Plain frameworks, honest questions and working tools for boards, founders and marketers who want to use AI well and be able to show it. Built for the laws and markets we actually operate in.
As of October 2026, almost no African country has a dedicated, binding AI law. Bills are moving in Nigeria and Kenya, and Morocco has a draft framework law, but none has yet been confirmed as enacted. In practice, data protection law does most of the work, especially the rules on automated decisions, registration with the regulator and cross-border transfers, while national AI strategies and policies are multiplying fast under the African Union's 2024 Continental AI Strategy.
See the country-by-country picture (22 countries, as of October 2026).
AI governance is the set of rules, roles and routines an organisation uses to decide which AI to use, how to use it safely and lawfully, and who answers when it goes wrong. In practice it means a register of your AI uses, a policy staff can follow, risk checks before launch, monitoring after launch and a named owner. It is not a document you write once. It is how decisions get made. For an African organisation it also means mapping your duties under local data protection laws and any foreign laws, such as the EU AI Act, that reach you. Sources: [1] [2] [3] [4] [5]
Not yet a dedicated one, as far as I can confirm in October 2026. The National Digital Economy and E-Governance Bill, which would give NITDA powers to classify AI systems by risk and require assessments for higher-risk uses, was reported in July 2026 to be at a late stage in the National Assembly; check its current status before relying on it. What already applies is the Nigeria Data Protection Act 2023, including section 37 on automated decisions, and the NDPC's GAID, effective 19 September 2025, which addresses AI and other emerging technologies. Nigeria's National AI Strategy was released in 2025. Sources: [1] [2] [3] [4] [5] [6] [7] [8]
It can. Article 2 applies the Act to providers placing AI on the EU market wherever they are based, and to providers and deployers outside the EU where the output of the AI system is used in the EU. A Lagos fintech serving European customers, or a Nairobi firm building AI for an EU client, may be in scope. A Johannesburg retailer using AI only on South African customers probably is not. The bans have applied since February 2025, and the main high-risk duties now apply from December 2027 after the 2026 Digital Omnibus. Get advice on your specific case. Sources: [1] [2] [3] [4] [5]
Start with three things you can finish in a month. First, list every AI tool your team uses, including free chatbots and AI features inside software you already pay for. Second, write a one-page acceptable use policy: what tools are allowed, what data must never go into them, and who to ask. Third, name one person as owner. Then look at your riskiest use, usually anything that decides something about a customer or employee, and check it against your data protection law. Frameworks such as ISO/IEC 42001 can come later. Sources: [1] [2] [3]
One named senior executive should be accountable, with the board overseeing. That person is often the chief risk officer, chief data officer, general counsel or chief operating officer, depending on where AI is used most. Ownership is not the same as doing all the work: a small cross-functional group covering technology, legal and data protection, risk, HR and the business should run it day to day. The mistake I see most often is leaving it entirely to IT. AI risk is a business risk. The people who benefit from a use case should answer for it. Sources: [1] [2]
ISO/IEC 42001:2023 is the international standard for an AI management system, published in December 2023 by ISO and IEC. It sets out how an organisation should establish, run, monitor and improve its governance of AI, using the same management system structure as ISO/IEC 27001 for information security. It can be certified by an accredited body. It suits organisations that build or deploy AI at scale, or that sell to customers who ask for evidence. For smaller African firms it is a useful blueprint even if certification is not worth the cost yet. Sources: [1] [2] [3]
The AIGP, or Artificial Intelligence Governance Professional, is a certification from the IAPP, the global association for privacy professionals. Its exam launched in 2024. It tests understanding of how AI works, the laws and standards that apply to it, and how to govern AI across its lifecycle. It is aimed at lawyers, privacy, risk, compliance and technology professionals. It is a credential for individuals, not for organisations. I am preparing for it myself because it is one of the few vendor-neutral benchmarks in this field. Sources: [1] [2]
You will not stop it with a ban alone; people use what helps them. Give them a safe alternative, such as an enterprise AI account whose terms say your data is not used for training. Write a short rule on what must never go into any AI tool: customer personal data, financial records, passwords, unreleased results. Train people with real examples from your business. Then use your existing data loss prevention and web controls to catch the worst cases. Make it easy to ask, and treat early mistakes as lessons, not dismissals. Sources: [1] [2]
Not always. Data protection laws in Nigeria, Kenya, South Africa and elsewhere give several lawful bases, of which consent is one. Others include performing a contract, legal obligation and legitimate interests. What matters is whether the AI use fits the purpose you collected the data for, whether you told customers, and whether it is fair. Training a model on customer data, or making significant automated decisions about people, usually needs more care and often an impact assessment. Where you rely on consent, it must be freely given, specific and withdrawable. Sources: [1] [2] [3]
A good AI policy is short enough to read. It should cover: why the organisation uses AI and its risk appetite; who owns AI governance; which tools are approved and how to request new ones; what data may and may not be used; when AI output must be reviewed by a person; disclosure to customers; prohibited uses; how to report a problem; and training expectations. Keep the detailed procedures, such as risk assessment templates and vendor checklists, in supporting documents so the policy itself stays readable. Sources: [1]
They overlap but are not the same. Data protection governs personal data: how it is collected, used, shared and kept. AI governance covers the whole AI system, including uses that involve no personal data at all, such as a model that sets prices or writes marketing copy. It also deals with accuracy, safety, bias, security, intellectual property and accountability for outcomes. In Africa, data protection law is currently the main binding rule that touches AI, so your data protection team is a natural partner. They should not carry AI governance alone. Sources: [1] [2]
Shadow AI is AI used at work without the organisation knowing or approving it: a manager drafting a performance review in a free chatbot, an analyst uploading a client spreadsheet to an AI tool, or a marketing team switching on AI features in an ad platform. The risk is data leaving your control, decisions nobody can trace, and errors nobody checks. The answer is visibility, not punishment. Ask people what they use, approve good tools quickly, and make the safe route the easy route. Sources: [1]
Ask the questions you would ask any critical supplier, plus a few more. What does the system actually do, and what evidence supports its accuracy claims? What data does it need, where is it hosted, and is your data used to train their models? How was it tested for bias and security? Who is responsible when it is wrong? How will they tell you about model changes or incidents? Can you get your data out if you leave? Put the answers in the contract, not just the sales deck. Sources: [1] [2]
An AI governance consultant helps an organisation use AI with confidence by putting the right structure around it. Typical work includes mapping current AI use, writing an AI policy, setting up a risk assessment process, briefing boards and executives, reviewing vendors, aligning with frameworks such as ISO/IEC 42001 or the NIST AI RMF, and explaining how laws such as the EU AI Act and local data protection acts apply. A good one leaves you able to run it yourselves. A consultant cannot replace legal advice on specific regulatory questions. Sources: [1] [2] [3] [4]
How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.
By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.