How African Governments Are Regulating AI, And Who Is Getting It Right
Two years ago, most African governments treated artificial intelligence as a subject for conference panels rather than policy documents. That has changed quickly. By the middle of 2026, more than half the continent’s countries had either adopted, drafted, or begun consultations on a national AI strategy, according to a recent OECD review of AI governance in Africa. The shift did not happen because African bureaucracies suddenly discovered AI. It happened because the cost of staying silent on data sovereignty, algorithmic risk, and who profits from AI deployed on African soil became too high to ignore.
What is emerging is not a single African approach to AI regulation but several, shaped by each country’s institutional capacity, political priorities, and appetite for early-mover risk. Some governments are legislating. Others are still writing strategy documents with no binding force. A few are trying to do both at once.
Rwanda Set the Pace, and Kept Widening the Lead
Rwanda became the first African country to adopt a comprehensive national AI policy, approved by Cabinet in April 2023 and developed jointly by the Ministry of ICT and Innovation and the Rwanda Utilities Regulatory Authority (RURA). The policy is built around five ethical principles — beneficence, non-maleficence, autonomy, justice, and explicability and, notably, it does not exist in isolation. It is anchored to Rwanda’s 2021 data protection law, giving RURA actual enforcement teeth against AI systems that breach ethical guidelines, rather than leaving the principles as aspirational language.
Rwanda has kept building on that foundation. In 2025 it hosted the Kigali Global AI Summit, which produced the Africa Declaration on Artificial Intelligence, and more recently it approved a National AI Agency, making it the first African country with a standalone institution dedicated to AI governance across the full lifecycle of development, adoption, investment, and oversight. For a country with Rwanda’s modest economic scale, this is a case of institutional sequencing done deliberately: policy, then legal grounding, then a dedicated regulator, in that order.
Nigeria’s Strategy Is Broad. Its Enforcement Is Still Catching Up
Nigeria published its draft National Artificial Intelligence Strategy (NAIS) in August 2024, positioning the country as an aspiring continental leader in AI by 2030. The strategy leans heavily on existing initiatives, the National Centre for Artificial Intelligence and Robotics, the 3MTT talent programme, and AI research grants under NAIRS, and lays out five pillars covering national AI principles, a proposed regulatory body, and a risk-management framework.
Where Nigeria differs from Rwanda is in the gap between strategy and law. The NAIS remains a policy document, not legislation, and as of 2025 the country was still working through the National Artificial Intelligence Commission (Establishment) Bill, which would create a dedicated commission with actual regulatory authority, alongside a separate Digital Sovereignty and Fair Data Compensation Bill addressing who gets paid when Nigerian data trains foreign AI models. Until those bills clear the National Assembly, Nigeria’s AI governance rests on ambition and on adjacent frameworks, chiefly the Nigeria Data Protection Act rather than on AI-specific enforcement power. For a market of Nigeria’s size and startup density, that lag matters more than it would elsewhere, because more AI products are actually being deployed here, on more Nigerian users, before the rules catch up.
The Continental Layer: Ambitious Framework, Uneven Follow-Through
Above the national strategies sits the African Union’s Continental Artificial Intelligence Strategy, adopted by the AU Executive Council in Accra in July 2024. It set five focus areas: harnessing AI’s benefits, building capability, minimising risk, stimulating investment, and fostering cooperation, with an implementation window running to 2030 and an accompanying Africa Artificial Intelligence Fund, reportedly targeting tens of billions of dollars in blended public, private, and philanthropic capital.
The gap between the strategy’s scale and its early execution is stark. Independent tracking of the first eighteen months of implementation found funding heavily concentrated in a handful of countries, with private capital mobilisation still far short of what the continent’s infrastructure needs actually require, per analysis published via ResearchGate. This is the recurring tension in African AI policy: governance frameworks are being written faster than the compute, connectivity, and institutional capacity needed to act on them. A continent that holds roughly one percent of global AI compute capacity, a figure cited at the AU’s own 2025 policy dialogue in Addis Ababa, cannot regulate its way around that constraint. It can only build alongside it.
Kenya, Egypt, and Mauritius: The Early Movers
Mauritius was actually first off the mark on the continent, publishing an AI strategy back in 2018, long before AI regulation was a mainstream policy conversation anywhere. Egypt followed with a national strategy in 2020, later revised into a more ambitious second edition covering 2025 to 2030 under its National Council for Artificial Intelligence. Kenya launched its own National AI Strategy for 2025–2030 in March 2025, after a public consultation process that started the previous year, with a stated focus on closing regulatory and skills gaps while positioning Nairobi’s tech sector for further investment, according to Bowmans’ analysis of the strategy launch.
South Africa, despite having the continent’s most mature AI industry uptake in absolute business terms, has had the roughest path of any country on this list. Its Department of Communications and Digital Technologies published a Draft National AI Policy in the Government Gazette on April 10, 2026, following Cabinet approval, only to withdraw it weeks later after officials discovered the document contained fabricated, AI-generated academic references. Communications Minister Solly Malatsi pulled the policy in late April 2026 and suspended two officials over the episode, according to Reuters. A newly appointed seven-member independent expert panel is now rewriting the text from scratch, with the department targeting Cabinet resubmission by November 2026 and a fresh public comment draft in January 2027. It is an unusually literal illustration of the risks the policy itself is meant to address, an AI governance document undone by unverified AI output in an economy where private-sector AI adoption is already running ahead of most of the continent.
What “Getting It Right” Actually Means Here
Judged purely on ambition, most of these strategies read similarly: economic growth, ethical safeguards, capacity building, international cooperation. The real differentiator is sequencing, whether a country pairs its AI ambitions with an enforcement mechanism, a funded institution, and a data protection law already doing work in the background. Rwanda has managed that sequencing better than most, precisely because it built the smallest, most executable version of the problem first and expanded from there. Nigeria and Kenya have the market size and technical talent to eventually outpace Rwanda’s impact, but only once their legislative processes deliver actual regulatory bodies rather than draft bills sitting in committee.
For now, Africa’s AI governance landscape looks less like a race with a single finish line and more like a set of parallel experiments, each testing how much regulatory ambition a country’s institutions can realistically carry. The strategies that endure will likely be the ones written with that constraint in mind from the start.


