CIPESA Weighs in on Kenya’s Draft Guidance Notes on AI and Emerging Technologies

By Raylenne Kambua |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) submitted comments on two draft Guidance Notes that Kenya’s Office of the Data Protection Commissioner (ODPC) opened for public participation: one on Artificial Intelligence (AI), and another on Emerging Technologies.

The draft Notes provide guidance to entities on how to make sure their AI systems and emerging technologies comply with the Data Protection Act, 2019. While this is a positive step toward the responsible adoption and deployment of AI and emerging technologies, CIPESA highlights gaps the ODPC should address to ensure these technologies are governed in a rights-respecting, transparent, and accountable manner.

CIPESA’s Comments on the Draft Guidance Note on AI

A first set of concerns relates to how the AI Note fits with other legal frameworks. The Note cites only national laws, yet AI in Kenya operates within a wider regional and international framework, which risks regulatory inconsistency. Continental frameworks such as the AU Continental AI strategy, the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) and the AU Data Policy Framework offer guidance on AI development and harmonised data governance.

The Note requires entities to conduct adequacy assessments before transferring AI-processed personal data across borders. Although intended to protect privacy, this requirement could trigger blanket data localisation and impede cross-border AI inference and cloud computing capabilities. CIPESA recommends aligning these assessments with the AU Data Policy Framework and the African Continental Free Trade Area (AfCFTA) Protocol on Digital Trade to balance privacy safeguards with Africa’s digital trade ambitions.

As AI is increasingly deployed as an assistive technology, it risks excluding persons with disabilities when training data and biometric information are developed without their input. CIPESA observes that the Note omits Article 54 of the Constitution of Kenya, which protects persons with disabilities. Incorporating this provision would align the guidance with other standards, which set a benchmark for how regulation can protect groups that AI systems often overlook.

Furthermore, the draft Note lacks cross-references to the ODPC’s 2025 Guidance Note for Processing Children’s Data, and the Children Act, 2022, which enforces online protection and the best-interest principle for minors. This shortcoming creates disharmony among related efforts on children’s protection.

The submission points to the 2025 High Court judgment against Worldcoin, which found that iris data from hundreds of thousands of Kenyans was processed without a Data Protection Impact Assessment (DPIA). The Note’s biometric provisions prohibit only real-time surveillance without legal authority. This leaves retrospective analysis of stored facial or iris images unregulated, even though it carries equivalent privacy risks. CIPESA advocates mandatory pre-deployment registration with the ODPC and submission of DPIAs before any biometric data processing begins.

As generative AI spreads, so do its risks, such as hallucination. CIPESA recommends implementing verifiable content records and labelling requirements, such as watermarking or equivalent disclosure, for synthetic media used in decisions affecting individuals. This aligns with constitutional consumer rights under Article 46 and supports digital trust in continental trade involving automated electronic services covered by the AfCFTA Digital Trade Protocol.

The AI shaping Kenyans’ daily consumption centres around algorithmic feeds rather than enterprise chatbots. CIPESA argues that if AI laws regulate only technical enterprise tools while ignoring social media algorithms and content curation systems, they risk missing the AI that mostly shapes consumers’ public discourse. Global and local platforms that process Kenyan users’ data must also be subject to algorithmic governance and regular audits.

CIPESA also notes that the Note’s high-risk AI table omits information systems deployed in political and electoral environments. This is despite political opinion being classified as sensitive personal data under major data protection laws, and the AI Bill, 2026 addressing synthetic political content. CIPESA recommends adding categories for AI in political communication, voter micro-targeting, and synthetic political media ahead of the 2027 general election.

Other recommendations concern who the rules protect and who they hold to account. Kenya’s data annotators, content moderators, and reinforcement learning from human feedback (RLHF) workers help train both local and foreign AI models. However, the Note’s obligations focus entirely on end-user rights. CIPESA calls for extending data protection rights to this workforce, including protections over performance and monitoring data collected about them.

The Note requires entities to register with the ODPC as data controllers or processors before deploying any AI system that processes personal data. However, it does not address the separate Commissioner-maintained public register of high-risk AI models that is proposed under the AI Bill, 2026. CIPESA recommends clarifying how registration functions will be divided between the ODPC and the prospective AI Commissioner.

Regarding Digital Public Infrastructure such as interoperable digital identity systems, the Social Health Authority’s premium assessments, and the Kenya Revenue Authority’s automated eTIMS processes, CIPESA advises mandatory pre-deployment DPIAs, equity assessments before deployment, publicly disclosed methodologies, and human review guarantees.

Finally, AI governance is incomplete if it regulates companies but leaves government and security agencies outside meaningful oversight and accountability. CIPESA warns that without accountability for state use of AI in public services and surveillance, critical systems remain unmonitored. Citizens should be able to challenge public sector AI decisions just as they can challenge those of private entities.

CIPESA’s Comments on the Draft Guidance Note on Emerging Technologies

CIPESA also submitted comments on the Draft Guidance Note on Emerging Technologies. On cloud computing, it cautions that restricting systems tied to “the strategic interests of the state” risks becoming a de facto data localisation rule. CIPESA recommends confining data localisation to cases where a specific statutory requirement applies, in line with the AfCFTA Digital Trade Protocol and the AU Data Policy Framework’s emphasis on responsible intra-African data flows.

The submission advocates a complete prohibition on real-time remote biometric identification and indiscriminate mass surveillance in public spaces. It warns against using biometric categorisation to infer sensitive traits, alongside AI-based emotion recognition in schools and workplaces. Law enforcement remote biometric identification must require legal authorisation, judicial warrant, and independent oversight.

To strengthen impact assessments, CIPESA suggests publishing executive summaries of all DPIAs, excluding trade secrets, on a public High-Risk Technology Register before deployment. This would improve transparency and accountability and build public trust in high-risk emerging technology deployments.

Concerning automated decisions, CIPESA recommends meaningful human review by a reviewer with real authority to overturn or modify the outcome, not a rubber stamp. This should apply specifically to decisions on employment, credit, insurance, healthcare, social protection, immigration, and policing. To reduce the compliance burden, CIPESA recommends simplified registration and DPIA templates.

Building on CIPESA’s Wider Work on Kenya’s AI Governance

The two submissions follow CIPESA’s August 2026 submission on the Draft Kenya AI and Other Emerging Technologies Policy, which raised similar concerns about institutional independence and biometric safeguards at the policy level. They also draw on the Navigating the Implications of AI on Digital Democracy in Kenya report and its regional companion. The AI Guidance Note’s argument on algorithmic feeds echoes Kenya Doesn’t Have an AI Regulation Gap, It Has an Accountability Gap and Who Holds Digital Power Accountable? Lessons from Platform Governance in Africa.

Read CIPESA’s full comments on the Draft Guidance Notes on AI here and on Emerging Technologies here.

Rethinking Africa’s Approach to the Politics of AI Governance and Regulation

By Paul Kimumwe |

The past few years have witnessed a growing urgency for frameworks that regulate and harness the development and implementation of new and emerging technologies, especially Generative Artificial Intelligence (Gen AI).

At the international and regional level, the United Nations (UN) and the African Union (AU) have established norms through resolutions, strategies and guidelines to affirm the relationship between technology and human rights, and provide benchmarks for Member States developing rights-respecting AI governance and regulatory frameworks.

In March 2024, the UN adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that also benefit sustainable development. The resolution also calls upon Member States and other stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”

The 2024 resolution reaffirmed that “the same rights that people have offline must also be protected online, including throughout the life cycle of artificial intelligence systems.” It called upon member states to ensure that national AI governance and regulatory frameworks “promote safe, secure and trustworthy artificial intelligence systems” that are inclusive and benefit everyone in an equal manner.

In August 2025, the UN adopted resolution 79/325, establishing the Independent International Scientific Panel on AI and Global Dialogue on AI Governance. It aims to provide a platform to discuss international cooperation, share best practices and lessons learned, and to facilitate open, transparent and inclusive discussions on AI governance. However, a year earlier, in July 2024, the AU adopted the Continental AI Strategy, which emphasises the development of robust governance regimes for AI founded on ethical principles, democratic values, human rights, and the rule of law, in line with the AU  Agenda 2063.

Both the UN resolutions on AI and the AU continental strategy came on the backdrop of other AI-related policy guidelines such as Center for AI and Digital Policy’s 2018 Universal Guidelines for AI, the Organization for Economic Cooperation and Development (OECD) 2019 AI Principles / G20 AI Guidelines, the United Nations Education Scientific and Cultural Organization (UNESCO’s) 2021 Recommendation on the Ethics of AI, and the European Union Commission’s (EUC) 2024 European Union AI Act.

Many African countries have been actively developing AI-related laws, policies, and strategies. Rwanda was the first to adopt a national AI policy in 2019, followed by Ghana’s National Artificial Intelligence Strategy in October 2022, Egypt’s National Artificial Intelligence Strategy in January 2025, and Kenya’s own strategy in May 2025. Benin, Côte d’Ivoire, Ethiopia, Mauritius, Nigeria, Tunisia, Zambia, and Zimbabwe are among others that have developed AI policies or strategies. Others, such as Burkina Faso, Guinea, Lesotho, Mali, Namibia, and Uganda, are still at different stages in developing their AI policies or strategies.

A case of history repeating itself?

While all these have been welcome developments in the governance and regulation of AI, studies show that the adoption of international and regional human rights instruments and national laws, policies and strategies is often just the first step in a long process. If not well managed, it often results in provisions that are, although of a progressive nature, are hard to implement and fail to address local needs and realities.

This is because the process of drafting these laws and strategies in many developing contexts is often devoid of meaningful multistakeholder consultations and engagement. Moreover, there has also been a tendency to adopt and replicate models from the global North, whose texts, while progressive, have faced strong resistance from Member States as they sometimes do not align with local contexts and cultural norms.

For example, many African countries, including Algeria, Ethiopia, Cameroon, Kenya, Mauritius, Namibia, Rwanda, South Africa, and Uganda, expressed strong reservations about certain provisions contained in the Protocol to the African Charter on Human and People’s Rights on the Rights of Women in Africa (Maputo Protocol).

Additionally, most of these models are state-centric and grounded in frameworks that create a distinct binary between duty-bearers and rights-holders, but do not articulate how and what each party needs to do to ensure meaningful implementation of the initiatives.

While the state-centric and rights-based approaches may seem attractive, in practice, their relevance in advancing digital rights is often undermined, especially when the prescribed provisions and action points do not align with the country’s current social, economic and political realities. Indeed, cases abound in which initial promises have fizzled over time due to the political leadership’s inaction (and sometimes unwillingness) to fully adopt and implement the resolutions or strategies.

For example, it took almost nine years for the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) to enter into force on June 8, 2023, after its adoption in 2014. Indeed, more countries (40) have enacted data protection laws as compared to those that have ratified (16), highlighting a disconnect between national legal reforms and their commitment to continental frameworks. Similarly, the AU Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa, adopted on January 30, 2018, took six years to enter into force, after the 15th ratification was achieved.

More critically, however, the lack of political will often reflect in the absence of clearly defined funding mechanisms for the implementation of these policies and strategies. As a result, even well-designed and progressive frameworks face implementation challenges due to structural flaws and insufficient funding.

For example, while Africa has scored highly in enacting Data Protection laws, which have become central to ongoing AI governance frameworks, one issue affecting their effective implementation is the lack of clear funding mechanisms for the regulatory bodies responsible for oversight and implementation. Other challenges include weak governance structures that deny these oversight bodies financial, decisional and operational independence and place them under the supervision of political appointees rather than parliament.

Designing for Failure?

Apart from Kenya, most African countries that have developed or are in the process of developing an AI strategy or policy do not provide for budgetary allocations or estimates for the implementation of their AI strategies, laws or policies. Countries such as Rwanda provide for a project-level funding framework, while others, such as Egypt and Mauritius, rely on programmatic budgets to fund the implementation of their strategies.

Even then, while implementation of Kenya’s National Artificial Intelligence Strategy (2025–2030) was costed at KSh 152 billion over a period of five years, a review of Kenya’s 2026/27 national budget shows no dedicated funding allocation for the strategy. Instead, the Sh8.6 billion allocated to the ICT sector mainly targets the expansion of broadband access, the strengthening of digital skills, and the digitisation of government services.

Additionally, in countries such as Ethiopia and Rwanda, while the policies provide for the establishment of an implementation body, several functions have been split across different ministries, departments and agencies (MDAs), which, in practice, would pose a significant challenge to meaningful execution.

For example, Rwanda’s AI policy mandates the Responsible AI office under the Ministry of ICT and Innovation to be responsible for effective tech implementation. It also positions the Rwanda Utilities Regulatory Authority (RURA) as the technical regulator responsible for developing ethical AI guidelines and principles, and the National Cyber Security Authority (NCSA) to oversee data protection compliance relevant to AI systems.

In Ethiopia, the policy designates the Ethiopian Artificial Intelligence Institute (EAII) as the national coordinating body responsible for implementation, standards development, and capacity building, and the Ministry of Innovation and Technology is responsible for providing policy oversight. Other sectoral agencies, such as the Ethiopian Communications Authority (ECA), the Ministry of Health, and the National Bank, have mandates over telecommunications and data matters, health-sector-related AI, and financial AI, respectively.

While a multisectoral approach to policy and strategic implementation can improve cohesiveness and legitimacy, the approach is prone to risks such as divergent priorities, internal conflicts, power struggles, and regulatory fragmentation, which are likely to affect how the policies and strategies are executed.

Implications for the Future of AI Governance and Regulation

In many African countries, the development of AI governance and regulatory structures is still in its infancy and presents a unique opportunity for Africans to shape their own destiny on how AI should be developed and deployed in ways that respond to and respect local needs and contexts.

Enactment of AI-specific Laws

In many countries, governments are relying on existing laws, such as data protection, communications, and cyber-related legislation, alongside the AI policies and strategies being developed. Given the evolving nature of AI, countries need to work towards enacting AI-specific laws that clearly define and contextualise AI.

Empowering the Oversight Bodies

As currently structured, many of the existing and proposed oversight bodies are either not yet operational or lack a clear mandate and sufficient resources for effective oversight. Additionally, many of them are situated within fragmented regulatory environments with overlapping responsibilities, which results in uncoordinated implementation. It is important, therefore, that the mandate of the oversight bodies and resources are clearly defined and guaranteed to ensure independence and eliminate the possibility of political interference.

Meaningful Stakeholder Participation

Having empowered stakeholders who are meaningfully engaged and participate in the development processes for policies, laws and strategies is critical to ensuring that the resulting instruments address real needs, are people-centred and implementable, and have government buy-in, as reflected in the government’s funded priorities.

Adopting a Human Rights-Centred Approach

A 2025 study by CIPESA shows that in many countries, the adoption of a human rights-centred approach to AI governance remains aspirational due to gaps in implementation, technical capacity, and stakeholder engagement in policy development and implementation. It is important, therefore, that current efforts prioritise safeguarding fundamental human rights and freedoms, enhancing human capabilities over replacement, and ensuring meaningful human control, transparency, fairness, and inclusivity in AI systems.

What Global South Civil Society Wants from AI Governance

By CIPESA Writer |

As global discussions on the future of Artificial Intelligence (AI) governance take place at the AI for Good Global Summit and the Global Dialogue on AI Governance, questions about who shapes AI systems, whose interests they serve, and how affected communities can participate in decision-making are becoming increasingly urgent.

The Collaboration on International ICT Policy for East & Southern Africa (CIPESA) is pleased to share this joint statement by the Global Digital Justice Forum and the Global South Alliance, of which it is a member. The statement reflects concerns that CIPESA has consistently raised through its research and policy engagement, namely, current approaches to AI development risk deepening existing inequalities, and meaningful AI governance requires stronger corporate accountability, equitable data governance, and investment in public-interest AI infrastructure.

Through submissions to national AI strategies in Africa, analysis of AI governance trends across 14 African countries, and engagement with global AI policy discussions, CIPESA has consistently advocated for inclusive, rights-based approaches that ensure communities most affected by AI developments have a meaningful role in shaping its future.

The statement below brings together civil society perspectives from across the Global South and calls for an AI governance approach grounded in human rights, equity, public interest, and meaningful participation.

Joint Statement issued by the Global Digital Justice Forum and the Global South Alliance in the lead-up to the Global Dialogue on AI Governance

July 2026

The current trajectory of Artificial Intelligence (AI) innovation has consolidated the neocolonial structures of development. Today, a handful of US and Chinese transnational corporations dominate global AI systems. Driven by massive capital, semiconductor manufacturing dominance, and hyperscale cloud infrastructure, these companies control over 90% of global AI data center capacity. Their market capitalization exceeds the combined national income of many countries in the Global South. The wealth and power amassed by these corporations come at a staggering cost, borne disproportionately by the South. From the devalued, dehumanizing labor that is essential for training AI models to the critical minerals, land, energy, and water, communities in the South continue to provide the scaffolding for the AI economy and society, without the voice and power to shape and benefit from this paradigm. These systemic injustices also perpetuate deep dependencies on current and future infrastructures — over which communities lack control and sovereign agency.

The Global Digital Justice Forum (GDJF) and the Global South Alliance (GSA) believe that the emerging AI order lacks legitimacy; it grants unbridled impunity to powerful corporations, while reducing humanity and nature to objects of limitless extraction. The many summits and conversations about AI governance have failed to tackle these core issues. 

Against this backdrop, we exhort the UN Global Dialogue on AI Governance to deliver on a South-led AI paradigm, anchored in a vision of rights-based development, respectful of planetary boundaries, and committed to intergenerational justice and human rights. We urge that the Global Dialogue on AI Governance commit to the following.

  • End AI extractivism 

A ‘move-fast-break-things’ approach to digital innovation aids profit, not people. In particular, the systemic and collective risks and harms associated with the violation of human rights, the erosion of democratic processes, the abuse of the environment, and the discrimination and invisibility of marginalized citizens in AI-driven decision-making in public services remain consistently ignored and underplayed in international consensus declarations. AI innovation must embrace the precautionary principle. It must be ethically and transparently developed, democratically accountable, and grounded in a globally agreed minimum floor for meaningful and dignified work, pluralistic knowledge, diversified economies, and planetary flourishing.

  • Apply the Common But Differentiated Responsibilities (CBDR) principle in international AI cooperation

The reckless path of data and AI technologies, designed and controlled by a few, has led to predatory value capture, strengthening the geo-economic and geo-political power of a handful of corporate actors and countries. The human and planetary costs arising from such opportunism are indeed a common concern. However, power diff erentials in international economic law have led to a status quo where trade, taxation, and Intellectual Property regimes clearly disadvantage developing countries, disproportionately enabling a massive transfer of wealth from the South to the North. This seriously undermines the development of digital infrastructure and human and institutional capabilities in developing countries. Such asymmetry must be remedied through global commitments to underwrite the development of regenerative, locally-led, AI infrastructures and models in the South.

  • Address corporate impunity in data and AI value chains

A global moratorium on the sale and use of AI systems that pose a high risk to human rights (such as remote biometric recognition, social scoring, spyware, and AI-driven autonomous weapons) is urgently needed. The proposed UN Binding Treaty on Transnational Corporations (TNCs) to hold global businesses accountable for human rights violations and environmental degradation in supply chains needs to be adopted without delay and appropriately future-proofed against the specific risks of harms and abuses in data and AI value chains.

  • Design a data governance framework that delivers on global equity

A ‘one-size-fits-all’ policy playbook for cross-border data flows governance will not deliver on equitable development. Development sovereignty must be recognized as a core principle in the global governance of cross-border data flows. Furthermore, the governance of the non-personal data commons requires a societal approach that includes safeguards for collective privacy and the rights of communities to steward the use and re-use of their data resources in innovation ecosystems, together with strong personal data protection rights.

  • Invest in the development of global public compute

The foundational infrastructure of compute is controlled by a few corporations. Even open-source AI models are often dependent on closed/proprietary infrastructure systems for their hosting and distribution. To ensure that data science and AI innovation deliver on public innovation, a global facility for public compute is needed. A ‘CERN for AI’ could support a distributed network of AI research centers coordinated by a central hub and provide access to innovators and researchers from developing countries.

The current trajectory of AI innovation is not working for the majority. The Global Dialogue on AI Governance must move the needle with conviction and courage towards people’s participation, planetary wellbeing, and public value. Anything less will not do justice to the people of the South.

Please find the links to prior submissions from GDJF and GSA to official consultations of the Global Dialogue below:
● GDJF’s April 2026 submission
● GSA’s April 2026 submission

Zimbabwe’s National AI Strategy: Policy Lessons for Africa

By Edrine Wanyama |

Zimbabwe recently adopted its National Artificial Intelligence (AI) Strategy 2026–2030 (AI strategy)  to guide digital technology and transformation in the country. The strategy aims to accelerate development, enhance industrialisation, and improve service delivery in sectors such as health, finance, agriculture, education and public administration. The strategy emphasises building local data infrastructure as opposed to relying on foreign data storage infrastructure while promoting an AI governance approach grounded in Ubuntu, human rights, accountability, transparency and inclusivity.

However, an important question is whether Zimbabwe’s approach offers useful lessons for other African countries developing national AI strategies.

Lessons for Other African Countries

The country’s AI strategy is organised around six pillars that together map a practical path for AI adoption and deployment. First, AI talent and capacity development is essential for ensuring that institutions have the skills needed to implement AI effectively. Second, AI infrastructure and computational sovereignty are necessary for ensuring digital and data sovereignty. Third, AI adoption and service transformation are critical for supporting the integration of AI across public and private sectors to improve their productivity, accountability and transparency.

The fourth pillar, AI governance, ethics and regulation, is essential for building public trust and creating a framework that supports responsible innovation. The fifth pillar, AI research, development, and innovation, can drive investments, expand knowledge production and strengthen academic output. The sixth pillar, strategic international collaboration, presents an opportunity for global partnerships with key players and stakeholders, technology exchange, and potentially greater investment.  

Consequently, these pillars offer useful lessons for other countries seeking to harness AI for socio-economic transformation while protecting data rights and data sovereignty.

Alignment with the African Union (AU) AI Strategy

Zimbabwe’s AI Strategy reflects several priorities contained in the AU Continental Artificial Intelligence Strategy, particularly the emphasis on coordinated AI governance, digital sovereignty, and sectoral innovation. Zimbabwe’s strategy aims to harmonise the deployment and use of AI across sectors such as health, finance, agriculture, education and public administration through common governance benchmarks for AI governance. If implemented effectively, these goals could help to address digital neo-colonialism, an issue that has been dominant in Africa’s technological space.

The Strategy also places strong emphasis on AI as a tool for socio-economic development, aligning with Agenda 2063 and the Sustainable Development Goals (SDGs), particularly in sectors such as health, agriculture, and education. The Strategy promotes the deployment of AI to improve agriculture through crop disease prevention, as well as mining and mineral development, which is consistent with the AU AI strategy’s priorities on resource optimisation and climate resilience.

However, Zimbabwe faces significant governance and implementation challenges. The country scored 0 in the 2024 Global Index on Responsible AI Governance, highlighting the gap between policy ambition and institutional readiness. This means it requires major actions to implement the strategy, such as the establishment of robust legal safeguards, accountability mechanisms, oversight institutions, and rights-based governance frameworks, which are also emphasised within the AU strategy.  Other African countries can draw lessons from Zimbabwe’s approach, such as the need to complement AI strategies with stronger governance capacity, clearer regulatory safeguards, and more coherent data governance frameworks to support responsible and accountable AI deployment.

UNESCO Guidance on AI

The UNESCO Recommendations on Ethics of Artificial Intelligence, adopted in 2021, is a global normative framework that promotes human rights, including human dignity, transparency, fairness, human oversight in AI systems, and democratic participation. It also provides practical policy action areas covering issues such as data governance, gender, education and research, health, and social wellbeing.

While the UNESCO Guidance is emphatic on ethical and privacy considerations, Zimbabwe’s strategy falls short. Ambitions to integrate AI into public service delivery sectors such as education, health, and public administration will require stronger safeguards to ensure alignment with the human-centric principles articulated in the UNESCO framework. In the age of AI, data security concerns, intellectual property rights, algorithmic bias, and institutional accountability are central to responsible deployment of AI and require clearer policy and regulatory attention.

Similarly, the UNESCO Guidance warns against the use of AI in a manner that undermines democratic participation, civic engagement, and collective decision-making. This is especially important in contexts where surveillance technologies such as facial recognition, drone monitoring, communication tracking, and social media surveillance are deployed without clear safeguards or independent oversight. Zimbabwe, like several other African countries, has invested in AI-enabled infrastructures, such as the “smart city” systems to monitor and surveil citizens in ways that are opaque and lack clear accountability mechanisms.

As African countries continue developing national AI strategies and governance frameworks, they must strive to ensure that the deployment of AI is transparent, publicly accountable, and pays close attention to ethical and human rights standards. Without these safeguards, AI risks reinforcing exclusion, surveillance, and digital authoritarianism rather than advancing development.

Conclusion

Zimbabwe’s adoption of an AI Strategy is an important step toward advancing tech-enabled digital and socio-economic transformation. It also reflects the country’s intent to align national priorities with the African Union’s vision for AI-driven development across the entire continent. However, for such strategies to be effective and legitimate, they must be grounded in ethical and human rights standards laid down in regional and international benchmarks.

Why Data and AI Governance Are Central to Africa’s Digital Trade Ambitions

By CIPESA Writer |

Digital technologies are changing how African businesses trade and connect across borders. However, digital trade on the continent remains hugely constrained, including by regulatory fragmentation, infrastructure gaps, and bureaucratic hurdles. How then should African countries leverage the growing digitalisation and emerging technologies such as Artificial Intelligence (AI) to boost their digital economies?

According to the World Trade Organization (WTO), in 2024, Africa’s exports of digitally delivered services (DDS) were valued at USD 41.3 billion, representing just one percent of global exports. Nonetheless, the continent’s prospects are promising. The WTO and the World Bank project that greater use of digital technologies could boost Africa’s digital services exports by USD 74 billion between 2023 and 2040, doubling Africa’s share of global exports.

Evidently, if African countries do not address existing barriers and take decisive action, the continent risks becoming an even more marginal player in the global digital trade ecosystem. How to bridge the barriers and leverage data and AI to shape digital trade and Africa’s economic future was at the centre of discussions at the African Economic Research Consortium (AERC) Summit 2025, held in Nairobi, Kenya, last December.

A panel on digital trade and the governance of digital and AI economies, where the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) featured, stressed that, although frameworks such as the African Continental Free Trade Area (AfCFTA) Digital Trade Protocol are a step in the right direction, they could fail to significantly grow digital trade if member states lack enabling data and AI governance systems and practices.

Today, DDS account for approximately 35% of Africa’s total services export value, and have been rising at a double-digit rate, outpacing growth in other regions globally. However, growth in digital services trade remains uneven, concentrated in a handful of countries, mostly South Africa, Morocco, Ghana, Egypt, and Mauritius. Kenya, Nigeria and Tunisia are also notable players but with lower export values than the leading African countries.

Regional initiatives such as the AfCFTA Digital Trade Protocol can help to expand digital trade beyond domestic markets, including in countries that currently lag. The protocol, which was adopted two years ago, aims to harmonise rules for cross-border digital trade across Africa, including on electronic transactions, data governance, and digital payments. Meanwhile, the African Guidelines on Integrating Data Provisions in Protocols on Digital Trade of 2024, emphasise harmonised data governance as an enabler of secure and inclusive digital trade across Africa.

The African Union Data Policy Framework (AUDPF) similarly provides for interoperable data ecosystems across the continent, that are enabled by harmonised laws that support both innovation and rights protection. The various regional efforts support the dream of a Digital Single Market by 2030, as envisaged by the Africa Digital Transformation Strategy of the African Union.

The Galore of Barriers

The region currently lacks an operational continent‑wide harmonised framework for data protection, e‑commerce regulation, digital taxation, or AI governance. This gap raises compliance costs and presents a barrier to businesses that aim to scale operations across borders. This undermines cross‑border digital trade and data flows. Moreover, lack of regulations for paperless trade, including on electronic invoicing, e-signatures and e-contracts, presents an additional hurdle.

On the other hand, high taxes on goods, services, data, and devices drive up costs for businesses, yet several entrepreneurs struggle to access affordable digital financial services, including for effecting cross-border payments. These challenges are made worse by low internet speeds, unreliable electricity supply, as well as weak understanding of export regulations, data protection, and cybersecurity.

Addressing these barriers would offer entrepreneurs a range of benefits. Businesses can reach new customers beyond national borders without investing much in physical export infrastructure, which can reduce costs and expand their market reach. Also, interoperable digital payments can help to minimise settlement delays and overcome currency conversion hurdles.

Priorities on AI and Data Governance

Projections by a WTO 2025 report show that AI could boost the value of cross-border flows of goods and services by around 40% by 2040, due to productivity gains and lower trade costs. However, Africa’s readiness for AI regulation and uptake, particularly by small and medium enterprises, remains low. The WTO report points to AI’s potential to reduce logistics costs, overcome language barriers, ease regulatory compliance, and boost productivity.

In a March 2025 survey among firms from across the world, the most cited benefits of AI were improved trade efficiency (22%), optimised trade decision-making (14%), expanding the foreign customer base (10%), enhanced supply chain management (9%), and broader import and export product ranges (9% and 8% respectively).

How data and AI are governed is therefore key for the future of Africa’s digital economy. If African countries do not put in place robust and harmonised legislation, they will risk perpetuating patterns of the so-called “AI colonialism” in which African data and users fuel global AI markets yet their economies do not receive proportionate economic benefits. Many African countries are adopting AI in the public and private sectors but lack comprehensive AI-specific laws and governance frameworks and often rely instead on outdated laws that pre-date the current technologies.

The State of Internet Freedom in Africa 2025 report calls for human‑centred AI laws that ensure transparency in algorithms, clear accountability, and effective mechanisms for liability and redress. The report urges governments to strengthen independent AI and data oversight institutions, invest in digital infrastructure and inclusion, expand internet access, and ensure AI tools serve local languages. The report also highlights that Africa’s AI market is projected to grow from USD 4.51 billion in 2025 to USD 16.5 billion by 2030.

Africa thus urgently needs cross-border data governance frameworks that support trusted data flows, reduce fragmented national rules, and establish interoperable standards to boost regional digital trade under initiatives such as AfCFTA and the AUDPF. At the same time, investments in affordable connectivity, local cloud capacity, public digital platforms, and datasets in African languages are essential.

The Role of Civil Society and Think Tanks

The Summit discussion stressed the urgent need for research to inform policy, particularly on cross-border data flows, AI adoption, and ways for Africa to avoid new forms of dependency while getting greater value from its data and digital innovation.

Also essential is civil society engagement in monitoring the implementation of continental digital trade and data initiatives, supporting harmonisation of policies and standards, and building the capacity of policymakers, regulators, and businesses.

Actions to Grow Digital Trade in Africa

  • Embrace digital transformation and connectivity by investing in robust networks and backup systems.
  • Implement robust cyber security frameworks while ensuring effective cyber leadership and prioritising investments in cyber infrastructure, skilling, awareness.
  • Recognise data as a trade enabler by ensuring trade agreements have provisions that prevent unnecessary restrictions on data flows.
  • Harmonise data protection standards to reduce compliance costs for businesses and build trust among different stakeholders.
  • Adopt and implement Intellectual Property (IP) laws to ensure that local innovators and individuals in the region benefit.
  • Build robust digital infrastructure with a focus on Digital Public Infrastructure (DPI) and data privacy.
  • Assess and address the impact of emerging technologies like artificial intelligence, blockchain and IoT, ensuring they foster innovation and address ethical challenges.

Source: CIPESA – Policy Considerations for Enhancing Digital Trade in East Africa