Africa’s $2 Billion Surveillance Blind Spot: 11 Governments, AI Policing Systems, and the Laws That Don’t Apply

Eleven African governments collectively spent more than $2 billion on AI-powered surveillance systems built on Huawei and ZTE infrastructure, financed by…
Total
0
Shares
Africa's $2 Billion Surveillance Blind Spot: 11 Governments, AI Policing Systems, and the Laws That Don't Apply
11 min read

Eleven African governments collectively spent more than $2 billion on AI-powered surveillance systems built on Huawei and ZTE infrastructure, financed by Chinese state banks. A March 2026 investigation by Rest of World, produced with support from the Institute of Development Studies and the African Digital Rights Network, found that most of those governments did not have adequate legal frameworks to regulate what they had bought. That finding is accurate. What it understates is why: every African country with a functioning data protection law has written the state a blank exemption to use it.

The regulatory gap on African AI surveillance is not primarily a legislative vacuum. It is an architectural decision. Data protection laws across the continent — Nigeria’s National Data Protection Act, Kenya’s Data Protection Act, South Africa’s POPIA, Uganda’s Data Protection and Privacy Act — all include national security carve-outs broad enough to exempt the vast majority of government surveillance activity from their scope. The laws exist. They simply do not apply.

This is the distinction that matters for business intelligence and rights analysis. The question for each of the eleven countries is not merely “does a data protection law exist?” It is: “does that law have any reach into government surveillance operations?” In most cases, the honest answer is no.

The Exemption That Swallows the Rule

Data protection legislation across Africa follows a broadly consistent design: individual rights protections, accountability obligations on data controllers, and — almost universally — a national security exemption. These exemptions are modelled on similar provisions in the GDPR and in pre-GDPR European data protection law. In the European context, they are partially constrained by constitutional rights frameworks, independent oversight bodies with genuine enforcement powers, and parliamentary accountability mechanisms. In most African contexts, those constraints are absent.

Nigeria’s National Data Protection Act 2023, which replaced the NDPR and represents Africa’s most comprehensive data protection statute to date, explicitly excludes processing carried out for national security and defence purposes from its scope. The exclusion applies to NITDA’s enforcement powers as well as to individual rights of access and objection. A Nigerian surveillance system capturing biometric data on citizens exercising their rights to assembly, provided it is framed as a national security operation, falls outside the NDPA entirely.

Kenya’s Data Protection Act 2019 contains an exemption under Section 54 for processing necessary for national security, prevention of crime, and apprehension or prosecution of offenders. The Office of the Data Protection Commissioner, which has become one of the continent’s more active enforcement bodies, has no jurisdiction over surveillance conducted under that exemption. Ethiopia has no data protection law at all — and its telecommunications infrastructure, largely built and maintained by Chinese vendors, has been reported by digital rights organisations as subject to direct government interception capability.

The practical consequence is a legislative architecture that gives citizens data rights in one hand and removes them in the other. The laws that digital rights advocates point to as evidence of a maturing African data governance landscape are, for the specific question of state AI surveillance, largely inoperative.

Country Regulatory Matrix

The eleven countries identified in the Rest of World investigation represent a cross-section of the continent’s regulatory development. The matrix below maps the operative legal framework against surveillance-specific governance capacity for the countries where detail is available.

Country Est. Surveillance Spend Data Protection Law State Surveillance Coverage Independent Oversight Body AI-Specific Law
Nigeria ~$470M NDPA 2023 (in force) Excluded — national security exemption None for surveillance; NITDA enforces commercial only National Digital Economy & E-Governance Act signed into law March 2026 — Africa’s first binding AI statute; does not cover government surveillance
Kenya Undisclosed DPA 2019 (in force) Excluded — Section 54 security carve-out ODPC has no surveillance mandate AI Bill 2026 proposed; no surveillance provisions
South Africa Undisclosed POPIA 2021 (in force) Partial — POPIA Section 37 state exemption; Inspector-General of Intelligence exists but limited Inspector-General of Intelligence (weak mandate) Draft National AI Policy under consultation; no surveillance provisions
Uganda Undisclosed Data Protection and Privacy Act 2019 Excluded — national security exemption; CCTV networks documented by CIPESA None None
Tanzania Undisclosed No comprehensive DPA; Electronic Communications Act only No coverage None None
Ethiopia Undisclosed None No coverage None; state controls telecoms None
Egypt Undisclosed Law 151/2020 on Personal Data Protection Excluded — broad national security exemption; limited enforcement history None for surveillance AI Strategy 2022 (non-binding)
Zambia Undisclosed Data Protection Act 2021 Excluded — national security exemption None None
Zimbabwe Undisclosed Cyber and Data Protection Act 2021 Excluded — national security and law enforcement exemptions None with surveillance mandate None

The pattern is consistent enough to constitute a design principle rather than a coincidence. Across every country with a functioning data protection law, the state has preserved its operational freedom through blanket exemptions. South Africa comes closest to an exception, with the Inspector-General of Intelligence holding some oversight mandate over intelligence service activities — but that body’s capacity, independence, and interest in AI-specific surveillance governance has not been tested.

The Audit Vacuum

Data protection law aside, a functioning surveillance governance architecture typically requires a second institutional layer: an independent body with technical competence to audit government surveillance systems and verify that they are being used within authorised parameters. In Europe and North America, this function is performed — imperfectly but meaningfully — by parliamentary intelligence committees, independent technical inspectors, and judicial warrant systems.

Across the eleven countries in question, this institutional layer is absent. CIPESA — the Collaboration on International ICT Policy for East and Southern Africa — has documented the rapid expansion of CCTV networks and biometric data collection systems in Uganda, Tanzania, and Zimbabwe, and has consistently found no independent technical auditing capacity for those systems. Nigeria’s NCC regulates telecommunications operators and has issued guidance on lawful interception, but NCC’s mandate does not extend to auditing how intelligence agencies use the data they intercept. Kenya’s ODPC is building enforcement capacity against commercial actors; it has no mandate over government surveillance systems.

The absence of audit capacity creates a specific governance risk that is distinct from the absence of law. Even where national security exemptions are narrowly defined and time-limited in statute, the practical ability of governments to exceed authorised parameters — to use systems purchased for counter-terrorism purposes to monitor political opponents, journalists, and civil society — depends on whether anyone is checking. Currently, no one is.

This is where the investment pattern documented by the Rest of World investigation becomes most consequential. AI-powered surveillance systems — facial recognition networks, predictive policing platforms, social media monitoring tools — are significantly harder to audit than legacy surveillance infrastructure. Their outputs are probabilistic and non-transparent by design. Auditing them requires technical expertise that most African parliamentary oversight bodies do not have and that no African intelligence inspector currently possesses.

The Human Rights Dimension

The CIPESA report that informed the Rest of World investigation documents specific targeting: journalists covering political opposition, civil society organisations monitoring electoral processes, human rights defenders working on land rights and extractives accountability. These are not hypothetical harms. The African Commission on Human and Peoples’ Rights has received communications from at least four African countries alleging unlawful surveillance of civil society actors using Chinese-supplied technology, according to submissions published on the Commission’s case register.

The regulatory gap compounds the harm. A journalist in Nigeria whose communications have been intercepted under national security authority has no access to the NDPA’s individual rights provisions — she cannot request disclosure, cannot object to the processing, and cannot invoke the law’s accuracy principles to challenge what her surveillance record shows. The law that would protect her in every other context explicitly excludes the context in which she faces the greatest risk.

Paradigm Initiative, which has been tracking digital rights enforcement across West Africa, has documented three categories of chilling effect attributable to visible surveillance infrastructure: reduced willingness to attend political meetings, reduced secure communications usage (paradoxically increasing exposure), and self-censorship among journalists covering security topics. The investment in AI surveillance infrastructure has governance consequences beyond the direct targeting of individuals.

Where Continental Governance Fails

The African Union’s Data Policy Framework, adopted in 2022, and the AU’s AI Policy Framework, finalised in 2024 with Google partnership, both position data protection as the foundation for AI governance across the continent. Neither framework specifically addresses state AI surveillance. The AU Convention on Cyber Security and Personal Data Protection — the Malabo Convention, adopted in 2014 — has been ratified by only 15 of 55 AU member states and contains its own national security exemption for member state discretion.

The AU Digital Transformation Strategy 2020–2030 includes commitments to “people-centred” digital governance and references human rights principles, but its surveillance governance provisions are hortatory rather than binding. There is currently no AU instrument that requires member states to maintain independent oversight of government AI systems, establish parliamentary accountability for surveillance procurement, or audit AI surveillance platforms against proportionality standards.

Smart Africa, the AU-affiliated alliance that coordinates digital infrastructure development across 35 member states, has focused its AI work on economic opportunity, skills development, and infrastructure access. Surveillance governance has not featured in its published workplans.

The gap at continental level is not accidental. Surveillance is a state prerogative that most African governments — and most governments globally — have been unwilling to subject to supranational oversight. The EU’s General Data Protection Regulation excludes national security from its scope on the same logic. The difference is that European member states have national-level constitutional oversight mechanisms, independent intelligence inspectors, and functioning parliamentary committees with security clearances. The institutional infrastructure that compensates for the continental governance gap in Europe does not exist in most African contexts.

What Adequate Reform Would Require

The regulatory architecture adequate for governing AI surveillance differs from standard data protection law in three ways, and reform initiatives that do not address all three are unlikely to produce meaningful accountability.

First, targeted surveillance legislation rather than reliance on data protection law. Several jurisdictions — including the United Kingdom’s Investigatory Powers Act and South Africa’s Regulation of Interception of Communications Act — have enacted dedicated surveillance laws that govern how government bodies may use communications interception and related technologies. These laws can be designed with AI-specific provisions: requirements that AI surveillance tools be subject to procurement review before deployment, that their accuracy rates be independently tested, that their use be recorded in a manner that enables after-the-fact auditing, and that proportionality standards be applied before deployment in any category of case.

Second, independent technical audit capacity. Parliamentary oversight of AI surveillance requires technical competence. Most African parliamentary intelligence committees lack staff with the expertise to evaluate an AI surveillance system’s accuracy rates, bias characteristics, or architectural security. Building that capacity — through secondments, partnerships with academic institutions, or dedicated specialist offices — is a precondition for meaningful oversight, not a luxury after laws are passed.

Third, removal of blanket national security exemptions from data protection law, replaced with narrowly-defined, time-limited, judicially-supervised carve-outs. The current model — in which governments can exempt any surveillance activity from data protection requirements by labelling it a national security function — is not a workable governance architecture. It is the absence of governance. The GDPR’s national security exemption is constrained by EU constitutional rights principles, the European Court of Human Rights, and national courts. Most African constitutional courts have not yet developed the jurisprudence to impose equivalent constraints, making the statutory reform more — not less — urgent.

Nigeria’s National Digital Economy and E-Governance Act — signed into law by President Tinubu in March 2026, making Nigeria the first African country with binding AI legislation — will not govern government surveillance. Kenya’s proposed AI Commissioner will have significant enforcement powers over private sector AI deployment. The bill as currently drafted does not establish any surveillance oversight mechanism. South Africa’s multi-regulator AI governance model will distribute AI oversight across sector regulators, but no regulator in that model has a surveillance mandate.

The continent is building AI governance architecture. It is building it around commercial AI risk. The $2 billion already spent on government surveillance infrastructure, and the political will required to hold that spending accountable, requires a different conversation — one that African legislatures have not yet been willing to have.

— Policy & Regulation Desk, BETAR.africa

You May Also Like