The Forum on Internet Freedom in Africa (FIFAfrica26) opened in Mauritius on 28 September and runs to 1 October. CIPESA, the Kampala-based policy group that organises it, describes the 13th edition as a multi-stakeholder gathering of more than 500 policymakers, regulators, journalists, platform operators and law enforcement. It also plans to launch the 2026 State of Internet Freedom in Africa report there. The forum's themes include artificial intelligence and emerging technologies, and the hook for this piece is the question that theme raises: who watches the systems that watch African citizens?
The strongest case for the cameras
Governments adopt AI-enabled surveillance for reasons that are not frivolous. Fast-growing cities have real violent crime, traffic deaths and under-resourced police forces. A vendor that offers command centres, cameras and analytics under one financing package looks like a shortcut to state capacity. Nairobi's system is an example. According to the Africa Center for Strategic Studies, it linked 1,800 high-definition cameras to a command centre supporting 9,000 police officers across 195 stations. If a system measurably cuts robbery or speeds up emergency response, that is a legitimate public benefit, and a blanket ban would be both unrealistic and unwise.
What the evidence says about oversight
The problem is not the existence of the technology. It is the absence of rules around it. CIPESA's 2025 State of Internet Freedom in Africa report studied 14 countries: Cameroon, Egypt, Ethiopia, Ghana, Kenya, Mozambique, Namibia, Nigeria, Rwanda, Senegal, South Africa, Tunisia, Uganda and Zimbabwe. It found that governments are deploying AI-powered surveillance, "which has led to widespread privacy violations and a chilling effect on freedoms." Its most striking structural finding is that none of the 14 has AI-specific legislation. Fragmented rules on data protection, cybercrime and copyright are stretched to cover AI, and CIPESA calls them inadequate.
That gap matters because the oldest deployments predate any serious legal framework. Uganda's police said they spent $126 million on a Huawei CCTV system with facial recognition, according to the Africa Center's account. The same account reports allegations that Ugandan officials used Huawei technology against the encrypted communications of opposition figure Bobi Wine. Those allegations come from an independent investigation the Africa Center cites, and I have not independently confirmed them. They show the risk, though: a tool sold for crime control can be turned on critics when no warrant requirement, audit trail or independent regulator stands in the way.
The continental baseline is thin. The African Union Convention on Cyber Security and Personal Data Protection was adopted on 27 June 2014. The Africa Center's older account says only five member states had ratified it (Namibia, Senegal, Ghana, Guinea and Mauritius) and that about half of African countries lacked data protection laws. That count is dated, and some countries have legislated since. Even so, a decade-old convention that few states have ratified is not an oversight regime for facial recognition or predictive policing.
Why a rights-based framework is also the pro-innovation one
The usual objection from governments and some industry voices is that early AI rules will choke a young sector. That is a fair concern for general-purpose AI development, where Africa's startups need room to build. Surveillance is a different case. It is a state power, not a consumer product, and the people subject to it never agreed to any terms of service.
Three features of the surveillance market also argue for clear rules rather than none.
- Legal uncertainty hurts buyers and builders. A procurement contract signed without a statutory basis can be challenged, suspended or reversed after a change of government. Firms that sell into such a market carry political and reputational risk, and local firms that avoid these contracts lose business to the ones that don't.
- Trust is an input to the digital economy. If citizens believe every platform and every street is monitored, they are less willing to use digital payments, civic platforms and telehealth. Africa's fintech and startup ecosystem depends on that willingness.
- Chilled speech is a measurable cost. CIPESA's finding that unregulated surveillance chills speech and activism is not an abstract worry. It describes people self-censoring in the public sphere where policy debates, including debates about technology, take place.
What proportionate regulation looks like
Proportionate does not mean prohibitive. Four measures would address the main harms without halting deployment.
- Statutory basis and judicial authorisation. Facial recognition and biometric tracking should be authorised by law, limited to defined serious-crime purposes, and require prior judicial approval for targeted use.
- Independent oversight. Existing data protection authorities, where they exist, should have the mandate and budget to audit police and municipal systems. They also need powers to publish findings.
- Procurement transparency. Contracts, financing terms, data-retention rules and vendor access to data should be disclosed, with narrow national-security exceptions reviewed by a legislature or court.
- Impact assessments before rollout. A public rights and accuracy assessment should come before any city-wide deployment, as is standard for other high-risk public infrastructure.
The forum's location is a useful reminder that this is achievable. CIPESA notes that Mauritius combines strong rule of law with technology-driven governance, and it is one of the few states the Africa Center lists as having ratified the AU data protection convention. A small, digitally ambitious democracy is not a bad place to test what balanced governance looks like.
What to watch
CIPESA's 2026 report is due to launch at the forum. I have not seen its contents, so this analysis relies on the 2025 edition. The test is whether it finds any of its countries moving from stretched general laws to specific, enforceable rules on AI surveillance. Without that movement, forums like this one will keep documenting a gap that governments are widening with every procurement cycle. Africa does not need to choose between safer cities and open societies. It needs to write the rules before the cameras are all installed.