Practical AI governance for African organisations

Plain frameworks, honest questions and working tools for boards, founders and marketers who want to use AI well and be able to show it. Built for the laws and markets we actually operate in.

AI governance in Africa · Frameworks · Laws and policy by country · Questions to ask · Glossary · Ideas and quotes · Free AI governance tools · Work with Stanislaus

Frameworks

  • The Unseen to Assured Ladder: A five-rung maturity ladder that tells an African organisation where its AI governance really stands, from AI it cannot see to AI it can prove is under control. Each rung has a plain test, so you climb on evidence rather than on the strength of a policy document.
  • Find, Frame, Prove: the 90-day plan: A 30-60-90 day plan to stand up working AI governance in a mid-sized company without a large compliance team. You find what exists, frame the rules and the triage, then prove it works on real use cases before you scale it.
  • The PAUSE Triage: Five questions any manager can answer in fifteen minutes to sort an AI use case into green, amber or red, without needing a lawyer in the room. It decides how much scrutiny a use case gets, so scarce legal and risk time goes where it matters.
  • The CLEAR Code for customer-facing AI: Five tests for any AI that speaks to, targets or persuades customers: ads, content, chatbots and personalisation. Consent, Labelling, Evidence, Audience and Recourse keep marketing fast while keeping trust intact.

AI rules across Africa

As of October 2026, almost no African country has a dedicated, binding AI law. Bills are moving in Nigeria and Kenya, and Morocco has a draft framework law, but none has yet been confirmed as enacted. In practice, data protection law does most of the work, especially the rules on automated decisions, registration with the regulator and cross-border transfers, while national AI strategies and policies are multiplying fast under the African Union's 2024 Continental AI Strategy.

See the country-by-country picture (22 countries, as of October 2026).

Questions every board should ask about AI

  • Which AI systems are we already accountable for that this board has never discussed? Directors carry responsibility for AI in use today, including AI inside bought software.
  • If our chatbot gave a customer wrong information about fees tomorrow, who would find out first: us, the customer or social media? Monitoring and complaint routes decide whether an error stays small.
  • Would we be comfortable if every AI-generated ad we ran this year was published with a label saying so? Discomfort with disclosure is an early sign of a trust problem.
  • Who in this organisation can switch off an AI system that is causing harm, and do they know it? Without a clear stop authority, harm continues while people seek permission.
  • Are we using customer data to train or personalise AI for purposes customers never agreed to? Purpose limitation and lawful basis apply to AI as much as to any processing.
  • Which of our decisions about people are now made solely by a system, with no meaningful human review? Data protection laws in Nigeria, Kenya and South Africa set specific rules for solely automated decisions.
  • Do our human reviewers have the time and authority to overrule the AI, or do they simply approve it? Rubber-stamp review gives the appearance of oversight without the substance.
  • What would we lose if we paused our riskiest AI use case for a month to assess it properly? If the answer is little, the pause is cheap insurance.

Ideas

  • Africa should not copy and paste the EU AI Act: Learn from Brussels, by all means. Just do not hand over the pen.
  • Shadow AI is already in your organisation: The question is not whether your people use AI. It is whether you know how.
  • Governance is a growth tool, not a brake: Good brakes are what let you drive fast.
  • Data protection law already governs most of the AI you use: You do not need to wait for an AI Act. You already have homework.
  • Boards ask the wrong first question: Not 'what is our AI strategy?' but 'what AI are we already accountable for?'
  • Marketing is where AI risk meets the public first: Your customers will judge your AI by your chatbot and your ads, not your policy.
  • Language and local context are governance issues: A model that does not understand your customers cannot treat them fairly.
  • Procurement is the governance most companies forget: You will buy far more AI than you build. Govern the purchase.

Frequently asked questions about AI governance in Africa

What is AI governance?

AI governance is the set of rules, roles and routines an organisation uses to decide which AI to use, how to use it safely and lawfully, and who answers when it goes wrong. In practice it means a register of your AI uses, a policy staff can follow, risk checks before launch, monitoring after launch and a named owner. It is not a document you write once. It is how decisions get made. For an African organisation it also means mapping your duties under local data protection laws and any foreign laws, such as the EU AI Act, that reach you. Sources: [1] [2] [3] [4] [5]

Does Nigeria have an AI law?

Not yet a dedicated one, as far as I can confirm in October 2026. The National Digital Economy and E-Governance Bill, which would give NITDA powers to classify AI systems by risk and require assessments for higher-risk uses, was reported in July 2026 to be at a late stage in the National Assembly; check its current status before relying on it. What already applies is the Nigeria Data Protection Act 2023, including section 37 on automated decisions, and the NDPC's GAID, effective 19 September 2025, which addresses AI and other emerging technologies. Nigeria's National AI Strategy was released in 2025. Sources: [1] [2] [3] [4] [5] [6] [7] [8]

Does the EU AI Act apply to African companies?

It can. Article 2 applies the Act to providers placing AI on the EU market wherever they are based, and to providers and deployers outside the EU where the output of the AI system is used in the EU. A Lagos fintech serving European customers, or a Nairobi firm building AI for an EU client, may be in scope. A Johannesburg retailer using AI only on South African customers probably is not. The bans have applied since February 2025, and the main high-risk duties now apply from December 2027 after the 2026 Digital Omnibus. Get advice on your specific case. Sources: [1] [2] [3] [4] [5]

Where should a small business start with AI governance?

Start with three things you can finish in a month. First, list every AI tool your team uses, including free chatbots and AI features inside software you already pay for. Second, write a one-page acceptable use policy: what tools are allowed, what data must never go into them, and who to ask. Third, name one person as owner. Then look at your riskiest use, usually anything that decides something about a customer or employee, and check it against your data protection law. Frameworks such as ISO/IEC 42001 can come later. Sources: [1] [2] [3]

Who should own AI governance in a company?

One named senior executive should be accountable, with the board overseeing. That person is often the chief risk officer, chief data officer, general counsel or chief operating officer, depending on where AI is used most. Ownership is not the same as doing all the work: a small cross-functional group covering technology, legal and data protection, risk, HR and the business should run it day to day. The mistake I see most often is leaving it entirely to IT. AI risk is a business risk. The people who benefit from a use case should answer for it. Sources: [1] [2]

What is ISO/IEC 42001?

ISO/IEC 42001:2023 is the international standard for an AI management system, published in December 2023 by ISO and IEC. It sets out how an organisation should establish, run, monitor and improve its governance of AI, using the same management system structure as ISO/IEC 27001 for information security. It can be certified by an accredited body. It suits organisations that build or deploy AI at scale, or that sell to customers who ask for evidence. For smaller African firms it is a useful blueprint even if certification is not worth the cost yet. Sources: [1] [2] [3]

What is the AIGP certification?

The AIGP, or Artificial Intelligence Governance Professional, is a certification from the IAPP, the global association for privacy professionals. Its exam launched in 2024. It tests understanding of how AI works, the laws and standards that apply to it, and how to govern AI across its lifecycle. It is aimed at lawyers, privacy, risk, compliance and technology professionals. It is a credential for individuals, not for organisations. I am preparing for it myself because it is one of the few vendor-neutral benchmarks in this field. Sources: [1] [2]

How do I stop staff pasting confidential data into ChatGPT?

You will not stop it with a ban alone; people use what helps them. Give them a safe alternative, such as an enterprise AI account whose terms say your data is not used for training. Write a short rule on what must never go into any AI tool: customer personal data, financial records, passwords, unreleased results. Train people with real examples from your business. Then use your existing data loss prevention and web controls to catch the worst cases. Make it easy to ask, and treat early mistakes as lessons, not dismissals. Sources: [1] [2]

Do I need consent to use customer data in AI?

Not always. Data protection laws in Nigeria, Kenya, South Africa and elsewhere give several lawful bases, of which consent is one. Others include performing a contract, legal obligation and legitimate interests. What matters is whether the AI use fits the purpose you collected the data for, whether you told customers, and whether it is fair. Training a model on customer data, or making significant automated decisions about people, usually needs more care and often an impact assessment. Where you rely on consent, it must be freely given, specific and withdrawable. Sources: [1] [2] [3]

What does an AI policy include?

A good AI policy is short enough to read. It should cover: why the organisation uses AI and its risk appetite; who owns AI governance; which tools are approved and how to request new ones; what data may and may not be used; when AI output must be reviewed by a person; disclosure to customers; prohibited uses; how to report a problem; and training expectations. Keep the detailed procedures, such as risk assessment templates and vendor checklists, in supporting documents so the policy itself stays readable. Sources: [1]

How is AI governance different from data protection?

They overlap but are not the same. Data protection governs personal data: how it is collected, used, shared and kept. AI governance covers the whole AI system, including uses that involve no personal data at all, such as a model that sets prices or writes marketing copy. It also deals with accuracy, safety, bias, security, intellectual property and accountability for outcomes. In Africa, data protection law is currently the main binding rule that touches AI, so your data protection team is a natural partner. They should not carry AI governance alone. Sources: [1] [2]

What is shadow AI?

Shadow AI is AI used at work without the organisation knowing or approving it: a manager drafting a performance review in a free chatbot, an analyst uploading a client spreadsheet to an AI tool, or a marketing team switching on AI features in an ad platform. The risk is data leaving your control, decisions nobody can trace, and errors nobody checks. The answer is visibility, not punishment. Ask people what they use, approve good tools quickly, and make the safe route the easy route. Sources: [1]

How do I assess an AI vendor?

Ask the questions you would ask any critical supplier, plus a few more. What does the system actually do, and what evidence supports its accuracy claims? What data does it need, where is it hosted, and is your data used to train their models? How was it tested for bias and security? Who is responsible when it is wrong? How will they tell you about model changes or incidents? Can you get your data out if you leave? Put the answers in the contract, not just the sales deck. Sources: [1] [2]

What does an AI governance consultant do?

An AI governance consultant helps an organisation use AI with confidence by putting the right structure around it. Typical work includes mapping current AI use, writing an AI policy, setting up a risk assessment process, briefing boards and executives, reviewing vendors, aligning with frameworks such as ISO/IEC 42001 or the NIST AI RMF, and explaining how laws such as the EU AI Act and local data protection acts apply. A good one leaves you able to run it yourselves. A consultant cannot replace legal advice on specific regulatory questions. Sources: [1] [2] [3] [4]

About the author

How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.

By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.