Ideas on AI Governance in Africa | Stanislaus Martins

Short, practical thoughts on governing AI in African organisations: what works, what does not, and the questions leaders should be asking.

AI governance in Africa · Frameworks · Laws and policy by country · Questions to ask · Glossary · Ideas and quotes · Free AI governance tools · Work with Stanislaus

Africa should not copy and paste the EU AI Act

Learn from Brussels, by all means. Just do not hand over the pen.

Every few months someone asks me whether Nigeria, Kenya or South Africa should simply adopt the EU AI Act. I understand the appeal. It is detailed, it exists, and it will shape how global vendors build their products. But a law written for a market of mature regulators, deep courts and well-funded compliance teams will not land the same way in Lagos or Kigali.

Start with capacity. A law is only as good as the agency that enforces it. If we import obligations that our regulators cannot supervise, we get the worst of both worlds: heavy paperwork for honest firms and little real protection for citizens. Rules that cannot be enforced quietly teach everyone that rules do not matter, and that lesson is very hard to unlearn once it has spread.

Then there are our priorities. The African Union's Continental AI Strategy, endorsed in July 2024, puts development, skills and inclusion alongside risk. That is right for us. Our biggest AI risks include being left out of the benefits altogether, models that do not understand our languages, and data about Africans flowing out of the continent without value flowing back to the people it describes.

None of this means ignoring the EU. Its risk-based logic is sound, and any African firm that sells into Europe, or whose AI outputs are used there, should take it seriously. My argument is narrower. Borrow the principles, adapt the mechanics to our institutions, build on the data protection laws we already have, and write rules that our regulators and courts can actually run.

Sources: [1] [2] [3] [4]

Shadow AI is already in your organisation

The question is not whether your people use AI. It is whether you know how.

Walk through any office in Lagos, Nairobi or Johannesburg and you will find people using AI. A finance analyst summarising a board pack in a free chatbot. A sales lead drafting proposals. A customer service agent pasting a complaint, account number included, into a tool to get a polite reply. Most of them are not being careless. They are trying to do good work faster.

The risk is not the tool. It is the blind spot. Confidential plans, customer data and source code can end up with a provider whose terms nobody has read. Outputs that sound right but are wrong find their way into reports and decisions. And when something goes wrong, nobody can say what happened, because nobody in authority knew it was happening in the first place.

Banning AI rarely works. People switch to their phones and the blind spot grows. What works is simpler. Give staff an approved tool with sensible data terms. Tell them in plain words what must never go into a public tool. Ask them, without blame, what they already use. You will learn more in a week of honest conversations than in a month of policy drafting.

Treat shadow AI as a signal, not a crime. It shows you exactly where your people see value, which is useful information for any leader planning an AI strategy. Your job is to bring that energy into the light, give it an approved home, put sensible guardrails around it, and then let the organisation go faster with confidence rather than in secret.

Sources: [1]

Governance is a growth tool, not a brake

Good brakes are what let you drive fast.

Many executives hear the word governance and picture a committee that says no. I understand why. Too much of what passes for governance is slow, defensive and written mainly to protect the organisation from its own people. It produces long documents, longer meetings and very few better decisions. That kind of governance has earned its bad name, and I have no wish to defend it.

Done well, governance does the opposite. When teams know the rules, which uses are green, which need review and who decides, they stop waiting for permission that nobody knows how to give. Approval gets faster and more consistent. Pilots move into production because someone has already answered the questions that a regulator, a partner or a large corporate customer will eventually ask.

This matters commercially. Large companies, banks and public bodies are starting to add AI questions to their supplier due diligence, asking how a vendor governs AI before they sign. Take an illustrative example: a Nairobi fintech that can show an AI inventory, a risk triage and a human review process for credit decisions looks like a safer partner than one that cannot. That is a sales advantage, not a cost centre.

So measure governance like a growth function. How long does it take a good idea to get approved? How many pilots reached real customers? How many deals did our governance answers help close? If governance only ever slows things down, it is badly designed, and the right response is to fix the design. Dropping the governance altogether simply moves the risk somewhere you cannot see it.

Sources: [1] [2]

Data protection law already governs most of the AI you use

You do not need to wait for an AI Act. You already have homework.

I often hear leaders say they will deal with AI governance once their country passes an AI law. That is a mistake. Much of the AI that organisations use processes personal data, and where it does, data protection law already applies. Nigeria has the Data Protection Act 2023. Kenya has its Data Protection Act 2019. South Africa has POPIA. Ghana, Rwanda and Egypt have their own laws too.

These laws already reach into AI. Nigeria's Act, Kenya's Act and South Africa's POPIA each contain rules on decisions based solely on automated processing that significantly affect people. Nigeria's Act requires a data protection impact assessment where processing is likely to result in high risk to people's rights and freedoms. Purpose limitation, data minimisation and security apply whether a human or a model does the processing.

That gives you a practical starting point. Your Data Protection Officer, your records of processing and your impact assessment process are the foundations of AI governance. Extend them rather than replacing them. Add questions about model behaviour, bias, accuracy and human oversight to the assessments you already run, instead of building a parallel bureaucracy that competes with the one you have for attention and budget.

When dedicated AI laws arrive, and several African countries are discussing them, organisations that took data protection seriously will find they are most of the way there. They will already have inventories, assessments and accountable owners. Those that waited for an AI-specific law may discover that they were already falling short of the law they had all along, with the reputational cost that brings.

Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17]

Boards ask the wrong first question

Not 'what is our AI strategy?' but 'what AI are we already accountable for?'

When AI comes up in a boardroom, the first question is usually some version of: what is our AI strategy? It is a reasonable question, and it tends to produce a polished presentation full of opportunities. It rarely produces what directors most need, which is a clear and honest view of what the organisation is already doing with AI and what could go wrong.

The better first question is this: what AI are we already accountable for? It forces an inventory. It surfaces the vendor tools with AI switched on, the chatbot marketing launched last quarter, the scoring model quietly running in collections. It turns AI from a future topic into a present responsibility, which is exactly where a board's duty of oversight actually sits.

The follow-up questions then write themselves. Who owns each use? Which ones affect customers' money, jobs or access to services? How would we know if one was failing? What would we tell a regulator or a journalist who asked? None of these questions require technical expertise. They require the same discipline directors already apply to credit risk, fraud or cybersecurity.

Strategy still matters, of course. But a strategy built on an honest picture of today is far stronger than one built on slides about tomorrow. Ask about accountability first and the strategy conversation gets sharper, because everyone in the room now knows what the organisation is really working with, where the gaps are and what needs fixing before anything is scaled.

Marketing is where AI risk meets the public first

Your customers will judge your AI by your chatbot and your ads, not your policy.

I have spent my career in marketing and advertising, so let me say this plainly: marketing is where most organisations' AI meets the public first. Not the risk model in the back office. The chatbot on WhatsApp, the personalised offer, the AI-generated video in a campaign. If something goes wrong there, everyone sees it at once, and screenshots travel much faster than corrections.

The risks are specific. A chatbot that invents a refund policy. Synthetic presenters that viewers believe are real people. Targeting that pushes high-cost credit at people already in trouble. Customer data reused for profiling it was never collected for. Each of these is a trust problem, and several are legal problems under data protection rules on direct marketing and profiling.

Yet marketing teams are often the last to be invited into governance discussions and the first to adopt new AI tools. That gap needs closing. The people who know the customer, the brand and the channels need to sit at the same table as legal, data protection and technology. Each group sees risks the others miss, and the customer experiences all of them together.

My advice to marketers is simple. Disclose when people are talking to a machine. Check every claim that AI writes before it goes out. Know exactly where your audience data came from and what it was collected for. Always offer a route to a human. Do those four things well, consistently, and you will be ahead of most of the market.

Sources: [1] [2] [3] [4] [5] [6] [7] [8] [9]

Language and local context are governance issues

A model that does not understand your customers cannot treat them fairly.

Much of the AI on offer to African organisations was built mainly on English and other widely written languages, and on data from other markets. That shows up in practice. Try asking a general-purpose assistant the same customer question in English, Pidgin, Hausa, Swahili or isiZulu and compare the answers side by side. The difference is often obvious, even to a non-specialist.

This is not only a product quality issue. It is a fairness issue. If a support bot handles English well and Yoruba poorly, customers who are more comfortable in Yoruba get a worse service. If a screening tool misreads local names, addresses or school histories, some applicants are quietly disadvantaged. Nobody intended it, but for the people affected the outcome is exactly the same.

Governance should ask about language and context directly, not leave them to chance. Which languages will our customers actually use? Has the system been tested in them, with real local examples rather than translated test sets? Does it understand local formats, names, currencies and public holidays? And who in our team can judge whether the outputs make sense to the people receiving them?

There is opportunity here too. African organisations that invest in testing and adapting AI for local languages and contexts will serve their customers better than competitors who simply plug in a global default and hope. They will also build skills and data that are hard to copy. On this question, good governance and good business point firmly in the same direction.

Sources: [1] [2]

Procurement is the governance most companies forget

You will buy far more AI than you build. Govern the purchase.

Most African organisations will never train a large model of their own. They will buy AI instead: in their CRM, their HR software, their ad platforms, their call centre tools. Often the AI arrives as a feature switched on in an update nobody read. That makes procurement one of the most important points of control in any organisation, and one of the most neglected.

Ask vendors the right questions before you sign. What does the AI do, and what data does it use? Is our data used to train your models, and can we opt out? Where is the data processed and stored, and how do cross-border transfers comply with our law? What testing have you done for accuracy and bias, and in which languages? How will you tell us when the model changes?

Then put the answers in the contract. Limits on how the vendor may use your data, notice of material model changes, audit and information rights, incident reporting, and support for your own data protection obligations. A good vendor will welcome these questions because they signal a serious customer. A vendor who cannot answer them has told you something important about the risk you would be taking on.

Finally, check the contracts you already have. Many organisations are running AI they never consciously chose. Take an illustrative example: a Johannesburg retailer reviews its software suppliers and finds AI features active in several tools that were bought before anyone was asking about AI. A one-off review like that is cheap and quick. Discovering the same thing after a customer complaint is not.

Sources: [1] [2] [3] [4]

Quotes

  • "You cannot govern the AI you cannot see. Start with the inventory, not the policy." Stanislaus Martins
  • "Accountability does not transfer to an algorithm. Someone signed off. Find out who." Stanislaus Martins
  • "Good governance is what lets you say yes faster." Stanislaus Martins
  • "Africa should borrow principles from Brussels, not paperwork." Stanislaus Martins
  • "Your customers will judge your AI by your chatbot, not your ethics statement." Stanislaus Martins
  • "If a human cannot overrule it, a human should not be blamed for it." Stanislaus Martins
  • "Most AI governance in Africa starts with the data protection law we already have." Stanislaus Martins
  • "Banning AI at work does not stop its use. It just stops you seeing it." Stanislaus Martins
  • "A policy nobody reads is not governance. It is decoration." Stanislaus Martins
  • "The board's first AI question should be what we are already accountable for." Stanislaus Martins
  • "Trust is earned in small moments: a clear disclosure, an honest answer, a quick route to a human." Stanislaus Martins
  • "You will buy more AI than you build. Govern the purchase order." Stanislaus Martins
  • "If your AI does not understand your customers' language, it cannot treat them fairly." Stanislaus Martins
  • "Speed without governance is just risk you have not met yet." Stanislaus Martins
  • "Every AI system needs a name next to it, and that name should belong to a person." Stanislaus Martins
  • "Rules our regulators cannot enforce teach everyone that rules do not matter." Stanislaus Martins
  • "The question is not whether AI is risky. It is whether your use of it is." Stanislaus Martins
  • "Marketing is where AI risk meets the public first, and screenshots last forever." Stanislaus Martins
  • "Governance should be measured by decisions improved, not documents produced." Stanislaus Martins
  • "An AI that cannot say 'I do not know' needs a human who can." Stanislaus Martins
  • "Shadow AI is a signal of value. Bring it into the light, then put guardrails around it." Stanislaus Martins
  • "Africa's biggest AI risk may be exclusion from the benefits, not only harm from the tools." Stanislaus Martins
  • "Before you automate a decision, ask who carries the cost when it is wrong." Stanislaus Martins
  • "A vendor who cannot answer your AI questions has already answered one." Stanislaus Martins
  • "Leadership in AI is not knowing the technology best. It is owning the consequences." Stanislaus Martins
  • "Check the claim, label the synthetic, offer the human. That is most of responsible marketing." Stanislaus Martins
  • "Governance that only ever says no will be routed around." Stanislaus Martins
  • "Data about Africans should create value for Africans." Stanislaus Martins
  • "The best time to set AI rules was before the pilot. The second best is before the launch." Stanislaus Martins
  • "Responsible AI is not a department. It is how every department decides." Stanislaus Martins

One-liners

  • No inventory, no governance.
  • Every AI system needs an owner with a name.
  • Governance done well is a growth tool.
  • Shadow AI is already in your building.
  • Your data protection law already covers most of your AI.
  • Borrow principles. Adapt mechanics. Enforce what you write.
  • Tell people when they are talking to a machine.
  • Check every claim your AI writes.
  • Always offer a route to a human.
  • You buy more AI than you build. Govern procurement.
  • Read the vendor's data terms before your staff paste anything.
  • Test your chatbot in the languages your customers speak.
  • A policy nobody follows is not a control.
  • Automate the task, not the accountability.
  • Boards: ask what AI you are already accountable for.
  • Banning AI just moves it to personal phones.
  • Fast approvals come from clear rules.
  • Red lines first. Use cases second.
  • If you cannot undo it, slow it down.
  • Trust is the real product in customer-facing AI.
  • Synthetic people in ads need a label.
  • Profiling for marketing needs a lawful basis.
  • Governance is a habit, not a launch event.
  • The DPO belongs in every AI conversation.
  • Measure governance by decisions improved.
  • Know where your audience data came from.
  • African context is not an edge case.
  • Human review only counts if humans can say no.
  • Ninety days is enough to start properly.
  • Govern the use, not just the model.

How this page was made. Parts of these pages were drafted and researched with the help of AI tools, then reviewed and checked against the sources linked beside each claim. AI can get things wrong and laws change, so treat this as general information, not legal advice: the linked sources are the authority, and you should take qualified advice before relying on anything here. Spotted an error? Tell me and I will fix it. Last checked 7 October 2026. See the terms.

By Stanislaus Martins. Stanislaus Martins is Managing Director, Sub-Saharan Africa at Aleph, the digital advertising group, with teams in Lagos, Nairobi, Johannesburg and Cape Town. He has spent over two decades in marketing, digital business and technology across Sub-Saharan Africa, including roles as Head of Digital Business at Insight Publicis, VP of Growth Marketing and Advertising at Jumia Nigeria, and Agency Partner for Sub-Saharan Africa at Meta. He holds an MBA, is a Fellow of the Chartered Institute of Marketing (UK) and of NIMN, and is Immediate Past President of ADMARP. He has completed the AI Governance online course from Saïd Business School, University of Oxford, and Google Cloud's Gen AI: Beyond the Chatbot course, and is preparing for the IAPP AIGP certification. He runs the AI in Nigeria 2026 survey. He helps organisations put AI to work with clear ownership, sensible risk controls and evidence they can show customers, regulators and boards.