Technology Africa’s regulators confront growing AI and cybersecurity challenge
Technology

Africa’s regulators confront growing AI and cybersecurity challenge

African regulators are stepping up cooperation on AI, cybersecurity and digital governance as cyber threats surge and rapid technological change creates new challenges for governments, businesses and consumers across the continent.

Africa’s regulators confront growing AI and cybersecurity challenge
AI showcase room and cybersecurity image

African technology regulators are stepping up efforts to keep pace with rapid advances in artificial intelligence, digital platforms and cybersecurity, as increasingly connected digital systems create risks that can no longer be contained within national borders.

The issue is taking centre stage in Nairobi this week, where regulators from across Africa have gathered for a five-day Policy and Regulation Institutional Strengthening Programme (iPRIS) forum running from October 5 to 9. The meeting brings together representatives from Sierra Leone, Mauritius, Namibia, Zimbabwe, Tanzania and Liberia, alongside regional regulatory organisations and international partners.

The discussions come as African economies become increasingly dependent on digital infrastructure for banking, communications, government services and commerce. Regulators are now being challenged to create rules that encourage innovation while protecting consumers, businesses and critical infrastructure.

Cyber threats are escalating

Kenya’s experience illustrates the scale of the challenge.

Advertisement

Data from the Communications Authority of Kenya shows that the country’s National KE-CIRT/CC detected 3.37 billion cyber-threat events between January and March 2026. Although this represented a 26.1% decline from the previous quarter, the figure remains enormous.

System vulnerabilities accounted for the overwhelming majority of the detected threats, at more than 3.23 billion events. Kenya also recorded millions of malware, brute-force, web-application and distributed-denial-of-service incidents during the quarter.

The authority issued more than 20.5 million cybersecurity advisories during the same three-month period, highlighting the continuing pressure on institutions responsible for defending the country’s digital ecosystem.

For African regulators, the figures underline a broader reality: expanding connectivity creates new opportunities for economic development, but it also creates a larger attack surface for criminals and other malicious actors.

No country can tackle the problem alone

Speaking at the Nairobi forum, Communications Authority of Kenya Director General David Mugonyi warned that cybersecurity threats, digital fraud and attacks on critical communications infrastructure increasingly cross national boundaries.

Africa’s regulators confront growing AI and cybersecurity challenge

A cyberattack launched in one country can affect organisations and consumers elsewhere, while disruption to shared infrastructure such as submarine cables can have consequences across several economies.

That makes cooperation between regulators increasingly important.

The Nairobi programme is designed to give regulators an opportunity to exchange experiences, strengthen institutional capacity and develop coordinated approaches to emerging technology challenges. Participating organisations include regional bodies such as the East African Communications Organisation, the Communications Regulators’ Association of Southern Africa and the West Africa Telecommunications Regulators Assembly.

Advertisement

AI creates a new regulatory dilemma

Artificial intelligence is adding another layer of complexity.

AI systems are already being incorporated into businesses, public services and digital platforms, creating opportunities to improve productivity and access to services. At the same time, regulators must consider questions around privacy, accountability, consumer protection, online safety, discrimination and the use of personal data.

The Nairobi forum is therefore examining AI alongside digital platforms, next-generation networks, cybersecurity, competition, data governance and digital inclusion rather than treating the technology as a separate issue.

That approach reflects the reality of modern digital systems. An AI-powered service can simultaneously involve telecommunications infrastructure, personal data, cloud computing, online platforms and automated decision-making.

For regulators, this means traditional sector-by-sector rules may not always be sufficient.

Balancing innovation with protection

One of the central challenges facing African regulators is finding the right balance between regulation and innovation.

Excessive regulation could make it harder for startups and businesses to experiment with new technologies. But weak oversight could leave consumers exposed to fraud, privacy violations, unsafe products and other forms of digital harm.

Kenya’s Communications Authority says regulators must go beyond simply writing and enforcing rules. They must also enable innovation, promote fair competition, protect consumers and ensure that people are not excluded from the digital economy.

Advertisement

This balance is particularly important in Africa, where digital technologies have often developed faster than traditional regulatory frameworks.

Mobile money is one example. Services such as M-Pesa demonstrated how regulation and innovation can evolve together to expand financial access. The Nairobi iPRIS programme is using Kenya’s mobile-money experience as one of the examples of how regulation can support digital inclusion and innovation.

Building common approaches

The regulators’ meeting also points to a growing recognition that Africa needs stronger regional approaches to digital governance.

Different countries have developed their own laws and institutions, but technology companies, cybercriminals and digital platforms do not necessarily operate according to national boundaries.

Greater cooperation could help regulators share information about cyber threats, develop compatible approaches to data governance, improve cross-border enforcement and respond more effectively when digital incidents affect several countries.

The iPRIS programme is specifically intended to move discussions beyond policy ideas and toward practical regulatory action. Participants are working on institutional “Change Initiatives” designed to translate lessons and policy discussions into concrete measures within their respective countries and organisations.

A race against technological change

The urgency is likely to increase as AI becomes more capable and digital infrastructure expands.

For regulators, the challenge is not simply to understand today’s technology but to anticipate what is coming next. AI agents, automated decision-making, increasingly connected devices and rapidly evolving digital platforms could create regulatory questions that existing laws were never designed to address.

That is why the Nairobi discussions are placing emphasis on regulatory foresight and institutional adaptability. The goal is to ensure that policymakers are not constantly reacting to technological developments after problems emerge.

Africa’s digital transformation is creating enormous economic opportunities, but the benefits will depend partly on whether governments can build sufficient trust and security around the technologies driving that transformation.

The message emerging from Nairobi is clear: AI and cybersecurity are no longer issues that individual regulators can tackle in isolation. As Africa’s digital economy becomes more interconnected, cooperation, shared expertise and adaptable regulation will become increasingly important.

For millions of Africans moving more of their financial, commercial and social lives online, the success of that effort could determine not only how quickly the continent adopts new technology, but also how safely it does so.