Beyond AI Safety: Why Africa Needs Sovereignty and Agency in Global AI Governance  

By Lillian Nalwoga |

As artificial intelligence reshapes economies and everyday life, the essential question for African countries is not simply whether AI will be safe. It is whether African societies will have the power, infrastructure, skills, resources, and representation to shape how AI is built and used.

The Inaugural UN Global Dialogue on AI, held in July 2026, among its priorities called for the need for “safe and inclusive AI” among others. However, the message from African delegates pointed to a broader concern. Safety without sovereignty and agency is not enough. Delegates pointed to limiting factors such as the lack of access to computing power, locally relevant data, technical expertise, financing, and meaningful influence over global AI rules. The speed of AI development intensifies these challenges. The preliminary report of the Independent International Scientific Panel on AI rightly warns that technological advances are moving faster than governments’ ability to adapt. This could create risks that can be severe, further worsening existing inequalities and undermine digital rights. The report further notes that steps to close these gaps do exist, but they require sustained investment in Member States’ capacity to shape, evaluate, and deploy AI.

Many African countries are now developing AI strategies and policies with the goal to harvest opportunities and mitigate AI risks. However, regulating alone without the necessary infrastructure, data, and human capacity are unlikely to deliver the desired outcomes. Moreover, as noted in the preliminary report, current global AI systems often overlook indigenous languages and cultures resulting in inaccurate outputs and systems that are poorly suited to local realities.

The need to protect data sovereignty was another issue that emerged clearly from the dialogue. Africa member states emphasized the need to have control over how their data is used, while ensuring that cross-border data arrangements are fair and mutually beneficial. For this to manifest, African countries would require access to computing capacity, high-quality data, skilled talent, sustainable financing, reliable electricity, and robust digital infrastructure to support meaningful AI development.

These concerns were further highlighted by the governments of Rwanda and Uganda, who noted that more than half of the world’s data centers are located in just a handful of wealthy countries, while Africa possesses less than 1 percent of global AI computing capacity. This systemic inequality risks entrenching dependence on foreign platforms, cloud providers, and AI models that are not designed for African contexts. Despite its significant contribution to the global AI economy in terms of critical mineral resources and social data, Africa is still too often positioned as a consumer rather than a shaper of AI technologies, standards, and governance.

This imbalance cannot be solved by ethical principles alone. From an African perspective, AI governance is not only a regulatory exercise; it is an infrastructure, development, and justice agenda. African member states at the Dialogue reinforced this message. Government delegates from Rwanda and Kenya for instance highlighted the need to expand access to infrastructure and financing, invest in skills and talent, reduce regulatory fragmentation, and build on regional initiatives such as the Africa Declaration on Artificial Intelligence. Other delegates similarly stressed that AI must be transparent, accountable, and subject to meaningful human oversight. The protection of underrepresented languages, cultures, and data, as well as concrete forms of international cooperation, was also highlighted.

The priorities identified by African stakeholders. This distinction should define the future of the Dialogue. Unlike what was seen at the India AI Summit, the UNGDIA drew many high-level African government delegations, who clearly voiced the continent’s priorities for advancing AI. African participation and that of the Global South must go beyond consultation after key decisions have been made. Stakeholders from the Global South should play a leading role in setting priorities, developing standards, and monitoring AI implementation. The challenge for the Dialogue is therefore not only to identify risks but also to ensure that countries have the capacity to prevent them and to benefit from AI on fair and equitable terms. The choice should not be between innovation and rights. The Dialogue must ensure that AI advances development without compromising dignity, privacy, equality, or democratic participation. This is also anchored in calls by civic actors from the Global South, who have long called for not merely inclusion in global AI discussions but also a South-led rights-based AI paradigm grounded in planetary limits, democratic participation, and intergenerational justice. Additionally, CIPESA’s research on AI impact in Africa has highlighted the need for a human-rights approach to AI regulation and the adoption of a human- centred AI governance in Africa, through deliberated and inclusive approaches.

Moreover, the UN Global Dialogue on AI can make a meaningful contribution by moving from issuing broad statements to practical, measurable actions anchored in Africa’s sovereignty, agency, and capacity to shape its own digital future. As the dialogue moves into its intersessional phase, it must shift from discussion to action. Global South governments and civil society are demanding equal footing in AI governance, and the UN must listen. One way to do this would be for the UN to champion a consolidated fund for AI development and capacity building in the Global South. The UN Secretary-General suggested creating a Global Fund on AI with a target of $3 billion to facilitate building basic AI capacity in developing countries. According to him, this is “less than one per cent of the annual revenue of a single tech company.” If successfully adopted, it could help launch AI development initiatives in many Global South countries. However, relying solely on tech companies is unlikely to address Africa’s and the wider Global South’s AI challenges. That is why African countries are calling for a holistic approach to AI investment. The 2025 Africa Declaration on Artificial Intelligence proposes the creation of a $60 billion Africa AI Fund financed by public, private, and philanthropic capital. The fund will support AI infrastructure, African AI businesses, workforce development, and domestic research capacity. It still remains unclear when these funds will take effect.

Nonetheless, more efforts are still needed to create public awareness on the ethical use of AI while also strengthening civil society voices in advocating for human rights respecting AI development.

Mozambique’s Internet Shutdown Case: African Courts Draw a Line on Executive Power

By CIPESA Writer |

In July 2026, Mozambique’s Constitutional Council ruled that before a government can justify an internet shutdown, it must first have lawful authority to order one. The ruling signifies that before governments restrict connectivity, they must be able to show not only that the power to do so was lawfully created, but that it was exercised by a legally authorised authority.

The ruling comes against a wider pattern across the continent, where governments have used internet shutdowns to silence dissent and restrict fundamental rights.

The Constitutional Council declared 18 provisions of the Telecommunications Traffic Control Regulation (Decree No. 48/2025) unconstitutional, following a petition from the Center for Democracy and Human Rights. These provisions granted the telecommunications regulator, the National Communications Institute of Mozambique (INCM), broad powers to control telecommunications traffic, collect user data, intervene in operators’ networks using its own technology without their consent, and monitor communications on stated grounds including protecting state security and mitigating fraud.

The Council’s ruling was not about a recently imposed internet shutdown. Instead, it examined provisions of the regulation that gave the authorities powers to monitor communications, collect data, suspend telecommunications services and intervene in networks. The question was whether those powers could be created through regulation without a sufficient basis in legislation enacted by Parliament. The Council found that they could not, holding that the executive had effectively assumed the role of Parliament in defining the essential content of fundamental rights.

The Council described this as “organic unconstitutionality” and held that powers capable of restricting fundamental rights could not be created through executive regulation alone, but required parliamentary legislation that complies with constitutional and human rights protections.

In the Constitutional Council’s words, the provisions “substituted the Government for the Assembly of the Republic’s legislature in defining the essential content of fundamental rights”, contrary to Article 178 of the Constitution.

The Mozambique ruling also helps clarify three contentious questions emerging in shutdown litigation across the continent. What law permits the restriction, and who is authorised to order it? Which rights does it affect, including freedom of expression and access to information? And even where a legal power exists, is the restriction genuinely necessary and proportionate to the stated aim?

A Regional Pattern of Unlawful Interference
Mozambique’s ruling mirrors a broader African legal front against arbitrary internet shutdowns. Across the continent, governments have used shutdowns to restrict political opposition, communication, mobilisation, assembly, association and protest, in some cases without a sufficient legal basis.

In January 2019, the High Court of Zimbabwe ruled that the state security minister had no legal authority under the Interception of Communications Act to order an internet shutdown or issue an intercept directive to mobile network operators. The shutdown was ordered amid nationwide protests against rising fuel prices, but was later restored.

In Togo, the ECOWAS Community Court of Justice found that Togo’s three-day internet shutdown during the 2017 protests violated freedom of expression under Article 9 of the African Charter because it lacked authorisation under national law. The Court also ordered compensation to the applicants for the violation of their right to freedom of expression. The judgment affirmed that access to the internet enables people to exercise rights that are already protected, particularly freedom of expression and access to information.

In Nigeria, the court reached a similar conclusion, finding that the government’s seven-month suspension of Twitter violated freedom of expression, access to information, and media freedom. It described access to the platform as “a derivative right that is complementary to the enjoyment of the right to freedom of expression.”

The case of Association des Blogueurs de Guinée (ABLOGUI) and three others against Guinea shows that a legal basis alone is not enough. In that case, the ECOWAS Court found that restrictions on internet and social media access between October and December 2020 violated the applicants’ rights to information and freedom of expression. The case reinforces the rule that a government must show not only that a restriction is authorised by law, but also that it serves a legitimate aim and is necessary and proportionate.

In Senegal, the shutdowns imposed during the 2023 unrest violated freedom of expression and access to information for both applicants. The court also upheld Ndiaga Gueye’s individual claim that the shutdown violated his right to work as an IT consultant. The case illustrates that shutdowns can disrupt far more than speech. They can cut people off from work and other essential digital services, while disrupting journalism, education, payments and access to health information.

Strengthening Preventive Safeguards
Courts are not the only institutions shaping this debate. For years, the African Commission on Human and Peoples’ Rights (ACHPR) has set continental standards on open internet access. The Commission’s resolutions and declarations do not carry the same legal force as court judgments. Still, they provide important guidance on how African states should protect freedom of expression, access to information, and access to the internet.

Its 2019 Declaration of Principles on Freedom of Expression and Access to Information in Africa, Principle 38(2), provides that states “shall not engage in or condone any disruption of access to the internet and other digital technologies for segments of the public or an entire population.”

In March 2024, the Commission went further in Resolution 580, calling on states to ensure open and secure internet access before, during, and after elections, and to refrain from ordering shutdowns or disrupting digital communication platforms during the electoral process.

Conclusion
Despite judicial victories, the threat remains pervasive, and litigation alone is insufficient when judgments arrive years after the harm. In 2025, the #KeepItOn coalition recorded 30 shutdowns across 15 African countries.

There must be independent oversight, public transparency, and effective ways for people affected by an unlawful restriction to challenge it and seek redress. Telecommunications operators should also be protected from being forced to carry out unlawful orders. Only then can we ensure that the digital rights of millions are protected from the arbitrary exercise of power.

Mozambique’s ruling affirms that digital rights are not subject to executive whim. Governments must respect the rule of law, ensuring that restrictions on connectivity that limit fundamental rights are grounded in parliamentary legislation and subject to rigorous constitutional safeguards.

Uganda’s Digital Economy: Rights Trends, Regulatory Gaps and Policy Responses

By Doreen Elizabeth Namuyanja |

Uganda’s digital economy is expanding rapidly across finance, transport, agriculture, commerce, healthcare and public-service delivery. However, this growth is outpacing the legal, regulatory and institutional safeguards needed to address emerging concerns around personal and biometric data, artificial intelligence, platform work, digital exclusion and internet shutdowns.

Drawing on a 2025 survey, two commentaries and a policy submission by CIPESA, this policy brief examines Uganda’s evolving digital business landscape, business data practices, the future of work and the impact of internet disruptions. It highlights the gaps between technological advancement and effective governance and proposes actions for government, businesses, private sector associations and civil society to build an inclusive, resilient, and rights-respecting digital economy.

The brief finds that Uganda has established important legal protections, including the Data Protection and Privacy Act of 2019. The principal challenge, however, is implementation, enforcement, and the ability of regulatory and institutional frameworks to adapt to rapidly evolving technologies and business models. Businesses frequently collect personal and biometric data without sufficiently explaining how it will be used, stored, shared, or deleted. Meaningful consent, data security, and effective retention and deletion practices also remain inconsistent, particularly among businesses with limited compliance capacity.

These gaps have consequences beyond privacy and individual rights. Weak data governance can undermine trust in digital services, while inadequate safeguards for platform workers and persistent digital exclusion can limit who benefits from the digital economy. Internet shutdowns pose a broader threat, disrupting digital financial services, e-commerce, public services and other activities that increasingly depend on reliable connectivity.

The brief calls for coordinated action by government, businesses, private sector associations and civil society to:

Businesses

  • Strengthen data governance and informed consent: implement collection and processing frameworks built on explicit, freely given consent, backed by clear, accessible privacy notices.
  • Improve data security and lifecycle management: adopt encryption, regular security audits, and clear retention, deletion and minimisation policies.
  • Build organisational compliance capacity: appoint and train Data Protection Officers, embed privacy-by-design into product development, and run regular staff training on data protection, cybersecurity and phishing risks.
  • Strengthen digital resilience: develop business continuity plans for internet disruptions, and collaborate with civil society and legal actors to promote an open, secure and reliable internet.

Government of Uganda

  • Strengthen enforcement of the data protection framework by adequately resourcing the Personal Data Protection Office (PDPO) and other regulators to conduct audits, investigate violations, and impose proportionate sanctions.
  • Modernise the legal and policy framework to address biometric data, AI and platform work, aligned with constitutional and international human rights standards, and issue practical, sector-specific guidance to help businesses, particularly SMEs, comply.
  • Promote digital inclusion and public awareness through sustained education campaigns, including in local languages, and continued investment in affordable infrastructure and digital skills.
  • Safeguard the digital economy against internet disruptions by developing clear legal safeguards against shutdowns and ensuring any restrictions comply with constitutional and international human rights obligations.

Private Sector Associations

  • Build members’ capacity through regular training on data protection, cybersecurity, AI governance and business continuity planning.
  • Promote industry standards and peer learning by developing model policies and compliance toolkits for consistent implementation across member organisations.
  • Support risk management by encouraging periodic risk assessments among members and facilitating the sharing of lessons learned and mitigation strategies.

Civil Society Organisations

  • Strengthen multi-stakeholder collaboration among government, businesses, academia and technical experts on data protection, AI governance and digital rights.
  • Promote public awareness and digital rights literacy through accessible educational materials and community outreach.
  • Undertake research and evidence-based advocacy on biometric data governance, AI, platform work and internet shutdowns, including documenting their social, economic and human rights impacts, to support stronger legal frameworks and strategic litigation.
  • Support business compliance and resilience by developing practical guidance, templates and capacity-building support on responsible data governance.

Read the full brief here.

FIFAfrica26 Is One Month Away – It’s Time to Connect!

FIFAfrica26 | 

In just one month, the Forum on Internet Freedom in Africa 2026 (FIFAfrica26) will convene in Mauritius from September 28 to October 1, 2026, bringing together hundreds of participants from across Africa and beyond for critical conversations on digital rights, inclusion, governance, and the future of the continent’s digital landscape. Now is the time to begin engaging with the vibrant community that makes FIFAfrica such a powerful space for exchange and collaboration. 

Participants (in-person and remote) can already look forward to a rich agenda shaped by the digital rights community which reflects the pressing issues at the heart of Africa’s digital rights landscape. The Forum will spotlight themes including digital democracy and civic participation, data governance and sovereignty, artificial intelligence and emerging technologies, platform accountability, digital inclusion, digital economy and trade, movement building, and digital security and safety.

And the conversation does not have to wait until you arrive in Mauritius! You can start connecting and engaging with fellow participants and the wider community now by following @cipesaug and sharing your anticipation, insights, and reflections ahead of the Forum. Use #FIFAfrica26 and #InternetFreedomAfrica to join and amplify the conversations shaping a more open, inclusive, and secure digital future for the continent. Be sure to also join the engaging networks and communities within the event app too. You can start your own too!

As you prepare to attend or participate remotely, we encourage you to take a moment to read the FIFAfrica26 Code of Conduct. The Forum is built on dignity, respect, inclusion, and constructive engagement. The Code of Conduct applies to all Forum spaces including sessions, social events, and online platforms and is intended to ensure that every participant can engage free from intimidation, discrimination, harassment, or hostility. All attendees are expected to uphold these standards throughout the event. 

For those traveling, be sure to review the official Travel Note and plan accordingly. FIFAfrica26 will be hosted at the InterContinental Resort, Mauritius in Balaclava. 

We look forward to welcoming you online or in person at FIFAfrica26.

Cybercrime Laws, “False News” Offences, and Online Expression in Africa

By CIPESA Writer |

As African societies become increasingly digital, governments are grappling with the balance between the protection of citizens from online harms while preserving the fundamental freedoms of free expression, access to information and freedom to participate in governance.   

The legal tools adopted to address these challenges are raising an equally pressing concern. Cybercrime and so-called “false news” laws are increasingly extending beyond their stated purpose of combating digital harm and are instead being used to regulate political speech, suppress dissent, and narrow civic space.

This emerging tension sits at the heart of CIPESA’s latest policy brief, Cybercrime Laws, “False News” Offences, and Online Expression in Africa. Drawing on legislative developments, court decisions, and recent cases from select countries, the brief examines how cybercrime legislation has evolved into one of the defining governance issues of Africa’s digital era.

Many countries have introduced offences such as “false information”, “offensive communication”, “malicious communication”, and “harmful content”. While these provisions are often justified as necessary responses to online abuse, they frequently suffer from vague drafting and broad enforcement powers. This creates uncertainty about what constitutes unlawful speech and allows authorities considerable discretion in deciding who should face criminal investigation or prosecution.

In several African countries, journalists, activists, bloggers, opposition politicians, and ordinary citizens have been arrested or prosecuted for online expression that would ordinarily fall within the boundaries of legitimate public debate. At the same time, restrictions on online speech increasingly operate alongside expanding surveillance powers, internet shutdowns, and growing state control over digital communications, reinforcing broader patterns of digital authoritarianism.

Importantly, however, this is not simply a story of shrinking freedoms. Encouraging developments in several jurisdictions demonstrate that alternative approaches are both possible and necessary. Recent constitutional decisions in Uganda and Kenya have reaffirmed that restrictions on freedom of expression must be clearly defined, proportionate, and consistent with constitutional protections. Similarly, in Nigeria legislative reforms illustrate how sustained engagement by civil society can improve legal frameworks, even if implementation challenges persist.

These developments highlight an important policy lesson as to how regulation can effectively address genuine digital harms without criminalising legitimate expression or weakening democratic accountability.

This policy brief explores these issues in greater depth, examining the emerging patterns across Africa, the evolving role of national and regional courts, and the reforms needed to ensure that cybercrime regulation strengthens both digital security and democratic governance. It concludes that the future of digital freedom in Africa will depend on how governments, courts, regional institutions, and technology companies navigate this balance.

The brief sets out concrete recommendations for four groups of actors. Governments should repeal or amend vague offences, including those relating to false information, offensive communication, and similarly broad categories, that have been used to criminalise legitimate online expression. They should prioritise civil remedies over criminal sanctions in defamation and reputation-related disputes, refrain from imposing internet shutdowns, and ensure that any restrictions on freedom of expression comply with international human rights standards.

Legislators and regulators should ensure that cybercrime and digital governance laws comply with the principles of legality, necessity, and proportionality. They should also require human rights impact assessments before introducing new cybercrime or disinformation laws and establish meaningful public participation throughout the law-making processes. Laws developed without meaningful public scrutiny and civil society engagement are more likely to undermine rights than protect them.

Regional institutions should strengthen the monitoring and implementation of regional human rights commitments and promote common standards on digital rights and accountable digital governance to guide national legal reforms across the continent.

Finally, technology platforms should invest in African language content moderation and local contextual expertise, improve transparency around content moderation decisions and algorithmic decision making, and strengthen grievance and appeals mechanisms for users in African countries, where existing processes often remain inaccessible or ineffective.

Please read the full Policy Brief here.