African Lawyers Must Move From Using AI to Shaping its Governance

By Patricia Ainembabazi |

Artificial Intelligence (AI) is rapidly changing legal practice, presenting challenges for effective and accountable governance, professional responsibility, and the protection of clients’ rights and interests. Lawyers must develop institutional capabilities and learn how to verify AI-generated legal research and evidence, protect confidential information, challenge harmful automated decisions, and participate in shaping the policies governing these technologies.

These issues were at the heart of the AI Masterclass held during the 2026 Pan African Lawyers Union (PALU) Conference in Cairo, Egypt, themed “The African Lawyer in the Age of AI”. The masterclass was convened by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) and the African Legal Information Institute (African LII).

The discussions recognised that AI competence is increasingly becoming part of professional responsibility. Lawyers are already using AI for research, legal drafting and review, due diligence, and case preparation. However, while these tools can improve efficiency, they also introduce risks around confidentiality, legal privilege, client data, hallucinated authorities, intellectual property, bias and professional negligence.

Through a practical exercise involving an AI-generated legal opinion containing fabricated authorities and unsupported conclusions, participants considered a fundamental professional principle: “the lawyer remains responsible for the work, even where AI assisted in producing it”.

The session consequently emphasised a source-first approach to AI-assisted legal research. The African LII and National Legal Information Institutes (LIIs) provide authoritative primary legal sources that lawyers can use to ground and verify AI-generated analysis.

Participants explored a workflow that starts by locating the relevant primary law, providing authoritative source material to an AI tool, constructing a controlled legal prompt, and then checking the response against the original source. This approach is particularly important in jurisdictions where legal information may be fragmented and general-purpose AI systems may produce incomplete, outdated, or fabricated legal authorities.

The Cairo AI masterclass builds on CIPESA’s efforts to enhance the capacity of legal practitioners in technology governance and digital rights. Indeed, as part of the upcoming Forum on Internet Freedom in Africa (FIFAfrica26) slated for September 28 – October 1, 2026, in Mauritius, CIPESA and PALU will convene a litigation surgery and a session on how Bar Associations can champion internet freedom in Africa.

The AfricanLII, CIPESA and PALU masterclass reinforced AI literacy and professionalism for lawyers. Already, AfricanLII has trained more than 400 lawyers from across the continent on AI, including in Dakar, Abidjan, Accra and Dar es Salaam.

Beyond responsible use of AI, the masterclass addressed how lawyers can respond when algorithmic systems contribute to discriminatory decisions, unlawful biometric surveillance, technology-facilitated gender-based violence, exclusion from public services and opaque algorithmic scoring. This raised emerging litigation questions around access to algorithmic evidence, explainability, discovery and disclosure, expert evidence, jurisdiction, liability and appropriate remedies.

The evidentiary implications are equally significant. Deepfakes, fabricated documents, and synthetic media complicate traditional assumptions about the authenticity and reliability of evidence. Lawyers will increasingly need to interrogate provenance, authentication and admissibility when AI-generated or manipulated material enters the evidentiary record.

The masterclass connected these practical challenges to Africa’s wider regulatory environment. Its central proposition was that lawyers should not wait for comprehensive AI legislation before engaging with AI governance processes. Existing laws, such as those on data protection, already regulate significant aspects of AI use, while gaps in those frameworks create new opportunities for legal practice, litigation and policy advocacy. Lawyers must therefore be present not only in courtrooms but also in the policy processes where the rules governing AI are being designed.

The deliberations identified priorities for law firms, bar associations, judiciaries, governments and civil society organisations. They include continuing professional development, model AI-use policies, strategic litigation, judicial guidance, regulatory engagement, procurement transparency and stronger collaboration between lawyers and technologists.

The masterclass pointed to seven practical actions for African lawyers and bar associations:

  1. Develop professional AI-use policies for law firms and bar associations with clear guidance on confidentiality, privilege, client data, verification of AI-generated work, professional supervision, and responsibility for AI-assisted legal advice.
  2. Adopt source-first AI-assisted legal research, where AI outputs do not substitute authoritative legal sources. Lawyers should ground prompts in primary law and independently verify propositions, citations and authorities before relying on them.
  3. Bar associations should engage judiciaries and public institutions on procurement transparency, human oversight, data governance, evidentiary integrity and mechanisms for challenging AI-assisted decisions.
  4. Lawyers should begin testing existing constitutional, administrative, data protection and other legal remedies through litigation where algorithmic systems affect rights, while developing strategies for obtaining and interrogating algorithmic evidence.
  1. Lawyers and bar associations should monitor national AI strategies and regulatory consultations, make coordinated submissions and ensure that emerging policy frameworks incorporate human rights, due process, transparency, accountability and access to remedy.
  2. Bar associations, law societies and African legal-policy organisations should seek representation in processes such as the UN Global Dialogue on AI Governance, AI for Good, the Internet Governance Forum, the Africa AI Governance Summit and specialist law-and-governance conferences.
  3. African lawyers should, beyond attending conferences, submit proposals, contribute evidence from African jurisdictions, shape standards and negotiating positions, and build coalitions capable of translating global principles into enforceable domestic and regional safeguards.

Ultimately, the masterclass demonstrated that lawyers have a role throughout the AI lifecycle: advising on responsible use, assessing legal and rights risks, challenging harmful systems, scrutinising AI-generated evidence, shaping procurement safeguards, and participating in policy and regulatory processes.

The key issue facing the African legal profession is no longer whether lawyers will encounter AI within their practice. It is whether the profession will simply use technologies and operate under rules designed by others or actively shape how AI is deployed and governed across the continent.

Beyond AI Safety: Why Africa Needs Sovereignty and Agency in Global AI Governance  

By Lillian Nalwoga |

As artificial intelligence reshapes economies and everyday life, the essential question for African countries is not simply whether AI will be safe. It is whether African societies will have the power, infrastructure, skills, resources, and representation to shape how AI is built and used.

The Inaugural UN Global Dialogue on AI, held in July 2026, among its priorities called for the need for “safe and inclusive AI” among others. However, the message from African delegates pointed to a broader concern. Safety without sovereignty and agency is not enough. Delegates pointed to limiting factors such as the lack of access to computing power, locally relevant data, technical expertise, financing, and meaningful influence over global AI rules. The speed of AI development intensifies these challenges. The preliminary report of the Independent International Scientific Panel on AI rightly warns that technological advances are moving faster than governments’ ability to adapt. This could create risks that can be severe, further worsening existing inequalities and undermine digital rights. The report further notes that steps to close these gaps do exist, but they require sustained investment in Member States’ capacity to shape, evaluate, and deploy AI.

Many African countries are now developing AI strategies and policies with the goal to harvest opportunities and mitigate AI risks. However, regulating alone without the necessary infrastructure, data, and human capacity are unlikely to deliver the desired outcomes. Moreover, as noted in the preliminary report, current global AI systems often overlook indigenous languages and cultures resulting in inaccurate outputs and systems that are poorly suited to local realities.

The need to protect data sovereignty was another issue that emerged clearly from the dialogue. Africa member states emphasized the need to have control over how their data is used, while ensuring that cross-border data arrangements are fair and mutually beneficial. For this to manifest, African countries would require access to computing capacity, high-quality data, skilled talent, sustainable financing, reliable electricity, and robust digital infrastructure to support meaningful AI development.

These concerns were further highlighted by the governments of Rwanda and Uganda, who noted that more than half of the world’s data centers are located in just a handful of wealthy countries, while Africa possesses less than 1 percent of global AI computing capacity. This systemic inequality risks entrenching dependence on foreign platforms, cloud providers, and AI models that are not designed for African contexts. Despite its significant contribution to the global AI economy in terms of critical mineral resources and social data, Africa is still too often positioned as a consumer rather than a shaper of AI technologies, standards, and governance.

This imbalance cannot be solved by ethical principles alone. From an African perspective, AI governance is not only a regulatory exercise; it is an infrastructure, development, and justice agenda. African member states at the Dialogue reinforced this message. Government delegates from Rwanda and Kenya for instance highlighted the need to expand access to infrastructure and financing, invest in skills and talent, reduce regulatory fragmentation, and build on regional initiatives such as the Africa Declaration on Artificial Intelligence. Other delegates similarly stressed that AI must be transparent, accountable, and subject to meaningful human oversight. The protection of underrepresented languages, cultures, and data, as well as concrete forms of international cooperation, was also highlighted.

The priorities identified by African stakeholders. This distinction should define the future of the Dialogue. Unlike what was seen at the India AI Summit, the UNGDIA drew many high-level African government delegations, who clearly voiced the continent’s priorities for advancing AI. African participation and that of the Global South must go beyond consultation after key decisions have been made. Stakeholders from the Global South should play a leading role in setting priorities, developing standards, and monitoring AI implementation. The challenge for the Dialogue is therefore not only to identify risks but also to ensure that countries have the capacity to prevent them and to benefit from AI on fair and equitable terms. The choice should not be between innovation and rights. The Dialogue must ensure that AI advances development without compromising dignity, privacy, equality, or democratic participation. This is also anchored in calls by civic actors from the Global South, who have long called for not merely inclusion in global AI discussions but also a South-led rights-based AI paradigm grounded in planetary limits, democratic participation, and intergenerational justice. Additionally, CIPESA’s research on AI impact in Africa has highlighted the need for a human-rights approach to AI regulation and the adoption of a human- centred AI governance in Africa, through deliberated and inclusive approaches.

Moreover, the UN Global Dialogue on AI can make a meaningful contribution by moving from issuing broad statements to practical, measurable actions anchored in Africa’s sovereignty, agency, and capacity to shape its own digital future. As the dialogue moves into its intersessional phase, it must shift from discussion to action. Global South governments and civil society are demanding equal footing in AI governance, and the UN must listen. One way to do this would be for the UN to champion a consolidated fund for AI development and capacity building in the Global South. The UN Secretary-General suggested creating a Global Fund on AI with a target of $3 billion to facilitate building basic AI capacity in developing countries. According to him, this is “less than one per cent of the annual revenue of a single tech company.” If successfully adopted, it could help launch AI development initiatives in many Global South countries. However, relying solely on tech companies is unlikely to address Africa’s and the wider Global South’s AI challenges. That is why African countries are calling for a holistic approach to AI investment. The 2025 Africa Declaration on Artificial Intelligence proposes the creation of a $60 billion Africa AI Fund financed by public, private, and philanthropic capital. The fund will support AI infrastructure, African AI businesses, workforce development, and domestic research capacity. It still remains unclear when these funds will take effect.

Nonetheless, more efforts are still needed to create public awareness on the ethical use of AI while also strengthening civil society voices in advocating for human rights respecting AI development.

FIFAfrica26 is calling! How Will You Answer?

By FIFAfrica |

Accept the call and come ready to “Be The Experience”!

At the upcoming Forum on Internet Freedom in Africa 2026 (FIFAfrica26), be ready to do lots of the following:

  • Connect and meet people beyond your usual networks.
  • Question by bringing the difficult questions.
  • Learn by stepping into conversations beyond your usual area of work
  • Contribute through sharing your experience, ideas and perspective
  • Collaborate and find people you can build with
  • Experience and make the Forum your own!

As you enjoy the weekend, take a little time to think about what you are bringing to FIFAfrica26, what you hope to take away, and the conversations you want to be part of.

We look forward to engaging with you more next week as we get closer to the Forum.

Until then, get ready to Accept the Call and #BeTheExperience!

If you haven’t yet registered for FIFAfrica26, you can still do so here.

Mozambique’s Internet Shutdown Case: African Courts Draw a Line on Executive Power

By CIPESA Writer |

In July 2026, Mozambique’s Constitutional Council ruled that before a government can justify an internet shutdown, it must first have lawful authority to order one. The ruling signifies that before governments restrict connectivity, they must be able to show not only that the power to do so was lawfully created, but that it was exercised by a legally authorised authority.

The ruling comes against a wider pattern across the continent, where governments have used internet shutdowns to silence dissent and restrict fundamental rights.

The Constitutional Council declared 18 provisions of the Telecommunications Traffic Control Regulation (Decree No. 48/2025) unconstitutional, following a petition from the Center for Democracy and Human Rights. These provisions granted the telecommunications regulator, the National Communications Institute of Mozambique (INCM), broad powers to control telecommunications traffic, collect user data, intervene in operators’ networks using its own technology without their consent, and monitor communications on stated grounds including protecting state security and mitigating fraud.

The Council’s ruling was not about a recently imposed internet shutdown. Instead, it examined provisions of the regulation that gave the authorities powers to monitor communications, collect data, suspend telecommunications services and intervene in networks. The question was whether those powers could be created through regulation without a sufficient basis in legislation enacted by Parliament. The Council found that they could not, holding that the executive had effectively assumed the role of Parliament in defining the essential content of fundamental rights.

The Council described this as “organic unconstitutionality” and held that powers capable of restricting fundamental rights could not be created through executive regulation alone, but required parliamentary legislation that complies with constitutional and human rights protections.

In the Constitutional Council’s words, the provisions “substituted the Government for the Assembly of the Republic’s legislature in defining the essential content of fundamental rights”, contrary to Article 178 of the Constitution.

The Mozambique ruling also helps clarify three contentious questions emerging in shutdown litigation across the continent. What law permits the restriction, and who is authorised to order it? Which rights does it affect, including freedom of expression and access to information? And even where a legal power exists, is the restriction genuinely necessary and proportionate to the stated aim?

A Regional Pattern of Unlawful Interference
Mozambique’s ruling mirrors a broader African legal front against arbitrary internet shutdowns. Across the continent, governments have used shutdowns to restrict political opposition, communication, mobilisation, assembly, association and protest, in some cases without a sufficient legal basis.

In January 2019, the High Court of Zimbabwe ruled that the state security minister had no legal authority under the Interception of Communications Act to order an internet shutdown or issue an intercept directive to mobile network operators. The shutdown was ordered amid nationwide protests against rising fuel prices, but was later restored.

In Togo, the ECOWAS Community Court of Justice found that Togo’s three-day internet shutdown during the 2017 protests violated freedom of expression under Article 9 of the African Charter because it lacked authorisation under national law. The Court also ordered compensation to the applicants for the violation of their right to freedom of expression. The judgment affirmed that access to the internet enables people to exercise rights that are already protected, particularly freedom of expression and access to information.

In Nigeria, the court reached a similar conclusion, finding that the government’s seven-month suspension of Twitter violated freedom of expression, access to information, and media freedom. It described access to the platform as “a derivative right that is complementary to the enjoyment of the right to freedom of expression.”

The case of Association des Blogueurs de Guinée (ABLOGUI) and three others against Guinea shows that a legal basis alone is not enough. In that case, the ECOWAS Court found that restrictions on internet and social media access between October and December 2020 violated the applicants’ rights to information and freedom of expression. The case reinforces the rule that a government must show not only that a restriction is authorised by law, but also that it serves a legitimate aim and is necessary and proportionate.

In Senegal, the shutdowns imposed during the 2023 unrest violated freedom of expression and access to information for both applicants. The court also upheld Ndiaga Gueye’s individual claim that the shutdown violated his right to work as an IT consultant. The case illustrates that shutdowns can disrupt far more than speech. They can cut people off from work and other essential digital services, while disrupting journalism, education, payments and access to health information.

Strengthening Preventive Safeguards
Courts are not the only institutions shaping this debate. For years, the African Commission on Human and Peoples’ Rights (ACHPR) has set continental standards on open internet access. The Commission’s resolutions and declarations do not carry the same legal force as court judgments. Still, they provide important guidance on how African states should protect freedom of expression, access to information, and access to the internet.

Its 2019 Declaration of Principles on Freedom of Expression and Access to Information in Africa, Principle 38(2), provides that states “shall not engage in or condone any disruption of access to the internet and other digital technologies for segments of the public or an entire population.”

In March 2024, the Commission went further in Resolution 580, calling on states to ensure open and secure internet access before, during, and after elections, and to refrain from ordering shutdowns or disrupting digital communication platforms during the electoral process.

Conclusion
Despite judicial victories, the threat remains pervasive, and litigation alone is insufficient when judgments arrive years after the harm. In 2025, the #KeepItOn coalition recorded 30 shutdowns across 15 African countries.

There must be independent oversight, public transparency, and effective ways for people affected by an unlawful restriction to challenge it and seek redress. Telecommunications operators should also be protected from being forced to carry out unlawful orders. Only then can we ensure that the digital rights of millions are protected from the arbitrary exercise of power.

Mozambique’s ruling affirms that digital rights are not subject to executive whim. Governments must respect the rule of law, ensuring that restrictions on connectivity that limit fundamental rights are grounded in parliamentary legislation and subject to rigorous constitutional safeguards.

Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses

By Doreen Elizabeth Namuyanja |

Uganda’s digital economy is expanding rapidly across finance, transport, agriculture, commerce, healthcare and public-service delivery. However, this growth is outpacing the legal, regulatory and institutional safeguards needed to address emerging concerns around personal and biometric data, artificial intelligence, platform work, digital exclusion and internet shutdowns.

Drawing on a 2025 survey, two commentaries and a policy submission by CIPESA, this policy brief examines Uganda’s evolving digital business landscape, business data practices, the future of work and the impact of internet disruptions. It highlights the gaps between technological advancement and effective governance and proposes actions for government, businesses, private sector associations and civil society to build an inclusive, resilient, and rights-respecting digital economy.

The brief finds that Uganda has established important legal protections, including the Data Protection and Privacy Act of 2019. The principal challenge, however, is implementation, enforcement, and the ability of regulatory and institutional frameworks to adapt to rapidly evolving technologies and business models. Businesses frequently collect personal and biometric data without sufficiently explaining how it will be used, stored, shared, or deleted. Meaningful consent, data security, and effective retention and deletion practices also remain inconsistent, particularly among businesses with limited compliance capacity.

These gaps have consequences beyond privacy and individual rights. Weak data governance can undermine trust in digital services, while inadequate safeguards for platform workers and persistent digital exclusion can limit who benefits from the digital economy. Internet shutdowns pose a broader threat, disrupting digital financial services, e-commerce, public services and other activities that increasingly depend on reliable connectivity.

The brief calls for coordinated action by government, businesses, private sector associations and civil society to:

Businesses

  • Strengthen data governance and informed consent: implement collection and processing frameworks built on explicit, freely given consent, backed by clear, accessible privacy notices.
  • Improve data security and lifecycle management: adopt encryption, regular security audits, and clear retention, deletion and minimisation policies.
  • Build organisational compliance capacity: appoint and train Data Protection Officers, embed privacy-by-design into product development, and run regular staff training on data protection, cybersecurity and phishing risks.
  • Strengthen digital resilience: develop business continuity plans for internet disruptions, and collaborate with civil society and legal actors to promote an open, secure and reliable internet.

Government of Uganda

  • Strengthen enforcement of the data protection framework by adequately resourcing the Personal Data Protection Office (PDPO) and other regulators to conduct audits, investigate violations, and impose proportionate sanctions.
  • Modernise the legal and policy framework to address biometric data, AI and platform work, aligned with constitutional and international human rights standards, and issue practical, sector-specific guidance to help businesses, particularly SMEs, comply.
  • Promote digital inclusion and public awareness through sustained education campaigns, including in local languages, and continued investment in affordable infrastructure and digital skills.
  • Safeguard the digital economy against internet disruptions by developing clear legal safeguards against shutdowns and ensuring any restrictions comply with constitutional and international human rights obligations.

Private Sector Associations

  • Build members’ capacity through regular training on data protection, cybersecurity, AI governance and business continuity planning.
  • Promote industry standards and peer learning by developing model policies and compliance toolkits for consistent implementation across member organisations.
  • Support risk management by encouraging periodic risk assessments among members and facilitating the sharing of lessons learned and mitigation strategies.

Civil Society Organisations

  • Strengthen multi-stakeholder collaboration among government, businesses, academia and technical experts on data protection, AI governance and digital rights.
  • Promote public awareness and digital rights literacy through accessible educational materials and community outreach.
  • Undertake research and evidence-based advocacy on biometric data governance, AI, platform work and internet shutdowns, including documenting their social, economic and human rights impacts, to support stronger legal frameworks and strategic litigation.
  • Support business compliance and resilience by developing practical guidance, templates and capacity-building support on responsible data governance.

Read the full brief here.