Stakeholders Call for Digital Transformation That Bridges Business and Digital Rights in Uganda

By Doreen Namuyanja |

Uganda is embracing the opportunities offered by Artificial Intelligence (AI) and Digital Public Infrastructure (DPI) as drivers of national development. Both promise efficiency, improved service delivery, financial inclusion, and economic growth. However, as the country advances its digital transformation interests, questions linger on the adequacy of safeguards for citizens especially where business and rights intersect.

These questions were at the centre of a  High-Level Multi-Stakeholder Dialogue on Business and Digital Rights convened by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA)  on May 7, 2026, under the Advancing Respect for Human Rights by Businesses in Uganda (ARBHR) project, supported by Enabel and the European Union (EU). The dialogue brought together 81 individuals representing government officials, civil society actors, private sector representatives, researchers, and digital innovators to reflect on the growing recognition that digital transformation is not simply a technical process, but also a governance and human rights issue that demands transparency and accountability.

The discussions at the dialogue revealed a tension between innovation and human rights. Systems such as digital identity (ID), payment platforms, and data-sharing frameworks   centralise enormous amounts of personal data and are reshaping power relationships between citizens, the government, and corporations.

Participants noted that in the absence of strong governance frameworks, these systems can enable exclusion, surveillance, and misuse of personal information. Further,  concerns were raised about fragmented systems across government agencies, weak interoperability, and limited public awareness regarding how personal data is collected, stored, and shared.

Meanwhile, as emerging technologies such AI take hold in the country,  the Uganda National AI Landscape Assessment positions  AI as a key digital technology driver to drive economic growth.

However, the Assessment documents the absence of a dedicated AI policy and regulatory framework, a shortage of AI skills, and insufficient collaboration between academia and the technology sector. Similarly, like its counterpart governments across Africa, Uganda is increasingly investing in DPI systems including digital ID and payment systems,  as well as data exchange frameworks. DPI is being positioned as a key pillar of digital transformation strategies across Africa. However, DPI  systems remain heavily reliant on public data and algorithmic decision-making. Thus, if   designed and deployed without sufficient citizen participation, independent oversight, legal safeguards, and alignment with the public interest, they risk becoming tools of exclusion, exploitation, and foreign dependency.

Various efforts related to the adoption of emerging technologies are underway.  Ambrose Ruyooka, the Assistant Commissioner at the Ministry of ICT and National Guidance, Uganda noted that the Ministry is taking a cautious approach to regulation by prioritising standards, policy guidance, and institutional learning before introducing binding laws. This includes efforts to domesticate the UNESCO Recommendations on the Ethics of AI and a Readiness Assessment process. The dialogue also came on the heels of the Ministry’s call for stakeholder input to the National AI and Emerging Technologies Strategy – signaling a growing policy focus on responsible digital transformation.

Further he stressed that in the midst of AI, stakeholders should not be “passive consumers” of the digital economy but actively “participate in shaping it” while pointing out that participation requires local technical capacity to “build, operate and audit” systems such as AI and DPI systems independently.While government efforts are laying the foundation for AI governance, businesses also have an obligation to innovate responsibly and adopt robust human rights due diligence processes to support regulatory compliance and foster trust and sustainability.

At a broader level, the dialogue demonstrated how digital rights are increasingly intertwined with economic rights and social justice. As a result, corporate responsibility can no longer be limited to traditional labour or environmental concerns. Companies are now expected to consider how their digital operations affect privacy, equality, freedom of expression, and access to information.

This shift is especially significant for Uganda’s small and medium enterprises (SMEs), many of which are digitising rapidly but often lack the resources and expertise needed to manage cybersecurity and data effectively.

Presentations from implementing partners, including the Private Sector Foundation Uganda (PSFU), Evidence and Methods Lab (EML), Wakiso District Human Rights Committee (WDHRC), Boundless Minds, and Girls for Climate Action (G4CA), highlighted both the scale of the challenge and the potential for practical intervention. Partner interventions on digital rights and cybersecurity are strengthening awareness and practices among entities – both rural and urban.

The European Union’s (EU) Commitment to Human Rights in Business

Laurianne Comard, Programme Officer at the EU Delegation to Uganda,  noted that the EU and its member states are currently among Uganda’s largest investors in the private sector, with over 1.4 billion euros deployed to foster sustainable economic growth and high-value exports. Specifically, she stated that the EU supports Uganda’s National Action Plan (NAP) on Business and Human Rights with over 20 billion Uganda Shillings, with a specific focus on strengthening human rights practices in business operations, particularly around labour standards and women’s rights.

Course-Correcting on Inclusion

Participants also noted that public participation in digital governance remains limited. Several civil society actors argued that consultations around national AI strategy have not been broad enough, particularly for rural communities, labour unions, youth groups and persons with disabilities. Frameworks developed without broad public engagement risk lacking legitimacy and failing to address the lived realities of those most affected.

The dialogue also reflected on the NAP on Business and Human Rights and the consultative processes underpinning its evaluation and development of NAP II. Lydia Nabiryo, Assistant Commissioner at the Ministry of Gender, Labour and Social Development, acknowledged that the government is actively working to broaden participation in the NAP’s revision.

Her remarks were a candid recognition that the first NAP, while a significant milestone, left representational gaps, and that those gaps are now being deliberately addressed. She noted, “If you have noticed this time round, we are having a more inclusive dialogue with stakeholders that were not necessarily represented in the first NAP. So, not only is the government evaluating, but we’re also course correcting.”   

Participation should not only be limited to policy processes. Shane Ssenyonga, an innovator, pointed out the need for collaborative spaces that support entrepreneurs and businesses to build scalable solutions that are responsive to social, cultural, and economic realities.

Recommendations for Action

The dialogue called for stronger human rights safeguards and access to remedy within digital transformation strategies and business operations. The strategies should be in harmony with existing digital laws and policies and strengthen oversight and enforcement by relevant institutions. For businesses, adoption of forward looking internal policies and risk management practices was emphasised to ensure trusted deployments and reduce barriers to uptake. Advocacy, documentation, and digital literacy interventions remain critical to public education and compliance monitoring.

CIPESA Annual Report 2025 Highlights Agility in A Changing Funding and Policy Landscape

By CIPESA Writer |

The Collaboration on International ICT Policy for East and Southern Africa (CIPESA) is pleased to present its 2025 Annual Report. Made possible by a wide network of collaborators across Africa and beyond, our work reflects a year marked by agility, resilience, and responsiveness amid rapid shifts in technology, policy, and governance.

Across Africa, governments rapidly expanded the use of artificial intelligence (AI) and Digital Public Infrastructure (DPI), including national digital ID systems, surveillance tools, and e-government platforms, reshaping how power is exercised, services are delivered, and citizens engage with the state. At the same time, digital platforms remained central to political and civic life, amplifying both civic participation and manipulation.

Through our research, advocacy, and partnerships, the report highlights how digital transformation is reshaping everyday life and why protecting civic space and digital rights remains more important than ever.

Over the year, our work moved beyond who participates in digital governance across Africa to strengthening the quality and influence of that participation. We are deeply grateful to all our Network of allies whose support made our 2025 work possible.

In a year marked by significant shifts in the global funding landscape, their continued trust and commitment to digital rights in Africa was both enabling and affirming.

We remain committed to advancing an open, inclusive, and rights-respecting digital ecosystem in Africa, confident that when evidence, advocacy, and collective action come together, meaningful change is possible. Read more on the report below.

CIPESA Annual Report 2025

Zimbabwe’s National AI Strategy: Policy Lessons for Africa

By Edrine Wanyama |

Zimbabwe recently adopted its National Artificial Intelligence (AI) Strategy 2026–2030 (AI strategy)  to guide digital technology and transformation in the country. The strategy aims to accelerate development, enhance industrialisation, and improve service delivery in sectors such as health, finance, agriculture, education and public administration. The strategy emphasises building local data infrastructure as opposed to relying on foreign data storage infrastructure while promoting an AI governance approach grounded in Ubuntu, human rights, accountability, transparency and inclusivity.

However, an important question is whether Zimbabwe’s approach offers useful lessons for other African countries developing national AI strategies.

Lessons for Other African Countries

The country’s AI strategy is organised around six pillars that together map a practical path for AI adoption and deployment. First, AI talent and capacity development is essential for ensuring that institutions have the skills needed to implement AI effectively. Second, AI infrastructure and computational sovereignty are necessary for ensuring digital and data sovereignty. Third, AI adoption and service transformation are critical for supporting the integration of AI across public and private sectors to improve their productivity, accountability and transparency.

The fourth pillar, AI governance, ethics and regulation, is essential for building public trust and creating a framework that supports responsible innovation. The fifth pillar, AI research, development, and innovation, can drive investments, expand knowledge production and strengthen academic output. The sixth pillar, strategic international collaboration, presents an opportunity for global partnerships with key players and stakeholders, technology exchange, and potentially greater investment.  

Consequently, these pillars offer useful lessons for other countries seeking to harness AI for socio-economic transformation while protecting data rights and data sovereignty.

Alignment with the African Union (AU) AI Strategy

Zimbabwe’s AI Strategy reflects several priorities contained in the AU Continental Artificial Intelligence Strategy, particularly the emphasis on coordinated AI governance, digital sovereignty, and sectoral innovation. Zimbabwe’s strategy aims to harmonise the deployment and use of AI across sectors such as health, finance, agriculture, education and public administration through common governance benchmarks for AI governance. If implemented effectively, these goals could help to address digital neo-colonialism, an issue that has been dominant in Africa’s technological space.

The Strategy also places strong emphasis on AI as a tool for socio-economic development, aligning with Agenda 2063 and the Sustainable Development Goals (SDGs), particularly in sectors such as health, agriculture, and education. The Strategy promotes the deployment of AI to improve agriculture through crop disease prevention, as well as mining and mineral development, which is consistent with the AU AI strategy’s priorities on resource optimisation and climate resilience.

However, Zimbabwe faces significant governance and implementation challenges. The country scored 0 in the 2024 Global Index on Responsible AI Governance, highlighting the gap between policy ambition and institutional readiness. This means it requires major actions to implement the strategy, such as the establishment of robust legal safeguards, accountability mechanisms, oversight institutions, and rights-based governance frameworks, which are also emphasised within the AU strategy.  Other African countries can draw lessons from Zimbabwe’s approach, such as the need to complement AI strategies with stronger governance capacity, clearer regulatory safeguards, and more coherent data governance frameworks to support responsible and accountable AI deployment.

UNESCO Guidance on AI

The UNESCO Recommendations on Ethics of Artificial Intelligence, adopted in 2021, is a global normative framework that promotes human rights, including human dignity, transparency, fairness, human oversight in AI systems, and democratic participation. It also provides practical policy action areas covering issues such as data governance, gender, education and research, health, and social wellbeing.

While the UNESCO Guidance is emphatic on ethical and privacy considerations, Zimbabwe’s strategy falls short. Ambitions to integrate AI into public service delivery sectors such as education, health, and public administration will require stronger safeguards to ensure alignment with the human-centric principles articulated in the UNESCO framework. In the age of AI, data security concerns, intellectual property rights, algorithmic bias, and institutional accountability are central to responsible deployment of AI and require clearer policy and regulatory attention.

Similarly, the UNESCO Guidance warns against the use of AI in a manner that undermines democratic participation, civic engagement, and collective decision-making. This is especially important in contexts where surveillance technologies such as facial recognition, drone monitoring, communication tracking, and social media surveillance are deployed without clear safeguards or independent oversight. Zimbabwe, like several other African countries, has invested in AI-enabled infrastructures, such as the “smart city” systems to monitor and surveil citizens in ways that are opaque and lack clear accountability mechanisms.

As African countries continue developing national AI strategies and governance frameworks, they must strive to ensure that the deployment of AI is transparent, publicly accountable, and pays close attention to ethical and human rights standards. Without these safeguards, AI risks reinforcing exclusion, surveillance, and digital authoritarianism rather than advancing development.

Conclusion

Zimbabwe’s adoption of an AI Strategy is an important step toward advancing tech-enabled digital and socio-economic transformation. It also reflects the country’s intent to align national priorities with the African Union’s vision for AI-driven development across the entire continent. However, for such strategies to be effective and legitimate, they must be grounded in ethical and human rights standards laid down in regional and international benchmarks.

 How the WHO Digital Health Strategy Should Govern Data, AI and Digital Public Infrastructure

By Raylenne Kambua |

As the World Health Organization (WHO) develops the Global Digital Health Strategy for 2028–2033, the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) has submitted recommendations urging that the strategy be anchored on human rights, equity, and accountability, alongside technological innovation. 

Across Africa, Artificial Intelligence (AI), telemedicine, disease surveillance systems, and automated diagnostic systems are transforming healthcare delivery. However, CIPESA pointed out in the submission to the WHO Regional Office for Africa that technological innovation without proper governance can worsen exclusion, undermine privacy protections, and reinforce inequalities in healthcare delivery.

The submission comes at a time when key global and regional digital health governance frameworks are being reshaped. Last year, the World Health Assembly extended the Global Strategy on Digital Health 2020–2025, and simultaneously mandated a successor framework to be completed in 2027. 

Furthermore, global initiatives such as the World Summit on the Information Society (WSIS) and the Global Digital Compact emphasise that digital transformation must integrate the Sustainable Development Goals and ensure inclusive development.

At the continental level, the Africa Centres for Disease Control and Prevention (Africa CDC) has rolled out the Africa CDC Digital Transformation Strategy which alongside the  African Union (AU) Data Policy Framework advances interoperability, transparency, privacy, and the ethical deployment of digital systems in the health sector. However, CIPESA notes that despite these commitments, implementation gaps remain significant, particularly regarding health data governance, accountability, and protection against algorithmic harm.

CIPESA’s work on health data governance in Uganda, patient data privacy in Ghana, Rwanda, and Uganda, and analysis of Kenya’s Digital Health Act, point to the same reality. The rules governing who controls health data, who is included in digital health systems, and who is held accountable when data is mishandled are still weak across most of the continent.

“As countries embrace AI, digital public infrastructure, and data-driven healthcare systems, the real test will be whether these technologies strengthen confidence in public health systems or deepen concerns about exclusion, surveillance, and the misuse of personal data,” said CIPESA Executive Director Dr. Wairagala Wakabi.

He added: “Trustworthy digital health systems require transparent digital infrastructure, accountable AI systems, and strong data protection safeguards. Africa has the chance to shape a digital health governance model that is innovative, inclusive, and based on the public interest and human dignity.”

CIPESA’s Core Positions and Recommendations

Digital health offers significant potential to enhance Universal Health Coverage and strengthen health systems across Africa. However, without governance anchored in rights, equity, inclusion, and accountability, this promise will remain unfulfilled. It is against this backdrop that CIPESA submitted the following recommendations:

1. Digital Public Infrastructure (DPI)

Digital health infrastructure should be open, interoperable, transparent, and rights-respecting, with safeguards to prevent exclusion and misuse of shared systems.

    2. Health Data Governance

    Most African countries lack specific laws that govern health data. Countries should therefore establish clear legal frameworks governing health data, including informed and meaningful patient consent, limits on data sharing, independent oversight mechanisms, and enforceable accountability structures.

    3. Artificial Intelligence (AI)

    CIPESA warns that most AI systems used in healthcare are trained on non-African datasets, which increases the risk of inaccurate diagnoses and exclusion. The submission recommends that AI tools and systems should be tested and validated in Africa, and include mandatory “explainability” standards so that health professionals understand how the AI reaches conclusions, and safeguards against bias in clinical decision-making tools.

    4. Interoperability

    Many digital health tools are isolated across countries and institutions, meaning they can not share data with each other. In this light, CIPESA recommends the adoption of national interoperability standards, including the WHO SMART Guidelines, to ensure secure and efficient health data exchange. Also, all digital health vendors should adhere to interoperability standards and the utilisation of shared infrastructure.

    5. Equity and Inclusion

    The digital divide continues to expand in most African countries and limits access to digital health services. CIPESA recommends conducting “equity impact assessments” before launching new systems, continued availability of offline options, and supporting digital literacy initiatives.

    6. Stronger Governance

    CIPESA holds that technology fails without clear leadership and coordination between health and technology departments. Therefore, creating clear governance structures for accountability and embracing a multi-stakeholder approach in decision-making processes are vital for resilient health systems. Other recommendations are the publication of institutional AI and digital health use policies and mandatory human rights impact assessments for high-risk systems.

    7. Sustainable Financing

    Many digital health initiatives rely on short-term donor funding, resulting in countries being dependent and unable to scale such programmes. Additionally, gaps in workforce capacity constrain implementation. CIPESA urges governments to invest in domestic financing of digital health systems and training of health and technical personnel.

    In conclusion, CIPESA’s submission emphasises that while digital technologies offer significant opportunities to strengthen health systems and improve service delivery, without strong safeguards, digital health risks reproducing and scaling existing inequalities in new, technologically mediated forms. A rights-based, inclusive, and accountable approach is therefore essential to ensure that Africa’s digital health future is not only innovative, but also equitable and just.

    Read the full submission here.

    Outpaced by Its Own Ambition: Can Kenya Bridge Its AI Regulation  Gap?

    By Raylenne Kambua |

    The raw paradox at the heart of Kenya’s Artificial Intelligence (AI) moment is that the country is simultaneously sprinting ahead in AI adoption while grappling with a shrinking space for the very digital voices that AI empowers.

    According to the Digital Global Update Report, Kenya recorded the world’s highest usage rate of AI tools in 2025, with 42.1% of internet users aged 16 and above reporting active use of AI-powered technologies. This level of usage indicates that AI is increasingly being woven into the daily life of Kenyans.

    However, the Navigating the Implications of AI on Digital Democracy in Kenya report by the Collaboration on International ICT Policy for East and Southern Africa (CIPESA) highlights that while AI empowers citizens, it also enables unprecedented surveillance and manipulation.

    A Nation Leading the Way in AI Adoption

    Kenya has made significant investments in digital services, innovation hubs, and connectivity under the National Digital Master Plan 2022–2032.

    These developments are also transforming how citizens interact with the government. Tools such as the Office of the Data Protection Commissioner’s Linda Data chatbot and platforms such as Sauti ya Bajeti have expanded access to rights information and budget tracking.

    Yet, even as AI delivered clear benefits, it also revealed its dual nature, most visibly during the 2024 #RejectFinanceBill protests, during which Gen Zs mobilised through AI-generated infographics, satire, and short-form videos. At the height of the protests on June 25, a nationwide internet disruption was enforced despite assurances from the Communications Authority. The disruption was confirmed by network monitors like Cloudflare and NetBlocks, exposing the fragility of internet freedom in Kenya.

    Civil society condemned the internet shutdown as a violation of rights, while telecoms Safaricom and Airtel attributed it to outages in their undersea cable. In the aftermath, reports of abductions and enforced disappearances of digital activists escalated, with the Kenya National Commission on Human Rights documenting at least 82 cases between June and December 2024.

    Kenya’s AI Policy Landscape

    The launch of the Kenya National AI Strategy 2025–2030 in March 2025 signalled the country’s ambition to position itself as Africa’s leading AI innovation hub. The strategy prioritises governance, ethics, investment, digital infrastructure, data ecosystem development, and support for AI research and innovation.

    Kenya has also strengthened its international profile through participation in programmes such as the United Nations High-Level Advisory Board on AI, joining the International Network of AI Safety Institutes, and assuming leadership in the World Summit on the Information Society (WSIS+20).

    At the national level, initiatives such as Digital Platforms Kenya (DigiKen) and the Kenya Bureau of Standards’ draft AI Code of Practice reflect growing momentum toward operationalising AI governance and skills building. The government is also developing an AI and Emerging Technologies Policy and a Data Governance Policy, both of which are expected to be in place by July 2026.

    However, the gap between ambition and readiness remains wide. Kenya ranks 93rd in the 2025 Government AI Readiness Index, due to persistent weaknesses in infrastructure, implementation, and institutional capacity.

    Moreover, Kenya’s legal framework for AI remains fragmented and incomplete. Currently, there is no standalone AI law in force, but a controversial Artificial Intelligence Bill, 2026, that has raised significant concerns about over-regulation and censorship  is under discussion. Additionally regulation is based on broader laws such as the Data Protection Act 2019 and the Computer Misuse and Cybercrimes Act 2018, which were not designed to address AI-specific risks such as deepfakes, automated decision-making, algorithmic discrimination, or synthetic disinformation.

    As highlighted in the CIPESA report, critical gaps remain in the use of AI. These include the absence of mandatory algorithmic impact assessments, weak safeguards against AI-driven surveillance such as facial recognition, and scant measures to address AI-generated electoral misinformation. Furthermore, regulatory authorities lack sufficient capabilities to audit and monitor sophisticated AI systems, and there are no clear licensing or accountability frameworks for AI creators and deployers.

    “Without deliberate, inclusive, and rights-centred governance, AI risks entrenching authoritarianism and exacerbating inequalities.” (Navigating the Implications of AI on Digital Democracy in Kenya, 2025)

    The Way Ahead: AI Governance Focused on Human Rights

    The CIPESA report outlines a human rights–centred approach to AI governance that is built on the following key principles:

    1. Life-Centred and Human-Centred Design and Accountability: AI should support and not replace human judgment, with strong oversight to ensure transparency and accountability.
    2. Equity and Fairness: Design AI to prevent bias and expand inclusive access, especially for underrepresented groups.
    3. Transparency and Trust: Ensure AI systems are explainable, well-documented, and open to public scrutiny and challenge.
    4. Safety, Security and Resilience: Build resilient systems with ongoing risk assessments and strong protections against misuse.
    5. International Collaboration and Ethical AI Development: Advance ethical AI through international collaboration while upholding constitutional values and human oversight.
    6. Environmental sustainability: Align AI development with climate resilience and sustainable resource use.
    7. Inclusive Participation and Cultural Relevance: Reflect local diversity and involve marginalised communities in AI design.
    8. Robust Governance and Adaptive Regulation: Maintain flexible, responsive regulation that keeps pace with technological change.

    The report calls for a coordinated, multi-stakeholder approach to AI governance. It recommends that:

    • The government should enact a comprehensive AI law aligned with constitutional and international human rights standards, establish a legally mandated National AI Advisory Council with inclusive representation and strong enforcement powers.  It should also introduce clear prohibitions on high-risk practices such as real-time biometric surveillance without judicial oversight.
    • Civil society and the media should strengthen public awareness, promote accountability, and counter AI-driven disinformation.
    • Private sector actors should uphold transparency, fairness, and ethical standards across AI systems, including fair labour practices. Labour protections must be guaranteed for gig workers and data annotators within the AI value chain.
    • Academia and research institutions should continue generating evidence that can guide context-specific policy and regulation.
    • Across all stakeholders, digital literacy must be expanded, especially in underserved and rural communities, so that citizens can understand and challenge AI systems that affect them.

    With the ongoing legislative processes on AI, this is a pivotal time for Kenya, as it has the momentum and the attention of the world. But momentum without action will not work. The country cannot afford slow, fragmented debates while technology is fast progressing. Additionally, Kenya must strike a careful balance between regulation and innovation, as overly restrictive rules could limit access, slow local innovation, and lock the country out of AI’s economic and social benefits. The goal should be a flexible, forward-looking framework that protects rights while still enabling growth and opportunity.

    Read the full report, Navigating the Implications of AI on Digital Democracy in Kenya.