Article 18 Gives Your Software Rights to Whoever Wrote It, Not Whoever Paid

Article 18 Gives Your Software Rights to Whoever Wrote It, Not Whoever Paid
The Council of Ministers approved the new Saudi Copyright Law on 27 January 2026. It was published in Umm Al-Qura issue 5144 on 13 February 2026, and Article 61 sets it in force 180 days after publication, which is 12 August 2026. The law is live now, and it replaces the 2003 copyright law issued under Royal Decree M/41 of 2/7/1424H that governed protected works for more than two decades.
Most coverage of the new law focused on penalties, licensing and the AI training exception. But if you run a company that has ever paid for a website, an app or a custom system, the article you will actually feel is Article 18. It is not about piracy or infringement. It answers a simpler and more consequential question: after you pay for the software, who owns the rights to it?
Three cases, two very different outcomes
Article 18 separates three situations, each with its own rule, and every one of them ends with the same qualifier: unless otherwise agreed.
- An employee who creates a work during employment that relates to the employer's activities: the copyright belongs to the employer. This is the comfortable case, and the one everyone assumes applies everywhere. A developer on your payroll writes your internal sales system, and the rights are yours.
- A work created for the account of another person: the economic rights return to the author. This is the outsourcing case: a software house, a freelancer or a design agency delivering a project on your instructions and for a fee. The law does not assume that payment moves ownership.
- An employee who creates a work unrelated to the employer's activities: the economic rights stay with the employee. What your staff build on their own time, outside your line of business, is not yours.
The second case is the trap, because it describes how most digital projects in the Saudi market are actually delivered: a company hires an outside party to build an app, a store or an internal system. Most owners walk away from signing with the impression that the invoice bought the whole thing. The law says the opposite unless the contract says otherwise, and the distance between the two is one written sentence.
What not holding the economic rights actually costs you
Economic rights are not an abstraction. Article 9 lists what they cover: reproduction, translation and adaptation and any modification, distribution, rental, communicating the work to the public, and licensing its commercial exploitation generally. Whoever holds them decides whether the work can be reused, who may modify it, and who else may be sold a copy.
Picture the effect on a working business. Three years ago you bought a custom system from an external developer on a short contract that never mentioned ownership. Today you want to hand the source to a different team to extend it, or license the system to a sister branch, or sell the business with its systems included. In each of those moments, the party holding the right to reproduce, modify and license is not you.
That does not leave you with nothing. Article 12 makes computer programs, applications and databases subject to the licence accompanying them, and the buyer is bound by that licence's terms. But a licence and ownership are different instruments. A licence gives you the right to use within limits; ownership gives you the right to dispose. The gap between them appears at exactly the moment you need to dispose of something.
Moral rights never move, even when everything else does
This is where many contracts are misread. Article 7 divides copyright into moral rights and economic rights. Economic rights transfer by lawful disposition under Article 10, in whole or in part. Moral rights are described in Article 7(2) as perpetual, not subject to prescription, not capable of disposal, not capable of waiver, and not extinguished by granting any form of economic exploitation.
In practice: even with the strongest assignment clause your lawyer can draft, moving every economic right to you, the developer keeps the right to be credited as the author and the right to object to a modification that distorts the work in a way that harms their reputation. That is not a drafting failure, it is a statutory rule that agreement cannot change. So treat an ownership clause as a precise description of what moved to you and what stayed with them, not as an eraser.
There is also Article 17, covering collective works: the person who directed the creation of the work, managed it, and published it in their own name and for their own account holds the sole right to exercise copyright, unless otherwise agreed. That is a different route with its own conditions, and it is not a substitute for a written clause.
The clause your contract needs
The good news is that all of the above can be changed by agreement. The phrase unless otherwise agreed is not a loophole, it is the intended exit: the law supplies a fallback rule for parties who wrote nothing, and defers to the parties who wrote something. The difference between a company that owns its systems and one that does not is usually a single paragraph in a development contract.
What deserves to be stated explicitly:
- Transfer of economic rights: clear wording that all economic rights in the work pass to the client on acceptance or on full payment, not merely a licence to use it.
- Definition of the work: exactly what is included. Source code, database schema, designs, content and technical documentation. Broad terms park a disagreement for later.
- Open-source and third-party components: every modern system is built on libraries and frameworks with their own licences, and nobody transfers ownership of those. Ask for the inventory and its licences, because a clause promising absolute ownership of every line is a clause that cannot be honoured.
- Source code delivery: ownership without an actual handover of the source and repository access does not help you the day you want to change vendors. Tie delivery to a defined milestone, not an open-ended promise.
- Freelancers and subcontractors: if your vendor brings in others, the vendor must first secure their rights in order to pass them to you. A rights chain breaks at its weakest link.
Registration: a presumption, not a grant of ownership
Article 42 allows works to be registered with the Saudi Authority for Intellectual Property, along with documentation of amendments and dispositions affecting them, and states that registration constitutes a rebuttable presumption of ownership of the work.
Registration is therefore optional, and it does not create ownership that did not exist. What it changes is the burden of proof. A company that has registered its system, designs and original content walks into a dispute presumed to be the owner until someone proves otherwise, rather than assembling old emails to show it commissioned the work. Paired with a contract that clearly transfers the economic rights, the file is complete: a written agreement, and an official record of the transfer.
The wider shift: from made locally to owned locally
Article 18 does not stand alone. The Council of Ministers approved the National Intellectual Property Policy on 25 August 2026, extending the National Intellectual Property Strategy launched in December 2022, whose implementation the Saudi Authority for Intellectual Property oversees. The direction in both documents is the same: move from protecting rights to using them, and from recognising intangible assets to treating them as economic assets that can be transferred, licensed and valued.
For a business owner, that means the ownership question is no longer a legal matter raised only during a dispute. It is raised at valuation, when an investor comes in, during an acquisition, and when applying for financing. Companies that cannot prove they own their systems usually discover it at the worst possible moment: in the middle of due diligence.
The Origami view
We are the party Article 18 describes in its second case, so we will say it plainly: the transfer of economic rights belongs in the contract, and it is not in the client's interest to leave it to the fallback rule. When we build a custom system, ownership of the code, designs and data is settled in writing before the first function is written, and the full repository is handed over, not just a build. A company that builds your system and resists that clause is telling you something about the relationship it wants.
The other half of the picture is that absolute ownership is a fiction. Every modern system rests on open-source libraries and frameworks with their own licences, and on cloud services with their own terms. Honest drafting separates what we transfer to you from what you use under a third-party licence, with an explicit inventory. That distinction reads as a technical detail today, and it is what keeps your file sound on the day a lawyer, not a programmer, reviews it. It runs through all of our services, and follows on from our first read of the new law.
Three questions to answer this week
You do not need a full legal review to start. You need three answers about the systems you already run.
- Does the contract for your site, app or system contain explicit wording transferring the economic rights? If ownership is not mentioned at all, you are in Article 18's second case.
- Do you actually hold the source code, or do you hold a working system and a dashboard login? The first is an asset, the second is a service.
- Who builds for you today: an employee on your payroll, or an external contractor? Under Article 18 that is the difference between a right you get automatically and a right that needs wording.
If the answers are uncomfortable, the fix is not complicated. A signed addendum transferring the economic rights corrects the position on completed projects, and a standing clause in your contract template stops it recurring. Future contracts are easier than past ones, and both are far easier than a dispute over a system your company runs on every day.
Sources
- Bureau of Experts at the Council of Ministers — text of the Copyright Law, specifically Articles 7, 9, 10, 12, 17, 18, 42, 59 and 61.
- Umm Al-Qura Gazette — the law was published in issue 5144 on 13 February 2026, and Article 61 sets entry into force 180 days after publication.
- Saudi Authority for Intellectual Property — the authority responsible for registering works and documenting dispositions affecting them.
- National Intellectual Property Strategy — launched December 2022; the National Intellectual Property Policy was approved by the Council of Ministers on 25 August 2026.
Frequently asked questions
I paid an external software house for my app, so is it not mine?+
Not automatically. Article 18 of the Copyright Law provides that a work created for the account of another person has its economic rights return to the author unless otherwise agreed. Payment alone does not move the economic rights to you unless your contract says so explicitly. By contrast, a work created by an employee during employment that relates to your business activities belongs to you by operation of the law.
What is the difference between a licence to use software and owning its rights?+
A licence gives you the right to use the software within the terms accompanying it, and Article 12 subjects computer programs, applications and databases to that licence. Owning the economic rights gives you the right to dispose: reproduce, modify, distribute and license to others. The difference surfaces when you change developers, sell the business, or license the system to another party.
Does an assignment clause move all of the developer's rights to me?+
It moves the economic rights, but moral rights do not transfer. Article 7(2) states they are perpetual, not capable of disposal or waiver, and not extinguished by granting economic exploitation. They include attribution of the work to its author and the right to object to a modification that distorts it in a way harming their reputation. A contract defines which economic rights move; it does not cancel those rights.
Is registering software with the Saudi Authority for Intellectual Property mandatory?+
No. Article 42 makes registration permissive rather than mandatory, and protection exists without it. What registration adds is a rebuttable presumption of ownership of the work, which shifts the burden of proof in your favour in a dispute. Amendments and dispositions affecting the work can also be documented with the authority.
Follow Origami in Google
Pin Origami as a preferred source and our articles will surface first for you in Google Search and Top Stories.

Related articles
- Compliance and RegulationYour Customer Conversations and the Personal Data Protection Law: What Is Actually RequiredPart five divided the roles between the assistant and the employee, and ended on a sentence that deserves a whole part of its own: your customer conversations are personal data. This part covers the lawful basis and notifying the customer, collecting only what you need and deleting what has served its purpose, who on your team can see conversations, what it means when data leaves the Kingdom, and where your responsibility as controller ends and your vendor's as processor begins.
- Digital TransformationDocument Management System and Digital Archiving: A Guide for Saudi BusinessesA practical guide to document management systems and digital archiving for Saudi businesses: when you need one, what it must provide, and how to start without stopping work.
- E-InvoicingZATCA Wave 25 of E-Invoicing: Is Your Business In, and How to Integrate by February 2027ZATCA announced Wave 25 of e-invoicing, halving the threshold to SAR 187,500. If your VAT revenue passed that in any year from 2022 to 2025, you must integrate by 1 Feb 2027.
- Data ProtectionCollecting Fan Data the Right Way: PDPL-Compliant World Cup 2026 Marketing for Saudi BusinessesWith the 2026 World Cup under way, brands are collecting huge volumes of fan data. Learn to run PDPL-compliant campaigns: consent, data minimization, individual rights, and secure retention.
- Data ProtectionSDAIA's PDPL Compliance Verification Form: What Your Business Must Prove NowSDAIA is now circulating a PDPL Compliance Verification Form to Saudi data controllers. Here is what it demands, the penalties, and how to get your business ready.
- E-commerceSaudi E-commerce Law 2026 and Maroof: What Your Store Must Comply WithA practical guide to making your online store comply with the Saudi e-commerce law and Maroof: disclosure, the 7-day return right, data protection, and penalties.
Have a project in mind?
We build custom systems, apps and websites for your business. Tell us your idea and we will give you a straight answer on it.
