African governments are deploying AI faster than governance frameworks can keep up. Forty-five of 54 nations now have data protection laws, yet AI-specific regulation remains rare, and only around 39 have a functioning regulator. A five-pillar governance model—covering legal basis, data rights, algorithmic accountability, procurement standards, and institutional capacity—provides a practical scaffold for responsible AI deployment without stalling innovation.
In 2023, the Ghanaian government deployed an AI-assisted fraud detection system for the National Health Insurance Authority (NHIA). The system flagged over 14,000 claims as potentially fraudulent in its first month. What the procurement documents did not include: an appeals mechanism, an audit trail accessible to claimants, or an independent review process. Citizens whose claims were denied had no recourse and no explanation.
This is not an unusual story. Across Africa, governments are procuring AI systems—for welfare disbursement, criminal risk scoring, border management, and tax enforcement—from vendors whose models are trained on data from other continents, tested in other legal environments, and optimised for metrics that do not map cleanly to African institutional contexts.
The urgency is real. AI offers genuine benefits for under-resourced public institutions: faster document processing, better fraud detection, improved crop yield forecasting. But without governance frameworks, these deployments create new categories of harm: automated discrimination, unaccountable decision-making, and data practices that violate the rights citizens are entitled to under their own constitutions.
Any AI system that makes decisions about citizens must have a clear legal basis for collecting and processing the data it uses. Ghana's Data Protection Act (Act 843, 2012) establishes this principle, requiring that personal data be collected for specified, explicit, and legitimate purposes. The AI applications built on top of government data must inherit this constraint—yet most procurement specifications do not address it.
The practical fix is straightforward: every AI procurement must include a data processing impact assessment (DPIA) completed before deployment, not after. The DPIA should identify which categories of personal data the system processes, the legal basis for processing, the retention period, and the access controls in place. The National Information Technology Agency (NITA) in Ghana has begun requiring DPIAs for certain categories of government software—this should be extended to all AI systems.
When an AI system makes or influences a decision about a citizen—a loan denial, a benefit rejection, a flag for investigation—that citizen has a right to a meaningful explanation. This is established in Ghana's Data Protection Act and mirrored in South Africa's POPIA and Kenya's Data Protection Act. In practice, "meaningful explanation" is hard to implement with black-box models.
We recommend a tiered approach. High-stakes decisions—those affecting liberty, significant financial outcomes, or access to essential services—should be made by explainable models (logistic regression, decision trees, gradient boosting with SHAP values) or by hybrid systems where a complex model's output is reviewed by an accountable human before action is taken. Medium-stakes decisions require audit logs with feature importance scores. Low-stakes optimisation tasks (routing, scheduling, document classification) can use complex models without per-decision explanations, provided aggregate performance audits occur quarterly.
Government AI procurement in Africa currently has no equivalent to the EU's AI Act requirements or the US NIST AI Risk Management Framework. Tender documents for AI systems routinely omit: model accuracy benchmarks on African data, bias testing across ethnic, regional, and gender dimensions, data localisation requirements, and model update notification procedures.
Nova Create Hub has developed an AI procurement checklist, now adopted by two West African ministries, that adds these requirements to standard tender specifications. The checklist requires vendors to provide: accuracy and fairness metrics tested on local datasets, a model card documenting training data sources and known limitations, a data processing agreement compliant with applicable national law, and a remediation commitment should post-deployment audits reveal discriminatory outcomes. Vendors who cannot provide these should not win public sector AI contracts.
Governance frameworks without institutional capacity to enforce them are decorative. The most common failure mode we observe is not bad policy—it's the absence of people within government who understand enough about AI to identify when a vendor's claims are implausible, when a deployed system is behaving unexpectedly, or when an audit has found a real problem rather than a false positive.
The solution is a modest but sustained investment in AI literacy within government. This does not mean training civil servants to build models. It means equipping ICT teams, procurement officers, and senior policy advisors with enough conceptual knowledge to ask the right questions of vendors and to interpret audit reports accurately. Ghana's NITA, ECOWAS's AI Working Group, and the African Union's Smart Africa initiative all provide frameworks for this investment. The missing element is sustained budget commitment and clear accountability for building this capacity.
Nova Create Hub, 32 Fourth Circular Rd 9, Cantonments, Accra, Ghana. info@novacreatehub.com