What is an AI agent, and how is it different from a chatbot?
An AI agent is a language model given a set of tools and allowed to decide which tool to call next to finish a task. A chatbot talks; an agent talks and then does something in your systems, such as updating an order, booking a slot or writing a report.
In practice the difference shows up in three places. A chatbot answers from a knowledge base and hands off to a person when it cannot help. An agent can call functions you define, for example get_order_status, find_free_slots or create_refund_draft, read the result and decide the next step. It can also run without a customer at all, on a schedule, like a reporting agent that wakes up at 7 am Riyadh time and summarises yesterday’s sales.
That extra power is also the extra risk. A chatbot that makes a mistake gives a wrong answer; an agent that makes a mistake can issue a wrong refund. This is why any serious AI agent development company in Saudi Arabia, or anywhere, should talk to you about permissions and approvals before it talks about models. If you only need customers’ questions answered, our Arabic chatbot page is the better starting point.
Which tasks can an AI agent safely handle in a Saudi business?
Agents are safest where the action is reversible, the data is structured and a mistake is cheap to catch. Start there, then widen the agent’s permissions only after its logs show it behaving well.
We sort every proposed action into four tiers. Read: look up an order, a booking or a stock level; low risk. Draft: prepare a refund, a purchase order or a reply for a person to send; low risk because nothing leaves without a click. Act with approval: execute the step after a named person approves in WhatsApp, email or a dashboard. Act alone: execute without review, reserved for small, reversible actions such as rescheduling a booking within the customer’s own rules.
Tasks that fit well in Saudi SMEs include answering “where is my order” for Salla and Zid stores, rescheduling appointments, producing daily branch summaries from Foodics, qualifying WhatsApp leads, and matching supplier invoices to purchase orders. Tasks we advise keeping with people include anything involving medical advice, legal commitments, large payments, hiring decisions and messages that could harm a customer relationship if the tone is wrong.
- Read: look-ups only, no changes
- Draft: prepares a change for a person to send
- Act with approval: executes after a named person says yes
- Act alone: small, reversible actions within set limits
How AI agent development works, step by step
Building an agent is mostly careful integration and testing work; the model itself is the smallest part. Our process moves from a list of actions to a tested, logged agent running in your cloud.
We start with a task inventory: the exact requests the agent will handle, the systems it touches and the tier for each action. Next comes tool design, where each action becomes a small, documented function with strict inputs, for example an order number rather than free text, so the model cannot improvise a database query. Then model selection: we test two or three current models on your own Arabic and English examples and pick on accuracy, speed and cost, not brand.
The orchestration layer holds the conversation state, the approval queue and the logs. For simpler flows we use n8n or a small Python service; for agents inside a larger product, a Node.js or Python backend. Finally comes the evaluation stage: the agent must pass the agreed test set before it touches live data, and it runs in a shadow mode, where it drafts but does not act, for a short period so your team can compare its choices with their own.
Connecting an AI agent to Salla, Zid and Foodics
Salla, Zid and Foodics each publish developer APIs, so an agent can read and update your store or POS data through documented, permission-scoped access rather than screen scraping.
According to Salla’s developer documentation, apps built through Salla Partners get scoped access to a merchant’s store through OAuth 2.0 and can subscribe to webhooks, including conditional webhooks, so an agent can react when an order is created or its status changes. Salla also applies rate limits on its API endpoints, which we design around by caching look-ups and queuing bulk jobs. Zid’s developer documentation describes APIs for building apps, a Partner Dashboard with webhook logs, and a choice between public apps in the Zid App Market or private apps for a single store; a private app is usually the right route for one merchant’s agent.
Foodics offers developer documentation and an API and webhooks area in its settings, which lets a reporting or reorder agent read orders, menus and branch data. For each platform we request only the scopes the agent needs; a reporting agent, for example, gets read-only access. If you run a Salla store and want wider changes beyond the agent, our Salla store developer page covers themes and custom apps.
Approval checkpoints and audit logs: how you stay in control
Every action an agent takes should be traceable to a request, a decision and, where needed, a named approver. We build that record into the agent from day one rather than bolting it on after an incident.
An approval checkpoint pauses the agent and sends a short summary to the right person: “Refund 2 of 3 items on order 48213, reason: damaged on arrival, photo attached. Approve?” The approver replies in WhatsApp, email or an admin screen, and only then does the tool run. Rules decide who approves what, for instance branch managers for rescheduling and the finance lead for refunds.
The audit log stores, for every step, the user request, the model’s chosen tool, the exact inputs, the system response, the final message and the approver if any. Logs are kept in your own database with a retention period you choose, and personal data in them is limited to what you need for review. When something goes wrong, you can replay the exact chain of decisions, which is also how we improve the agent’s instructions.
- Per-action approval rules with named roles
- Approval requests on WhatsApp, email or dashboard
- Tool inputs and outputs logged for every step
- Retention period and access to logs set by you
- Kill switch that returns the agent to draft-only mode
Testing an AI agent in Arabic: building an evaluation set
An Arabic evaluation set is a list of real requests with the correct outcome for each, used to test the agent before launch and after every change. Without one, “it works in Arabic” is just a feeling.
We build the set with you from real messages, stripped of personal details: formal Arabic, Gulf dialect, Arabizi written in Latin letters, English, and mixed sentences that switch halfway. For each request we record the expected tool call and the expected answer. Examples include “وين طلبي؟” with an order number, a reschedule request that names a day in the Hijri calendar, and a customer writing prices with Eastern Arabic numerals.
The team writes and runs the tests; a native Arabic speaker on your side reviews the tone and correctness of the answers, because we do not offer native Arabic copywriting. We report the pass rate per category, and the agent goes live only when you accept the results. The same set is rerun whenever a model version changes, so an update from the model provider does not silently change your agent’s behaviour.
Hosting and data residency choices for AI agents in Saudi Arabia
You decide where the agent’s code, database and logs run, and you choose which model provider processes the text. Both choices affect where personal data travels, so settle them with your legal adviser before the build.
For hosting, the agent can run in your existing cloud account. Google Cloud, for instance, lists a Dammam region (me-central2) in Saudi Arabia; its Dammam region access page explains that KSA-based customers access it through CNTXT, its reseller for the region. Other providers offer regions elsewhere in the Gulf or in Europe. We deploy to the region you pick.
The model call is a separate question. Hosted models from the major AI providers usually process requests in the provider’s own data centres, which may be outside the Kingdom. Where that is a concern, the options are to minimise and mask personal data before it reaches the model, to use a provider or model deployment available in a region you accept, or to run an open-weight model on your own servers, trading some quality for control. We explain the trade-offs in plain terms; the decision and the legal sign-off are yours.
PDPL, SDAIA guidance and responsible AI agent design
Saudi Arabia’s Personal Data Protection Law applies to agents that handle customers’ personal data, and the SDAIA data protection portal is the official source for it, including its breach-notification service and a self-compliance assessment tool. We design the agent to support your obligations; compliance itself stays with you and your counsel.
In the build that means collecting only the fields the task needs, masking identifiers in logs where review does not require them, keeping consent records for marketing messages, controlling who can read the logs, and making it possible to find and delete a person’s data on request. SDAIA has also published AI ethics principles that stress points such as transparency, accountability and human oversight; approval checkpoints and audit logs are practical ways of showing those in a small system.
We also make sure customers know they are dealing with an automated assistant and can reach a person. That is good practice, it reduces complaints, and it keeps the agent honest about what it cannot do. We do not provide legal advice or certify compliance, so ask your lawyer to review the data flow diagram we hand over with the build.
How much does AI agent development cost in Saudi Arabia?
With us, a focused AI agent connected to one or two systems starts from US$600 and takes about 2–4 weeks. The price moves with the number of tools, the approval workflow and the size of the evaluation set, not with the size of your company.
Running costs are separate and mostly go to other providers: model usage billed per token by the model provider, hosting billed by your cloud provider, and WhatsApp or SMS messages billed per message. During testing we measure how many tokens a typical request uses and give you a monthly estimate at your expected volume, so you can decide whether a cheaper model is good enough for simple steps.
An agent built into a new customer portal or app is part of a larger build from US$900. After launch you get two months of free maintenance, then care plans start from US$120/mo, covering model version updates, rerunning the evaluation set and adjusting tools when Salla, Zid or Foodics change their APIs. If you want to compare with an app budget, see app development cost in Saudi Arabia.
How to choose an AI agent development company in Saudi Arabia
Choose the team that talks first about your actions, permissions and test cases, and only then about models. A demo that answers clever questions tells you little; a written list of tools, tiers and pass criteria tells you a lot.
Ask each candidate five questions. Which actions will the agent be allowed to take, and which need approval? How will you test it in Gulf Arabic before launch? Where will the logs live and who can read them? Which API scopes will you request from Salla, Zid or Foodics? What happens when the model provider releases a new version? Good answers are specific and written; weak answers lean on the name of a famous model.
Also check ownership. The agent’s code, prompts, tool definitions and evaluation set should sit in your repository, and the model API keys in your account, so you are free to change providers or developers. Whether you choose a local specialist or a remote team like ours, insist on that.
- Written list of tools and permission tiers
- Arabic and English evaluation set with pass criteria
- Logs stored in your database
- Least-privilege API scopes
- Code, prompts and keys owned by you
Risks and red flags in AI agent projects
The biggest risks in agent projects are too much permission too early, no evaluation set, and no plan for model updates. Each is easy to avoid if you know to look for it.
Be wary of a proposal that gives the agent admin-level API keys “to keep it simple”, promises full autonomy from day one, or cannot explain how it will stop the model from inventing order numbers or prices. Prompt injection is a real concern too: a customer message or a supplier email can contain instructions aimed at the agent. We handle that by treating all incoming text as data, validating tool inputs strictly, and never letting the agent change its own permissions.
Another red flag is a quote that hides model and hosting costs inside a vague monthly fee, so you cannot see what you pay for. Finally, beware any claim that an agent will replace your staff outright. A well-built agent removes repetitive steps and speeds up routine work; people still handle exceptions, complaints and judgement calls.
Reporting agents: turning Foodics and store data into daily summaries
A reporting agent reads your sales, orders and stock data on a schedule and writes a short summary that tells managers what changed and what needs attention. It is often the safest first agent, because it only reads data.
A typical reporting agent for a restaurant group pulls yesterday’s Foodics orders per branch, compares them with the same weekday last week, highlights items that sold out, and posts a five-line Arabic or English summary to a WhatsApp group or email at a time you choose. For a Salla or Zid store, it might list unpaid orders, delayed shipments and products with falling views.
Numbers are calculated in code, not by the model; the model only writes the words around figures that have already been computed. That avoids the classic failure of an AI inventing a total. When managers want charts and drill-downs rather than text, a dashboard is the better tool, which our Power BI developer page covers.
Working with an AI agent team in India from Saudi Arabia
The team works remotely from India, two and a half hours ahead of Saudi time, so a Riyadh or Jeddah working day overlaps with ours for most of its hours. Calls happen on video, updates on WhatsApp, and there are no office visits.
In the first week after you approve the written quote, we hold a scoping call to build the task inventory and permission tiers, and you create or share accounts: your cloud project, the model provider account with its API keys, and developer access to Salla, Zid or Foodics. We also agree who collects the first thirty or so real example messages for the evaluation set. In week two, the first tools run against a test store or sandbox, and you see the agent drafting answers in shadow mode.
Quotes are in US dollars and paid in milestones by Wise, bank wire or PayPal; nothing is billed before written approval. Invoices come from India, and your accountant should confirm how payments to a non-resident provider are treated. Another of us leads the AI and data work, one of us builds the integrations and backend, and the third of us manages the project and automation flows.
Worked example: an order-status and returns agent for a Jeddah Salla store
This is a hypothetical example to show the shape of a project. Say a Jeddah abaya and fragrance store on Salla receives many WhatsApp messages a day asking where orders are and how to return items.
The agent gets three tools: get_order (read), get_return_policy (read) and create_return_request (act with approval). When a customer writes in Gulf Arabic asking about an order, the agent asks for the order number if missing, calls get_order, and replies with the status and courier tracking. If the customer asks to return an item, the agent checks the policy window, collects the reason and a photo, and posts an approval card to the store manager. Only after the manager approves does the return request get created.
Before launch the agent passes an evaluation set of real, anonymised messages, including mixed Arabic-English ones and a few attempts to talk it into a refund outside the policy. The build would start around US$600, with the WhatsApp connection handled as described on our WhatsApp automation page. Model and message costs go to the owner’s own accounts, and the logs show every decision the agent made.
AI agent readiness checklist for Saudi businesses
Before asking for an AI agent quote, gather the items below. They let us price accurately and they tell you whether an agent is the right tool at all or whether a simpler automation would do.
- The one task you want off your team’s plate, described in five sentences
- Thirty or more real example requests, with personal details removed
- The systems involved: Salla, Zid, Foodics, Sheets, CRM, email, WhatsApp
- Which actions need approval and who approves them
- Where you want the agent and logs hosted
- Who on your side reviews Arabic answers for tone and accuracy
- Monthly request volume, to estimate model and message costs
If the task has no judgement in it, for example “copy every new order into a sheet”, an agent is overkill: a plain workflow is cheaper and more predictable. Our AI automation services page explains that route, and our guide to hiring developers in India covers the engagement model in general.