business leaders. There is now a pressing need to navigate how to utilize AI without losing visibility, accountability, or control of business-critical data and networks.
AI Risk as a Boardroom Challenge
For Saudi Arabia, the stakes around AI-driven insider risk are high. Critical sectors such as energy, healthcare, transport, finance, and public services are becoming more connected, data-driven and AI-enabled, introducing more points of vulnerability. Within such critical environments, cybersecurity resilience is central to enabling operational continuity, public trust, and the Kingdom’s wider economic growth.
The importance of protecting these elements escalates AI-driven insider risk to a boardroom-level concern. According to Exabeam research, the Middle East shows the strongest insider concern globally, with 70% of security leaders identifying internal actors as the primary threat. In highly connected digital environments, even a single compromised account, misused AI tool, or manipulated employee action can cause consequences that extend to impact the wider organization.
As a result, business leaders need to recognize that insider risk is becoming more distributed, harder to attribute, and more closely tied to the way employees interact with AI tools.
The top challenges around AI-driven risk include:
- Personalized Social Engineering: The use of AI is advancing social engineering attacks by making them harder to detect. The creation of highly personalized, context-aware attacks is redefining social engineering by mirroring trusted communication styles, referencing real business activity, and scaling campaigns faster. The challenge lies in not only identifying anomalous behavior, but helping employees recognize how everyday interactions can be manipulated into unintentional insider risk.
- Changing Workplace Behaviors: Hybrid work, digital-native habits, and AI-assisted workflows are changing how employees interact with each other and approach work tasks. The risk of accidental data exposure, poor judgment, or manipulated employee behavior becomes harder for security teams to monitor and control as work becomes faster, more distributed, and more integrated with external tools.
- AI Visibility Gaps: Businesses need a clear view of how employees are using AI and where it is influencing decisions. Without that visibility, teams can lose oversight of what data has been shared with AI tools and become too dependent on automated outputs. This is a particular challenge with AI chatbots, where sensitive data could be inputted into platforms or exposed without the organization realizing.
- Unclear AI Accountability: AI tools can support decisions, but they don’t always understand context, regulations, or operational priorities. When an AI tool makes the wrong call, such as blocking legitimate activity or missing a real threat, the organization is still responsible for the outcome. The challenge for security leaders is to ensure AI-driven decisions always remain governed and accountable.
Combining AI Efficiency with Human Control
With the Kingdom’s rush to digitalization, human input needs to remain as a key pillar for keeping digital workplaces secure.
Beyond a certain point, removing human judgement introduces operational risk, particularly when decisions are made on incomplete or evolving signals. This is where adopting a human-on-the-loop (HOTL) approach offers a practical balance to securing against emerging insider risk. This allows automation to operate continuously while ensuring security analysts retain oversight and the ability to step in when required.
Striking the right balance between AI innovation and human oversight depends on:
- Clear Governance Frameworks: AI agents and autonomous systems may act with legitimate access, but their actions still need guardrails. Organizations should define what AI can do, where human approval is required and how activity is monitored over time. Behavior Intelligence can help identify when users or agents act outside normal patterns, while humans remain responsible for governing critical decisions.
- Deploying Agent Behavior Analytics: Organizations need behavior-based detection that extends beyond human users to include AI agents and human-agent interactions. Agent Behavior Analytics (ABA) can establish baselines for normal activity, detect deviations, and identify subtle signs of misuse or behavioral drift that traditional rules-based tools may miss. Instead of asking, “Is this known bad?” it asks, “Is this normal for this identity?”
- Testing AI With Real-World Cases: AI models need to perform effectively in environments where threats, employee behaviors, and attack techniques continue to evolve. Organizations should train AI against realistic insider threat scenarios, malicious prompts, and changing attack patterns to understand how they respond and where human intervention may still be required.
- Investing in Local Talent: Enabling cybersecurity resilience against insider risk in Saudi Arabia depends on investing in and developing skilled local talent. Training schemes, workshops, and cybersecurity courses build practical expertise needed to manage AI-enabled environments and nurture the next generation of security talent.
Resilience Becomes the End Goal
As AI adoption accelerates across Saudi Arabia, organizations need security strategies that keep automation governed, measurable, and aligned with business risk. AI can help teams move faster, but trust depends on maintaining human oversight for decisions that affect access and critical business operations.
Understanding where humans sit in relation to automated decisions will play a critical role in ensuring security teams remain able to oversee, guide, and intervene to maintain cyber resilience. This means that even when AI behaves in ways we didn’t anticipate, humans can still step in and take control.
Author Bio
Sultan Alanazi | Exabeam Country Regional Director
Sultan Alanazi is the Country Regional Director for Saudi Arabia at LogRhythm | Exabeam, with over 10 years of experience in cybersecurity, enterprise sales, and project leadership. He specializes in driving regional growth, leading high-performing teams, and enabling large-scale digital transformation across government and enterprise sectors. Sultan holds a Master’s in Cybersecurity and is PMP and Prosci certified, with a strong focus on aligning cybersecurity strategy with business outcomes.
Disclaimer: The views expressed are the author’s own and do not represent StrongYes, which assumes no liability for its application. Because AI environments evolve quickly, this information should not replace consultation with certified security experts.
