African regulators are confronting a digital economy where AI, cybersecurity, data and platforms increasingly overlap


African ICT regulators are confronting a digital economy that is becoming harder to govern within traditional telecom boundaries.

AI, cybersecurity, digital platforms, cloud infrastructure, data protection, online safety and digital inclusion are now connected policy questions, bringing regulators from across the continent together in Nairobi to compare approaches and work on practical institutional reforms.

The five-day meeting, running from October 5 to 9, is the eighth cohort follow-up phase of the ICT Policy and Regulation – Institutional Strengthening (iPRIS) programme. Regulators from Liberia, Mauritius, Namibia, Sierra Leone, Tanzania and Zimbabwe are participating alongside regional bodies including the Communications Regulators’ Association of Southern Africa (CRASA), East African Communications Organisation (EACO) and West Africa Telecommunications Regulators Assembly (WATRA).

Experts from Sweden, Luxembourg and Portugal are also involved, giving the Nairobi sessions a wider regulatory perspective.

The significance of the meeting extends beyond the issues on its agenda. The regulators are reviewing Change Initiatives, practical institutional projects developed by participating authorities to address specific regulatory priorities in their own countries.

JOIN OUR TECHTRENDS NEWSLETTER

Those initiatives were launched during the cohort’s first gathering in Sweden in May 2026 and have now reached their halfway point. Their final reports are due in May 2027, creating a defined period in which regulators are expected to turn lessons from the programme into changes within their institutions.

Africa’s digital economy is raising the stakes for regulators

The pressure on regulators is coming from the speed and breadth of digital adoption.

GSMA estimates that mobile technologies and services contributed about $240 billion to Africa’s economy in 2025, equivalent to 7.8% of the continent’s GDP, while supporting around 13 million jobs. The figure is projected to rise to about $290 billion by 2030.

That economic contribution gives governments a strong reason to support digital investment, but the same expansion creates regulatory questions that were less prominent when telecom regulation centred mainly on networks, spectrum and conventional voice services.

Digital platforms now provide services across multiple sectors. Cloud infrastructure supports financial services, government systems and businesses. AI can influence lending decisions, customer service, fraud detection and public-sector operations. Cybersecurity risks can spread across networks and institutions, while data generated in one service can be reused by another.

For regulators, that creates an institutional problem as much as a technological one. Rules written for individual sectors can struggle when a single digital system touches telecommunications, finance, data protection, competition and consumer rights at the same time.

David Mugonyi, Director General of the Communications Authority of Kenya, captured the breadth of the challenge at the Nairobi meeting, pointing to competition, consumer protection, cybersecurity, trust, online safety, inclusion and sustainable investment as issues facing regulators across Africa.

The value of regional cooperation, therefore, lies partly in allowing regulators to compare how different institutions are approaching problems that increasingly have cross-border implications.

AI governance is becoming a practical regulatory issue

AI gives this regulatory shift its clearest example.

African governments and businesses are looking at AI for productivity, public services, financial services and other applications, while regulators are having to deal with questions about transparency, accountability, privacy, security and human oversight.

Kenya’s financial sector already offers a practical example. New rules covering non-deposit-taking credit providers require lenders that use AI in credit decisions to address issues including transparency, bias, accuracy, privacy and security, while maintaining appropriate human oversight.

That moves AI governance away from broad discussions about future risks and into everyday regulatory decisions.

The same issue becomes more complicated when AI systems connect to government databases, identity systems, financial platforms or other critical infrastructure. An AI application may be only one component of a larger system, yet its decisions can affect consumers and citizens through services regulated by several different institutions.

This is where the regional cooperation highlighted by iPRIS becomes important. Regulators can compare how different jurisdictions approach automated decisions, accountability and oversight, rather than each institution having to develop responses in isolation.

Cybersecurity is becoming harder to contain

Cybersecurity presents an even broader coordination challenge because digital threats rarely respect institutional or national boundaries.

Kenya’s National KE-CIRT/CC detected more than 3.36 billion cyber threat events between January and March 2026 and issued more than 20.6 million advisories during the period. The scale of these figures needs context: a detected threat event is not the same as a confirmed successful attack or breach. It reflects the volume of suspicious or malicious activity observed across monitored digital infrastructure.

The threat environment is also becoming more sophisticated as attackers use AI and automation to improve phishing, reconnaissance, social engineering and other malicious activity.

That puts pressure on regulators to work alongside cybersecurity agencies, operators and other institutions. Telecommunications regulation alone cannot address the entire threat surface when businesses, government platforms, cloud systems and digital services depend on interconnected infrastructure.

The iPRIS programme is addressing this institutional dimension directly. Cybersecurity is one of the areas covered by the Change Initiatives, while cybersecurity experts are also participating in the Nairobi sessions.

The practical question is therefore how lessons from one jurisdiction can improve another country’s institutional response, particularly where the same threats can affect several markets.

Digital inclusion remains part of the regulatory equation

The expansion of digital infrastructure does not automatically translate into widespread use.

GSMA estimates that nearly one billion Africans, representing about 63% of the population, were not using mobile internet in 2025 despite mobile broadband coverage being available. Affordability, access to suitable devices and digital skills remain important barriers.

That gap complicates the way regulators measure digital progress.

Infrastructure deployment is one measure. Adoption is another. The ability to use digital services productively and safely is another altogether.

Prof. Caroline Wamala Larsson, Director of SPIDER, made this point in Nairobi by stressing that Africa’s digital transformation should also be judged by who can access new technologies, who can use them meaningfully, who benefits from them and who remains excluded.

This matters as governments and companies invest in AI and other advanced digital services. If access to connectivity, devices, skills and affordable services remains uneven, the economic benefits of new technologies will also be unevenly distributed.

Digital inclusion therefore sits alongside AI governance and cybersecurity as a regulatory concern rather than as a separate development issue.

Digital infrastructure is becoming part of the regulatory picture

The changing digital economy is also expanding the infrastructure that regulators have to understand.

Kenya’s technology sector is seeing growing investment interest in data centres, cloud infrastructure and AI computing capacity. At the same time, connectivity providers are expanding alternative forms of broadband access, while network capacity and affordability remain practical concerns.

Data centres are particularly important because they sit underneath many of the services now being discussed by policymakers. Cloud computing, enterprise software, AI workloads, digital financial services and government platforms all depend on physical computing and connectivity infrastructure.

That raises questions around licensing, power availability, data protection, resilience, cybersecurity and investment.

The regulatory challenge is therefore no longer confined to the traditional question of who operates a telecommunications network. It increasingly involves the infrastructure and digital systems built on top of those networks.

Competition and platforms are changing the old regulatory boundaries

Digital platforms create another complication.

A company can operate an application, payment service, logistics network, cloud platform or marketplace while interacting with several different regulatory regimes. Competition concerns can also emerge in markets where traditional telecom operators compete with global technology platforms and cloud providers.

That is one reason competition policy is appearing alongside cybersecurity, consumer protection and AI in discussions among ICT regulators.

African regulators are having to consider whether existing competition frameworks are sufficient for markets shaped by platforms, cloud services, applications and data.

Kenya’s own regulatory experience illustrates the shift. Authorities have been creating or adapting rules for digital businesses that do not fit neatly into older categories, including app-based courier and delivery platforms.

The underlying issue is institutional coordination. A regulator dealing with one part of the digital economy may encounter a problem whose causes or consequences sit within another regulator’s jurisdiction.

Africa also needs the capacity to build its own AI economy

Regulation is only one side of the continent’s AI challenge.

African countries are also trying to build the infrastructure, skills and applications needed to participate in the AI economy. Partnerships involving organisations such as the UNDP and GSMA are placing greater attention on locally developed AI applications, African-language solutions and the computing infrastructure required to support them.

That creates another policy balancing act.

African regulators need to manage the risks associated with AI while also ensuring that regulation does not make it unnecessarily difficult for local companies, researchers and public institutions to develop useful applications.

The infrastructure question is equally important. AI requires computing capacity, reliable electricity, connectivity, data and technical skills. Without those foundations, Africa risks becoming primarily a market for technologies developed elsewhere rather than a place where more of the technology is built and adapted.

This is why AI governance cannot be separated completely from digital infrastructure, competition, skills and inclusion.

The real measure will be what changes inside regulators

The Nairobi iPRIS meeting provides a useful way to judge whether regulatory cooperation can translate into institutional improvements.

The Change Initiatives give participating regulators specific projects against which progress can be assessed. They cover areas such as spectrum management, connectivity, cybersecurity, consumer protection and digital inclusion, with final reports expected in May 2027.

That creates a longer-term measure for the programme.

The value of regulators sharing experiences is ultimately determined by whether those lessons change policies, procedures, institutional capabilities or regulatory outcomes at home.

Africa’s digital economy is already crossing the boundaries that once separated telecommunications from finance, government, cloud computing, data protection and digital platforms. Regulators are responding by building more institutional links across those areas and by comparing approaches with counterparts facing similar pressures.

The Nairobi discussions show that the regulatory challenge is no longer simply keeping rules aligned with new technologies. It is building institutions capable of governing a digital economy in which infrastructure, data, platforms, AI, cybersecurity and access are increasingly part of the same system.

Real ESG impact doesn’t happen in panels alone, it happens in the rooms where financiers, operators, and policymakers actually align. Our GreenShift Forum 2026 cuts the noise, bringing together the people rewiring Africa’s sustainability and energy frameworks for one focused day in Nairobi. Secure your seat.

Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.

Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to info@techtrendsmedia.co.ke

Facebook Comments

By George Kamau

I brunch on consumer tech. Send scoops to george@techtrendsmedia.co.ke
Back to top button
×