Africa's AI Governance Landscape: A Deep Dive into the AFTEC Policy Tracker

AFTEC maps 1,034 African tech policies, exposing AI governance gaps, data sovereignty struggles, and the Brussels Effect.
The Africa Technology Policy Tracker (AFTEC), developed by Carnegie Endowment and the Africa Telecommunications Union, catalogs over 1,034 policy records across all 54 African nations. The database reveals a continent where AI strategies are multiplying but dedicated legislation lags behind, data sovereignty remains contested, and laws often mirror GDPR rather than reflecting homegrown priorities.
Who Is Writing the Rules for Africa's Algorithmic Ecosystem?
While the global AI race is largely framed as a US-China technology rivalry, the African continent is quietly building its own governance framework. At a technology policy seminar hosted by the Carnegie Endowment for International Peace, Dr. Jane Munga — a researcher in the foundation's Africa program — presented the findings of a project she leads: the Africa Technology Policy Tracker (AFTEC).
AFTEC covers all 54 African countries plus the African Union, making it the most comprehensive database of digital economy policy on the continent. Dr. Munga defines her research focus as "the policy layer governing Africa's algorithmic ecosystem" — a term she uses to describe the full AI landscape: from the code and algorithms developers write, to the applications built on top of them, to the laws and policies that regulate it all.
For anyone working in the tech industry, understanding this "invisible rulebook" is essential. As Munga puts it: "Whether you know it or not, there are laws defining what you can and cannot do."

AFTEC: A Policy Database Spanning More Than Half a Century
AFTEC was co-developed by the Carnegie Endowment and the Africa Telecommunications Union (ATU). Founded in 1977, the ATU is an intergovernmental organization under the African Union framework dedicated to coordinating telecommunications and ICT policy across African nations, headquartered in Nairobi. The ATU plays a key role in advancing digital infrastructure standardization, spectrum management, and broadband access policy across the continent. Its partnership with Carnegie to co-develop AFTEC represents an important recent effort to bridge policy research and technology governance — and reflects a broader continental push to build knowledge bridges between international academic institutions and local regulatory bodies.
The database currently holds approximately 1,034 metadata records, spanning from 1971 to the present. The oldest entries date back to the 1970s; the most recent is Zimbabwe's newly released AI strategy.
Three Layers of Governance: Strategy, Law, and Regulation
Using Kenya as an example, Dr. Munga broke down the three-tier logic of digital governance in African countries:
- Strategic vision: Sets direction and defines the socioeconomic goals a country wants to achieve through technology. Most African nations view technology as a core driver of leapfrogging development. The classic example is M-PESA: the continent skipped fixed-line infrastructure entirely and went straight to mobile-based financial services. This logic is widely applied to AI — proponents argue Africa can bypass traditional industrialization and directly modernize agriculture, healthcare, and education through AI; critics counter that effective AI deployment depends heavily on data infrastructure, computing resources, and locally trained datasets, and that the prerequisites for "leapfrogging" are far from in place.
- Law: Such as Kenya's Information and Communications Act of 1998, which has been amended multiple times and remains in effect. No dedicated AI law has yet been formally passed anywhere on the continent.
- Regulation: Specific enforcement rules created by regulatory bodies — for example, the Office of the Data Protection Commissioner, established shortly after Kenya passed its Data Protection Act in 2019.
Four Pillars of the Digital Economy
AFTEC draws on the World Bank's "Digital Economy for Africa" initiative, OECD classification frameworks, and the Smart Africa Blueprint to organize all documents into four pillars: digital infrastructure, digital platforms, digital skills, and innovation ecosystems. Each document is also tagged with approximately 25 thematic labels (such as digital identity and digital payments) to enable precise searches by researchers.
Africa's AI Governance Today: Ambition Ahead of Legislation
Through a systematic review of all 1,034 documents, AFTEC paints a clear picture of AI governance in Africa — strategic awareness is awakening, but dedicated legislation remains significantly behind.
A Surge in AI Strategies
Africa's first AI strategy was published by Mauritius in 2018, with Algeria, Egypt, and others following suit. The past two years have been a critical turning point, with a large number of countries recognizing the urgency of developing AI policy. To date, approximately 15 African countries plus the African Union have released dedicated AI strategies or policies. Kenya and Côte d'Ivoire have both published theirs, with Ghana and Zimbabwe following close behind.

A Data Snapshot of the Three Governance Pillars
Dr. Munga summarizes the "algorithmic governance layer" around three core dimensions, with the following figures:
- AI strategies: 15 countries + the African Union
- Data protection laws: 44
- Cybersecurity laws: 48
The number of cybersecurity and data protection laws far outpaces dedicated AI strategies, confirming the reality that "the vision is there, but the dedicated legislation is still catching up." When all three are analyzed together, 14 countries have all three frameworks in place — spanning North Africa (Egypt, Algeria), West Africa (Senegal, Ghana, Nigeria), and East and Southern Africa (Kenya, Rwanda, Zimbabwe, Ethiopia) — forming Africa's vanguard in AI governance.
One cautionary note: South Africa's recently released AI policy was retracted after it was found to contain fabricated data generated by a large language model. Dr. Munga cited this as a warning: "AI is already participating in the governance process itself. We must ensure the data integrity of government documents."
Data Sovereignty: The Deeper Stakes in African AI Governance
The most heated discussion at the seminar centered on data sovereignty.
The Cross-Border Data Dilemma
One audience member asked: when most African data is stored abroad, what is the practical value of local data protection laws? Dr. Munga's answer was nuanced: data flows themselves are not the problem — cross-border trade and international money transfers all depend on the free movement of data. What truly matters is "who can access it and who can benefit from it."
Take M-PESA as an example: the mobile payment system launched by Kenyan telecom operator Safaricom in 2007 now has over 30 million users and processes roughly half of Kenya's GDP in transactions. Yet its settlement data is processed through nodes in London (Vodafone headquarters) and South Africa (Vodacom), making the tension between data localization and financial inclusion particularly acute in an African context. M-PESA's success has also spawned a wide range of products — credit scoring, micro-loans, and agricultural insurance — built on transaction data, lending weight to Africa's "data as an asset" narrative: whoever controls the data controls the ability to build business models from it.

Health Data as a Geopolitical Flashpoint
The most contentious example came from the health data domain. Dr. Munga revealed that international organizations have attempted to exchange health aid funding for access to African countries' medical data. Cases of this kind have gone to court in Kenya, while Zambia and Ghana have chosen outright rejection. She argued that data protection laws cannot stop at "protection" — they must also create "economic value" by opening up legitimate, secure pathways for local innovators to access data.
New Sovereignty Challenges from Emerging Technologies
Dr. Munga also highlighted several emerging challenges. Low-Earth orbit satellites (such as Starlink) allow users to access the internet directly from space, bypassing domestic telecom regulation and raising concerns about data outflows and sovereignty.
Low Earth Orbit (LEO) satellite internet services, led by SpaceX's Starlink — operating at roughly 550 km altitude with latency as low as 20–40 ms — have received operating licenses in Kenya, Nigeria, Rwanda, and several other African countries. However, their "direct-to-user" architecture routes data traffic around domestic internet exchange points (IXPs) and telecom operators, effectively rendering existing data localization requirements and traffic monitoring mechanisms unenforceable. African regulators face a dilemma: requiring landing gateways increases operating costs and may reduce coverage, but turning a blind eye effectively means voluntarily surrendering jurisdiction over domestic data flows. Rwanda has already taken the lead by requiring Starlink to establish a local business entity and pay spectrum fees — an early example of African regulatory responses to the LEO challenge.
In addition, "iris scans for cash" programs have exposed the ethical risks and regulatory blind spots of biometric data extraction. Such programs (like the World ID project from Tools for Humanity) use specialized hardware to scan users' irises, generating a unique biometric hash in exchange for token rewards worth approximately 17,000 Kenyan shillings. Iris data is among the most sensitive category of biometric information — unlike passwords, a compromised iris cannot be changed, and it can be used for cross-context identity tracking. The program was suspended by Kenya's Office of the Data Protection Commissioner, which launched an investigation into whether its informed consent process complied with the Data Protection Act — marking a shift in African regulators' posture from reactive to proactive when confronting data collection practices by global tech companies.
The "Brussels Effect": The Question of Legislative Originality in Africa
Toward the end of the seminar, an audience member with a background in both software engineering and law raised a pointed question: what is the quality of these laws? He observed that data protection laws across African countries are "strikingly similar — almost copy-pasted."
Dr. Munga acknowledged this as a manifestation of the "Brussels Effect." The term was systematically articulated by Columbia Law School professor Anu Bradford in her 2020 book of the same name. It describes how the EU, leveraging the scale of its single market, unilaterally exports its regulatory standards (such as GDPR, product safety regulations, and competition law) to the rest of the world. Companies seeking access to the EU market comply with EU standards and then apply them globally, creating a "regulatory export" effect. African data protection legislation's deep GDPR influence is no accident — European development aid agencies (such as the EU External Action Service and the French Development Agency) often tie legislative technical assistance to funding, further reinforcing this path dependency.
Dr. Munga's core concern is that GDPR was designed around the protection of European citizens' rights — a framework that may not align with African countries' priority of using data to drive economic development. "When a law is inspired by another jurisdiction, it also inherits that jurisdiction's normative system. So what are Africa's own norms?"
A transplanted law may achieve basic data protection but fail to unlock the domestic economic value of data. She called on Africa's technology community to actively engage in the legislative process — whether through industry associations like the Kenya Private Sector Alliance (KEPSA), grassroots developer communities like Indaba X, or by directly submitting feedback to ministries — to ensure that "Africa's voice is stronger and louder."
Conclusion: Policy Is Not Silent Background — It Is a Decisive Force
Dr. Munga closed with a single line: "AI policy is not a silent layer — it is a decisive one."
For practitioners, researchers, and policymakers working in Africa's AI ecosystem and beyond, AFTEC offers a unique mirror. It both reveals the expectations African countries have for AI across priority domains such as health, agriculture, and public services (digital infrastructure is mentioned in over 90% of documents), and confronts the structural challenges of legislative lag, compromised data sovereignty, and insufficient legal originality.
In the global contest over AI governance discourse, whether Africa can move from being a "policy recipient" to a "rule maker" will profoundly shape the continent's technological future.
Key Takeaways
Related articles

Kimi K3 Launches on Telnyx Inference API: A New Path for Chinese LLMs Going Global
Moonshot AI's Kimi K3 is now available on Telnyx Inference API. Explore how Chinese LLMs are entering global developer ecosystems through third-party inference platforms.

The Truth Behind Codex 'Build a Website in 5 Minutes': AI Isn't Creating Sites—It's Helping You Copy Them
Exposing the truth behind viral Codex 5-minute website videos: creators aren't building original sites with AI—they're copying shared prompts or scraping others' work. Learn AI coding tools' real limits.

Getting Started with AI Agent Development: A Complete Guide from Concept to Practice
A comprehensive guide to AI Agent architecture and development, covering automated marketing, intelligent customer service, and investment analysis scenarios with single and multi-agent collaboration.