Home / Blogs

Africa Is Adopting AI but Who Is Governing the Risks?

Artificial intelligence is becoming part of Africa’s digital transformation. Governments are exploring AI for public services, healthcare, education, agriculture, tax administration and fraud detection. Businesses are adopting AI tools to improve productivity, automate processes and compete in an increasingly digital economy.

The opportunity is significant.

But as African countries move from experimenting with AI to integrating it into critical systems, a more difficult question deserves attention: Who governs the risks when AI becomes part of the infrastructure society depends on?

This is not simply a question about whether AI should be adopted.

It is a question about who controls it, who is accountable when it fails, how it is secure, and whether institutions have the capacity to govern systems they may not have designed or developed.

Africa’s AI conversation must move beyond adoption.

It must address governance.

The AI conversation is moving faster than institutional readiness

Across the continent, governments are developing AI strategies, exploring regulatory approaches and identifying opportunities to use AI in public administration.

Yet AI governance remains an evolving field.

Yilma and Wodajo (2026), in their introduction to a special section of Science and Public Policy, examine how African countries are approaching AI governance through national and continental strategies. Their analysis highlights the need to look beyond the excitement surrounding AI and examine the assumptions and governance approaches embedded in these initiatives.

This is important because a national AI strategy is not the same as an operational governance system.

A strategy may identify priorities, establish ambitions, and describe principles.

But institutions still need to determine who approves AI systems, who evaluates their risks, who monitors their operation and who is responsible when something goes wrong.

A government can announce its intention to use AI without having established the technical, legal and institutional arrangements required to oversee it.

That is where the governance challenge begins.

AI introduces a new dimension to cybersecurity

For years, cybersecurity governance has focused on protecting systems, networks, applications and data. AI does not eliminate those responsibilities. It expands them.

An AI-enabled public service may depend on cloud infrastructure, external APIs, third-party models, training data, software libraries, identity systems, and interconnected government databases.

Each dependency introduces potential risks. A model can produce unreliable outputs. A dataset can contain inaccurate or manipulated information. An AI application can expose sensitive information through inappropriate access or insecure integration. A malicious actor can attempt to manipulate model inputs, compromise an AI supply chain or exploit weaknesses in the systems surrounding a model.

The consequences become more serious when AI is integrated into healthcare, financial services, digital identity or critical public infrastructure.

The problem is not that every AI system will fail.

The problem is that governance arrangements designed for conventional information systems may not fully address the additional risks introduced by AI.

A 2026 study by Ibekwe, Mbanaso, and Ibekwe, published in the Journal of Policy and Development Studies, proposes a multi-tiered framework for AI-driven cybersecurity governance in Africa. The authors argue that effective AI cybersecurity depends substantially on governance structures, institutional capacity, and ethical oversight, rather than technological sophistication alone.

This reinforces an important point: AI security is not only a technical capability. It is an institutional responsibility.

Who is accountable when an AI system makes a harmful decision?

Consider a government agency using AI to support decisions about welfare eligibility, healthcare prioritization or public-service access.

An algorithm may recommend that an application be rejected. A public official may rely on that recommendation. The vendor may argue that the system operates according to its technical specifications. The agency may argue that the final decision was made by a human. And the affected citizens may have no clear way to understand or challenge the outcome.

Who is accountable?

This is not a hypothetical governance problem confined to Africa. It is a central question in public-sector AI governance.

Mhlanga (2026), in a review published in Frontiers in Big Data, examines AI applications in African public services, including welfare targeting, healthcare, taxation and urban governance. The study identifies institutional capacity and human oversight as important conditions for achieving responsible governance outcomes.

The implication is that deploying AI does not remove the responsibility of public institutions.

If anything, it increases the need for clear accountability. A public institution cannot transfer its responsibility to an algorithm simply because a vendor supplied the technology. Nor should a vendor’s technical assurances replace independent scrutiny of how a system is used.

AI governance needs clear answers to several questions:

  • Who authorises the use of an AI system?
  • Who is responsible for assessing its risks before deployment?
  • Who monitors its decisions and performance?
  • Who investigates incidents or harmful outcomes?
  • How can affected individuals challenge decisions?

Without clear answers, responsibility can become fragmented across agencies, technology providers and technical teams.

Digital sovereignty becomes more complicated in the age of AI

The question of who governs AI is also a question of digital sovereignty. In previous discussions about digital sovereignty, the debate has often focused on data centers, cloud infrastructure, data localization and control over critical digital systems. AI adds another layer.

A country may host its public-sector data locally while depending on foreign-developed models, external computing infrastructure, proprietary software and overseas service providers.

Local data storage does not necessarily provide control over the technology processing that data. A government may own the database but have limited visibility into how an externally hosted model processes information, how it generates outputs or how changes to the model affect public services.

This does not mean that foreign AI systems should automatically be rejected. International technology partnerships can provide access to capabilities that individual countries may find difficult or expensive to develop independently.

The question of governance is whether those partnerships preserve meaningful institutional control. A government should understand the dependencies it is accepting, the risks it is assuming and the arrangements available if a provider changes its terms, discontinues a service or experiences a major security incident.

For Africa, AI sovereignty should therefore not be reduced to building every model domestically. It should include the ability to assess, procure, secure, monitor and, where necessary, replace AI systems. The ability to govern technology is an important dimension of sovereignty, even when that technology is developed elsewhere.

African AI governance must reflect African realities.

There is another challenge.

Many of the dominant AI governance frameworks have emerged from institutions and regulatory environments outside Africa.

These frameworks offer useful principles, including transparency, accountability, privacy, safety and human oversight. But translating principles into practice requires attention to local institutional and social conditions.

In a 2025 article in Ethics and Information Technology, Yilma examined the relationship between Ubuntu, AI ethics and emerging African AI governance initiatives. The paper questioned whether existing initiatives provide a sufficiently clear and practical articulation of African perspectives on AI ethics and called for relevant actors on the continent to help define those perspectives.

This is an important distinction.

Developing an African approach to AI governance does not require rejecting international principles. It requires examining how those principles can be applied in African contexts and whose interests they are designed to protect.

For example, an AI system used in a multilingual public-service environment must account for local languages and differences in access to technology. A system used in healthcare must consider data protection, clinical accountability and the consequences of unreliable outputs.

A system used in public administration must provide meaningful ways for citizens to question decisions that affect them. And a system used in critical infrastructure must be assessed against the consequences of disruption, manipulation or compromise.

African AI governance should be grounded in the needs of the people and institutions affected by AI, rather than treated as a straightforward transfer of external frameworks.

The danger of governing AI only through strategy documents

One of the risks facing African countries is the assumption that publishing an AI strategy or adopting a set of principles is sufficient.

Strategies matter.

They establish direction and can help coordinate public and private investment. But governance also requires operational capacity. A functioning AI governance system needs institutions that can evaluate technical claims, assess cybersecurity risks, understand data dependencies, and enforce relevant obligations. It also needs coordination between organisations responsible for data protection, cybersecurity, telecommunications, public administration and sector-specific regulation.

The OECD’s 2026 report on strengthening AI governance in Africa identifies institutional coordination, regulatory capacity, and technical expertise as important challenges. It also notes that AI governance responsibilities are often distributed across institutions, with coordination mechanisms still developing.

This creates a practical problem.

AI systems do not respect traditional administrative boundaries. A single public-sector AI application may involve a government ministry, a technology vendor, a cloud provider, a data protection authority, and a cybersecurity agency.

If their responsibilities are unclear or disconnected, important risks can fall between institutional mandates. The answer is not necessarily to establish a new regulator for every emerging technology. It is to ensure that existing institutions have clear responsibilities, appropriate expertise and effective mechanisms for working together.

Cybersecurity must be built into AI procurement.

For public institutions, one of the most practical places to begin is procurement. Governments frequently depend on external providers to supply digital systems and technical expertise. AI procurement introduces additional questions that should be addressed before a contract is signed.

  • What data will the system access?
  • Where will that data be processed?
  • Can the provider use institutional data to improve or train its models?
  • What security controls protect the system and its interfaces?
  • Can the institution independently assess the system’s performance?
  • What happens if the provider changes the model or withdraws the service?
  • How will incidents be reported and investigated?
  • Can the institution retrieve its data and transition to another provider?

These are not merely technical questions for IT departments.

They affect legal obligations, public accountability, institutional continuity, and national resilience. A procurement process that evaluates only cost, functionality, and delivery timelines may overlook important long-term governance risks.

AI procurement should therefore involve cybersecurity professionals, legal teams, data protection officers, operational departments, and senior institutional decision-makers.

It should also include proportionate requirements for testing, monitoring, documentation, and incident response. The objective is not to prevent public institutions from adopting AI. It is to ensure that the conditions of adoption do not undermine their ability to govern the systems they acquire.

Africa needs an AI governance architecture, not just AI ambition.

A practical approach should connect governance to three levels.

  • National level: Governments need clear legal responsibilities, coordinated regulatory institutions, appropriate cybersecurity capabilities, and mechanisms for accountability.
  • Sectoral level: Healthcare, finance, education, telecommunications, and other sectors need governance requirements that reflect the consequences of AI failures in their respective environments.
  • Institutional level: Individual organizations need AI inventories, risk assessments, procurement controls, security monitoring, incident-response procedures, and clearly assigned responsibility for AI-enabled decisions.

These levels should reinforce one another.

National policies cannot provide effective governance if sectoral institutions lack implementation capacity. Sectoral standards cannot succeed if individual organizations do not have the people, processes, and technical resources to apply them.

And institutional controls may be insufficient when national laws and regulatory responsibilities remain unclear. The challenge is to connect these levels into a functioning system. This is especially important for smaller institutions that may not have the resources to develop sophisticated AI governance capabilities independently.

Shared technical expertise, regional cooperation, common standards, and capacity-building programmes can help reduce the burden.

The question Africa should ask next

Africa has legitimate reasons to pursue AI. Technology can support public services, research, healthcare, agriculture, cybersecurity, and economic development. But adoption should not be treated as the final measure of progress. A country can deploy AI without developing the institutional capacity to govern it. It can purchase advanced systems without gaining meaningful control over its technological dependencies. It can publish ethical principles without establishing clear accountability when those principles are violated. And it can automate public services without ensuring that citizens can question or challenge the decisions that affect them.

The next phase of Africa’s digital transformation must address these questions directly. The goal should not be to adopt AI as quickly as possible, nor to reject it because of the risks. It should be to build the institutional capacity to use AI responsibly, securely, and in ways that serve public interests.

That means investing in cybersecurity expertise, strengthening regulatory coordination, improving procurement practices, and ensuring that human accountability remains meaningful. It also means recognizing that AI governance is not a responsibility that belongs exclusively to technology companies or technical departments.

It is a responsibility shared by governments, regulators, institutions, researchers, businesses, and the communities affected by these systems. Africa’s AI future will depend not only on the technologies it adopts but also on the institutions it builds around them. The real question is no longer simply whether Africa is ready to adopt AI. It is whether Africa is building the capacity to govern what it adopts.

That is where responsible AI adoption must begin.

References

  1. Ibekwe, U. U., Mbanaso, U. M., & Ibekwe, D. U. (2026). A multi-tiered framework for AI-driven cybersecurity governance in Africa: Pathways to cyber resilience and sustainable development. Journal of Policy and Development Studies, 20(3), 334–362. https://doi.org/10.4314/jpds.v20i3.17
  2. Mhlanga, D. (2026). Using artificial intelligence to improve governance and public services in Africa. Frontiers in Big Data, 9. https://doi.org/10.3389/fdata.2026.1835663
  3. OECD. (2026). Strengthening AI governance in Africa. OECD Artificial Intelligence Papers. OECD Publishing.
  4. Yilma, K. (2025). Ethics of AI in Africa: Interrogating the role of Ubuntu and AI governance initiatives. Ethics and Information Technology, 27. https://doi.org/10.1007/s10676-025-09834-5
  5. Yilma, K., & Wodajo, K. (2026). Strategy as governance: The governance of AI in Africa. Science and Public Policy, 53(2), 236–244. https://doi.org/10.1093/scipol/scag011
NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Abubakari Saddiq Adams, Business IT & IT Legal Consultant, Cybersecurity & IT Governance Specialist

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

DNS Security

Sponsored byWhoisXML API

IPv4 Markets

Sponsored byIPv4.Global

DNS

Sponsored byDNIB.com

Domain Names

Sponsored byVerisign

Brand Protection

Sponsored byCSC

Cybersecurity

Sponsored byVerisign

New TLDs

Sponsored byRadix