Rethinking Africa’s Approach to the Politics of AI Governance and Regulation

By Paul Kimumwe |

The past few years have witnessed a growing urgency for frameworks that regulate and harness the development and implementation of new and emerging technologies, especially Generative Artificial Intelligence (Gen AI).

At the international and regional level, the United Nations (UN) and the African Union (AU) have established norms through resolutions, strategies and guidelines to affirm the relationship between technology and human rights, and provide benchmarks for Member States developing rights-respecting AI governance and regulatory frameworks.

In March 2024, the UN adopted a landmark resolution on the promotion of “safe, secure and trustworthy” artificial intelligence (AI) systems that also benefit sustainable development. The resolution also calls upon Member States and other stakeholders “to refrain from or cease the use of artificial intelligence systems that are impossible to operate in compliance with international human rights law or that pose undue risks to the enjoyment of human rights.”

The 2024 resolution reaffirmed that “the same rights that people have offline must also be protected online, including throughout the life cycle of artificial intelligence systems.” It called upon member states to ensure that national AI governance and regulatory frameworks “promote safe, secure and trustworthy artificial intelligence systems” that are inclusive and benefit everyone in an equal manner.

In August 2025, the UN adopted resolution 79/325, establishing the Independent International Scientific Panel on AI and Global Dialogue on AI Governance. It aims to provide a platform to discuss international cooperation, share best practices and lessons learned, and to facilitate open, transparent and inclusive discussions on AI governance. However, a year earlier, in July 2024, the AU adopted the Continental AI Strategy, which emphasises the development of robust governance regimes for AI founded on ethical principles, democratic values, human rights, and the rule of law, in line with the AU  Agenda 2063.

Both the UN resolutions on AI and the AU continental strategy came on the backdrop of other AI-related policy guidelines such as Center for AI and Digital Policy’s 2018 Universal Guidelines for AI, the Organization for Economic Cooperation and Development (OECD) 2019 AI Principles / G20 AI Guidelines, the United Nations Education Scientific and Cultural Organization (UNESCO’s) 2021 Recommendation on the Ethics of AI, and the European Union Commission’s (EUC) 2024 European Union AI Act.

Many African countries have been actively developing AI-related laws, policies, and strategies. Rwanda was the first to adopt a national AI policy in 2019, followed by Ghana’s National Artificial Intelligence Strategy in October 2022, Egypt’s National Artificial Intelligence Strategy in January 2025, and Kenya’s own strategy in May 2025. Benin, Côte d’Ivoire, Ethiopia, Mauritius, Nigeria, Tunisia, Zambia, and Zimbabwe are among others that have developed AI policies or strategies. Others, such as Burkina Faso, Guinea, Lesotho, Mali, Namibia, and Uganda, are still at different stages in developing their AI policies or strategies.

A case of history repeating itself?

While all these have been welcome developments in the governance and regulation of AI, studies show that the adoption of international and regional human rights instruments and national laws, policies and strategies is often just the first step in a long process. If not well managed, it often results in provisions that are, although of a progressive nature, are hard to implement and fail to address local needs and realities.

This is because the process of drafting these laws and strategies in many developing contexts is often devoid of meaningful multistakeholder consultations and engagement. Moreover, there has also been a tendency to adopt and replicate models from the global North, whose texts, while progressive, have faced strong resistance from Member States as they sometimes do not align with local contexts and cultural norms.

For example, many African countries, including Algeria, Ethiopia, Cameroon, Kenya, Mauritius, Namibia, Rwanda, South Africa, and Uganda, expressed strong reservations about certain provisions contained in the Protocol to the African Charter on Human and People’s Rights on the Rights of Women in Africa (Maputo Protocol).

Additionally, most of these models are state-centric and grounded in frameworks that create a distinct binary between duty-bearers and rights-holders, but do not articulate how and what each party needs to do to ensure meaningful implementation of the initiatives.

While the state-centric and rights-based approaches may seem attractive, in practice, their relevance in advancing digital rights is often undermined, especially when the prescribed provisions and action points do not align with the country’s current social, economic and political realities. Indeed, cases abound in which initial promises have fizzled over time due to the political leadership’s inaction (and sometimes unwillingness) to fully adopt and implement the resolutions or strategies.

For example, it took almost nine years for the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) to enter into force on June 8, 2023, after its adoption in 2014. Indeed, more countries (40) have enacted data protection laws as compared to those that have ratified (16), highlighting a disconnect between national legal reforms and their commitment to continental frameworks. Similarly, the AU Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa, adopted on January 30, 2018, took six years to enter into force, after the 15th ratification was achieved.

More critically, however, the lack of political will often reflect in the absence of clearly defined funding mechanisms for the implementation of these policies and strategies. As a result, even well-designed and progressive frameworks face implementation challenges due to structural flaws and insufficient funding.

For example, while Africa has scored highly in enacting Data Protection laws, which have become central to ongoing AI governance frameworks, one issue affecting their effective implementation is the lack of clear funding mechanisms for the regulatory bodies responsible for oversight and implementation. Other challenges include weak governance structures that deny these oversight bodies financial, decisional and operational independence and place them under the supervision of political appointees rather than parliament.

Designing for Failure?

Apart from Kenya, most African countries that have developed or are in the process of developing an AI strategy or policy do not provide for budgetary allocations or estimates for the implementation of their AI strategies, laws or policies. Countries such as Rwanda provide for a project-level funding framework, while others, such as Egypt and Mauritius, rely on programmatic budgets to fund the implementation of their strategies.

Even then, while implementation of Kenya’s National Artificial Intelligence Strategy (2025–2030) was costed at KSh 152 billion over a period of five years, a review of Kenya’s 2026/27 national budget shows no dedicated funding allocation for the strategy. Instead, the Sh8.6 billion allocated to the ICT sector mainly targets the expansion of broadband access, the strengthening of digital skills, and the digitisation of government services.

Additionally, in countries such as Ethiopia and Rwanda, while the policies provide for the establishment of an implementation body, several functions have been split across different ministries, departments and agencies (MDAs), which, in practice, would pose a significant challenge to meaningful execution.

For example, Rwanda’s AI policy mandates the Responsible AI office under the Ministry of ICT and Innovation to be responsible for effective tech implementation. It also positions the Rwanda Utilities Regulatory Authority (RURA) as the technical regulator responsible for developing ethical AI guidelines and principles, and the National Cyber Security Authority (NCSA) to oversee data protection compliance relevant to AI systems.

In Ethiopia, the policy designates the Ethiopian Artificial Intelligence Institute (EAII) as the national coordinating body responsible for implementation, standards development, and capacity building, and the Ministry of Innovation and Technology is responsible for providing policy oversight. Other sectoral agencies, such as the Ethiopian Communications Authority (ECA), the Ministry of Health, and the National Bank, have mandates over telecommunications and data matters, health-sector-related AI, and financial AI, respectively.

While a multisectoral approach to policy and strategic implementation can improve cohesiveness and legitimacy, the approach is prone to risks such as divergent priorities, internal conflicts, power struggles, and regulatory fragmentation, which are likely to affect how the policies and strategies are executed.

Implications for the Future of AI Governance and Regulation

In many African countries, the development of AI governance and regulatory structures is still in its infancy and presents a unique opportunity for Africans to shape their own destiny on how AI should be developed and deployed in ways that respond to and respect local needs and contexts.

Enactment of AI-specific Laws

In many countries, governments are relying on existing laws, such as data protection, communications, and cyber-related legislation, alongside the AI policies and strategies being developed. Given the evolving nature of AI, countries need to work towards enacting AI-specific laws that clearly define and contextualise AI.

Empowering the Oversight Bodies

As currently structured, many of the existing and proposed oversight bodies are either not yet operational or lack a clear mandate and sufficient resources for effective oversight. Additionally, many of them are situated within fragmented regulatory environments with overlapping responsibilities, which results in uncoordinated implementation. It is important, therefore, that the mandate of the oversight bodies and resources are clearly defined and guaranteed to ensure independence and eliminate the possibility of political interference.

Meaningful Stakeholder Participation

Having empowered stakeholders who are meaningfully engaged and participate in the development processes for policies, laws and strategies is critical to ensuring that the resulting instruments address real needs, are people-centred and implementable, and have government buy-in, as reflected in the government’s funded priorities.

Adopting a Human Rights-Centred Approach

A 2025 study by CIPESA shows that in many countries, the adoption of a human rights-centred approach to AI governance remains aspirational due to gaps in implementation, technical capacity, and stakeholder engagement in policy development and implementation. It is important, therefore, that current efforts prioritise safeguarding fundamental human rights and freedoms, enhancing human capabilities over replacement, and ensuring meaningful human control, transparency, fairness, and inclusivity in AI systems.

African Commission Resolution 655 and What it Offers for the Future of Electoral Democracy

By Edrine Wanyama |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) welcomes the African Commission on Human and Peoples’ Rights (ACHPR) adoption of the Resolution on Elections in Africa in 2026 – ACHPR/Res. 655, which calls on all Member States to uphold human rights, the rule of law, and democratic governance.

The resolution comes at a time when several African countries are experiencing democratic regression, marked by harassment of opposition politicians and civil society actors, and mistrust in  electoral processes.  

With 12 countries – Algeria, Benin, Cape Verde, Democratic Republic of Congo, Djibouti, Ethiopia, Gambia, Guinea, Guinea-Bissau, Republic of the Congo, Sao Tome & Principe, and Zambia – scheduled to hold elections in 2026, the resolution provides a timely reminder to governments to ensure that elections are free, fair, and transparent, with the playing field levelled for all contestants.

Resolution 655 builds on existing regional instruments that seek to promote democratic governance on the continent. The main instrument is the African Charter on Democracy, Elections and Governance , which has been  ratified by 39 out of 55 AU member states. Notably, some countries that are preparing to hold elections, including the Democratic Republic of Congo and the Republic of the Congo, are yet to ratify the Charter on Democracy, raising concerns about alignment with its standards.

The resolution also complements the Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Women in Africa, whose article 9 calls for the inclusive participation of women in political and electoral processes.

Elections in the Digital Age
A notable strength of Resolution 655 is its recognition of the evolving digital landscape and its impact on electoral integrity. In line with Resolution ACHPR.Res. 580(LXXVIII)2024 on Internet Shutdowns and Elections in Africa, this new resolution re-echoes the need to respect internet freedoms, including freedom of expression and access to information, which are core to the conduct of free and democratic elections. Moreover, the resolution notes with concern, the human rights violations that were perpetuated in Tanzania and Cameroon, and the disruptions in Guinea-Bissau, during their elections in 2025.

The resolution also highlights emerging risks associated with the use of Artificial Intelligence, misinformation and disinformation, all of which can compromise  electoral integrity.

CIPESA stands in solidarity with the Commission’s call to end repression against voters, civil society, journalists, and opposition actors. We call upon all member states, particularly those holding elections in 2026, to implement the recommendations and ensure inclusive,  rights-respecting electoral processes.

CIPESA Welcomes the Annulment of Sections of Uganda’s Computer Misuse Act

By Edrine Wanyama |

Uganda’s Constitutional Court has delivered a major ruling that has outlawed several sections of the Computer Misuse Act, Cap 96, and ordered the government and its agencies to stop any further enforcement of the nullified provisions. These stringent provisions had significantly restricted the use of various communication platforms, including social media. The court ruling marks an important step towards ending enduring limitations on freedom of expression, access to information and other online freedoms.

The Computer Misuse (Amendment) Act, 2022, which introduced a range of offences including unauthorised access, unauthorised sharing of information about children, hate speech, sharing of unsolicited and malicious information, and misuse of social media, has been outlawed in its entirety. These provisions were overly broad, vaguely worded and carried severe penalties.

In response to a number of petitions filed by individuals and civil society organisations, which were consolidated for determination, the Constitutional Court found that the Computer Misuse (Amendment) Bill, 2022, was passed into law without complying with the provisions of rule 24(3) of the Rules of Procedure of Parliament, which contravened articles 88 and 89 of the Constitution. Parliament’s rules of procedure and the Constitution require that the quorum should be ascertained before passing of laws.

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA), which was a co-petitioner in the case, had in its analysis and comments to the Parliamentary Committee on Information and Communications Technology argued that while addressing cybercrime was necessary, overly broad laws risk shrinking the digital civic space by limiting freedom of expression and access to information.

Moreover, the law was passed long after the Supreme Court ruling in Charles Onyango Obbo and Another v Attorney General, which had outlawed the criminalisation of false news in section 50 of the Penal Code Act. CIPESA had raised concerns about this inconsistency in the law prior to the filing of the petition.

Importantly, the Constitutional Court also struck down sections 162 and 163 of the Penal Code Act, which criminalised defamation. The Court found that these provisions violate article 9 of the African Charter on Human and Peoples’ Rights and are a limitation to the right to freedom of expression, contrary to regional and international human rights standards.

In the lead judgement of Justice Irene Mulyagonja, Court found that:

  • “Parliament passed the Computer Misuse (Amendment) Bill, 2022 into an Act of Parliament without complying with the provisions of rule 24(3) of the Rules of Procedure of Parliament made under Article 94 of the Constitution.
  • The enactment of the Computer Misuse (Amendment) Bill into an Act of Parliament without complying with rule 24(3) of the Rules of Procedure of Parliament was inconsistent with Articles 88 and 89 of the Constitution, and as a result, the Computer Misuse (Amendment) Act, 2022, was null and void.
  • The provisions of the Computer Misuse Act (2023 Edition) that were challenged in Constitutional Petitions 34, 37 and 42 of 2022 are therefore all null and void because they were enacted without following the law.
  • Section 162 of the Penal Code Act contravenes Article 9 of the African Charter on Human and Peoples’ Rights; and section 163 that defines the term “defamation” therein does not meet the standard of the law that is required by Article 9(2) of the Charter, and is inconsistent therewith to that extent and therefore null and void.”

Uganda has in recent years experienced significant restrictions on digital civic space. During the general elections in January 2026, the government shut down the internet for five days. In 2024, in the lead up to elections, were charged under the annulled law with malicious information on X and insulting the President and the First Family. These actions are often justified on grounds such as preventing online misinformation and disinformation or safeguarding national security, but their broad application raises serious concerns for digital rights and the right to free expression.

Over the years,  several civic actors, including journalists and media professionals, human rights defenders, political opponents, have faced intimidation, arrests, and prosecution under these contentious provisions of the Computer Misuse Law.

Despite the Constitutional Court’s progressive decision, which is a positive step towards enhancing legislative accountability and reaffirming Uganda’s commitments under regional and international human rights instruments, there is no ultimate guarantee that the right to fundamental freedoms and civic liberties guaranteed by the Constitution will be respected.

It should be noted that the Court’s decision largely focused on procedural issues rather than examining the constitutional guarantees on freedom of expression and access to information. This leaves open the possibility that similar provisions could be reintroduced if proper legislative procedures are followed.

Continuous advocacy for progressive provisions remains necessary.

Given the volatile nature of Uganda’s digital space, there is a need for Parliament to ensure harmonisation of national laws with regional and international standards, conduct wide consultations on proposed laws, and undertake human rights impact assessments.

CIPESA welcomes the current judgement as progressive but emphasises the need for decisiveness in implementation of the orders by the court. Without sustained vigilance, restrictive laws in addition to the Uganda Communications Act, Public Order Management Act, Uganda Peoples Defence Forces Act, the Regulation of Interception of Communications Act and the Anti-terrorism Act may re-emerge in different forms.

The protection and promotion of civil liberties in digital spaces must remain a priority.

Human Rights Implications of Health Care Digitalisation in Kenya

By CIPESA Writer |

The evolution of digital health is largely driven by technological advancements, the quest for more efficient healthcare, and the growing demand for available, accessible, affordable and quality services. The United Nations’ 2030 Agenda for Sustainable Development recognises the transformative potential of Information and Communications Technology (ICT) in fostering human progress, bridging digital divides, and creating knowledge societies. Despite technological advancements, the World Health Organization (WHO) notes that many countries, including Kenya, have yet to fully leverage digital health for positive outcomes. 

​​The transition from the National Health Insurance Fund (NHIF) to the Social Health Insurance Fund (SHIF) presents a policy shift towards realising Universal Health Coverage (UHC) in Kenya. However, this transition has faced significant challenges that impact the right to health, particularly for vulnerable and marginalised groups (VMGs). A major concern within this transformation is the role of digitalisation in health care management and its implications for service delivery. 

It is against this background that the Collaboration on International ICT Policy for East and Southern Africa (CIPESA), the Danish Institute for Human Rights and the Kenya National Commission on Human Rights (KNCHR) undertook a human rights impact assessment on digitalisation of the health care sector in Murang’a, Laikipia, Kisii and Homabay counties in Kenya. The assessment included the NHIF to SHIF transition, digitalised solutions in the sector and their potential impacts especially on Vulnerable and Marginalized Groups (VMGs) to access quality health care.

This report presents the findings of the assessment which was conducted through literature review and field data collection, as elaborated in the methodology section below. The report highlights the positive impacts of digitalisation of health services, pressing challenges, and impacts on the state of healthcare. It also provides targeted and actionable recommendations for improving the effectiveness, inclusivity, and human rights compliance of digital health initiatives in Kenya.

As an integral part of a human rights-based approach, this assessment took a gender-responsive approach to adequately reflect the experiences of women and to understand gender relations within households and communities. It included a gender-responsive context analysis and representative participation in engagements as well as the conceptualisation, adaptation, and utilisation of existing public sector digital infrastructure for enhanced gender responsiveness.

A Human Rights-Based Approach to public sector digitisation should include Human Rights Impact Assessments (HRIA) in the conceptualisation, development, implementation, and monitoring of digital solutions, and the results thereof should be made publicly available. As such, HRIA is often called for, but examples of such assessments are hard to come by, making few public examples of HRIA of public digitalisation products. Therefore, this assessment documents and shows outcomes that may serve as a model and practical guidance for conducting future human rights impact assessments in the public sector in Kenya and beyond.

Read the full report here.

The AU Disability Protocol Comes Into Force: Implications for Digital Rights for Persons with Disabilities in Africa

By Paul Kimumwe & Michael Aboneka |

On this International Day for Persons with Disabilities, CIPESA reflects on the impact of the African Union (AU) Disability Protocol and its Implication on digital rights for persons with disabilities in Africa and calls upon the African Commission to establish a Special Mandate to enhance the respect for and protection of the rights for persons with disabilities in Africa

Six years after its adoption, the Protocol to the African Charter on Human and Peoples’ Rights on the Rights of Persons with Disabilities in Africa came into force in May 2024 after securing the mandatory 15th ratification by the Republic of Congo. The other 14 African Union member states that have ratified the Protocol are Angola, Burundi, Cameroon, Kenya, Mali, Malawi, Mozambique, Namibia, Nigeria, Niger, Rwanda, South Africa, the Sahrawi Arab Democratic Republic, and Uganda. 

For disability rights activists, this was a defining moment as the protocol augments the rights of persons with disabilities to barrier-free access to the physical environment, transportation, information, and other communication technologies and systems. Specifically, under articles 23 and 24 of the protocol, States Parties should take “effective and appropriate measures” to facilitate the full enjoyment by persons with disabilities of the right to freedom of expression and opinion and access to information, including through the use of Information and Communication Technologies (ICT).

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) has been a longstanding advocate for African governments to urgently ratify the protocol. However, CIPESA has also stated, including in submissions to the Africa Commission on Human and People’s Rights (ACHPR), that ratifying the protocol would be a major but insufficient step in ensuring that persons with disabilities access and use digital technologies and that there is sufficient disaggregated data to inform programme interventions.

Indeed, article 24(2) requires States Parties to put in place policy, legislative, administrative, and other measures to ensure that persons with disabilities enjoy the right to freedom of expression and access to information on an equal basis, including:

  1. Providing information intended for the general public as well as information required for official interactions with persons with disabilities in accessible formats and technologies appropriate to different kinds of disabilities in a timely manner and without additional cost to persons with disabilities. 
  2. Requiring private entities that provide services to the general public, including through the internet, to provide information and services in accessible and usable formats for persons with disabilities. 
  3. Recognising and promoting the use of sign language. 
  4. Ensuring that persons with visual impairments or with other print disabilities have effective access to published works, including by using information and communication technologies.

The protocol adds to the available digital rights advocacy tools for disability rights actors, including the 2006 United Nations Convention on the Rights of Persons with Disabilities (CRPD), which places significant obligations on States Parties to take appropriate measures to ensure that persons with disabilities have equal and meaningful access to ICT, including the internet. 

The CRPD was the first international human rights treaty requiring the accessibility of digital tools as a prerequisite for persons with disabilities to fully enjoy their fundamental rights without discrimination. It highlights the inherent risks of exclusion of persons with disabilities from participating equally in society by defining ICT accessibility as integral to general accessibility rights and on par with access to the physical environment and transportation.

While there has been some progress in the enactment of disability rights-respecting and ICT-enabling laws for persons with disabilities in Africa, implementation is a challenge. Moreover, the Protocol comes into force when the digital divide and exclusion of persons with disabilities has worsened despite the exponential growth and penetration of digital technologies on the continent. Persons with disabilities have consistently remained disproportionately excluded from the digital society due to factors such as low levels of ICT skills, high illiteracy levels, and high cost of assistive technologies such as screen readers, screen magnification software, text readers, and speech input software.

It is against this background that CIPESA adds its voice to other calls to the African Commission to expedite the establishment of a special mandate at the level of Special Rapporteur for Persons with Disabilities. This elevated position will ensure that the rights of persons with disabilities in Africa are mainstreamed and upheld.

CIPESA recognises that as a regional human rights instrument, the protocol empowers disability rights actors to demand the enactment and full implementation of policies and laws that promote the rights of persons with disabilities, including in accessing and using digital technologies.

For example, disability rights actors, including civil society, activists, and Disability Rights Organisations (DPOs), should develop mechanisms to monitor the status of implementation of the protocol, including ensuring that the states parties submit their statutory reports as required by Article 34 of the protocol. The DPOs should also actively participate in developing shadow reports on the status of implementation of the protocol, especially on access to information and participation in public affairs.

In addition, disability rights organisations should work with policymakers and the executive to ensure that more countries ratify the protocol and domesticate it through national policies, laws, and practices. Both the protocol and the CRPD should become a reference point during any discussions of draft laws and policies that affect persons with disabilities.

For the media, it is important that, through their reporting, they hold governments accountable for failure to ratify or to fully implement the provisions of the protocol.

Member countries can also demand for accountability of their peers on the status of implementation of the key provisions of the protocol through the African Peer Review Mechanism (APRM).

Please read more about CIPESA submissions on policy actions governments should take after ratifying the protocol. See also The Disability and ICT Accessibility Framework for Monitoring the Implementation of ICT Accessibility Laws and Policies in Africa.

1 2 3 9